Costs, licensing, consumer protection Privacy, self-custody, censorship resistance

Trezor Trezor Safe 3

A plan byTrezor

4.5/5 4.8/5
Custody Self-custody

Data verified on last change the sources

Worth it if you want to be able to verify what you use: firmware and hardware design are open-source, with an EAL6+ secure element already on the ~€59 Safe 3.

Avoid it if you want an air-gapped device or you buy and swap in-app: no model is air-gapped, and inside Suite you pay third-party provider fees plus a Trezor commission.

Trezor, made by SatoshiLabs (Czech Republic), is the first hardware wallet ever sold and one of the most respected for transparency: firmware and design are open-source and auditable. The current lineup starts with the Safe 3 (≈€59) with an EAL6+ certified secure element and two buttons, moves up to the Safe 5 (≈€129) with a colour touchscreen and haptic feedback, and tops out with the Safe 7 (≈€249) with Bluetooth, Qi2 wireless charging and the auditable TROPIC01 chip. Every model also comes in a Bitcoin-only edition. Devices are managed through the Trezor Suite app (desktop and web), which also integrates buy/sell/swap (Invity) and staking for ADA, ETH, SOL and TRX. The legacy Model One and Model T have been discontinued.

Trezor Safe 3

Price
€59

What's included

  • EAL6+ secure element
  • Two physical buttons
  • USB-C
  • Optional Shamir backup
Self-custody
Custody
Open-source
Source code
20+
Chains
€59
Price
65
Transparency: Medium
65/100 · see methodology
65
Data exposure: Medium
65/100 · lower is better for sovereignty · methodology

Data & conditions

Fund custody Self-custody (funds in your control)
Type Hardware (cold storage)
Source code Open-source
Recovery Seed phrase 12/24 parole (BIP-39); opz. backup Shamir (SLIP-39)
Bitcoin-only No
Supported chains Bitcoin, Ethereum, Litecoin, Cardano, Solana
Price €59
Secure element Yes
Air-gapped No
Connectivity USB-C, Bluetooth
Companion app Trezor Suite
Built-in swap Yes
Built-in staking Yes
Built-in fiat on-ramp Yes
Segment B2C
MiCA / License status Nessuna (hardware wallet self-custody)

Strengths

  • Auditable open-source firmware and design; EAL6+ secure element on Safe models; mature Trezor Suite app; industry pioneer with a long track record.
  • Self-custody: funds stay in your wallet — the platform cannot touch them.
  • No KYC: usable without identity verification.
  • Open-source, verifiable code.
  • Self-hostable: you can run your own instance or node.

Weaknesses

  • USB-C connection (Bluetooth on the Safe 7), not air-gapped; the Model One and Model T have been discontinued; coin support mainly handled via Suite; buying and swapping inside Suite carries third-party provider fees plus a Trezor commission.
  • No notable sovereignty drawback documented.

Verdict

S S ★ 4.5/5 ★ 4.8/5

Score 4.5/5, outstanding profile. In its favour: auditable open-source firmware and design; EAL6+ secure element on Safe models; mature Trezor Suite app; industry pioneer with a long track record. The trade-off to weigh: uSB-C connection (Bluetooth on the Safe 7), not air-gapped; the Model One and Model T have been discontinued; coin support mainly handled via Suite; buying and swapping inside Suite carries third-party provider fees plus a Trezor commission.

On the Sovereignty lens the score is 4.8/5 (outstanding): the strength is fund control (5.0/5), while privacy & anonymity (4.5/5) is the weak link.

Privacy & anonymity 30% 4.5
Fund control 20% 5.0
Censorship resistance 20% 4.8
Trustless / auditability 20% 5.0

Promp's editorial rating based on real fees and net annual cost. Promp reviews third-party products independently.

"Sovereignty" rating: score computed on privacy/anonymity (30%), fund control (20%), censorship resistance (20%), trustless/auditability (20%) and costs (10%). Same data, different weights.

Reputation

What happened to people who used Trezor, and what users say. External signals: they do not feed the promp.it rating.

Incidents & regulatory actions

Notable incidents

Documented events with consequences still open. Each entry carries a source and a date.

