Trezor
Best for verifiable firmware openness
How it rates
- Firmware source published in a public repository
- Device security or specification page published
- Technical documentation reachable without an account
- Several indicators could not be verified from public sources at this check
Each indicator scores 2, 1 or 0. A pillar is the points earned over the points available; the overall score is the weighted sum. Every source below is public — check any of them yourself.
- MetFirmware source published in a public repository
Vendor repository reachable at this check.
github.com/trezor/trezor-firmware - MetDevice security or specification page published
Security or specification page reachable at this check.
trezor.io/security - MetIndependent security research or audit programme published
Security research programme published by the vendor.
trezor.io/security - MetTechnical documentation reachable without an account
Documentation open at this check.
trezor.io/support - MetVendor organisation identifiable from the repository
Repository published under the vendor organisation (SatoshiLabs).
github.com/trezor/trezor-firmware
- Met
- Met
- Met
- Met
- MetPurchase information viewable without an account
No account required to reach the shop at this check.
trezor.io/
- Met
- MetFirmware repository is the vendor's own
Repository published by the vendor.
github.com/trezor/trezor-firmware - Met
- MetDocumentation site separate from marketing
Dedicated documentation or support resource published.
trezor.io/support - Met
- Met
- MetVendor entity identifiable
Vendor organisation identifiable as SatoshiLabs.
github.com/trezor/trezor-firmware - Met
- Met
- Met
- Met
- Met
- Met
- Met
- Met
The only device in this comparison to pass every indicator we checked: open firmware, published security documentation and legal terms all reachable before purchase.
Our assessment
Trezor is the only device in this comparison that passed every indicator we checked. Its firmware source is public, its security and specification pages are reachable, its documentation needs no account, and — unusually for this category — its legal terms are published at a conventional address. On what an outsider can verify before buying, nothing here beats it.
Open firmware is the whole argument
The Safe range pairs an EAL6+ secure element with firmware that stays fully open source, so the secure element guards the PIN and the entropy while the logic that builds and signs transactions remains auditable by anyone. That split is a deliberate design position, and it is the opposite of the approach taken by devices whose secure-element operating system is closed.
What our score does and does not measure
This rubric scores verifiable openness, not physical security. We do not test tamper resistance, we do not attempt side-channel attacks, and we do not score marketing claims about chip certification. What we can check is whether the code, the specifications, the documentation and the legal terms are published where a buyer can read them before paying — and here they all are.
The gap that remains
Several questions in this category cannot be settled from a browser: supply-chain integrity, how the device behaves in an adversary's hands, the response to a future firmware vulnerability. Trezor's own history includes a physical extraction demonstrated by researchers on older models, which is exactly the kind of finding that open hardware makes public rather than hides.
Who it suits
Trezor fits buyers who want the maximum amount of independently checkable evidence and are comfortable with a device that publishes its weaknesses along with its strengths. Buyers who want a Bitcoin-only attack surface should look at Coldcard, BitBox or Foundation Passport instead.
Frequently asked
Does this score mean Trezor is secure?
No. It measures what a buyer can verify before purchase: published firmware source, documented security claims, and open documentation. Physical security is not tested by us and is not scored.
Why does firmware openness matter so much here?
It is the one substantive security property an outsider can check without specialist equipment. Everything else on a hardware wallet requires trusting the vendor or a third-party teardown.
What would raise this score?
Publishing firmware source, a dedicated security or audit page, and open technical documentation at stable public addresses — all of which are checkable by anyone.