Hardware wallets compared: criteria, devices, incidents
BitBox, Trezor, Jade, COLDCARD, Ledger and SeedSigner compared: open code, security chip, air gap, display, prices – and every major incident.
In short~47 sec
- 01All good hardware wallets keep the keys offline and sign payments inside the device. They differ in how they secure this.
- 02Four criteria help you compare: open-source code, a security chip, an air gap and an easy-to-read display – plus whether you store only bitcoin.
- 03Many incidents were data leaks and phishing at shops and service providers; there were also flaws in firmware and chips – including at manufacturers we earn from. The COLDCARD bug in 2026 led to stolen funds.
- 04More important than the model: buy from the manufacturer, keep the backup safe and check every address on the device.
- 05We receive a commission on purchases made via links marked as ads (with *) – which manufacturers that currently applies to is listed under ‘How we earn money’. We present all manufacturers by the same standards.
Good to read firstBacking up your seed phraseFirst withdrawal
A few criteria decide which hardware wallet fits your needs – and so does how openly a manufacturer deals with its flaws. This comparison covers both for six widely used device families. You don’t need any technical background: we explain each technical term where it first comes up.
What all good devices have in common
A hardware walletGlossaryHardware walletA small dedicated device that keeps your private keys offline and signs transactions internally. The key never leaves the device, so malware on your computer can’t get at it.In the glossary → generates your keys itself, keeps them offline and signs payments internally. You check addresses and amounts on its own display. Everything is backed up with a seed phraseGlossarySeed phrase (recovery phrase)A sequence of usually 12 or 24 words from which your wallet derives all its private keys. Anyone who knows the words has full access to your bitcoin – so they belong in an offline backup and never in anyone else’s hands.On the learning path: Stage 5 · Step 3 – Backing up your seed phrase →In the glossary → or a comparable backup. Setting up a hardware wallet shows how setup works.
So the differences are smaller than the advertising suggests. A cheap device set up carefully protects you better than an expensive one with a sloppily written-down backup.
The criteria
Open-source code
If the firmware is open source, independent experts can review the code and bugs are more likely to be found. That fits the principle ‘don’t trust, verify’ from Nodes & decentralisation.
- Open: BitBoxProvider · Hardware walletBitBox02Hardware wallet from Switzerland with open-source firmware – optionally as a Bitcoin-only edition fixed at the factory.Hardware manufacturer – no financial licence required · reviewed Sept 2026Price: BitBox02 Nova €175 (manufacturer price for Germany incl. VAT, as of Sept 2026)Our profile →Official website ↗Only buy hardware wallets from the manufacturer or an authorised reseller.AdVisit BitBox (paid link, opens in a new window)on bitbox.swissOnly buy hardware wallets from the manufacturer or an authorised reseller.*Paid link: if you sign up or buy through it, we earn a commission. Your price stays the same. How we make money →, TrezorProvider · Hardware walletTrezor SafeHardware wallets by SatoshiLabs from the Czech Republic – Safe 3, Safe 5 and Safe 7, each also as a Bitcoin-only edition.Hardware manufacturer – no financial licence required · reviewed Sept 2026Price: Safe 3: $59 · Safe 5: $129 · Safe 7: $249 (same amounts in euros, as of Sept 2026)Our profile →Official website ↗Only buy hardware wallets from the manufacturer or an authorised reseller.AdVisit Trezor (paid link, opens in a new window)on trezor.ioOnly buy hardware wallets from the manufacturer or an authorised reseller.*Paid link: if you sign up or buy through it, we earn a commission. Your price stays the same. How we make money →, Blockstream JadeProvider · Hardware walletBlockstream JadeAffordable open-source hardware wallet from Blockstream: Jade Core without a camera, Jade Plus with a camera for QR signing without a cable.Hardware manufacturer – no financial licence required · reviewed Sept 2026Price: Jade Core $99, Jade Plus $149 (plastic) or $169 (metal) (as of Sept 2026)Our profile →Official website ↗Only buy hardware wallets from the manufacturer or an authorised reseller.AdVisit Blockstream Jade (paid link, opens in a new window)on blockstream.comOnly buy hardware wallets from the manufacturer or an authorised reseller.*Paid link: if you sign up or buy through it, we earn a commission. Your price stays the same. How we make money → and SeedSignerProvider · Hardware walletSeedSignerOpen-source DIY signing device: Raspberry Pi Zero, camera, small display – Bitcoin-only, no key storage, QR only.Open-source project – no company, no financial licence · reviewed Sept 2026Price: Parts usually under $50 (project’s figure) (as of Sept 2026)Our profile →Official website ↗Only buy hardware wallets from the manufacturer or an authorised reseller..[1],[2],[6],[14]
- Publicly viewable: COLDCARDProvider · Hardware walletCOLDCARDBitcoin-only signing device from Coinkite (Canada) with an air gap via microSD, NFC and QR – more for advanced users.Hardware manufacturer – no financial licence required · reviewed Sept 2026Price: Q $319, Mk5 $219 (promotional prices, as of Sept 2026)Our profile →Official website ↗Only buy hardware wallets from the manufacturer or an authorised reseller.’s code is on GitHub, and technically savvy users can compare it with the firmware on their device.[7] Its licence doesn’t allow selling the software, though, so strictly speaking it isn’t open source.[8]
- Closed: Ledger uses a proprietary operating system.[10] That doesn’t make it insecure, but you have to trust the manufacturer more.
