Trading Education Platform SystemSubscribe for FreeSupport
Wallets / Trezor Safe 3
HARDWARE WALLET REALITY CHECK · READ 11 OCT 2026

Trezor Safe 3: what the sources say

Current 2 disclosed weaknesses 4 company incidents

Key facts

The questions, with sources

QuestionWhat the sources saySource
Status
Current — Product page and compare page on trezor.io list Safe 3 alongside Safe 5 and Safe 7 on 2026-10-11; no discontinuation notice found. Models T2B1/T3B1 per docs. Newer models in lineup: Safe 5, Safe 7.
Company
SatoshiLabs s.r.o. (Trezor), Czech Republic (Prague)
List price
n/v — Official trezor.io product page fetched on 2026-10-11 shows no price to the fetcher; launch price announced 2023-10-12 was 79 EUR / 79 USD (SatoshiLabs press); current store price not verified.
Secure element
Yes: OPTIGA Trust M (V3), Infineon; Common Criteria EAL6+ (as stated by Trezor)
Firmware code
Yes (GPL-3.0 (as shown on a fork of trezor/trezor-firmware; official repo page not opened)); reproducible build: yes. Trezor states open-source security and design; reproducible-build documentation covers Safe 3 (T2B1/T3B1); local builds are unsigned so comparison requires zeroing signature bytes. Secure Element internal firmware: not stated in sources read.
Companion app
Not verified. Trezor Suite open-source status not verified in this research pass.
—
Connections
USB: USB-C. Bluetooth: no (not listed). NFC: no (not listed). QR: no (not listed). microSD: no (not listed).
Screen
0.96-inch monochrome OLED, 128 x 64 px; touch: no (buttons)
Assets
'1000s' of coins and tokens (maker); launch press cited more than 7,000; Bitcoin-only option: yes (Bitcoin-only edition/firmware exists)
Multisig and PSBT
Not verified. Not verified on pages read.
—
Passphrase
Yes. 'PIN & passphrase protection'.
Shamir backup (SLIP-39)
Yes. Multi-share Backup based on SLIP-39 supported on Safe 3.
Recovery phrase standard
BIP39-style 12/20/24-word backups; SLIP-39 multi-share option
Optional recovery service
Not verified. No optional recovery service found in the pages read.
—
FIDO / passkeys
Yes. 'FIDO2 Standard' listed.
Bug bounty
Yes

"n/v" or "not verified" means we could not confirm it from a source we could read. Maker claims are marked as such. Confirm on the maker's site before you buy. Education only, not investment advice.

Summary

Five facts

  • Safe 3 uses an OPTIGA Trust M (V3) secure element described by Trezor as EAL6+ certified [source 4].
  • Ledger Donjon reported a voltage-glitch bypass of Safe 3 authenticity and firmware-hash checks on 2024-11-12; Trezor says no key or PIN was extracted and the Safe 5 is not affected [source 6].
  • Trezor listed the Safe 3 at 79 EUR / 79 USD at launch in October 2023 [source 19].
  • Multi-share Backup (SLIP-39) is supported on Safe 3 [source 15].
  • Trezor runs a bug bounty paying 500 to 100,000 USD [source 14].
Independent checks

Audits

  • 2024-11 Ledger Donjon (independent research by a competitor's team). Scope: Safe 3 evaluation / supply-chain countermeasures source
Device record

Publicly disclosed weaknesses

  • 2024-11-12 Ledger Donjon (a competitor's research team) reported voltage-glitching on the Safe 3 microcontroller that bypassed the authenticity check and firmware-hash check (supply-chain countermeasures). Trezor states no private key or PIN was extracted and the Secure Element protects against seed extraction by glitching. Trezor says the Safe 5 is not affected (newer microcontroller). Funds lost: no. Fix status not verified source
  • 2025-09-24 Trezor security portal entry 'Side-channel in BIP-39 mnemonic processing when unlocked'; the listing does not name affected models or the reporter. Funds lost: not verified. Fixed source

Disclosed weaknesses are listed whatever their severity. "Funds lost" is what the sources say. "Fixed" means the source states a fix exists, which only helps if you update.

Company record

Incidents at the maker or its service providers

  • 2024-01-17 Unauthorized access to a third-party support ticketing portal exposed names/nicknames and email addresses of about 66,000 users who had contacted support; at least 41 users received phishing messages asking for their seed phrase. Customer funds lost: no. Outcome: Trezor disclosed on 2024-01-20 and emailed affected users; stated no user assets were compromised. source
  • 2024-03-20 Trezor's official X account was compromised and used to promote a fake token presale with drainer links; a third-party researcher reported about 8,100 USD taken from Trezor's own Zapper account. Customer funds lost: not verified. Outcome: Trezor confirmed a security incident and warned users; reported customer losses not established in the source. source
  • 2025-06-23 Attackers abused Trezor's support contact form to send phishing emails that appeared to come from Trezor support. Customer funds lost: no. Outcome: Trezor said no access to its systems or user data occurred; phishing site taken down; no fund loss reported in the source. source
  • 2026-09-09 Breach of third-party email provider Brevo exposed Trezor's opt-in newsletter list (about 347,000 addresses) and phishing emails posing as a security alert were sent; about 2,500 users clicked the link per the report. Customer funds lost: not verified. Outcome: Trezor took the phishing domain down within 20 minutes and suspended the Brevo account; the source reports no fund loss figure. source

These affect the company or its customers and apply to every device of the brand. They are not weaknesses of this device.

Questions

Questions about Trezor Safe 3

Is Trezor Safe 3 safe?

We do not give a yes or no, because safety depends on what you need to protect and on facts that change. We found 2 publicly disclosed weaknesses and 4 company incidents in our search. Read the sources above before you buy.

Does Trezor Safe 3 need an internet connection?

Signing happens on the device. How the device talks to your phone or computer depends on its connections: USB. The companion app or software that builds the transaction is online.

Who found the weaknesses listed for Trezor Safe 3?

The page names who disclosed each one when the source does. Several were found by a competing maker's research team or by independent security firms. We cite the affected company's own statement where we found one, and label press-only reports.

Sources

Where this comes from

Not verified: Current store price not shown to the fetcher (launch price only). Not verified: warranty terms; Trezor Suite open-source status; exact current store price (trezor.io product pages show no price to the fetcher; github.com/trezor/trezor-firmware could not be opened directly); official repository URL; closed/open status of the Secure Element internal firmware (not stated in sources read). Whether the Safe 3 glitch issue is 'fixed': Trezor says not patched via firmware (per Cointelegraph quote), the security portal lists it as resolved; status left unclear. Cointelegraph's report that the firmware-check bypass applies to Safe 3 and Safe 5 conflicts with Trezor's statement that the Safe 5 is unaffected.

See how we check. To report an error, use corrections and right of reply.