Skip to content

SYSTEM ONLINE

LIVE TAPE
BTC$85,381.00▼ 1.0%·
ETH$2,699.47▼ 0.8%·
USDT$0.999857▲ 0.0%·
BNB$778.86▼ 1.7%·
XRP$1.50▼ 1.5%·
USDC$0.999978▲ 0.0%·
SOL$119.99▼ 1.3%·
TRX$0.336555▲ 0.3%·
FIGR_HELOC$1.03▲ 0.0%·
ZEC$1,326.11▲ 0.4%·
HYPE$92.96▲ 0.8%·
DOGE$0.094496▼ 2.1%·
XMR$561.23▲ 3.7%·
LINK$13.87▼ 2.5%·
ADA$0.271341▼ 0.1%·
WBT$85.36▼ 0.5%·
USDS$0.99968▼ 0.0%·
LEO$8.90▼ 0.2%·
BTC$85,381.00▼ 1.0%·
ETH$2,699.47▼ 0.8%·
USDT$0.999857▲ 0.0%·
BNB$778.86▼ 1.7%·
XRP$1.50▼ 1.5%·
USDC$0.999978▲ 0.0%·
SOL$119.99▼ 1.3%·
TRX$0.336555▲ 0.3%·
FIGR_HELOC$1.03▲ 0.0%·
ZEC$1,326.11▲ 0.4%·
HYPE$92.96▲ 0.8%·
DOGE$0.094496▼ 2.1%·
XMR$561.23▲ 3.7%·
LINK$13.87▼ 2.5%·
ADA$0.271341▼ 0.1%·
WBT$85.36▼ 0.5%·
USDS$0.99968▼ 0.0%·
LEO$8.90▼ 0.2%·

Wallets & Custody

Best Hardware Wallets

Devices whose only job is to keep a key away from the internet. Custody carries 45% — the highest weighting on the site — because nothing else about a signing device matters if that fails.

◆ Radar Score · rubric v2.05 rated◆ Sources checked · 27 Sept 2026How we score →

All 5 compared

Sorted by computed score. Column headers carry this category's weighting; the highest score in each pillar is marked. Tap a name for the full assessment.

Hardware Wallets compared: overall Radar Score and the five pillar scores behind it. Pillar weightings for this category are given in the column headers.
#ServiceScoreCustody45%Cost15%Regulation5%Performance15%Access20%
01Trezor Safe 5Verifiable open-source firmware with a secure element8.6Strong9.0 — best in table7.47.68.68.8 — best in table
02BitBox02A simple, open, well-built device for people who want neither extreme8.2Strong8.47.6 — best in table7.8 — best in table8.08.6
03Keystone 3 ProAir-gapped QR signing with multi-chain support8.0Strong8.37.6 — best in table6.88.28.0
04Ledger Nano XThe widest asset coverage and the best mobile experience7.7Solid7.07.6 — best in table7.08.8 — best in table8.6
05Coldcard Mk4Air-gapped Bitcoin-only signing — only with a seed made on fixed firmware−1 penalty4.0Not recommended5.07.06.08.06.2

The assessments

what each score rests on
  1. 01
    8.6/10

    Trezor Safe 5

    Best for verifiable open-source firmware with a secure element

    Company file: Trezor, owners, incidents →
    Strong◆ Sources checked · 27 Sept 2026

    A secure element paired with firmware you can read and reproduce — a combination BitBox also offers, and one Ledger does not. Trezor’s historical weakness was physical extraction on the Model One and Model T, which have no secure element; the Safe series fixes that without giving up the open-source position that makes the device auditable.

