Verdict
Fully open-source firmware, a Czech company with a long track record, and hardware that is now competitive on physical security since the Safe series added a certified secure element. The cheapest credible way to hold your own keys.
- Best for
- Bitcoin holders who want verifiable open-source firmware
- Cost
- Safe 3 ~$79, Safe 5 ~$169
What works
- Firmware is fully open source and reproducibly buildable
- Safe 3 and Safe 5 add a certified secure element to the open design
- Trezor Suite is clean, local-first and does not push financial products
- Passphrase implementation creates genuinely hidden wallets
What does not
- Pre-Safe models are extractable with physical access and time
- Altcoin support lags Ledger noticeably
- Suite's built-in buy and exchange routes carry partner markups
- Touchscreen on the Safe 5 is a meaningful price jump for limited benefit
The argument
A hardware wallet makes one promise: the private key never leaves the device. Verifying that promise requires either trusting the manufacturer's auditors or reading the code yourself.
Trezor lets you read the code. All of it, including firmware, with reproducible builds so you can confirm that what runs on your device matches what is published in the repository. For a decade that came at a genuine cost — the older models used general-purpose microcontrollers and were demonstrably extractable by someone with physical possession and laboratory equipment.
The Safe 3 and Safe 5 closed that gap by pairing a certified secure element with the open firmware. You no longer have to choose between verifiability and physical resistance, which was the central trade-off in this category for years.

Which one
Safe 3 at around $79 is the right device for almost everybody: secure element, open firmware, two buttons, a small screen. Safe 5 at around $169 adds a colour touchscreen and haptic feedback. It is nicer to use and it protects your keys identically.
If the extra $90 is the difference between buying a hardware wallet and continuing to keep everything on an exchange, buy the Safe 3 today and stop reading comparisons.
Passphrases are the feature to learn
Trezor's passphrase support creates entirely separate wallets from the same seed. Enter one passphrase, get one wallet. Enter a different one, get a different wallet with no cryptographic relationship to the first.
Nothing on the device indicates that other wallets exist. Under coercion, you can open the wallet holding a small balance, and there is no evidence anywhere on the device that anything else is there.
A passphrase is not a password — there is no reset, and a typo silently produces a valid but empty wallet.
Back it up separately from the seed, in a different physical location.
Test recovery of the passphrase wallet before funding it properly. Test it again in six months, when you have forgotten exactly how you typed it.
Trezor Suite
The desktop application is local-first, will connect to your own node if you want it to, and does not spend its screen space selling you staking products. Coin control for Bitcoin is exposed properly, which matters for anyone thinking seriously about UTXO privacy and is hidden or absent in most competing software.
The built-in buy and exchange routes go through partners at partner rates. Same advice as every wallet in this category: sign here, source elsewhere.
Coin control, and why it matters
Trezor Suite exposes Bitcoin coin control properly: you can see individual UTXOs, label them, and choose which ones a transaction spends. Most wallets hide this entirely and pick for you.
It matters because Bitcoin's privacy model is UTXO-level. Combining coins from two sources in one transaction publicly links them forever, and a wallet that selects inputs automatically will do exactly that without telling you. If you care about not building a permanent public map of where your coins came from, this feature is the difference between a wallet that helps and one that quietly works against you.
Where it loses to Ledger
Asset support. If you hold tokens across many chains, Ledger's coverage is wider and its app ecosystem deeper. Trezor's support is solid for Bitcoin, Ethereum and the major chains and thinner past that, and the gap is not closing quickly.
For a Bitcoin-heavy holder that is irrelevant. For someone holding twelve assets across six chains it is decisive.

Verdict
Shamir backup
The Safe series supports splitting a recovery seed into multiple shares, any threshold of which reconstructs the wallet — three shares of which two are needed, for example. Lose one and you are fine; an attacker who finds one has nothing.
For anyone who has agonised over where to keep a single piece of paper that unlocks everything, this is a materially better answer than a safe deposit box. It is also more moving parts, and more moving parts is more ways to be wrong. Use it if you will actually store the shares in genuinely separate places; otherwise a single well-hidden metal backup is better than a badly executed split.
Buying safely
Buy from Trezor or an authorised reseller, never a marketplace listing.
Check the packaging seal and verify the firmware signature in Suite on first connection — Suite does this automatically and tells you if it fails.
Generate the seed on the device. Nothing that arrives pre-written is legitimate.
Test the recovery before funding, then again months later when your memory of the process has faded.
Score: 8.2 — the highest in this category. Open firmware, a certified secure element, honest software and the lowest price for a credible device. For a Bitcoin-heavy holder, the Safe 3 is the easiest recommendation in this entire library.
