Secure Elements: What Certification Proves, and What It Does Not
A secure element is one of the few genuinely strong components in consumer crypto hardware, and its certification is a real, audited claim. It is also a claim about a narrow question, and the marketing that surrounds it routinely stretches it to cover things it was never about.
By Olivia Bennett, Blockchain Security Researcher
Smart Contract Security, Audit Reports, Exploits, DeFi Hacks, White-Hat Research
✓ Reviewed by Emily Volker· Editor-in-Chief

A secure element is a dedicated chip designed to hold a secret and resist attempts to extract it, including by someone holding the device. Certification schemes test that resistance against defined attack budgets and publish the result. Both the chip and the certificate are real engineering. What they cover is narrower than the phrase suggests, and the difference is where most confusion about hardware wallet security lives.
The threat it is built for
The problem a secure element solves is physical. If someone has your device, an ordinary microcontroller will surrender its contents to a determined attacker with laboratory equipment: probing the silicon, inducing faults with voltage or laser glitches, or reading power consumption to infer the key being used.
A secure element is hardened against each of these. Sensors detect abnormal voltage and clock behaviour and wipe or halt. The physical layout resists probing. Cryptographic operations are implemented so that timing and power draw do not vary with the secret. None of that is marketing; it is the specific engineering the certification tests.
This matters most in the scenarios people find easiest to imagine: a stolen device, a lost device, a device seized at a border. Without a secure element, the seed on a hardware wallet is recoverable by an attacker with the right equipment and enough interest. With one, it is not, within the attack budget the certificate describes.
What certification actually says
Certificates in this field state a scope and an assurance level, and both qualifiers do work.
The scope names what was evaluated. It is frequently the chip alone rather than the finished product, which means the certificate belongs to a component the manufacturer bought rather than to the device you are holding. A wallet built badly around a certified chip inherits the chip's resistance and none of its own.
The assurance level describes how thoroughly it was tested and against what attacker capability. Higher levels mean a better-resourced attacker was assumed and more of the design was examined. A certificate without its level quoted is close to meaningless, and it is quoted less often than it should be.
The date matters too. Attack techniques improve, and a certificate is a statement about the state of the art when the evaluation ran.
The gap: what the chip is asked to sign
Here is the limit that the phrase secure element does the most to obscure. The chip holds the key and performs signatures on request. It does not decide what to sign. That decision belongs to the firmware, and the firmware is separate.
So a device with an impeccable secure element can still sign a transaction that sends your funds to an attacker, if the firmware displays one thing and requests another. The chip did exactly what it was built for. The failure happened one layer up, in the part the certificate never covered.
This is the reason firmware verifiability is a separate question from chip certification, and why the two together are stronger than either alone. Certification answers: can someone with my device extract the key. Verifiability answers: does the device do what it says it does. A product can be strong on one and weak on the other, and several are.
The clearest demonstration of the gap
The most instructive case in this category was not an exploit at all. It was a manufacturer announcing a feature that let seed material be exported from devices as encrypted shards, as an optional recovery service.
The security debate that followed was not about whether the secure element had failed — it had not. It was about the discovery that signed firmware could instruct the chip to export key material at all. Owners who had assumed the architecture made that impossible learned that the constraint was a policy in firmware rather than a property of the hardware.
Whatever one thinks of the feature, the episode drew the boundary precisely: a secure element protects a secret from someone attacking the device from outside. It does not protect it from the code the device is running.
Reading a device's claims
- Find the certificate's scope. If it covers the chip rather than the product, it does not describe the device you are buying.
- Find the assurance level and the evaluation date. Both qualify the claim substantially.
- Ask separately whether the firmware is open and whether builds are reproducible, because certification says nothing about either.
- Check whether key export is architecturally impossible or merely disabled by firmware policy — these are different guarantees.
- Treat a certified chip as necessary rather than sufficient. It closes one attack class completely and leaves another entirely open.
The right conclusion is not that certification is theatre. It is that it answers one question extremely well, and buyers keep hearing it answer a second one it never addressed.
Sources
2 references- 01FIPS 140-3: Security Requirements for Cryptographic Modules
NIST · accessed August 22, 2026
- 02Security
ethereum.org · accessed August 22, 2026
Frequently asked questions
Do I need a hardware wallet with a secure element?+
For meaningful holdings, yes. Without one, a device in an attacker's hands can have its key extracted using known laboratory techniques. A secure element closes that attack class within the budget its certificate describes, which is the main reason to prefer a device that has one.
Does a secure element mean the manufacturer cannot access my keys?+
No. The chip resists extraction by someone attacking the device physically. It performs signatures and, on some designs, other operations when the firmware asks. Whether the firmware can be made to export key material is a separate question answered by the firmware, not by the chip.
Is a certified chip enough on its own?+
No. Certification typically covers the chip rather than the finished product, and it says nothing about whether the device displays truthfully what it is about to sign. Pair it with firmware you can verify — reproducible builds turn the second question from a promise into a check.
What does the assurance level on a certificate mean?+
It describes how thoroughly the component was evaluated and how well-resourced an attacker was assumed. A higher level implies a stronger attacker was modelled and more of the design examined. A certificate quoted without its level, and without its date, tells you very little.

