Trading Education Platform SystemSubscribe for FreeSupport
Home / Wallets
HARDWARE WALLET REALITY CHECK · READ 11 OCT 2026

Hardware wallets compared: 18 devices, sourced facts

We read each maker's own pages, code repositories, audit reports and incident notices, and put the facts side by side. No sponsors, no affiliate links, no ranking by who pays most. We do not tell you which one to buy.

Read this first

What this page can and cannot tell you

  • A hardware wallet protects keys, not decisions. Most losses come from a recovery phrase typed into a fake site or app, a fake support contact, or a fake device. No device on this page prevents that.
  • Record length is not a ranking. A long list of disclosed weaknesses can mean a device has been studied hard by researchers. A short list can mean nobody has looked yet. "None found" is not proof of absence.
  • Some research is by competitors. Several disclosed weaknesses were found by another maker's research team. We label it each time and cite the affected company's own statement where we found one.
At a glance

What the facts add up to

Every figure is counted from the table below, by a fixed rule. Nobody picks a winner.

Firmware open source with a reproducible build7 of 18BitBox02 (Multi and Bitcoin-only editions) · Blockstream Jade Plus · Foundation Passport · SeedSigner · Trezor Safe 3 · Trezor Safe 5 · Trezor Safe 7Anyone can check that the published code matches the firmware, as stated in the sources
Physical secure element15 of 18Without one: Blockstream Jade Plus, SeedSignerChip and certification as stated by the maker; SE not verified for the others
Signs through QR codes, no data cable9 of 18Blockstream Jade Plus · Coldcard Q · Ellipal Titan 2.0 · Foundation Passport · Keystone 3 Pro · NGRAVE ZERO · OneKey Pro · SafePal S1 Pro · SeedSignerAir-gapped signing: the device does not connect to the computer or phone for signing
Lowest verified list price (not DIY)$54.90Tangem WalletList price on the maker's own page, before promotions. SeedSigner is a do-it-yourself build, costs vary
Weakness recorded as not fixed2 of 18Tangem Wallet · Trezor Safe 7Publicly disclosed weakness whose source says it has no firmware fix. Read the device page
On sale as current model16 of 18Superseded or discontinued: Coldcard Mk4, Foundation PassportPer the maker's own lineup on 11 Oct 2026
Side by side

18 devices, same questions

Every fact comes from the maker's own pages or a named independent source, read on 11 Oct 2026. "n/v" means we could not verify it. Click a device for the sources and what is missing.

DeviceStatusList priceSecure elementFirmwareConnectionsMultisig / passphraseWeaknesses recordedCompany incidents
Current
n/v
Yes
Open source · reproducible build
USB
Yes / Yes
2
1
Current
$149
No
Open source · reproducible build
USB · Bluetooth · QR
Yes / Yes
2
1
Superseded
n/v
Yes
Partly open · reproducible build
USB
Yes / Yes
6
3
Current
n/v
Yes
Partly open · reproducible build
USB · QR
Yes / Yes
5
3
Current
€149 / $169
Yes
n/v
QR
n/v / Yes
1
2
Discontinued
n/v
Yes
Open source · reproducible build
QR
Yes / Yes
1
None found
Current
$149
Yes
Partly open
USB · QR
Yes / Yes
2
None found
Current
n/v
Yes
Partly open
USB · Bluetooth · NFC
Yes / Yes
None found
4
Current
n/v
Yes
Partly open
USB
Yes / n/v
1
4
Current
n/v
Yes
Partly open
USB · Bluetooth
Yes / n/v
1
4
Current
$398
n/v
Partly open
QR
n/v / Yes
None found
None found
Current
$278
Yes
Partly open
USB · Bluetooth · NFC · QR
Yes / Yes
1
None found
Current
$89.99
Yes
Partly open
QR
n/v / Yes
1
1
Current
$50
No
Open source · reproducible build
QR
Yes / Yes
None found
None found
Current
$54.90
Yes
n/v
NFC
n/v / Yes
1 (1 not fixed)
1
Current
n/v
Yes
Open source · reproducible build
USB
n/v / Yes
2
4
Current
n/v
Yes
Open source · reproducible build
USB
n/v / Yes
1
4
Current
n/v
Yes
Open source · reproducible build
USB · Bluetooth
n/v / Yes
4 (1 not fixed)
4

