Skip to content

October 3, 2026

CRYPTO·COINBEAT

Journalism for the digital-asset economy

Ratings / Custody & Wallets

Best Hardware Wallets

Ranked on what the secure element actually does, how open the firmware is, and how recovery fails.

8 services ratedLast verified August 15, 2026Methodology

Security architecture
35%
Secure element, PIN and passphrase handling, and resistance to physical extraction.
Openness
25%
How much of the firmware and hardware design can be independently reviewed.
Recovery model
20%
Seed standard, backup options and what happens when the device is lost or bricked.
Usability
20%
Day-to-day signing experience, chain support and quality of the companion software.

The table at a glance

8 rated · top score 9.2 · tap a row for the full entry

  1. 01Trezor Safe 5Open firmware with a secure element, without a compromise on either9.2
  2. 02BitBox02A minimal, auditable device that does exactly one thing well9.1
  3. 03Foundation PassportBitcoin users who want air-gapped signing with a usable interface8.8
  4. 04Keystone 3 ProAir-gapped signing with a large screen and multi-chain support8.8
  5. 05Blockstream JadeBudget-conscious Bitcoin holders who still want open source8.5
  6. 06Ledger Nano XBroadest asset and application support8.3
  7. 07TangemPeople who will never write down a seed phrase8.0
  8. 08Coldcard Mk4Air-gapped Bitcoin signing — on a seed not generated under the 2021 firmware6.6
Editor’s pickRank 01

Trezor Safe 5

Open firmware with a secure element, without a compromise on either

Trezor's Safe line finally pairs the company's fully open firmware with a proper secure element, closing the gap that made earlier models vulnerable to physical extraction. The colour touchscreen makes verifying what you sign genuinely easier.

In its favour

  • Firmware is fully open source and independently reviewable
  • Secure element protects against physical seed extraction
  • Excellent transaction display and clear-signing support

Against it

  • Fewer supported chains than the market leader
  • Older Trezor models remain vulnerable to physical attack
  • VendorSatoshiLabs, Czechia
  • FirmwareOpen source
  • Secure elementYes
Score9.2

The weighted mean of the 4 axes below — each read from the fact printed beside it.

Strongest
Openness9.6
Weakest
Usability8.8

Scorecard — and what it was read from

Security architecture
9.2
Pairs a certified secure element with PIN verification inside the element; published research showed earlier Trezor models without a secure element were vulnerable to physical seed extraction, which this line was built to address.
Openness
9.6
Firmware is published under an open licence with reproducible builds, and the vendor runs a public vulnerability disclosure process.
Recovery model
9.0
Standard BIP-39 seed with optional passphrase plus SLIP-39 share-based backup; recovery works on any compatible wallet.
Usability
8.8
Colour touchscreen decodes transaction details before signing; supported by the major third-party wallets.

Read the full Trezor Safe 5 review →

The rest of the table

A minimal, auditable device that does exactly one thing well

A deliberately small device with fully open firmware, a dual-chip design and the cleanest backup workflow in the category via microSD. It supports fewer chains than its rivals because it chose to.

In its favour

  • Open firmware with a dual-chip security design
  • microSD backup that is simple to execute correctly
  • Bitcoin-only firmware option minimises attack surface

Against it

  • Limited chain support compared with Ledger
  • Companion app is functional rather than rich
  • VendorShift Crypto, Switzerland
  • FirmwareOpen source
  • Secure elementYes, dual-chip

Scorecard — and what it was read from

Security architecture
9.2
Dual-chip design pairing a general microcontroller with a secure element, with PIN attempts and attack counters enforced in hardware; third-party security reviews published.
Openness
9.4
Firmware fully open source with documented reproducible builds.
Recovery model
9.0
BIP-39 seed plus an encrypted microSD backup written at setup; recovery possible from either the card or the words.
Usability
8.6
Small screen with an explicit confirmation for every operation; strong desktop app, narrower chain support than the market leader.