    Pillar scores

    Custody & Security45%
    9.0
    Cost & Fee Transparency15%
    7.4
    Regulation & Legal Standing5%
    7.6
    Performance & Reliability15%
    8.6
    Access & Support20%
    8.8

    Strengths

    • Open-source firmware with reproducible builds — the device can be independently verified
    • Secure element without abandoning auditability
    • The clearest published recovery documentation in the category

    Against it

    • More expensive than the entry-level Safe 3
    • Older Trezor models without a secure element remain open to physical extraction
    • Support-portal breach in January 2024 put 66,000 contacts in phishers’ hands
  2. 02
    8.2/10

    BitBox02

    Best for a simple, open, well-built device for people who want neither extreme

    Company file: BitBox, owners, incidents →
    Strong◆ Sources checked · 27 Sept 2026

    Swiss-made, open source with reproducible builds, and easier to live with than the hardcore options. The record is not spotless: on 17 August 2026 BitBox fixed two severe firmware bugs its own audits found, and on 10 September 2026 a breach at its newsletter provider Brevo sent phishing from BitBox’s real account. No funds lost through the device have been reported.

    Pillar scores

    Custody & Security45%
    8.4
    Cost & Fee Transparency15%
    7.6
    Regulation & Legal Standing5%
    7.8
    Performance & Reliability15%
    8.0
    Access & Support20%
    8.6

    Strengths

    • Open source with reproducible builds, and a secure chip
    • Bitcoin-only edition available at the same price
    • Easiest setup among the fully open devices

    Against it

    • Two severe firmware bugs fixed in August 2026 — keep firmware current
    • Brevo breach (10 Sep 2026) put subscriber emails in phishers’ hands
    • Narrower asset coverage and fewer integrations than Ledger
  3. 03
    8.0/10

    Keystone 3 Pro

    Best for air-gapped QR signing with multi-chain support

    Company file: Keystone, owners, incidents →
    Strong◆ Sources checked · 27 Sept 2026

    Air-gapped operation via QR codes, three secure chips, and support well beyond Bitcoin, on a display large enough to read what you sign. The firmware is published and can be checked by checksum, but it is not fully open: some third-party microcontroller libraries are vendor-restricted and the secure-element firmware is closed. The maker is a Hong Kong company manufacturing in China, with a shorter record than the European incumbents.

    Pillar scores

    Custody & Security45%
    8.3
    Cost & Fee Transparency15%
    7.6
    Regulation & Legal Standing5%
    6.8
    Performance & Reliability15%
    8.2
    Access & Support20%
    8.0

    Strengths

    • Air-gapped QR signing with no data cable at all, across many chains
    • Three secure chips; firmware published with a checksum guide
    • Large display makes transaction verification actually practical

    Against it

    • Not fully open source: vendor-restricted MCU libraries and closed secure-element firmware
    • Hong Kong maker, made in China, with a shorter disclosure record
    • QR workflow is slower than plugging in a cable
  4. 04
    7.7/10

    Ledger Nano X

    Best for the widest asset coverage and the best mobile experience

    Company file: Ledger, owners, incidents →
    Solid◆ Sources checked · 27 Sept 2026

    The best-supported device in the category by asset coverage and app quality, and the one with the most damaging trust history around it. The 2020 customer-data breach put home addresses of owners online, the 2023 Recover announcement confirmed that signed firmware can export seed material, the December 2023 Connect Kit attack drained about $600,000 from users who blind-signed, and customer order data leaked again through payment processor Global-e in January 2026.

    Pillar scores

    Custody & Security45%
    7.0
    Cost & Fee Transparency15%
    7.6
    Regulation & Legal Standing5%
    7.0
    Performance & Reliability15%
    8.8
    Access & Support20%
    8.6

    Strengths

    • Widest asset coverage and by far the best mobile app
    • Certified secure element with no key extraction on record
    • Mature, polished onboarding

    Against it

    • Closed-source firmware — you cannot verify what the device does
    • Recover confirmed firmware can export seed shards at all
    • Customer data leaked in 2020 and again via Global-e in January 2026
  5. 05
    4.0/10

    Coldcard Mk4

    Best for air-gapped Bitcoin-only signing — only with a seed made on fixed firmware