Security chip (secure element)
A secure elementGlossarySecure element (security chip)A chip specially hardened against physical attacks, like the ones in bank cards and passports. In many hardware wallets it protects the PIN and secrets if the device falls into the wrong hands.In the glossary → is a chip hardened against physical attacks. It’s meant to stop someone who steals your device from reading the keys straight out of the hardware.
- The BitBox02 Nova and Trezor Safe 3 use a chip certified to EAL6+.[1],[2] The Trezor Safe 7 combines such a chip with the TROPIC01, whose design is open to public review.[3]
- COLDCARD has two secure elements from different chip makers, Ledger one secure element.[7],[10]
- Jade relies on a ‘virtual secure element’: a method called ‘blind oracle’ is designed to prevent keys from being physically extracted.[6]
- SeedSigner has no security chip, but it doesn’t store any keys either.[14]
Air gap
Air gapGlossaryAir gapAn air-gapped signing device has no cable or wireless connection to other devices. Transactions travel back and forth by QR code or memory card – so the private key stays completely offline.In the glossary → means the device is never connected to a computer by cable or wirelessly. The not-yet-signed transaction (PSBTGlossaryPSBT (partially signed Bitcoin transaction)A standard format for Bitcoin transactions that are not yet fully signed. It lets a wallet app, a hardware wallet and co-signers pass a payment between them without sharing private keys.In the glossary →) and then the signature travel back and forth by QR code or memory card. This shrinks the attack surface but is more cumbersome. Jade Plus (QR camera), COLDCARD (microSD, the Q also QR) and SeedSigner (QR only) offer an air gap.[6],[7],[14]
For getting started, a device with a cable is fine: the keys don’t leave it either way.
Display and connection
You check addresses and amounts on the display – you can’t trust your computer screen for that. The bigger it is, the easier it is to compare a long address. Sizes range from small displays such as the Trezor Safe 3’s 0.96 inches to the Ledger Stax’s 3.7 inches.[2],[11]
Also check that the device works with your computer or smartphone. Devices that connect via Bluetooth include the BitBox02 Nova (optional), Trezor Safe 7, Jade and most Ledger models.[1],[3],[6],[12]
Only bitcoin, or other crypto assets too?
All the devices listed here store bitcoin. The difference is the scope of the firmware: less code means fewer possible bugs. A serious BitBox flaw in August 2026, for example, affected only the multi-coin edition, because the faulty code isn’t in the Bitcoin-only firmware.[26]
With BitBox and Trezor, you choose between a Bitcoin-only and a multi-coin version when you buy. The two BitBox editions can’t be converted into each other later.[1],[2],[3] More in Types of wallet.
The devices at a glance
| Device | Bitcoin only? | Source code | Security chip | Air gap | Connection | Manufacturer’s price |
|---|---|---|---|---|---|---|
| BitBox02 Nova | as a separate edition | open | EAL6+ | no | USB-C, optional Bluetooth | €175 |
| Trezor Safe 3 / Safe 7 | as a separate edition | open | EAL6+, Safe 7 also TROPIC01 | no | USB-C, Safe 7 also Bluetooth | $59 / $249 |
| Blockstream Jade Core / Plus | Bitcoin and Liquid | open | ‘virtual secure element’ | Plus: via QR camera | USB-C, Bluetooth | $99 / from $149 |
| COLDCARD Mk5 / Q | yes | publicly viewable | two secure elements | yes: microSD, Q also QR | USB-C, microSD, NFC | $219 / $319 (promotion, normally $269 / $369) |
| Ledger (Nano, Flex, Stax) | no, universal device | proprietary operating system | secure element | no | USB-C, Bluetooth and NFC depending on model | $59 to $399 |
| SeedSigner (DIY) | yes | open | none, stores nothing | yes, QR only | QR code only | parts under $50 |
Manufacturers’ figures, as of September 2026.[1],[2],[3],[6],[7],[11],[12],[14] BitBox’s shop for Germany lists a euro price including VAT; the other manufacturers list dollar prices, some excluding taxes and shipping – hence two currencies. The current price in the manufacturer’s shop is what counts.
