MKT

Ratings · Documented, not tested

Hardware wallets

A hardware wallet has exactly one job: make sure that what you see on its screen is what you actually sign. We scored these on the chip, on whether the code running on it can be read and rebuilt by anyone, and on whether your seed is allowed to leave — because a wallet you cannot escape is not self-custody.

BEST OVERALL

Shows you every output, every time — because it is Bitcoin-only and has no blind-signing surface at all. Fully air-gapped. And useless if you hold anything else.

BEST FOR EVERYTHING ELSE

Apache-2.0, reproducible builds, published schematics, no incidents. Its one weakness: the audit is named but the report was never published.

BEST VALUE

Open, reproducible, and it shows you what you sign. No secure element, and Blockstream says so plainly instead of hiding it.

What we did · July 14, 2026We read the certificates, the licences, the build-reproducibility docs and the incident record — not the marketing. We did not buy the devices: that is Level C evidence and we say so rather than implying we plugged them in.

The thing nobody weights properly

When a hardware-wallet company leaks its customer list, it publishes the names, home addresses and phone numbers of people known to hold crypto.

That is not a privacy inconvenience to be listed under “cons”. In 2020, roughly 272,000 Ledger customers had exactly that dumped in public, and the documented consequence was extortion emails and physical threat letters arriving at their homes. It happened to Ledger again in January 2026. Trezor leaked names and emails — no addresses — in 2024. We give this its own criterion, at 10%, because the industry treats it as a footnote and the people it happened to do not.

The ranking

#NAMESCORE

Click any row for the quick read, or open a company for its full profile and per-criterion scores. Measured July 14, 2026. How we rate.

HOW WE SCORED THIS — CRITERIA AND WEIGHTS+

A hardware wallet has one job: make sure that what you see on its screen is what you actually sign. We rank these on the chip, on whether the code that runs on it can be read and rebuilt by anyone, and on whether your seed can leave — because a wallet you cannot escape is not self-custody.

Security architecture · 30% · level A

Secure element: present or not, which chip, and the actual certification level (EAL5+, EAL6+) as published by the certifying body rather than the vendor’s marketing. Then the three questions vendors like to blur into one: is the firmware open source, is the hardware design open, and are the builds REPRODUCIBLE — can you verify that the binary on your device was built from the source you just read? Audits count only when the firm is named and the report is public.

Clear signing · 15% · level A

Its own criterion, not a footnote to UX, because this is the hole the money actually leaves through. Does the device parse and display what you are signing — the ERC-20 approval amount, the swap destination, the EIP-712 payload — or does it show you a hash and ask you to trust the computer it is plugged into? Read from vendor documentation and firmware source. NOT hands-on: we have not bought these devices, and we say so rather than implying we pressed the buttons.

Recovery and seed portability · 15% · level A

BIP39, SLIP39/Shamir, passphrase support. The decisive question: can the seed be restored into a DIFFERENT vendor’s wallet? If it cannot, that is vendor lock-in, and it loses points — the entire premise of self-custody is that you can walk away from the company that sold you the device.

Company and customer-data safety · 10% · level A

Jurisdiction, ownership, and the history of customer-data leaks. This carries more weight than it looks: when the buyer list of a hardware wallet leaks, it publishes the names, home addresses and phone numbers of people known to hold crypto. That is a physical-safety event, not a privacy inconvenience, and it is scored as one.

Connectivity and air-gap · 10% · level A

Is the device fully air-gapped (QR or SD only), or does it require USB or Bluetooth? Which software wallets it interoperates with, from vendor documentation.

Assets and networks · 8% · level A

What the official support list actually contains, and — importantly — whether support is native on the device or delegated to third-party software with caveats. This is the vendor’s own claim; we mark it as such, because verifying it properly means buying the device and trying ten coins, which is Level C and which we have not done.

Price and true cost · 7% · level A

Vendor store price, plus any accessory the device genuinely needs to be usable. A cheap device that requires a paid dongle is not a cheap device.