    Company file: Coldcard, owners, incidents →
    Not recommended◆ Sources checked · 27 Sept 2026

    Air-gapped signing over microSD, two secure elements and a Bitcoin-only scope — and, from March 2021 until the fixes of 31 July 2026, seed generation that used a weak software PRNG instead of the hardware random number generator. Attackers began sweeping those seeds on 30 July 2026 and took about 1,789 BTC (~$114.7m, Galaxy Research). Coinkite offers no compensation. If your seed was created on affected firmware without 50+ private dice rolls, make a new seed on updated firmware and move the funds now.

    Pillar scores

    Custody & Security45%
    5.0
    Cost & Fee Transparency15%
    7.0
    Regulation & Legal Standing5%
    6.0
    Performance & Reliability15%
    8.0
    Access & Support20%
    6.2

    Deductions applied

    • −2.0Unrecovered user-fund loss. Users lost funds in the last 24 months and were not made whole. Applies once, regardless of cause.

    Strengths

    • True air-gapped signing with no USB data path required
    • Two secure elements from different vendors; no key was extracted from a device in the 2026 exploit
    • Bitcoin-only scope removes approval and contract-signing attacks

    Against it

    • Seeds generated on firmware from March 2021 to July 2026 were guessable; about 1,789 BTC stolen from 30 July 2026
    • No compensation from Coinkite; only 52.37 BTC placed in a white-hat recovery trust by 22 Sep 2026
    • The steepest learning curve in the category, and Bitcoin only
    Full assessment of Coldcard Mk4 →not recommended · 4.0/10

A signing device has exactly one job: keep a private key away from a computer that might be compromised, and refuse to sign anything you did not agree to. Custody carries forty-five per cent here — the joint-highest weighting on the site — because nothing else about the product survives a failure at that layer. The Coldcard seed-entropy exploit that began on 30 July 2026 is the reminder that the layer includes how the key was generated, not only how it is stored.

Frequently asked questions

Does open-source firmware actually matter?+

It is the difference between trusting a claim and checking one. A closed device may well be secure, but you are taking the manufacturer’s word for what it does with your seed — and Ledger’s Recover announcement showed that assumption can be wrong in ways owners had not considered. It is not a guarantee either: Coldcard’s source was public for five years while its seed generation was broken. Reproducible builds and people actually reading the code are what turn "open source" from a label into a property.

Is a secure element necessary?+

For physical-attack resistance, yes. Without one, someone with your device and the right equipment can often extract the seed. The historical tension was that secure elements were closed, forcing a choice between auditability and physical security; the current generation of devices no longer requires that trade. A secure element does not help if the seed was weak when it was created, which is what went wrong at Coldcard in 2026.

Why does Ledger still score well after everything?+

Because the rubric does not do reputation. Its secure element has no key extraction on record, and its coverage and app quality are the best available. No user has lost crypto through an exploit of Ledger device firmware; users did lose about $600,000 in December 2023 when Ledger’s Connect Kit software library was compromised. The closed firmware, the Recover capability, Connect Kit and the 2020 and 2026 data leaks all cost it points in the pillars where they belong.

I own a Coldcard. What should I do?+

If the seed was generated on a Mk2 or Mk3 with firmware 4.0.1–4.1.9, or on a Mk4, Mk5 or Q before firmware 5.6.0 / 1.5.0Q, treat it as exposed unless you added at least 50 private dice rolls. Update the firmware, generate a new seed on the updated device, send a small test transaction, then move the rest. Updating firmware alone does not fix an old seed.

What is the single most common way people lose money with these?+

Not device compromise. It is losing the recovery seed, or entering it into something that asked for it. No device in this table protects against typing your seed into a website, which is why we score recovery documentation inside the access pillar rather than treating it as a nice-to-have.

Assessed by

Olivia Bennett

By Olivia Bennett

Blockchain Security Researcher · September 27, 2026