Trezor, made by Satoshi Labs (Prague, Czech Republic), is the original hardware wallet — first shipped in 2014 by the team that authored BIP-39 and SLIP-39. The current flagship (Oct 2025) is the Trezor Safe 7 (129, touchscreen) and Safe 3 ($79, buttons), with the Model T (discontinued) and Trezor One remaining firmware-supported. Distinguishing features are native SLIP-39 support (essentially unmatched by other major hardware wallets), fully open-source firmware and hardware schematics, and a mainstream UX that has made Trezor a typical first-hardware-wallet recommendation. Trade-offs: broad altcoin support that some treat as attack-surface expansion, multisig signing performance that lags Coldcard and BitBox02 per Lopp's 2024 report, and past hardware vulnerabilities (notably the 2018 STM32 attack on the original Trezor One) addressed through later hardware revisions. The strongest fit is mainstream holders, SLIP-39 users, and the open-source-aligned.


What this is

Vendor: Satoshi Labs (Prague, Czech Republic). Founded by Marek “slush” Palatinus and Pavol Rusnak (2013). The team is also responsible for authoring BIP-39 (mnemonic seeds), SLIP-39 (Shamir’s secret sharing for seeds), and operating Slush Pool (the first Bitcoin mining pool). Their pedigree in Bitcoin infrastructure runs deep.

Product line as of 2026-07-17:

  • Trezor Safe 7 ($249) — the current flagship (launched Oct 2025). 2.5″ colour touchscreen, wireless (encrypted Bluetooth, incl. iPhone) + USB-C, aluminium body with Qi2 charging and a LiFePO₄ battery, and a “quantum-ready” boot chain. Its landmark feature is a dual secure element pairing a certified EAL SE with TROPIC01 — the first auditable (open-design) secure element in a hardware wallet, addressing the long-standing “the SE is a closed black box” critique. Native SLIP-39.
  • Trezor Safe 5 ($129) — the middle model; 1.54″ colour touchscreen; single EAL 6+ secure element; native SLIP-39; USB-C only. The touchscreen sweet spot below the flagship.
  • Trezor Safe 3 ($79) — entry-level; button-based UX + small mono screen; single EAL 6+ secure element; native SLIP-39; USB-C only. Budget hold-and-forget pick.
  • Trezor Model T (legacy, ~$215 historical) — predecessor flagship; touchscreen but older architecture; now discontinued (production ended), though still firmware-supported
  • Trezor One (legacy, ~$59; verify current) — the original 2014 device; still firmware-supported but architectural limitations apply

The three Safe models share firmware, Trezor Suite, native SLIP-39, passphrase support, and on-device approval; they differ in screen/input, wireless, secure-element design, and price. All remain multi-coin.

Firmware: Fully open-source under GPL. Hardware schematics are also published. This is the strongest open-source posture in the hardware-wallet field; independent researchers can audit both firmware and hardware design.

Secure element: Trezor Safe 5 and Safe 3 use the Optiga Trust M (Infineon, EAL 6+ certified). This is a meaningful upgrade from the Trezor One/Model T, which used general-purpose microcontrollers without dedicated secure elements (a known concern in the original architecture).


Who this is for

Trezor is a strong fit for:

  • First-time hardware-wallet users — Trezor’s UX is the most mainstream of the major hardware wallets; the touchscreen-based flow on the Safe 5 is approachable
  • SLIP-39 / Shamir users — the canonical SLIP-39 implementation; no other major hardware wallet matches Trezor’s native support
  • Open-source purists — Trezor’s GPL firmware and open hardware schematics are the strongest open-source position in the field
  • Mainstream multisig holders — Trezor pairs well in multi-vendor multisig (typically with Coldcard or BitBox); coordinator support is universal
  • Holders who value vendor longevity — Satoshi Labs has shipped hardware wallets continuously since 2014; the longest track record in the industry

Trezor is less appropriate for:

  • Bitcoin-only purists who care about attack surface — Trezor supports many altcoins, which some treat as undesirable; the firmware paths for those coins are real code that could in principle harbour vulnerabilities affecting Bitcoin keys
  • High-volume multisig signers — Trezor’s 100-input PSBT signing was slower than Coldcard or BitBox02 in Lopp’s 2024 report; for routine large-transaction signing, others perform better
  • Strict air-gap holders — Trezor is USB-only; no QR-code or MicroSD signing paths
  • The deeply privacy-conscious — Trezor’s Suite (the official companion app) makes network requests on launch that some holders treat as undesirable telemetry; alternatives exist (Sparrow, Electrum) but the default workflow is Trezor-Suite-oriented

Features and capabilities

Trezor Safe 5 specifics (2026 flagship)

  • Colour touchscreen — 1.54-inch display; legible for long addresses; touch-input for passphrase entry
  • EAL 6+ secure element (Infineon Optiga Trust M) — physical-attack resistance comparable to Ledger, Foundation Passport, Coldcard
  • USB-C — modern connector
  • NFC — for contactless interaction with mobile coordinators
  • Native SLIP-39 — the canonical implementation; supports both single-group and multi-level configurations