Prices are list prices before promotions, read on the maker's own store; many store pages do not show them to automated readers, hence n/v. "Weaknesses recorded" counts publicly disclosed problems with the device or its firmware since 2020 (older ones are shown on the page with their date), whatever their severity. Rules and firmware change; confirm on the maker's site before you buy. Education only, not investment advice.

Checks and incentives

Audits and bug bounties

DeviceIndependent audits we foundBug bounty
Census Labs (plus unnamed third-party firms as consultants)
Yes
Not named on Coinkite's disclosure page (listed as… (2022-03)
Yes
none found
Yes
none found
Yes
Keylabs (2021-04)
n/v
SlowMist (2023-09); Keylabs (2023-11); Offside Labs; Least Authority (2025-03)
Yes
Synacktiv (2023-09); Unnamed external security labs (per Ledger)
Yes
Synacktiv (2023-09); Unnamed external security labs (per Ledger)
Yes
Synacktiv (2023-09); Unnamed external security labs (per Ledger)
Yes
none found
n/v
Not named on maker page (SlowMist inferred from report…
n/v
none found
n/v
none found
n/v
Cure53 (2026-03); Riscure (2023-12); Kudelski Security (2018-12)
Yes
Ledger Donjon (independent research by a competitor's team) (2024-11)
Yes
none found
Yes
Ledger Donjon (independent audit of the TROPIC01 chip, as… (2026-01)
Yes

An audit covers a version and a scope at a date, and does not certify the device today. We list only audits we could find a source for. A missing audit here means we did not find one.

Before you buy

Six habits that matter more than the model

  • Buy from the maker's own store or a listed reseller. A device from a marketplace listing can be tampered with or a copy.
  • Create the recovery phrase on the device. Never accept a phrase that came on a card in the box.
  • Never type the phrase into a computer, phone, website or support chat. The device only ever asks for it when you restore.
  • Test the recovery before you move real money. Wipe it, restore from the backup, check the same addresses appear.
  • Know what a passphrase does. It adds a hidden wallet and also a way to lose access forever if you forget it.
  • Treat any email that says your device is at risk as a phish. Makers have been impersonated after breaches; check on the official site.
Questions

Hardware wallet questions

Is a hardware wallet safe?

It is safer than keeping a seed phrase on a connected computer or phone, because the keys are generated and used inside a separate device. It is not risk-free. Devices have had disclosed weaknesses, some brands have had data breaches and phishing campaigns, and most losses come from people typing a recovery phrase into a website or app. We record what has been published about each device and do not give a yes or no.

Which one should I buy?

We do not recommend a device. The right choice depends on what you hold (Bitcoin only or many assets), whether you want to sign without any cable, whether you need multisig, how much you value open-source code you can check, and what you are willing to pay. Use the table to see which facts matter for you.

Why are some prices missing?

We publish a price only when we read it on the maker's own page. Several store pages load prices with scripts that automated reading cannot see, so they show n/v here. The price column is a list price before promotions and bundles.

Does a secure element make a wallet safe?

A secure element is a tamper-resistant chip that stores secrets. It raises the cost of a physical attack, but it does not protect against typing your phrase into a phishing page. Two devices in our list have no physical secure element by design, and some secure-element designs have had disclosed attacks. Read the weaknesses column and each device page.

What about the company incidents column?

These are events that affected the maker or its customers, such as a marketing-database leak or a newsletter-provider breach, and they are listed on every device of that brand. They are not weaknesses of the device itself, and a longer list can also mean a brand is better documented, not worse. Compare them with care.

Independence

How we work

We take no money from wallet makers and use no affiliate links. We read primary pages first and say what we could not verify. See how we check. If a maker believes something is wrong, tell us and we will correct it with a source.