Full BitBox02 review →

Score9.1

Bitcoin users who want air-gapped signing with a usable interface

Air-gapped Bitcoin signing with fully open hardware and firmware, a supply chain the vendor documents publicly, and an interface that is far friendlier than the security-maximalist alternatives. Bitcoin only, and priced accordingly.

In its favour

  • Open hardware and firmware with documented supply chain
  • Air-gapped QR or microSD signing
  • Best usability among Bitcoin-only air-gapped devices

Against it

  • Bitcoin only
  • Premium price relative to the category
  • VendorFoundation Devices, US
  • FirmwareOpen source
  • AssetsBitcoin only

Scorecard — and what it was read from

Security architecture
9.2
Secure element with the PIN verified in hardware and no data-carrying USB path; security documentation and supply-chain provenance published.
Openness
9.2
Hardware designs and firmware are both published under open licences.
Recovery model
8.6
BIP-39 with optional passphrase and microSD backup; recovery on any compatible Bitcoin wallet.
Usability
8.0
Bitcoin only; colour screen and camera make QR signing straightforward with the main Bitcoin wallets.

Full Foundation Passport review →

Score8.8

Air-gapped signing with a large screen and multi-chain support

Fully air-gapped QR signing on a phone-sized touchscreen with three secure elements and open firmware, which is the strongest combination of security and readability in the table. The device is bulky and the battery is one more thing to fail.

In its favour

  • QR-based air-gap with no USB, Bluetooth or NFC required
  • Large screen makes complex transactions genuinely readable
  • Open firmware with three independent secure elements

Against it

  • Physically large with a battery that ages
  • QR workflow is slower than a cable for frequent signing
  • VendorKeystone
  • FirmwareOpen source
  • Air-gapQR only

Scorecard — and what it was read from

Security architecture
9.0
Three secure elements with PIN and biometrics handled in hardware; fully air-gapped, with no USB data path, Bluetooth or NFC signing.
Openness
8.8
Firmware published under an open licence with reproducible builds documented.
Recovery model
8.6
BIP-39 with optional passphrase plus shard-based backup; recovery works on standard wallets.
Usability
8.8
Large touchscreen decodes transactions clearly; QR signing is supported by the major software wallets but slower than a cable.

Full Keystone 3 Pro review →

Score8.8

Budget-conscious Bitcoin holders who still want open source

Fully open source, inexpensive, and integrated with Blockstream's own wallet and Liquid infrastructure. It uses a virtual secure element rather than a dedicated chip, which is a real architectural difference at this price.

In its favour

  • Entirely open source hardware and firmware
  • Lowest price of any credible device here
  • Air-gapped QR mode supported

Against it

  • Virtual secure element rather than a dedicated chip
  • Best experience requires the vendor's own wallet software
  • VendorBlockstream
  • FirmwareOpen source
  • Secure elementVirtual

Scorecard — and what it was read from

Security architecture
8.4
Uses a firmware-implemented virtual secure element with an anti-exfiltration protocol rather than a dedicated certified chip; the design and its trade-offs are published.
Openness
9.4
Hardware and firmware are fully open source with reproducible builds.
Recovery model
8.0
BIP-39 with optional passphrase; recovery on any compatible wallet.
Usability
8.0
Small screen; best supported by the vendor's own wallet, with third-party support available.

Full Blockstream Jade review →

Score8.5

Broadest asset and application support

The best-supported device in the industry, with certified secure elements and integrations almost everywhere you might need to sign. The 2023 recovery-service announcement revealed that the firmware could always export key material under the right instruction, and trust in the category has not fully recovered.