Maintenance · 5% · level A

Firmware release cadence and how long old models keep receiving updates — counted from the public repository’s release history, not from a promise on the website.

DISQUALIFIERS FOR THIS CATEGORY
  • — A closed-source device whose seed cannot be restored elsewhere — you would be trusting a company you cannot audit and cannot leave.
  • — A known unpatched vulnerability that extracts the seed with physical access.
  • — A vendor that has leaked customer addresses and has not changed its data-retention practice.

Weights sum to 100. If we cannot verify a criterion, we delete it rather than score it on impressions — read the methodology.

Is there a free alternative?

The winner costs $249 and the runner-up costs $79. The difference between them is not security.

Blockstream Jade is $79, fully open source, reproducibly built, and shows you every output before you sign. It has no secure element at all — and Blockstream says so openly rather than burying it. That is a real trade-off, not a defect: a secure element resists someone who has your device in their hands, and for most people the realistic threat is a malicious transaction on the screen, not a laboratory attack on the chip. If your threat model is a thief with lab equipment, pay for the chip. If it is a drainer contract, the $79 device that shows you what you are signing is doing the job that actually matters.

What changed since last time

  • 2026-07-14Category rebuilt. The previous wallet rating scored five devices on a soft rubric including a "support" criterion we never measured.It contradicted our own published methodology, so it is gone.

Questions

Why does Ledger rank eighth when it has the best secure element?+

Because a secure element is not the only thing a hardware wallet company can get wrong. Ledger's chip is genuinely the best here — EAL6+ — and its clear-signing engine decodes contract calls better than Trezor's. But the firmware is still not open source in 2026: Ledger's own developer documentation says the secure-element firmware is under NDA and closed, so you cannot reproduce the binary running on your device from source you have read. And Ledger has leaked its customer list twice. The 2020 breach put the names, home addresses and phone numbers of roughly 272,000 crypto holders into public circulation and produced documented extortion and physical threat letters; it happened again in January 2026 through a payment partner. For a company whose customer list is by definition a list of people known to hold crypto, that is a physical-safety failure, not a privacy one.

A Bitcoin-only device wins? Is that useful advice?+

It is honest advice, which is not the same thing, and we say so in the card itself. The Coldcard Q wins on the criterion that actually decides whether people lose money — it shows you exactly what you are signing, always — and it does that precisely because it is Bitcoin-only and therefore has no EVM blind-signing surface. If you hold anything other than Bitcoin, it cannot help you, and that is a categorical exclusion rather than a compromise. The property that makes it safest is the property that makes it useless to you.

Why does the Tangem card score zero on clear signing?+

Because it has no screen. It signs whatever the phone tells it to sign. The entire purpose of a hardware wallet is to give you a trusted second screen that a compromised computer cannot lie to you through — and this device does not have one. That is not a harsh reading; it is the architecture.

Did you actually test these devices?+

No, and we will not pretend otherwise. Buying them is Level C evidence and we did not spend the money. So this rating scores what is documented and checkable: the chip and its certificate number, the licence, whether the firmware builds are reproducible, who audited it and whether the report is actually published, the incident record, and whether your seed can be restored into a rival's device. Where a criterion would have required our hands on the buttons, it is read from vendor documentation and labelled that way rather than dressed up as a field test.

What does "reproducible builds" mean and why does it carry so much weight?+

It means you can take the published source code, compile it yourself, and check that the binary you produced is byte-for-byte identical to the firmware the vendor shipped. Without it, "open source" tells you what the company says the code is — not what is actually running on the device in your hand. Trezor, BitBox and Blockstream document it. Ledger cannot offer it, because the OS binary is not published at all.

How this is funded

It is not. There are no affiliate links on this page or anywhere on this site, no paid placements, and no sponsored positions. Nobody in this table can buy a place in it, accelerate their inclusion, or influence a score — and none of them paid us anything, because there is nothing here to buy. The full policy.