MKT
T
Ranked #4

Trezor Safe 5 (SatoshiLabs)

7.5/10
Rank #4 of 13

The best open general-purpose device: an EAL6+ Infineon secure element, firmware AND hardware fully open, and reproducible builds you can verify yourself. When Ledger's own security lab demonstrated a voltage-glitch attack against the Safe 3, the Safe 5 was found not vulnerable — it uses a newer microcontroller — and Trezor published the finding on its own website, about its own product, which is the behaviour that earns trust.

Researched by the ChainWatch Daily ratings deskMeasured How we rateSomething wrong? Tell us

About Trezor Safe 5 (SatoshiLabs)

The Trezor Safe 5 is the best open general-purpose hardware wallet available: an EAL6+ certified Infineon secure element paired with firmware and hardware that are both fully open, and reproducible builds anyone can verify. Historically the trade in this category has been a certified chip or openness; the Safe 5 refuses to make it. SatoshiLabs also has a track record of behaving well in a crisis — when a competitor's recovery-service announcement caused an industry-wide panic, its position was clear and its architecture backed it up. As a general-purpose device it faces the blind-signing problem on complex EVM transactions that every multi-asset wallet faces.

Our verdict

The best open general-purpose device: an EAL6+ Infineon secure element, firmware AND hardware fully open, and reproducible builds you can verify yourself. When Ledger's own security lab demonstrated a voltage-glitch attack against the Safe 3, the Safe 5 was found not vulnerable — it uses a newer microcontroller — and Trezor published the finding on its own website, about its own product, which is the behaviour that earns trust.

The January 2024 breach of a third-party support portal exposed the contact details of up to 66,000 people who had written to Trezor Support, and the attacker emailed 41 of them asking for their recovery seed. Only names and emails, no home addresses — materially less dangerous than Ledger's leak, but still a leak. Ethereum clear-signing shows EIP-712 typed data on-device but does not decode arbitrary contract calls the way a descriptor registry does.

Strengths & trade-offs

What works

The best open general-purpose device: an EAL6+ Infineon secure element, firmware AND hardware fully open, and reproducible builds you can verify yourself. When Ledger's own security lab demonstrated a voltage-glitch attack against the Safe 3, the Safe 5 was found not vulnerable — it uses a newer microcontroller — and Trezor published the finding on its own website, about its own product, which is the behaviour that earns trust.

Where it loses points

The January 2024 breach of a third-party support portal exposed the contact details of up to 66,000 people who had written to Trezor Support, and the attacker emailed 41 of them asking for their recovery seed. Only names and emails, no home addresses — materially less dangerous than Ledger's leak, but still a leak. Ethereum clear-signing shows EIP-712 typed data on-device but does not decode arbitrary contract calls the way a descriptor registry does.

Evidence

secure element
Infineon OPTIGA Trust M V3
PUBLISHED[source]
EAL certification
EAL6+ (vendor-stated)
PUBLISHED[source]
firmware + hardware open source
yes, both
SOURCED[source]
reproducible builds
yes — documented
SOURCED[source]
third-party commissioned audit
not published
SOURCED
price
129
PUBLISHED[source]

Incidents

  • 2024-01-17 — Third-party support-portal breach exposed contact details of up to 66,000 users; 41 were directly emailed and asked for their recovery seed. [users made whole: n/a] [source]

Trezor Safe 5 (SatoshiLabs) FAQ

Does a secure element mean the wallet is closed source?

+

Not any more, and the Safe 5 is the proof. It pairs an EAL6+ certified secure element with fully open firmware and hardware plus reproducible builds. Earlier generations of this category forced a choice between certified silicon and verifiable code; that trade-off is no longer necessary.

Can the Trezor Safe 5 show me what I am signing?

+

For straightforward transactions, yes. For complex smart-contract interactions the same limitation applies as to every general-purpose device: arbitrary calldata frequently cannot be rendered into something a human can meaningfully verify, which is the structural weakness of multi-asset hardware wallets.

Who it’s not for

Anyone who needs an air-gap. USB-C only, no QR, no Bluetooth.

No affiliate links — nothing on this page is for sale. ← Back to the hardware wallets ranking