  1. Data breach Severe ● open

    Email provider Brevo breached: phishing delivered through Trezor's official channel to roughly 347,000 newsletter subscribers, 2,500 clicked; on 10 September Trezor named the provider and Brevo published its post-incident report closing the SAML SSO flaw, no theft of funds confirmed

    On 9 September 2026 at 22:37 CEST Trezor stated on its official X account that «our third-party e-mail provider has been breached» and that the email titled «Critical Security Alert: STM32 Entropy Vulnerability» does not come from the company: it is a phishing attempt, and no link should be clicked. The company added that it had taken the domain down and was investigating «the situation, including how the hackers got access to our legit domain». That is what separates this case from ordinary phishing: the message did not imitate the official channel, it came through the official channel. According to The Block and Cointelegraph the email used genuine domain names and signatures, falsely claimed a factory defect in the STM32 microcontrollers capable of weakening recovery-phrase generation on a share of newer devices, and pushed the recipient toward a «vulnerability check» page built to harvest recovery words. Trezor said keys and funds were not exposed and, as of our verification date, no source has confirmed any theft of funds or recovery phrases. On the same day BitBox reported an identical campaign coming through its own newsletter provider, pointing to a likely shared mail provider used by several bitcoin companies (see the BitBox entry): the campaign is therefore an upstream compromise of a communication channel, not generic phishing against the sector. It is Trezor's second third-party-supplier incident in a few weeks, after the August ShipMonk data leak reported below; no source has linked the two. As of 10 September the investigation is stated to be still open and no closing report has been published: it is not known which provider was breached, since when, or how many customers received the message. UPDATE OF 10 SEPTEMBER 2026, 14:00 CEST: the shared provider has been named publicly, but not by Trezor. At 23:32 CEST on 9 September CoinTracking — a crypto tax-reporting service, not listed in this register — wrote on its official X account that «our third-party email service provider Brevo has experienced a security breach», and reported a third lure from the same wave, an email titled «Data Breach Notice: Please refresh API Keys as soon as possible». It is the first and so far only affected company to name it: Trezor and BitBox still say «third-party provider» without naming it, and at 12:00 UTC on 10 September Brevo's status page reads «fully operational» and carries no security notice. On the headers of the message received by Trezor customers, Decrypt and Cryptopolitan report — on the basis of recipients' screenshots, not of a company confirmation — a sender «Trezor Security <[email protected]>», a return-path of [email protected], the Sendinblue campaign path (Sendinblue is Brevo's former name) and a DKIM, SPF and DMARC pass. If confirmed, that explains why the message landed in inboxes as genuine: the cryptographic signature was the real one for the Trezor domain. There is still no confirmation of stolen funds or recovery phrases, and no closing report: at 14:00 CEST on 10 September Trezor's latest public statement remains the one from 22:37 on 9 September, roughly 15 hours earlier. UPDATE OF 12 SEPTEMBER 2026, 08:00 CEST — TREZOR HAS NOW NAMED THE PROVIDER, AND THE NUMBERS ARE IN. What is written above as of 10 September («Trezor and BitBox still speak of a third-party provider without naming it») is superseded: Trezor published a notice on its official blog titled «Security incident at Brevo, our third-party email provider», dated 10 September 2026, naming the provider and quantifying the exposure. In Trezor's words: on 9 September «Brevo, the third-party marketing platform Trezor uses for newsletter campaigns, suffered a security incident affecting 120 Brevo accounts», and «an unauthorized actor gained access to Brevo's system and used it to send emails from various customer accounts, including Trezor's». THE FIGURES: the incident affected Trezor's opt-in newsletter database, «roughly 347,000 email addresses», which the company treats as exposed and reusable in future phishing attempts; 2,500 people clicked the link before the domain was disabled, within 20 minutes of detection. Trezor states that Brevo's system «holds no passwords, wallet data, or other personal information», that «no Trezor product, wallet, or account system was affected», and that it suspended its Brevo account to stop further sending. ONE POINT REMAINS OPEN, AND TREZOR SAYS SO ITSELF: the company cannot confirm whether the address list was exported. BREVO HAS ALSO SPOKEN, AND IT IS THE SOURCE ON THE MECHANISM: on 10 September Brevo published a post-incident write-up on its own status page, under the title «Attacker gained access to client accounts». It states that at 06:30 UTC on 10 September it identified «a security issue where an attacker exploited a flaw in the way Brevo handles SAML SSO to gain access to 138 Brevo accounts». The mechanism, in Brevo's words: the attacker created a Brevo account, enabled single sign-on on it and invited legitimate Brevo users into that configuration, then signed in through their own identity provider acting as those users; the access was not properly scoped — instead of being limited to the single organization where SSO was enabled, it «wrongly granted the attacker access to all organizations those users could reach». OFFICIAL BREAKDOWN OF THE 138 ACCOUNTS: 6 used to send phishing emails to the contacts stored in them, 43 with contacts exported, 93 with no meaningful activity. Trezor is among the 6 from which the emails were sent. Whether it is also among the 43 whose contacts were exported is stated by neither Trezor nor Brevo, and it is precisely the point Trezor declares it cannot confirm: we do not infer it. NOTE ON THE 120/138 DISCREPANCY: the lower number is Trezor's on 10 September, the higher one is Brevo's in its later write-up; the figure to use is the platform operator's, 138. REMEDIATION: Brevo states it closed the attack vector at 08:30 UTC on 10 September — two hours after detection — signed out all platform users, deployed permanent fixes limiting SSO access to the owning organization, and disabled the links contained in the phishing emails. WHY WE REMOVED THE «ONGOING» FLAG: as of 10 September this entry was marked as an event in progress. It no longer is — the vector is closed on the operator's own statement, the phishing domains have been taken down, the sending has stopped. What remains open, and is why this entry is not marked as resolved, is what the incident leaves behind: roughly 347,000 addresses in someone's hands, no confirmation as to whether Trezor's list was exported, and no final report from Trezor. As of 12 September no source — including BleepingComputer, SecurityWeek, Malwarebytes and The Record, all of which covered the case — has confirmed any theft of funds or recovery phrases traceable to this campaign. UPDATE OF 12 SEPTEMBER 2026, 13:30 CEST — A PRECISION ON TREZOR'S POSITION. Above it reads that Trezor «states it cannot confirm whether the list was exported»: that is accurate but incomplete, and the omission works against the company. In the same 10 September notice Trezor adds what it concludes operationally, and it is the most cautious conclusion available: «Until we hear more from Brevo, we are treating all roughly 347,000 newsletter addresses as known to the attacker and possibly reusable for phishing.» It is worth writing down because it is exactly the rule of conduct this register recommends below, adopted by the company first: the uncertainty about the export is not used to play the incident down. On 11 September a Trezor spokesperson repeated the same sentence to Cointelegraph, also confirming that «the initial email was sent to 347,000 customers», all of whom were subsequently contacted about the risk.