The devices in detail
BitBox02 Nova
The BitBox02 Nova is the current BitBox generation and runs with Windows, macOS, Linux, Android and iOS. The backup goes onto a supplied microSD card. If you wish, the device also shows it as a BIP 39 word list for you to write down on paper or steel.[1] That’s worthwhile, because a memory card can age or get lost.
A good fit if you’re looking for a simple device with a straightforward companion app, including on an iPhone.
Trezor Safe 3 and Safe 7
The Safe 3 is Trezor’s low-cost entry model with a small display. You can’t use it with an iPhone to set up or send.[2] The Safe 7 has a 2.5-inch colour touchscreen and a battery with wireless charging, and is protected against dust and splashes to IP54.[3] Via Bluetooth, you can use it with an iPhone too.[4] By default, both create a 20-word SLIP-39 backup instead of BIP 39 (the Safe 3 since June 2024).[5] Setting up a hardware wallet explains what that means.
A good fit if you want open code and either a low-cost start or convenient touchscreen operation.
Blockstream Jade Core and Jade Plus
Both Jade models have a 1.9-inch colour display and connect via USB-C or Bluetooth. Thanks to its camera, Jade Plus can also sign by QR code with no connection at all. The companion app is the Blockstream App.[6]
A good fit if your budget is small or you’d like to try signing by QR code.
COLDCARD Mk5 and Q
COLDCARD from Coinkite is aimed more at advanced users. It can be used entirely without a cable to the computer and has protective features for coercion situations, such as a ‘duress PIN’ that opens a different wallet instead of the main one.[7]
Ledger (Nano, Flex, Stax)
Ledger offers displays from 1.1 inches (Nano S Plus, Nano X) through 2.8 inches (Nano Gen5, Flex) to 3.7 inches (Stax).[11] All models use a secure element and a proprietary operating system.[10]
With the optional subscription ‘Recover’ ($9.99 a month), the device encrypts the seed information and deposits it in three parts with Ledger, Coincover and Escrowtech. It’s only activated with your consent on the device; to recover, you need an ID document and a selfie.[13] So the device software can release seed information in encrypted form – whether you’re comfortable with that is your decision.
Suitable if you want to store other crypto assets alongside bitcoin and are fine with the closed operating system.
Does open-source code matter to you, or do you only hold bitcoin? Then BitBox* (paid link, opens in a new window)BitBox and Trezor* (paid link, opens in a new window)Trezor offer open-source firmware, including as a Bitcoin-only edition. Blockstream Jade is open source too.[1],[2],[6]
SeedSigner (DIY)
SeedSigner is an open-source project: you build the device yourself for under $50 from standard parts, such as a Raspberry Pi Zero without Wi-Fi and Bluetooth. It stores no keys, communicates only by QR code and works with wallets such as Sparrow, BlueWallet or Nunchuk, including for multisig.[14] You load your seed afresh every time you use it. That’s consistent, but more for tinkerers.
Security incidents, openly assessed
No device is flawless. What matters is whether a manufacturer reports flaws openly, ships updates quickly and tells those affected clearly what to do. Here are the most important incidents – including at manufacturers we earn from.
Data leaks and phishing
July 2020
Ledger: shop database
Around 1 million email addresses were leaked, and for around 272,000 customers also their name, postal address and phone number. In December 2020, the data was published.[15]
July 2022
BitBox: marketing service ActiveCampaign
Unauthorised persons downloaded email lists: names, email and IP addresses, mainly of newsletter subscribers. Delivery addresses were not stored there.[20]
17 January 2024
Trezor: support provider
Unauthorised persons viewed the names and email addresses of around 66,000 people who had contacted support since December 2021. Phishing emails asking for the seed phrase followed.[16]
January 2026
Ledger: shop service provider Global-e
Names, postal addresses, email addresses, phone numbers and order data were stolen.[17]
August 2026
Trezor: shipping provider ShipMonk
Order data of almost 14,000 customers was stolen, including name, email, phone number and delivery address for 11,742 of them.[18]
9 September 2026
Trezor: hijacked newsletter service
Through a flaw at the email service provider Brevo, a fake ‘security warning’ went to around 347,000 newsletter recipients. The link led to an app that asked for the wallet backup. Around 2,500 people clicked before Trezor had the domain blocked after about 20 minutes.[19]
September 2026
BitBox: newsletter service Brevo
Through the same flaw at Brevo, attackers got into BitBox’s account and sent genuine-looking phishing emails to subscribers. They led to a page asking for the recovery words. Brevo only held email addresses.[21]
The devices themselves weren’t affected in any of these cases.[15],[20],[16],[17],[18],[19],[21] But the data is enough for targeted phishing.
