Skip to content
Crypto Almanac Daily
T
Hardware Wallets

Trezor

Best for verifiable firmware openness

Firmware repository:PublicSecurity or spec page:PublishedDocumentation:OpenVendor:SatoshiLabsRubric:v2.0 · verified 9 Aug 2026
Last verified August 9, 2026
Confidence ARubric v2.0Verified August 9, 2026
9.9
out of 10
Open account
Scorecard

How it rates

Key security & openness · 40%10.0
Purchase transparency · 10%10.0
Product openness · 20%10.0
Vendor transparency · 20%10.0
Public documentation surface · 10%10.0
Pros
  • Firmware source published in a public repository
  • Device security or specification page published
  • Technical documentation reachable without an account
Cons
  • Several indicators could not be verified from public sources at this check
How this score was built

Each indicator scores 2, 1 or 0. A pillar is the points earned over the points available; the overall score is the weighted sum. Every source below is public — check any of them yourself.

Key security & openness · 40% weight10/10 points · 10.0/10
  • Met
    Firmware source published in a public repository

    Vendor repository reachable at this check.

    github.com/trezor/trezor-firmware
  • Met
    Device security or specification page published

    Security or specification page reachable at this check.

    trezor.io/security
  • Met
    Independent security research or audit programme published

    Security research programme published by the vendor.

    trezor.io/security
  • Met
    Technical documentation reachable without an account

    Documentation open at this check.

    trezor.io/support
  • Met
    Vendor organisation identifiable from the repository

    Repository published under the vendor organisation (SatoshiLabs).

    github.com/trezor/trezor-firmware
Purchase transparency · 10% weight10/10 points · 10.0/10
  • Met
    Shop or purchase page public

    Reachable without an account at this check.

    trezor.io/
  • Met
    Model-specific product page public

    Model page reachable at this check.

    trezor.io/trezor-safe-5
  • Met
    Legal or terms page public

    Terms reachable at this check.

    trezor.io/legal
  • Met
    Support or help resource public

    Reachable at this check.

    trezor.io/support
  • Met
    Purchase information viewable without an account

    No account required to reach the shop at this check.

    trezor.io/
Product openness · 20% weight10/10 points · 10.0/10
Vendor transparency · 20% weight10/10 points · 10.0/10
Public documentation surface · 10% weight10/10 points · 10.0/10

The only device in this comparison to pass every indicator we checked: open firmware, published security documentation and legal terms all reachable before purchase.

Our assessment

Trezor is the only device in this comparison that passed every indicator we checked. Its firmware source is public, its security and specification pages are reachable, its documentation needs no account, and — unusually for this category — its legal terms are published at a conventional address. On what an outsider can verify before buying, nothing here beats it.

Open firmware is the whole argument

The Safe range pairs an EAL6+ secure element with firmware that stays fully open source, so the secure element guards the PIN and the entropy while the logic that builds and signs transactions remains auditable by anyone. That split is a deliberate design position, and it is the opposite of the approach taken by devices whose secure-element operating system is closed.

What our score does and does not measure

This rubric scores verifiable openness, not physical security. We do not test tamper resistance, we do not attempt side-channel attacks, and we do not score marketing claims about chip certification. What we can check is whether the code, the specifications, the documentation and the legal terms are published where a buyer can read them before paying — and here they all are.

The gap that remains

Several questions in this category cannot be settled from a browser: supply-chain integrity, how the device behaves in an adversary's hands, the response to a future firmware vulnerability. Trezor's own history includes a physical extraction demonstrated by researchers on older models, which is exactly the kind of finding that open hardware makes public rather than hides.

Who it suits

Trezor fits buyers who want the maximum amount of independently checkable evidence and are comfortable with a device that publishes its weaknesses along with its strengths. Buyers who want a Bitcoin-only attack surface should look at Coldcard, BitBox or Foundation Passport instead.

Reference

Frequently asked

Does this score mean Trezor is secure?

No. It measures what a buyer can verify before purchase: published firmware source, documented security claims, and open documentation. Physical security is not tested by us and is not scored.

Why does firmware openness matter so much here?

It is the one substantive security property an outsider can check without specialist equipment. Everything else on a hardware wallet requires trusting the vendor or a third-party teardown.

What would raise this score?

Publishing firmware source, a dedicated security or audit page, and open technical documentation at stable public addresses — all of which are checkable by anyone.