    ↗ source
  2. Data breach Severe ● open

    Customer data leak at logistics provider ShipMonk: about 80,700 buyers exposed, shipping addresses included

    ShipMonk, the logistics provider that ships Trezor orders, was breached on 6 August 2026 through a vulnerability in the third-party analytics platform Metabase, and on 10 August notified Trezor of unauthorised access to the systems holding order data. On 13 August Trezor disclosed the incident: 13,689 customers affected, of whom 11,742 had full name, email, phone number and shipping address exposed and 1,947 had partial exposure (name, city, email), covering orders delivered between 10 May and 8 August 2026 in the United States, United Kingdom, Sweden, Colombia, Brazil, ITALY and Portugal. On 2 September ShipMonk told Trezor the stolen material also contained order data from an earlier partnership between November 2019 and August 2021, which under the contract and the retention policy should have been deleted: on 4 September Trezor updated the notice, adding about 67,000 US customers with full exposure (name, email, phone, shipping address, order number), for a total of roughly 80,700 people. Trezor states that its own systems, devices, private keys and wallet backups were untouched, and says it had repeatedly received written confirmation from ShipMonk that the historical data had been deleted — a deletion that had not happened. The risk is not to the funds themselves but to the people: the list ties a name, phone number and home address to someone who owns a hardware wallet, the same raw material that after the 2020 Ledger breach fuelled years of targeted phishing, fake letters and physical-safety threats.

    ↗ source

verified on

Public reviews

4.7/5 7,254 reviews
  • Google Play ↗ 4.8/5 3,718 reviews

    Exact count from JSON-LD (ratingValue 4.7647). Measures the companion app, not the device.

  • Trustpilot ↗ 4.6/5 1,995 reviews

    Platform TrustScore read via uk.trustpilot.com (.com returns 403). Company profile trezor.io.

  • App Store ↗ 4.7/5 1,541 reviews

    Exact rating from itunes.apple.com/lookup ('Trezor Suite' app). Measures the companion app, not the hardware device.

Weighted average across 3 public review platforms (7,254 reviews in total), weighted by volume. This is not our rating: it is those platforms’ average.

FAQ

How much does a Trezor cost?

The entry-level Safe 3 costs about €59 ($59 on the official shop). The Safe 5 with a colour touchscreen costs about €129, and the flagship Safe 7, with Bluetooth and wireless charging, about €249. The older Model One and Model T are no longer sold.

Is Trezor open source?

Yes, largely so: firmware, software and hardware design are public and auditable. This is one of the brand's historic strengths versus competitors with closed-source firmware.

Does Trezor have a secure element?

The Safe 3, Safe 5 and Safe 7 use an EAL6+ certified secure element; the Safe 7 also adds the TROPIC01 chip, which Trezor presents as the first auditable secure element. The older Model One, now discontinued, had none and relied on the microcontroller alone.

Sources

Show 2 more sources

Update history

  1. reputazione Not affected by the 30 Jul 2026 Coldcard exploit (an entropy flaw specific to that firmware): Trezor stated user funds are safe, different randomness-generator design.
  2. reputazione TROPIC01 chip vulnerability (Safe 7) and a Safe 3 disclosure, found in lab conditions by Ledger Donjon (laser fault injection: requires physical access and advanced equipment). No real-world attack, funds safe, transparent handling via responsible disclosure.

🔔 Notify me of changes

← All Trezor plans