In its favour

  • Certified secure element with a strong physical-attack record
  • Widest chain and application support of any device
  • Polished companion software with clear-signing on major protocols

Against it

  • Firmware is closed source; the recovery-service episode remains contentious
  • A 2020 customer-data breach exposed buyers to targeted phishing
  • VendorLedger, France
  • FirmwareClosed source
  • Secure elementYes, certified

Scorecard — and what it was read from

Security architecture
8.8
Certified secure element with the PIN verified inside it and no published extraction of a seed from a current model; the 2023 Ledger Recover announcement confirmed the firmware can be built to export encrypted key shards, which is an architectural fact about closed firmware.
Openness
6.6
Firmware is closed source and only parts of the surrounding stack are published, so builds cannot be independently reproduced.
Recovery model
8.6
BIP-39 seed with optional passphrase, plus an optional paid recovery service using encrypted shards held by third parties; a 2020 e-commerce database breach exposed customer contact details and produced years of targeted phishing.
Usability
9.4
Widest chain and application support of any device, with clear-signing on major protocols and a mature companion app.

Full Ledger Nano X review →

Score8.3

People who will never write down a seed phrase

A card you tap against a phone, with the key generated inside a certified chip and backed up by issuing two or three identical cards instead of a seed phrase. It solves the backup problem that actually loses people their coins, at the cost of a very different threat model.

In its favour

  • No seed phrase to lose, photograph or mistype
  • Certified secure chip with a long stated lifespan
  • Genuinely simple for non-technical holders

Against it

  • No screen — you verify transactions on the phone, not the device
  • Backup means physically distributing duplicate cards
  • VendorTangem, Switzerland
  • Form factorNFC card
  • BackupDuplicate cards, no seed phrase

Scorecard — and what it was read from

Security architecture
8.0
Keys are generated inside a certified chip with no interface to export the private key; the card has no screen, so transaction details are verified on the paired phone rather than on the device.
Openness
7.4
The app is published and card firmware can be attested through the app, but the firmware itself is closed and audited by a named third party.
Recovery model
7.6
No seed phrase by default: backup is a set of two or three cards holding the same key, so recovery depends on physically holding another card; an optional seed-phrase mode exists.
Usability
9.2
Tap-to-sign on a phone with no cable or battery; broad chain list, but the absence of a device screen limits what can be verified.

Full Tangem review →

Score8.0

Air-gapped Bitcoin signing — on a seed not generated under the 2021 firmware

The design is still the most security-focused in the category — air-gapped operation, duress PINs, dual secure elements, a threat model documented in unusual detail — and a 2021 firmware bug nonetheless produced the largest hardware-wallet loss ever recorded, roughly $116m brute-forced out of weakened seeds from July 2026. Design intent and shipped record are different facts, and this table scores the record.

In its favour

  • True air-gapped signing without ever connecting to a computer
  • Duress PINs, decoy wallets and anti-tamper features
  • Open firmware source and a published threat model

Against it

  • A 2021 firmware entropy bug caused ~$116m of brute-force losses from July 2026
  • Bitcoin only, with a steep learning curve
  • VendorCoinkite, Canada
  • AssetsBitcoin only
  • Air-gapmicroSD and NFC

Scorecard — and what it was read from

Security architecture
4.5
Two secure elements from different manufacturers with the PIN verified in hardware, duress PINs and a threat model published in detail — and, from 30 July 2026, the largest hardware-wallet loss on record: roughly 1,816 BTC, about $116m, drained from more than 5,200 addresses in four waves. The cause was a March 2021 firmware bug that cut seed entropy from 128 bits to as little as 40, making those keys brute-forceable with no physical access to the device.
Openness
9.0
Firmware source is published under a licence restricting commercial reuse, and builds are reproducible.
Recovery model
6.5
BIP-39 with optional passphrase and encrypted microSD backup, and fully air-gapped PSBT recovery; seeds generated under the affected 2021 firmware have to be regenerated and the funds moved, which is the vendor's own guidance.
Usability
7.4
Bitcoin only; monochrome display and PSBT workflows that assume familiarity with coin control.

Full Coldcard Mk4 review →

Score6.6

↑ Back to the table at a glance

What the record supports

For most people a Trezor Safe or a BitBox02 gets the balance right: open firmware, a secure element and software that does not fight you. Coldcard's July 2026 losses are the cautionary case of the year — the strongest threat model in the category undone by a firmware bug shipped five years earlier, which is why this table scores the record rather than the design. Ledger still has the best chain coverage, and the recovery-service episode permanently changed what its customers believe it can do with their keys.

A conclusion drawn from the facts above, and the only part of this page that is.

How a score is read

Each axis is read off the same five bands. They describe what is on the record, not how impressed we are.

9.0–10
Documented and independently verifiable
The claim is evidenced by a published record a third party can check — an attestation, an on-chain contract, a regulator's register — and nothing adverse is on file.
8.0–8.9
Documented, with gaps
Evidence exists but is partial, dated, or covers only part of what the axis measures.
7.0–7.9
Self-reported only
The operator publishes the information and no independent party has verified it.
6.0–6.9
Adverse event on record
A recorded incident, enforcement action or failure that has since been resolved, remediated or repaid.
Below 6
Undocumented or unresolved
No published evidence, or an incident with no resolution on the record. An absence of evidence is scored as an absence.

How we scored this table

A hardware wallet has one job: keep a key inside a device that never connects to anything, and show honestly what is about to be signed. This table records the facts that bear on that — what the secure element protects, what is published as source, which seed standard is used, and what the device displays before it signs.

Published attack research counts more than certification badges. Where researchers have extracted a seed from a device, the finding and the vendor's response are on the page; where a vendor's own announcement revealed an architectural capability, that is recorded as an architectural fact rather than as an opinion about intent.

Openness is recorded as what can actually be reviewed: firmware licence, whether hardware designs are published, and whether builds are reproducible. Every certified secure element on the market is closed by contract, so that alone is not counted against a device — an unreviewable application firmware is.

  • Every score on this page carries the fact it was read from, printed beside the bar.
  • Standard seed formats are recorded as such; proprietary recovery schemes are recorded as proprietary.
  • Vendor response to a disclosed vulnerability is part of the security record.

What each axis records, and where the facts come from

Security architecture35%
Whether a certified secure element is present and what it protects; whether the PIN is verified inside it; how the passphrase is handled; published third-party physical-attack research and the vendor's response to it.
Source: Vendor security documentation and certification levels, published attack research and disclosures.
Openness25%
Which parts of the firmware and hardware are published under an open licence, and whether builds are reproducible by a third party.
Source: Public source repositories and licences, reproducible-build documentation.
Recovery model20%
Which seed standard is used, what backup options exist, and what happens when the device is lost, bricked or the vendor stops trading.
Source: Vendor recovery documentation, standards support such as BIP-39 and SLIP-39, firmware release notes.
Usability20%
What the device shows before signing and whether transactions are decoded into readable terms; which chains and third-party wallets it works with.
Source: Device firmware behaviour on test transactions, published integration lists.

Frequently asked questions

Do I actually need a hardware wallet?+

If your holdings would hurt to lose and you interact with anything on-chain, yes. The realistic threat is not a state actor; it is malware or a malicious signature request on a machine you also use for everything else.

Does a hardware wallet protect me from signing a malicious transaction?+

Only if you read the screen. The device shows what you are approving; it cannot know that a contract is hostile. Clear-signing support — where the device decodes the transaction into readable terms — is the feature that helps here.

Is a closed-source secure element a dealbreaker?+

Not necessarily. Every certified secure element on the market is closed by contract. What matters is whether the application firmware around it is open, and whether the vendor has been honest about what the chip can be asked to do.

What is the safest way to back up a seed phrase?+

Metal, in two geographically separated places, never photographed and never typed into anything. Multi-share schemes reduce single-point loss but add a procedure you must still be able to execute under stress years later.

More in Custody & Wallets