Vulnerabilities in devices and firmware
March 2025
Trezor Safe 3: tamper protection can be bypassed
Researchers from rival Ledger showed that the Safe 3’s protection against supply-chain tampering can be bypassed – with the device in hand, soldering and specialist knowledge. A device tampered with in this way could reveal the seed phrase. The Safe 5 isn’t affected. Trezor advises buying only through official channels and choosing a longer PIN.[22],[23]
December 2025
Blockstream Jade: older firmware
Certain older firmware was possibly vulnerable if Jade was paired with a malicious third-party app. No affected users were known. Blockstream urged users to install firmware 1.0.38 from an official source.[24]
June 2026
Trezor Safe 7: vulnerability in the TROPIC01 chip
Ledger researchers used laser fault injection to find a vulnerability in the open TROPIC01 chip. The attack needs the device, removal and exposure of the chip, and laboratory equipment. According to Trezor, the chip is only one of three independent layers of protection, and PIN and funds are not at risk. The hardware flaw can’t be fixed by an update.[25]
July 2026
COLDCARD: weak seeds
A firmware bug weakened seed generation; attackers stole funds by recalculating keys offline. An update alone doesn’t help those affected (see the warning in the COLDCARD section).[9]
17 August 2026
BitBox: two serious firmware flaws closed
Firmware 9.26.5 closed two serious flaws that BitBox had found itself: one in the multi-coin edition before setup on a compromised computer, one in payments to so-called silent payment addresses. BitBox also reclassified an already fixed flaw in the older BitBox02 as serious; exploiting it required successful phishing. No stolen funds are known, and existing seeds are not affected.[26]
Apart from the COLDCARD case, we’re not aware of any stolen funds relating to these device vulnerabilities (as of September 2026). That is no guarantee for the future.
What the incidents teach us
- Customer data is a target. More than half of the incidents hit shops and service providers, not the devices. Order with as little personal data as possible, for example to a parcel locker – see Protecting your data when you buy.
- Every leak is followed by phishingGlossaryPhishingFraud using fake emails, text messages, websites or calls that look like genuine exchanges, wallet makers or banks. The goal is your passwords, 2FA codes – and above all your seed phrase.On the learning path: Stage 6 · Step 2 – Spotting scams →In the glossary →. No manufacturer or support team will ever ask for your seed phrase. Anyone who does is a scammer – even if, as with Trezor’s hijacked newsletter, the email comes from a genuine sender address. More in Spotting & avoiding scams.
- Keep your firmware up to date. Install updates only via the official app. For larger holdings, multisig with devices from different manufacturers can make sense: then one manufacturer’s flaw isn’t enough on its own.
- Chip attacks need your device. Buying from the manufacturer, a long PIN and a safe storage place make them much harder.
Which device suits which need?
The table maps needs to the devices that meet them. It isn’t a personal recommendation.
| What matters to you … | What to look for | Devices that meet it |
|---|---|---|
| an easy start, including with an iPhone | a good companion app, Bluetooth | BitBox02 Nova, Trezor Safe 7, Jade with Blockstream App |
| only bitcoin, as little code as possible | Bitcoin-only firmware | BitBox02 Nova or Trezor as a Bitcoin-only edition, COLDCARD, SeedSigner |
| other crypto assets too | well-maintained multi-coin firmware | BitBox02 Nova Multi, Trezor Universal, Ledger |
| a small budget | basic functions without extras | Trezor Safe 3, Ledger Nano S Plus, Jade Core, SeedSigner (DIY) |
| no cable connection | air gap via QR or microSD | Jade Plus, COLDCARD, SeedSigner |
| larger holdings | combine devices from different manufacturers | two or three devices in a multisig setup |
Before you buy – your criteria
0/6 doneIf you buy one, buy it directly from the manufacturer or from a reseller it names. You decide from what amount a device is worthwhile – one pointer is the moment a loss would really hurt.
