Trezor
The only hardware wallet with firmware and hardware both fully open and reproducible builds — and which published the attack found against its own model.
- Founded
- 2013
- Registered
- Czech Republic
- Site
- trezor.io
The short answer
The Safe 5 is the best open general-purpose device we rate: an EAL6+ Infineon secure element, firmware and hardware both fully open, and reproducible builds you can verify yourself rather than take on faith. The behaviour that matters most is not in the specification — when Ledger’s security lab demonstrated a voltage-glitching attack against the cheaper Safe 3 in March 2025, Trezor published the finding itself. It needs physical access and desoldering, and the Safe 5 is not affected.
Key facts
| Openness | Firmware and hardware both fully open, with reproducible builds — unique in our hardware wallet ratingas of 14 Jul 2026 |
|---|---|
| Secure element (Safe 5) | EAL6+ Infineon; architecture scored 9 out of 10, the highest on the cardas of 14 Jul 2026 |
| Safe 3 price | $59 — on price-to-openness nothing else comes closeas of 14 Jul 2026 |
| March 2025 Safe 3 finding | Ledger’s security lab showed voltage-glitching the microcontroller can dump flash and reprogram the device, defeating supply-chain and authenticity protections. Physical access and desoldering required. Trezor published it. The Safe 5 is not affected.as of 14 Jul 2026 |
| January 2024 support breach | A third-party support portal exposed contact details for up to 66,000 people; an attacker emailed 41 asking for their recovery seed. Names and emails only — no home addresses.as of 14 Jul 2026 |
| Company and customer-data safety | 6 out of 10, against Ledger’s 2as of 14 Jul 2026 |
| Maintenance | 9 out of 10 — among the best-supported devices we rateas of 14 Jul 2026 |
Is Trezor safe?
It is the only device in our rating whose central claim you can actually check. Firmware and hardware are both fully open, and the builds are reproducible — meaning you can compile the source yourself and confirm the binary on your device matches it. Every other vendor asks you to trust that the software does what they say; this one lets you verify it, which is the entire reason a hardware wallet exists.
The Safe 5 pairs that with an EAL6+ Infineon secure element, and we score its architecture 9 out of 10, the highest mark on the card. Openness and a certified chip are usually presented as a trade-off. Here they are not.
The most useful evidence about Trezor is behavioural. In March 2025 Ledger’s security lab demonstrated that voltage-glitching the Safe 3’s microcontroller could dump its flash and reprogram the device, defeating the model’s supply-chain and authenticity protections. The attack requires physical access and desoldering, so it is not a remote threat — and Trezor published the finding itself rather than waiting to be forced into it. That is how a vendor you can trust behaves when a competitor finds a flaw.
Its weakest moment, the January 2024 breach of a third-party support portal, exposed contact details for up to 66,000 people who had written to support, and an attacker emailed 41 of them asking for their recovery seed. Names and emails, no home addresses. We score company and customer-data safety 6 out of 10 — an unforced error, and considerably less dangerous than handing out the home addresses of people known to hold cryptocurrency.
Safe 3 or Safe 5, and what $59 actually buys
The Safe 3 costs $59 and is, on price-to-openness, unmatched: a reproducibly-built open device with an EAL6+ secure element for less than a third of what flagship models cost. We score its price 8 out of 10 against the Safe 5’s 6.
What the extra money buys is the architecture score — 9 out of 10 for the Safe 5 against 7 for the Safe 3 — and that gap is the March 2025 finding. The voltage-glitching attack that defeats the Safe 3’s supply-chain protections does not affect the Safe 5.
Whether that matters depends entirely on one question: can someone get physical possession of your device, with the equipment and time to desolder it? For most people the answer is no, and the Safe 3 is the better value by a wide margin. If your device travels, is stored somewhere you do not control, or protects an amount that would justify the effort against you, buy the Safe 5.
Both carry the same openness, the same reproducible builds and the same maintenance record, which we score 9 out of 10. This is a genuine two-tier product line rather than an artificial one.
Incident record
| Date | Type | Amount | Were users made whole? |
|---|---|---|---|
| 17 Jan 2024 | Incident | — | No funds were taken. A third-party support portal exposed contact details for up to 66,000 people and an attacker emailed 41 of them asking for their recovery seed. Names and email addresses only, no home addresses — materially less dangerous than the comparable Ledger exposure.source |
In our ratings
Compared with
Our coverage of Trezor
- How to spot a fake proof of reserves27 Sept 2026
- Bitget loses $351.6m — and the fund it says covers it is one we could not verify25 Sept 2026
- Is Kraken safe? The evidence, and what it lacks25 Sept 2026
- What happens to your coins if an exchange goes bankrupt23 Sept 2026
- Is Coinbase safe? What its own filings say19 Sept 2026
- How to move crypto off an exchange, step by step17 Sept 2026
- Token approvals: the permission that drains wallets15 Sept 2026
- What "not your keys, not your coins" leaves out9 Sept 2026
- The seed phrase mistakes that cost people everything7 Sept 2026
- Hardware wallet or software wallet: how to decide5 Sept 2026
Questions people ask
Is Trezor safe?
It is the only device we rate whose firmware and hardware are both fully open with reproducible builds, so you can verify the software on your device rather than trusting a vendor claim. The Safe 5 adds an EAL6+ Infineon secure element and scores 9 out of 10 on architecture, the highest on the card.
Was Trezor hacked?
No funds have been taken. In January 2024 a third-party support portal exposed contact details for up to 66,000 people and an attacker emailed 41 asking for their recovery seed — names and emails only, no home addresses. Separately, a March 2025 physical attack on the Safe 3 required desoldering the device.
What was the March 2025 Trezor Safe 3 vulnerability?
Ledger’s security lab showed that voltage-glitching the microcontroller can dump its flash and reprogram the device, defeating the Safe 3’s supply-chain and authenticity protections. It requires physical access and desoldering. Trezor published the finding itself, and the Safe 5 is not affected.
Trezor Safe 3 or Safe 5?
The Safe 3 at $59 is the better value unless someone could realistically get physical possession of your device with time and equipment — that is the only scenario where the Safe 5’s stronger architecture, 9 out of 10 against 7, actually matters. Both are equally open and equally well maintained.
Trezor or Ledger?
Ledger has the better chip, a stronger clear-signing engine and broader asset support. Trezor is fully verifiable and has a much better record on customer data — 6 out of 10 against Ledger’s 2, whose breach exposed home addresses. If verifiability is your reason for buying hardware, Trezor answers it and Ledger does not.
What changed
- 27 Sept 2026 — Profile published. Covers both Safe 5 and Safe 3, which hold separate rating cards.