Written by
Olivia BennettBlockchain Security ResearcherSmart Contract Security, Audit Reports, Exploits, DeFi Hacks, White-Hat Research
Olivia Bennett is the Blockchain Security Researcher at CoinRadar Daily, where she specializes in smart contract security, DeFi risk analysis, blockchain infrastructure, and protocol vulnerabilities. Drawing on years of hands-on cybersecurity experience, she delivers in-depth reporting that explains both the technical details and the real-world implications of security incidents across the digital asset ecosystem. Before joining CoinRadar Daily, Olivia built her career in cybersecurity, working in penetration testing, blockchain security assessments, and smart contract auditing. She participated in numerous security reviews for decentralized applications and blockchain protocols, helping identify critical vulnerabilities before they could be exploited. Her responsible disclosure work has contributed to improving the security of several major DeFi projects and protecting millions of dollars in digital assets. Olivia earned a Bachelor of Science in Computer Science from the University of Edinburgh and later completed advanced professional training in offensive security and blockchain technologies. Her combination of software security expertise and blockchain knowledge enables her to provide readers with clear, evidence-based analysis of exploits, protocol upgrades, and emerging attack vectors. At CoinRadar Daily, Olivia publishes detailed investigations into blockchain exploits, smart contract audits, cross-chain security, wallet protection, and evolving cyber threats affecting the crypto industry. She is particularly committed to translating highly technical research into practical guidance that helps investors, developers, and blockchain users better understand protocol risk and security best practices. Alongside her editorial work, Olivia contributes educational resources covering secure wallet management, decentralized finance security, and blockchain infrastructure. She also participates in industry events and technical discussions focused on strengthening Web3 security standards, supporting CoinRadar Daily's mission to provide accurate, research-driven coverage of the rapidly evolving digital asset landscape.

✓Reviewed & edited by
Emily VolkerEditor-in-ChiefEditorial Strategy, Investigative Journalism, Crypto Media, E-E-A-T Standards
Emily Volker is the Editor-in-Chief of CoinRadar Daily, where she leads a multilingual editorial team covering cryptocurrency markets, blockchain innovation, Web3, and global digital asset regulation across eight languages. With more than a decade of experience in financial and technology journalism, she has played a key role in developing high editorial standards and trusted reporting within the digital asset industry. Emily began her career as a financial journalist reporting on commodities, energy markets, and emerging technologies before discovering Bitcoin and decentralized finance in the early 2010s. She later moved to London to join one of Europe's early blockchain-focused media organizations, where she advanced into senior editorial leadership. Her experience reporting through both the rapid expansion of the 2017 ICO boom and the subsequent market correction reinforced her commitment to fact-based, research-driven journalism in an industry often influenced by speculation. She holds a Master's degree in International Journalism from City, University of London, and has completed executive studies in digital media strategy through the Reuters Institute at Oxford. Emily is a strong advocate for editorial transparency, rigorous verification, and responsible financial reporting. She also helped integrate Google's E-E-A-T principles—Experience, Expertise, Authoritativeness, and Trustworthiness—into the editorial standards followed by CoinRadar Daily. Under her leadership, CoinRadar Daily has expanded into a global cryptocurrency news platform publishing content in eight languages with a network of editors, analysts, and contributors across four continents. Emily oversees investigative reporting, editorial policy, content quality, and fact-checking processes to ensure every article meets the publication's standards for accuracy, credibility, and independence. Alongside her editorial responsibilities, Emily mentors aspiring journalists through digital media initiatives and regularly speaks at international conferences focused on journalism, fintech, blockchain technology, and digital assets, where she discusses responsible reporting, combating misinformation, and the evolving future of financial media.
CoinRadar Daily content is written by named analysts and checked against our editorial standards. Market data is indicative and informational only — nothing here is financial advice.
Bitcoin services, rated
How we score →Independent, rubric-scored tables covering the services this bitcoin coverage keeps running into.
Best Hardware Wallets
Top rated: Trezor Safe 5 8.6
Devices whose only job is to keep a key away from the internet.
5rated →
Best Crypto Wallets
Top rated: Rabby 8.4
Software wallets for everyday use.
5rated →
Best Crypto Exchanges
Top rated: Kraken 8.6
Centralised venues that hold your funds while you trade.
6rated →
Keep Reading

Bitcoin Self-Custody: Hardware Wallets, Seed Phrases & Security
Self-custody means holding your own keys. Here is how hardware wallets and seed phrases protect Bitcoin, and the security habits that prevent loss.
James Park · May 25, 2026→

What Is a Spot Bitcoin ETF and How Does It Work?
A spot Bitcoin ETF holds actual bitcoin and lets investors gain exposure through a brokerage account. Here is how it works and what you give up.
Emily Volker · June 1, 2026→

Bitcoin vs Gold: Which Is the Better Store of Value?
Bitcoin is often called digital gold, but the two assets store value very differently. Here is how they compare on scarcity, volatility, and risk.
Olivia Bennett · June 5, 2026→