Frequently asked questions
Which hardware wallet is the best?
There isn’t a single best one. All the devices listed here keep bitcoin safe if you buy from the manufacturer, set them up carefully and store your backup well. A higher price mainly buys convenience such as a touchscreen, Bluetooth or a battery – not automatically more security.
Do I need a Bitcoin-only device?
Not necessarily. But less code means fewer possible bugs: a serious BitBox flaw in August 2026 affected only the multi-coin edition. With BitBox, you choose the edition when you buy.
Are Ledger devices unsafe after the data leaks?
The data leaks exposed customer data such as email and postal addresses, not the devices or funds. They do raise the risk of phishing. Separately, Ledger uses an operating system that isn’t open source and offers Recover, an optional service that deposits encrypted parts of the seed information with companies.
I own a COLDCARD. Do I need to do anything?
Check COLDCARD’s official status page to see whether the firmware that generated your seed was affected. If it was, an update isn’t enough: you have to move your funds to a newly generated seed. Open the status page yourself and don’t follow links in emails.
Can I switch manufacturers later?
Yes. The simplest way is to set up the new device with a new seed phrase and send your bitcoin – a test amount first – to an address you have checked on the new device’s display.
Your knowledge blockchain
Every article you complete becomes a block in your personal chain – stored only in your browser.
Sources26 sources · 14 publishers
The superscript numbers in the text refer to these sources.
- BitBox02 Nova – Shift Crypto (BitBox) (accessed 28/09/2026)
- Trezor Safe 3 Bitcoin-only – Trezor (accessed 28/09/2026)
- Trezor launches Trezor Safe 7, first hardware wallet with transparent secure element – SatoshiLabs, 21.10.2025 (accessed 28/09/2026)
- Trezor Safe 7 FAQs – Trezor (accessed 28/09/2026)
- Understanding Trezor wallet backups: 12, 20 or 24 words – Trezor (accessed 28/09/2026)
- Blockstream Jade – Hardware Wallet – Blockstream (accessed 28/09/2026)
- COLDCARD – Bitcoin Only Hardware Wallet – Coinkite (accessed 28/09/2026)
- COLDCARD firmware – licence (MIT with ‘Commons Clause’) – Coinkite (GitHub) (accessed 28/09/2026)
- COLDCARD Security Status – Coinkite (accessed 28/09/2026)
- Ledger – Hardware Wallets (home page) – Ledger (accessed 28/09/2026)
- Find the best Ledger wallet for you – comparison – Ledger (accessed 28/09/2026)
- Introducing Ledger Nano Gen5 – Ledger Academy, 23.10.2025, updated 12.03.2026 (accessed 28/09/2026)
- What Is Ledger Recover? – Ledger Academy (accessed 28/09/2026)
- SeedSigner – Build an offline, airgapped Bitcoin signing device – SeedSigner project (accessed 28/09/2026)
- A message from Ledger's CEO – Data leak – Ledger, 21.12.2020 (accessed 28/09/2026)
- Trezor support site breach exposes personal data of 66,000 customers – BleepingComputer, 22.01.2024 (accessed 28/09/2026)
- Ledger confirms leak of customer data after third-party Global-e hack – SiliconANGLE, 05.01.2026 (accessed 28/09/2026)
- Trezor discloses data breach affecting nearly 14,000 customers – BleepingComputer, 13.08.2026 (accessed 28/09/2026)
- Trezor: 347,000 users targeted in phishing attacks after Brevo breach – BleepingComputer, 11.09.2026 (accessed 28/09/2026)
- Data breach of marketing platform ActiveCampaign – Shift Crypto AG, 21.07.2022 (accessed 28/09/2026)
- Email address exposure at newsletter provider Brevo – Shift Crypto AG, 24.09.2026 (accessed 28/09/2026)
- Trezor discloses potential vulnerability in older Safe 3 crypto wallets following white hat research by rival Ledger – The Block, 13.03.2025 (accessed 28/09/2026)
- Ledger Donjon's Trezor Safe 3 evaluation – Trezor (accessed 28/09/2026)
- Important Jade Security Update – Blockstream, 05.12.2025 (accessed 28/09/2026)
- Trezor response: TROPIC01 chip disclosure (no impact to your funds) – Trezor, 03.06.2026 (accessed 28/09/2026)
- BitBox 08.2026 Dixence update – Shift Crypto (BitBox), 17.08.2026 (accessed 28/09/2026)
This article is for education only and is not investment, tax or legal advice.