Trezor Safe 3: what the sources say
Current 2 disclosed weaknesses 4 company incidents
The questions, with sources
"n/v" or "not verified" means we could not confirm it from a source we could read. Maker claims are marked as such. Confirm on the maker's site before you buy. Education only, not investment advice.
Five facts
- Safe 3 uses an OPTIGA Trust M (V3) secure element described by Trezor as EAL6+ certified [source 4].
- Ledger Donjon reported a voltage-glitch bypass of Safe 3 authenticity and firmware-hash checks on 2024-11-12; Trezor says no key or PIN was extracted and the Safe 5 is not affected [source 6].
- Trezor listed the Safe 3 at 79 EUR / 79 USD at launch in October 2023 [source 19].
- Multi-share Backup (SLIP-39) is supported on Safe 3 [source 15].
- Trezor runs a bug bounty paying 500 to 100,000 USD [source 14].
Audits
- 2024-11 Ledger Donjon (independent research by a competitor's team). Scope: Safe 3 evaluation / supply-chain countermeasures source
Publicly disclosed weaknesses
- 2024-11-12 Ledger Donjon (a competitor's research team) reported voltage-glitching on the Safe 3 microcontroller that bypassed the authenticity check and firmware-hash check (supply-chain countermeasures). Trezor states no private key or PIN was extracted and the Secure Element protects against seed extraction by glitching. Trezor says the Safe 5 is not affected (newer microcontroller). Funds lost: no. Fix status not verified source
- 2025-09-24 Trezor security portal entry 'Side-channel in BIP-39 mnemonic processing when unlocked'; the listing does not name affected models or the reporter. Funds lost: not verified. Fixed source
Disclosed weaknesses are listed whatever their severity. "Funds lost" is what the sources say. "Fixed" means the source states a fix exists, which only helps if you update.
Incidents at the maker or its service providers
- 2024-01-17 Unauthorized access to a third-party support ticketing portal exposed names/nicknames and email addresses of about 66,000 users who had contacted support; at least 41 users received phishing messages asking for their seed phrase. Customer funds lost: no. Outcome: Trezor disclosed on 2024-01-20 and emailed affected users; stated no user assets were compromised. source
- 2024-03-20 Trezor's official X account was compromised and used to promote a fake token presale with drainer links; a third-party researcher reported about 8,100 USD taken from Trezor's own Zapper account. Customer funds lost: not verified. Outcome: Trezor confirmed a security incident and warned users; reported customer losses not established in the source. source
- 2025-06-23 Attackers abused Trezor's support contact form to send phishing emails that appeared to come from Trezor support. Customer funds lost: no. Outcome: Trezor said no access to its systems or user data occurred; phishing site taken down; no fund loss reported in the source. source
- 2026-09-09 Breach of third-party email provider Brevo exposed Trezor's opt-in newsletter list (about 347,000 addresses) and phishing emails posing as a security alert were sent; about 2,500 users clicked the link per the report. Customer funds lost: not verified. Outcome: Trezor took the phishing domain down within 20 minutes and suspended the Brevo account; the source reports no fund loss figure. source
These affect the company or its customers and apply to every device of the brand. They are not weaknesses of this device.
Questions about Trezor Safe 3
Is Trezor Safe 3 safe?
We do not give a yes or no, because safety depends on what you need to protect and on facts that change. We found 2 publicly disclosed weaknesses and 4 company incidents in our search. Read the sources above before you buy.
Does Trezor Safe 3 need an internet connection?
Signing happens on the device. How the device talks to your phone or computer depends on its connections: USB. The companion app or software that builds the transaction is online.
Who found the weaknesses listed for Trezor Safe 3?
The page names who disclosed each one when the source does. Several were found by a competing maker's research team or by independent security firms. We cite the affected company's own statement where we found one, and label press-only reports.
Where this comes from
- [1] Trezor Safe 3 product page accessed 2026-10-11
- [4] Secure element in Trezor Safe 3 (Trezor Learn) accessed 2026-10-11
- [5] Trezor security portal: Donjon's Trezor Safe 3 evaluation accessed 2026-10-11
- [6] Trezor blog: Multi-layer defense against supply chain attacks accessed 2026-10-11
- [7] Cointelegraph: Trezor resolves security flaw identified by Ledger accessed 2026-10-11
- [12] Trezor Learn: past security issues accessed 2026-10-11
- [13] Trezor docs: reproducible build accessed 2026-10-11
- [14] Trezor Bug Bounty Program Terms accessed 2026-10-11
- [15] Trezor Learn: Multi-share Backup on Trezor accessed 2026-10-11
- [16] Trezor Safe 3 guide: introduction accessed 2026-10-11
- [18] Trezor compare page accessed 2026-10-11
- [19] SatoshiLabs: Trezor launches new hardware wallets (Safe 3) accessed 2026-10-11
- [21] Decrypt: Trezor launches Safe 7 (press release) accessed 2026-10-11
- [23] ForkLog: Data breach affects 66,000 Trezor users accessed 2026-10-11
- [24] ForkLog: Trezor's X account hacked to promote scam accessed 2026-10-11
- [25] The Block: Trezor phishing alert, support contact form abused accessed 2026-10-11
- [26] BleepingComputer: Trezor 347,000 users targeted in phishing after Brevo breach accessed 2026-10-11
- [27] GitHub fork of trezor/trezor-firmware (shows GPL-3.0) accessed 2026-10-11
Not verified: Current store price not shown to the fetcher (launch price only). Not verified: warranty terms; Trezor Suite open-source status; exact current store price (trezor.io product pages show no price to the fetcher; github.com/trezor/trezor-firmware could not be opened directly); official repository URL; closed/open status of the Secure Element internal firmware (not stated in sources read). Whether the Safe 3 glitch issue is 'fixed': Trezor says not patched via firmware (per Cointelegraph quote), the security portal lists it as resolved; status left unclear. Cointelegraph's report that the firmware-check bypass applies to Safe 3 and Safe 5 conflicts with Trezor's statement that the Safe 5 is unaffected.
See how we check. To report an error, use corrections and right of reply.