Common to current Trezor line (Safe 5, Safe 3)

  • Fully open-source firmware (GPL)
  • Open hardware schematics — published; independently reviewable
  • BIP-39 standard — Trezor authored the spec
  • SLIP-39 native — Trezor authored this spec too
  • PSBT v2 support — modern PSBT handling
  • BIP-380 output descriptors — for multisig
  • BIP-39 passphrase support — entered on the device (touchscreen on Safe 5, button-cycle on Safe 3)
  • Bitcoin + many altcoins — the multi-coin support is a trade

Trezor-specific quirks

  • SLIP-39 native support — the differentiating feature. A holder who wants SLIP-39 backup essentially must use Trezor (or one of the very few other supporting devices).
  • Trezor Suite — the official companion app; works well for single-sig but multisig holders typically use Sparrow, Specter, or Nunchuk
  • Recovery seed verification flow — Trezor’s “check backup” feature lets the holder verify the recorded seed against the device without exposing the seed to the host computer
  • Multi-coin firmware — Bitcoin support is the core; altcoin support is in the same firmware. Some holders see this as attack-surface expansion.

Tradeoffs vs alternatives

DimensionTrezor Safe 5Coldcard QBitBox02 BTC-onlyFoundation Passport
Price$129$249$137$199
Bitcoin-onlyNo (multi-coin)YesYes (BTC-only variant)Yes
Open-sourceYes (GPL, hardware too)Source-availableYes (OSI)Yes (OSI)
Secure elementYes (EAL 6+)YesYesYes
Air-gap signingNo (USB only)QR + MicroSDNo (USB only)QR only
Native SLIP-39YesNoNoNo
BIP-85GoodExcellentGoodLimited
TouchscreenYes (colour)Yes (colour, on Q)No (touch buttons)Yes (colour)
Passphrase entryExcellent (touchscreen)Best (QWERTY on Q)GoodGood (touchscreen)
Lopp 100-input signingModerateFastFastFast

Compared to Coldcard: Trezor’s open-source posture is stronger; Coldcard’s BIP-85 and air-gap features are stronger; the SLIP-39 native support is unique to Trezor among Coldcard’s competitors.

Compared to BitBox02: both are fully open-source; Trezor has SLIP-39 and a touchscreen, BitBox is cheaper and Bitcoin-only. Both pair well in multi-vendor multisig.

Compared to Foundation Passport: Passport is strict air-gap (no USB signing); Trezor is USB-connected. Both have touchscreens and secure elements; Passport is Bitcoin-only.


Setup and operation

The setup flow (high-level):

  1. Verify packaging — Trezor ships with tamper-evident seals; verify intact on arrival.
  2. Connect via USB — Trezor Suite walks through firmware install (the device ships without firmware, which is a security feature — the holder installs verified firmware as the first step).
  3. Choose seed format — standard BIP-39 (12 or 24 words) or SLIP-39 (multiple shares with threshold).
  4. Record the seed (or shares) — Trezor displays the words on the device screen; the holder writes them down.
  5. Verify the seed — Trezor’s check-backup flow asks the holder to enter specific words.
  6. Optionally set up a passphrase — Trezor supports BIP-39 passphrases entered on the device.
  7. Pair with a coordinator — Trezor Suite for single-sig; Sparrow, Specter, Nunchuk for multisig.

The operational flow for signing:

  • Coordinator builds the PSBT
  • Transfer to Trezor via USB
  • Trezor displays the transaction details on its touchscreen; the holder verifies addresses
  • Holder confirms; Trezor signs internally
  • Signed PSBT returns to coordinator via USB
  • Coordinator finalizes and broadcasts

For multisig, the same flow with multiple devices; each device signs in turn.

For SLIP-39 wallets, the recovery flow involves entering the threshold number of shares; the device reconstructs the master seed internally. The exposure window during reconstruction is the structural caveat discussed in SLIP-39 and Shamir Secret Sharing.


Security considerations

Strengths

  • Fully open-source firmware and hardware — strongest auditability in the field
  • EAL 6+ secure element (Safe 5, Safe 3) — physical-attack resistance
  • Long vendor track record — Satoshi Labs has shipped hardware wallets since 2014; transparent about past issues
  • Native SLIP-39 — the only mainstream hardware wallet with this capability
  • Authored the underlying specifications (BIP-39, SLIP-39) — deep alignment between firmware and protocol

Known concerns

  • Multi-coin firmware — the same firmware that signs Bitcoin transactions also handles many altcoins. Some holders treat this as attack-surface expansion; others see it as fine.
  • The 2018 STM32 vulnerability (Trezor One) — a physical-attack vulnerability that allowed seed extraction with specialized equipment. Affected the original Trezor One; the Safe 3 and Safe 5 use a secure element that addresses this class of attack.
  • Trezor Suite network requests — the default companion app makes some network requests at launch that some holders treat as undesirable. Alternative coordinators (Sparrow, etc.) avoid this.
  • The “Recovery” feature controversy — Trezor has at times offered seed-recovery services that critics treat similarly to Ledger’s 2023 Recover, though at smaller scale. Trezor has been clearer about user opt-in and the scope of these services.

