Trezor Safe 7: what the sources say
Current 4 disclosed weaknesses 4 company incidents 1 not fixed per source
The questions, with sources
"n/v" or "not verified" means we could not confirm it from a source we could read. Maker claims are marked as such. Confirm on the maker's site before you buy. Education only, not investment advice.
Five facts
- Safe 7 combines the TROPIC01 secure element with a second EAL6+ element and offers Bluetooth and a 2.5-inch touchscreen [source 3].
- Launch press release (2025-10-23) priced it at 249 USD (249 EUR) [source 21].
- On 2026-06-03 a laser fault-injection attack on TROPIC01 was disclosed; Trezor says it cannot be fixed by firmware update and that funds, PIN and backup are not exposed [source 8].
- The Block reports Tropic Square says a firmware mitigation (disabling MAINTENANCE mode) closes the main entry point and a hardened silicon revision is expected late 2026 [source 9].
- Two Safe 7 issues (THP pairing, authenticity proofs) were fixed per the Trezor security portal [sources 10, 11].
Audits
- 2026-01 Ledger Donjon (independent audit of the TROPIC01 chip, as described by Trezor). Scope: TROPIC01 secure element chip source
Publicly disclosed weaknesses
- 2026-06-03 Ledger Donjon, auditing TROPIC01, extracted a subset of chip secrets by laser fault injection and bypassed firmware verification; Tropic Square found a further path affecting PIN-related MAC-and-Destroy. Requires physical possession, decapsulation and lab equipment. Trezor says PIN, funds and backup are not exposed and the chip does not hold keys or backup. Funds lost: no. Not fixed (as of the source) source
- 2026-06-22 Reported via Trezor security portal: a connected host could complete THP pairing without entering the on-device code by sending degenerate values; such values are now rejected. Funds lost: not verified. Fixed source
- 2026-08-16 Reported anonymously: authenticity proofs were checked against a combined key set rather than per secure element, so one valid proof could pass all three checks; each proof is now bound to its own element (1,350 USD reward). Funds lost: not verified. Fixed source
- 2025-09-24 Trezor security portal entry 'Side-channel in BIP-39 mnemonic processing when unlocked'; the listing does not name affected models or the reporter. Funds lost: not verified. Fixed source
Disclosed weaknesses are listed whatever their severity. "Funds lost" is what the sources say. "Fixed" means the source states a fix exists, which only helps if you update.
Incidents at the maker or its service providers
- 2024-01-17 Unauthorized access to a third-party support ticketing portal exposed names/nicknames and email addresses of about 66,000 users who had contacted support; at least 41 users received phishing messages asking for their seed phrase. Customer funds lost: no. Outcome: Trezor disclosed on 2024-01-20 and emailed affected users; stated no user assets were compromised. source
- 2024-03-20 Trezor's official X account was compromised and used to promote a fake token presale with drainer links; a third-party researcher reported about 8,100 USD taken from Trezor's own Zapper account. Customer funds lost: not verified. Outcome: Trezor confirmed a security incident and warned users; reported customer losses not established in the source. source
- 2025-06-23 Attackers abused Trezor's support contact form to send phishing emails that appeared to come from Trezor support. Customer funds lost: no. Outcome: Trezor said no access to its systems or user data occurred; phishing site taken down; no fund loss reported in the source. source
- 2026-09-09 Breach of third-party email provider Brevo exposed Trezor's opt-in newsletter list (about 347,000 addresses) and phishing emails posing as a security alert were sent; about 2,500 users clicked the link per the report. Customer funds lost: not verified. Outcome: Trezor took the phishing domain down within 20 minutes and suspended the Brevo account; the source reports no fund loss figure. source
These affect the company or its customers and apply to every device of the brand. They are not weaknesses of this device.
Questions about Trezor Safe 7
Is Trezor Safe 7 safe?
We do not give a yes or no, because safety depends on what you need to protect and on facts that change. We found 4 publicly disclosed weaknesses, 1 of them not fixed according to the source and 4 company incidents in our search. Read the sources above before you buy.
Does Trezor Safe 7 need an internet connection?
Signing happens on the device. How the device talks to your phone or computer depends on its connections: USB, Bluetooth. The companion app or software that builds the transaction is online.
Who found the weaknesses listed for Trezor Safe 7?
The page names who disclosed each one when the source does. Several were found by a competing maker's research team or by independent security firms. We cite the affected company's own statement where we found one, and label press-only reports.
Where this comes from
- [3] Trezor Safe 7 product page accessed 2026-10-11
- [4] Secure element in Trezor Safe 3 (Trezor Learn) accessed 2026-10-11
- [8] Trezor response: TROPIC01 chip disclosure, no impact to your funds accessed 2026-10-11
- [9] The Block: Ledger researchers find flaw in chip used by Trezor Safe 7 accessed 2026-10-11
- [10] Trezor security portal: authenticity proofs not bounded to their secure element accessed 2026-10-11
- [11] Trezor security portal: THP pairing could be completed without the pairing code accessed 2026-10-11
- [12] Trezor Learn: past security issues accessed 2026-10-11
- [13] Trezor docs: reproducible build accessed 2026-10-11
- [14] Trezor Bug Bounty Program Terms accessed 2026-10-11
- [15] Trezor Learn: Multi-share Backup on Trezor accessed 2026-10-11
- [18] Trezor compare page accessed 2026-10-11
- [21] Decrypt: Trezor launches Safe 7 (press release) accessed 2026-10-11
- [22] Trezor blog: Meet Trezor Safe 7 accessed 2026-10-11
- [23] ForkLog: Data breach affects 66,000 Trezor users accessed 2026-10-11
- [24] ForkLog: Trezor's X account hacked to promote scam accessed 2026-10-11
- [25] The Block: Trezor phishing alert, support contact form abused accessed 2026-10-11
- [26] BleepingComputer: Trezor 347,000 users targeted in phishing after Brevo breach accessed 2026-10-11
- [27] GitHub fork of trezor/trezor-firmware (shows GPL-3.0) accessed 2026-10-11
Not verified: Current store price not shown to the fetcher. Not verified: warranty terms; Trezor Suite open-source status; exact current store price (trezor.io product pages show no price to the fetcher; github.com/trezor/trezor-firmware could not be opened directly); official repository URL; closed/open status of the Secure Element internal firmware (not stated in sources read). Whether the TROPIC01 firmware mitigation (MAINTENANCE mode) is deployed in Safe 7 firmware: from The Block only, not confirmed by Trezor; status left 'unfixed'. Secondary element chip maker named as Optiga only on the product page, not in the launch blog.
See how we check. To report an error, use corrections and right of reply.