Trading Education Platform SystemSubscribe for FreeSupport
Wallets / Trezor Safe 7
HARDWARE WALLET REALITY CHECK · READ 11 OCT 2026

Trezor Safe 7: what the sources say

Current 4 disclosed weaknesses 4 company incidents 1 not fixed per source

Key facts

The questions, with sources

QuestionWhat the sources saySource
Status
Current — Newest model in the Trezor lineup (announced 2025-10-23); product and compare pages on trezor.io list it on 2026-10-11. Model T3W1.
Company
SatoshiLabs s.r.o. (Trezor), Czech Republic (Prague)
List price
n/v — Official trezor.io product page fetched on 2026-10-11 shows no price to the fetcher; launch press release (2025-10-23) stated 249 USD (249 EUR); current store price not verified.
Secure element
Yes: Dual SE: TROPIC01 (Tropic Square) plus an NDA-free EAL6+ element (Optiga per product page); STM32U5 MCU; EAL6+ for the secondary element (as stated by Trezor); no EAL level stated for TROPIC01
Firmware code
Yes (GPL-3.0 (as shown on a fork of trezor/trezor-firmware; official repo page not opened)); reproducible build: yes. Trezor states open-source firmware and design; reproducible-build docs cover Safe 7 (T3W1). TROPIC01 design described as open to independent review; secondary element firmware not stated.
Companion app
Not verified. Trezor Suite open-source status not verified in this research pass.
—
Connections
USB: USB-C. Bluetooth: yes (encrypted BLE, Trezor Host Protocol with double pairing). NFC: no (not listed). QR: no (not listed). microSD: no (not listed).
Screen
2.5-inch color display, 520 x 380 px; touch: yes
Assets
'1000s' of coins and tokens (maker); Bitcoin-only option: yes (Bitcoin-only version in launch press)
Multisig and PSBT
Not verified. Not verified on pages read.
—
Passphrase
Yes. 'Passphrase Protection' named in product-page FAQ.
Shamir backup (SLIP-39)
Yes. Multi-share Backup (SLIP-39) supported on Safe 7.
Recovery phrase standard
12/20/24-word backups; SLIP-39 multi-share option (maker docs)
Optional recovery service
Not verified. No optional recovery service found in the pages read.
—
FIDO / passkeys
Yes. Compare page lists FIDO2 as a standard feature of all three Safe models.
Bug bounty
Yes

"n/v" or "not verified" means we could not confirm it from a source we could read. Maker claims are marked as such. Confirm on the maker's site before you buy. Education only, not investment advice.

Summary

Five facts

  • Safe 7 combines the TROPIC01 secure element with a second EAL6+ element and offers Bluetooth and a 2.5-inch touchscreen [source 3].
  • Launch press release (2025-10-23) priced it at 249 USD (249 EUR) [source 21].
  • On 2026-06-03 a laser fault-injection attack on TROPIC01 was disclosed; Trezor says it cannot be fixed by firmware update and that funds, PIN and backup are not exposed [source 8].
  • The Block reports Tropic Square says a firmware mitigation (disabling MAINTENANCE mode) closes the main entry point and a hardened silicon revision is expected late 2026 [source 9].
  • Two Safe 7 issues (THP pairing, authenticity proofs) were fixed per the Trezor security portal [sources 10, 11].
Independent checks

Audits

  • 2026-01 Ledger Donjon (independent audit of the TROPIC01 chip, as described by Trezor). Scope: TROPIC01 secure element chip source
Device record

Publicly disclosed weaknesses

  • 2026-06-03 Ledger Donjon, auditing TROPIC01, extracted a subset of chip secrets by laser fault injection and bypassed firmware verification; Tropic Square found a further path affecting PIN-related MAC-and-Destroy. Requires physical possession, decapsulation and lab equipment. Trezor says PIN, funds and backup are not exposed and the chip does not hold keys or backup. Funds lost: no. Not fixed (as of the source) source
  • 2026-06-22 Reported via Trezor security portal: a connected host could complete THP pairing without entering the on-device code by sending degenerate values; such values are now rejected. Funds lost: not verified. Fixed source
  • 2026-08-16 Reported anonymously: authenticity proofs were checked against a combined key set rather than per secure element, so one valid proof could pass all three checks; each proof is now bound to its own element (1,350 USD reward). Funds lost: not verified. Fixed source
  • 2025-09-24 Trezor security portal entry 'Side-channel in BIP-39 mnemonic processing when unlocked'; the listing does not name affected models or the reporter. Funds lost: not verified. Fixed source

Disclosed weaknesses are listed whatever their severity. "Funds lost" is what the sources say. "Fixed" means the source states a fix exists, which only helps if you update.

Company record

Incidents at the maker or its service providers

  • 2024-01-17 Unauthorized access to a third-party support ticketing portal exposed names/nicknames and email addresses of about 66,000 users who had contacted support; at least 41 users received phishing messages asking for their seed phrase. Customer funds lost: no. Outcome: Trezor disclosed on 2024-01-20 and emailed affected users; stated no user assets were compromised. source
  • 2024-03-20 Trezor's official X account was compromised and used to promote a fake token presale with drainer links; a third-party researcher reported about 8,100 USD taken from Trezor's own Zapper account. Customer funds lost: not verified. Outcome: Trezor confirmed a security incident and warned users; reported customer losses not established in the source. source
  • 2025-06-23 Attackers abused Trezor's support contact form to send phishing emails that appeared to come from Trezor support. Customer funds lost: no. Outcome: Trezor said no access to its systems or user data occurred; phishing site taken down; no fund loss reported in the source. source
  • 2026-09-09 Breach of third-party email provider Brevo exposed Trezor's opt-in newsletter list (about 347,000 addresses) and phishing emails posing as a security alert were sent; about 2,500 users clicked the link per the report. Customer funds lost: not verified. Outcome: Trezor took the phishing domain down within 20 minutes and suspended the Brevo account; the source reports no fund loss figure. source

These affect the company or its customers and apply to every device of the brand. They are not weaknesses of this device.

Questions

Questions about Trezor Safe 7

Is Trezor Safe 7 safe?

We do not give a yes or no, because safety depends on what you need to protect and on facts that change. We found 4 publicly disclosed weaknesses, 1 of them not fixed according to the source and 4 company incidents in our search. Read the sources above before you buy.

Does Trezor Safe 7 need an internet connection?

Signing happens on the device. How the device talks to your phone or computer depends on its connections: USB, Bluetooth. The companion app or software that builds the transaction is online.

Who found the weaknesses listed for Trezor Safe 7?

The page names who disclosed each one when the source does. Several were found by a competing maker's research team or by independent security firms. We cite the affected company's own statement where we found one, and label press-only reports.

Sources

Where this comes from

Not verified: Current store price not shown to the fetcher. Not verified: warranty terms; Trezor Suite open-source status; exact current store price (trezor.io product pages show no price to the fetcher; github.com/trezor/trezor-firmware could not be opened directly); official repository URL; closed/open status of the Secure Element internal firmware (not stated in sources read). Whether the TROPIC01 firmware mitigation (MAINTENANCE mode) is deployed in Safe 7 firmware: from The Block only, not confirmed by Trezor; status left 'unfixed'. Secondary element chip maker named as Optiga only on the product page, not in the launch blog.

See how we check. To report an error, use corrections and right of reply.