Trezor
How we make money from this listing. We may earn a commission if you sign up through our link. That buys position on a list — nothing else. It does not change a word of what follows, and we do not publish scores that could be bought. Our rules, in writing.
Trezor was the first hardware wallet anyone shipped, in 2013, and it is made by SatoshiLabs in Prague. That matters less for the history than for what it produced: more than a decade of the firmware and the hardware designs being open source, which means the claims are checkable by people with no stake in them being true. Most of this industry asks you to take its security on faith. This is one of the few places where you do not have to.
The thing to understand before buying is that "a Trezor" is now two quite different products. The older Trezor One and Model T store the seed on an ordinary microcontroller. In 2019 Ledger's Donjon research team, and again in 2020 Kraken Security Labs, showed that somebody holding the device with a few hundred dollars of equipment can voltage-glitch that chip and pull the encrypted seed out of it in roughly a quarter of an hour. The newer Trezor Safe 3 and Safe 5 add a certified secure element that is designed to resist exactly that class of attack. If you are buying today, this is the difference worth paying attention to, and it is the reason we would not describe the older models and the newer ones in the same sentence.
On the older devices the passphrase is not an optional extra, it is the defence. A passphrase acts as an additional word that is never written to the device, so a seed extracted from the chip is useless without something that only exists in your head. That is a real mitigation and Trezor implements it well. It is also a thing you can forget, and forgetting it loses the funds as completely as any attacker would — which is the trade you are accepting, and it should be a deliberate decision rather than a setting you switch on because a video told you to.
Trezor's customer data has been exposed twice, and both times the result was phishing aimed at seed phrases. In April 2022 a breach at the third-party mail provider MailChimp exposed data for around 107,000 Trezor customers, and the attackers used it to send a convincing "security incident" email that led to a fake Trezor Suite asking people to type in their recovery phrase. In January 2024 a support-portal incident exposed contact details for roughly 66,000 people who had contacted support since 2021. No funds were taken from the devices themselves in either case, and it is fair to say the mail provider was the weak link the first time. It is also fair to say that buying this product has twice put your email address in the hands of people who then used it to try to take your crypto, and that is a cost worth knowing about in advance.
The practical consequence is one rule: nobody from Trezor will ever ask for your recovery phrase. Not by email, not in a support chat, not in an app that says it needs to "verify" or "migrate" your wallet. Every attack described above ended at that same question, because it is the only question that works. A hardware wallet's entire purpose is that the phrase never has to be typed into anything connected to the internet, and the moment something asks you to, the thing asking is the attack — regardless of how well it reproduces the branding.
Buy it directly from the manufacturer. A hardware wallet bought from a marketplace listing, an auction site or a reseller can arrive with a seed the seller already knows, packaged to look untouched. Trezor's devices ship in a way intended to make tampering visible, but the cheapest defence is not being in that position at all. This is generic hardware-wallet advice rather than a criticism of Trezor, and it is skipped often enough to be worth the sentence.
Who it suits. Someone who wants a device whose security claims can be independently verified, who is willing to buy a current model rather than the cheapest one, and who will set up a passphrase deliberately and record it as carefully as the seed. Someone who wants to buy a device, write twelve words down and never think about it again will be fine with it too — but should buy a Safe 3 or Safe 5 rather than a Trezor One, because the older device's security assumes a passphrase that this person is not going to set.
Good for
- Open-source firmware and hardware
- Long, public track record
- Passphrase support done properly
- Broad coin coverage in one app
Watch out for
- Older models have no secure element
- Two customer-data breaches, both leading to phishing
- Physical access matters without a passphrase
- Buy direct, never from a marketplace
Visit Trezor → Commercial link
This listing is our own opinion. We are not affiliated with Trezor beyond any commercial relationship disclosed above, we never take custody of your assets, and nothing here is financial advice. Verify anything that matters against the company's own site before acting on it.