MKT

Ledger vs Trezor: the difference that matters

One publishes its firmware and one does not. Almost everything else in this comparison is preference; that part is not.

By Theo Walsh·Oct 1, 2026·9 min read·✓ Fact-checked by Ethan Brooks
Ledger vs Trezor: the difference that matters

Ledger vs Trezor: the difference that matters

Ledger has the better chip. Trezor has the better trust model. That sentence contains most of the comparison, and which one wins depends on whether you think a security claim you cannot verify is a security claim at all.

In our hardware wallet rating, Trezor Safe 5 places well ahead of Ledger, which finishes eighth despite having the strongest silicon in the category.

Where Ledger is genuinely better

  • The secure element. A genuine EAL6+ certified chip — the best in this rating. It is not the problem.
  • Clear-signing depth. Where a descriptor exists, a Ledger decodes a contract call into something a human can read. Trezor shows typed data on-device but does not decode arbitrary contract calls to the same depth. For someone signing complex DeFi transactions, that is a real advantage.
  • Asset coverage and app ecosystem, which is broader.

The thing that decides it

Ledger's firmware is not open source. The company publishes fragments of its OS under a bespoke, non-OSI "Source Code Accessibility License", and its own developer documentation states that the secure-element firmware is under NDA and therefore closed-source. You cannot reproduce the binary running on your device from source you have read.

That was an abstract objection until the recovery-service announcement made it concrete. In describing a service that could back up shards of a user's seed, Ledger confirmed that a signed firmware update could cause the seed to leave the device — something a large number of owners believed was architecturally impossible. The controversy was not really the service. It was the realisation of what closed firmware had always meant.

Trezor publishes firmware and hardware in full, with reproducible builds you can verify yourself, on an EAL6+ Infineon secure element in the Safe 5. The verification is available to anyone who wants to do it.

How each company handled a flaw in its own product

In March 2025, Ledger's security lab demonstrated that voltage-glitching the Trezor Safe 3's microcontroller could dump its flash and reprogram the device, defeating supply-chain and authenticity protections. It requires physical access and desoldering.

Trezor published that finding itself, on its own website, about its own product — and the Safe 5 was found not vulnerable, because it uses a newer microcontroller. Disclosing a competitor's research about your own device is the behaviour that earns trust, and it is why the fix here costs about $70.

The customer data problem

This is where the gap widens, and it is not a privacy footnote for a company whose customer list is by definition a list of people known to hold crypto.

  • Ledger, July 2020: an e-commerce database breach exposed the names, postal addresses and phone numbers of roughly 272,000 customers. It produced sustained phishing, extortion emails and physical threat letters.
  • Ledger, January 2026: a second exposure through a third-party payment provider. Names and contact details; the number affected was not disclosed.
  • Trezor, January 2024: a third-party support portal breach exposed the contact details of up to 66,000 people who had written to support, and the attacker emailed 41 of them asking for their recovery seed. Names and emails only, no home addresses.

All three are failures. Postal addresses attached to known crypto holders are a materially different category of harm from email addresses, and one company has now done it twice.

In fairness to Ledger

When the December 2023 Connect Kit supply-chain attack drained roughly $600,000 through a phished ex-employee's npm account, Ledger reimbursed affected users. Paying is not nothing, and plenty of companies in this market have not.

The device is excellent engineering. The trust model is the product.

The short version

Choose Trezor unless you specifically need Ledger's deeper clear-signing for complex DeFi work, and if you buy a Trezor, buy the Safe 5 rather than the Safe 3. The Safe 5's firmware and hardware are fully open with reproducible builds, its security element is certified to the same level, and its maker has a better record on both disclosure and customer data.

Frequently asked questions

Is Ledger or Trezor safer?+

Trezor, on the evidence you can verify. Its firmware and hardware are fully open with reproducible builds on an EAL6+ secure element, while Ledger's firmware is closed and its secure-element code is under NDA, so every claim rests on trusting the vendor. Ledger's chip and clear-signing are better; its trust model is weaker.

What was the Ledger Recover controversy?+

Ledger announced a service that could back up shards of a user's recovery seed, and in doing so confirmed that a signed firmware update could make the seed leave the device — something many owners believed was architecturally impossible. The issue was less the service than what it revealed about closed firmware.

Has Ledger leaked customer data?+

Twice. A July 2020 e-commerce breach exposed names, postal addresses and phone numbers of roughly 272,000 customers, producing documented extortion and physical threat letters, and a January 2026 exposure through a payment provider leaked names and contact details. Trezor had a 2024 support-portal breach affecting up to 66,000 people, limited to names and emails.

Should I buy the Trezor Safe 3 or Safe 5?+

The Safe 5. In March 2025 Ledger's security lab showed the Safe 3's microcontroller could be voltage-glitched to dump flash and reprogram the device, given physical access. The Safe 5 uses a newer chip and is not affected, so the fix costs roughly $70.

How this was reported

ChainWatch Daily is independent and reader-funded. Stories are written by named journalists and checked against primary sources before publishing. We disclose holdings, correct errors in the open, and never accept payment for coverage.

→

More like this