Supply-chain integrity

Buy directly from trezor.io or authorized resellers (typically vetted Bitcoin-focused stores). Avoid generic marketplaces. The tamper-evident packaging is the canonical check.

The Trezor Safe 5 ships without firmware installed — the holder installs verified firmware as the first setup step. This is a structural defence against supply-chain attacks: a tampered device must include malicious firmware, which the holder-installed verified firmware would overwrite.


Pricing and acquisition

As of 2026-07-17 (Safe 7 added; prices reverified against trezor.io/compare; prior review 2026-07-15):

  • Trezor Safe 7: $249 USD MSRP (flagship; dual SE incl. auditable TROPIC01; Bluetooth)
  • Trezor Safe 5: $129 USD MSRP
  • Trezor Safe 3: $79 USD MSRP
  • Trezor Model T: ~$215 (legacy; now discontinued — historical price; verify current)
  • Trezor One: ~$59 (legacy budget device; verify current)

Authorized channels: trezor.io directly; authorized resellers listed on their site (Coinkite, Bitcoin-focused stores). Trezor ships globally.

Bulk and business pricing: volume discounts for multisig configurations; institutional pricing available.


Common pitfalls

Trezor One in 2026 setups. The original Trezor One lacks a secure element; the 2018 physical-attack vulnerability is unaddressed in hardware. Acceptable for Tier 0 or very small balances; not appropriate for Tier 1+. Upgrade to Safe 3 or Safe 5.

Confusing SLIP-39 with multisig. Trezor’s SLIP-39 support is a backup-distribution scheme, not multisig. See SLIP-39 and Shamir Secret Sharing for the structural difference.

Using Trezor Suite for substantial multisig. Trezor Suite handles single-sig well but multisig workflows are better served by Sparrow, Specter, or Nunchuk. Mixing coordinators is fine; using Suite for everything is suboptimal.

Treating altcoin support as a feature. For Bitcoin-only holders, the altcoin support is irrelevant; for the strict Bitcoin-only crowd, it is a structural concern. Either way, the altcoin features should not influence the device choice.

Skipping the firmware-installation step. Trezor ships without firmware specifically so the holder verifies the install. Skipping verification (e.g., installing whatever firmware Suite suggests without checking signatures) undermines the structural defence.

Three identical Trezors in multisig. Defeats vendor diversity. Pair Trezor with Coldcard, BitBox02, or other distinct vendors.

Defaulting to BIP-39 when SLIP-39 is the better fit. If the holder genuinely wants Shamir-distributed backup, Trezor’s native SLIP-39 makes the workflow tractable; choosing BIP-39 by default misses the device’s distinguishing feature.


Tooling and resources

Trezor documentation (as of 2026-05-14):

  • trezor.io — official site
  • The Trezor support discussion — comprehensive
  • The Satoshi Labs blog — release notes, security advisories
  • The “slush” and “stick” accounts (Marek Palatinus, Pavol Rusnak) — running commentary

Coordinator software supporting Trezor:

  • Trezor Suite — official, single-sig optimal
  • Sparrow Wallet — multisig-friendly
  • Specter Desktop — multisig-focused
  • Nunchuk — desktop and mobile
  • Bitcoin Core (with PSBT)

The synthesis document: Bitcoin Self-Custody & Security (LegacyCipher, April 2026) — Trezor treated as the mainstream-UX choice with the SLIP-39 niche.

As of 2026-07-17: the Trezor Safe line spans three current models — Safe 3 (129, touchscreen), and the Safe 7 ($249, launched Oct 2025 — the flagship, with a dual secure element including the auditable TROPIC01 chip and encrypted Bluetooth). Firmware (Trezor Suite) is shared and actively updated across all three.


Open questions for further development

  • The multi-coin firmware question is contested. Is the attack-surface expansion a real concern, or is the engineering discipline sufficient that the altcoin paths don’t affect Bitcoin keys? The synthesis treats this as a contested point worth flagging.
  • SLIP-39 adoption beyond Trezor has been limited. If Trezor were to stop developing SLIP-39 support, what is the realistic migration path for existing SLIP-39 wallets? The open-source reference implementations provide a path but the UX would degrade.
  • Trezor’s open-source posture is the strongest in the field. Does this translate into measurable security improvements, or is the security parity with closed-source competitors? The empirical record is mixed.

The framing context:

Per-device alternatives:

Relevant capabilities:

Custody configurations:

Operational practice:

The principal practitioners:

The sub-MOC home: