Hardware wallets compared: 18 devices, sourced facts
We read each maker's own pages, code repositories, audit reports and incident notices, and put the facts side by side. No sponsors, no affiliate links, no ranking by who pays most. We do not tell you which one to buy.
What this page can and cannot tell you
- A hardware wallet protects keys, not decisions. Most losses come from a recovery phrase typed into a fake site or app, a fake support contact, or a fake device. No device on this page prevents that.
- Record length is not a ranking. A long list of disclosed weaknesses can mean a device has been studied hard by researchers. A short list can mean nobody has looked yet. "None found" is not proof of absence.
- Some research is by competitors. Several disclosed weaknesses were found by another maker's research team. We label it each time and cite the affected company's own statement where we found one.
What the facts add up to
Every figure is counted from the table below, by a fixed rule. Nobody picks a winner.
18 devices, same questions
Every fact comes from the maker's own pages or a named independent source, read on 11 Oct 2026. "n/v" means we could not verify it. Click a device for the sources and what is missing.
Prices are list prices before promotions, read on the maker's own store; many store pages do not show them to automated readers, hence n/v. "Weaknesses recorded" counts publicly disclosed problems with the device or its firmware since 2020 (older ones are shown on the page with their date), whatever their severity. Rules and firmware change; confirm on the maker's site before you buy. Education only, not investment advice.
Audits and bug bounties
An audit covers a version and a scope at a date, and does not certify the device today. We list only audits we could find a source for. A missing audit here means we did not find one.
Six habits that matter more than the model
- Buy from the maker's own store or a listed reseller. A device from a marketplace listing can be tampered with or a copy.
- Create the recovery phrase on the device. Never accept a phrase that came on a card in the box.
- Never type the phrase into a computer, phone, website or support chat. The device only ever asks for it when you restore.
- Test the recovery before you move real money. Wipe it, restore from the backup, check the same addresses appear.
- Know what a passphrase does. It adds a hidden wallet and also a way to lose access forever if you forget it.
- Treat any email that says your device is at risk as a phish. Makers have been impersonated after breaches; check on the official site.
Hardware wallet questions
Is a hardware wallet safe?
It is safer than keeping a seed phrase on a connected computer or phone, because the keys are generated and used inside a separate device. It is not risk-free. Devices have had disclosed weaknesses, some brands have had data breaches and phishing campaigns, and most losses come from people typing a recovery phrase into a website or app. We record what has been published about each device and do not give a yes or no.
Which one should I buy?
We do not recommend a device. The right choice depends on what you hold (Bitcoin only or many assets), whether you want to sign without any cable, whether you need multisig, how much you value open-source code you can check, and what you are willing to pay. Use the table to see which facts matter for you.
Why are some prices missing?
We publish a price only when we read it on the maker's own page. Several store pages load prices with scripts that automated reading cannot see, so they show n/v here. The price column is a list price before promotions and bundles.
Does a secure element make a wallet safe?
A secure element is a tamper-resistant chip that stores secrets. It raises the cost of a physical attack, but it does not protect against typing your phrase into a phishing page. Two devices in our list have no physical secure element by design, and some secure-element designs have had disclosed attacks. Read the weaknesses column and each device page.
What about the company incidents column?
These are events that affected the maker or its customers, such as a marketing-database leak or a newsletter-provider breach, and they are listed on every device of that brand. They are not weaknesses of the device itself, and a longer list can also mean a brand is better documented, not worse. Compare them with care.
How we work
We take no money from wallet makers and use no affiliate links. We read primary pages first and say what we could not verify. See how we check. If a maker believes something is wrong, tell us and we will correct it with a source.