Hardware Wallet Review

Trezor Safe 3 Review: Open-Source Security for $79

Our top pick for most people. Fully open-source hardware and firmware, an EAL6+ secure element, Bitcoin-only firmware option, and it costs less than dinner for two. Here's the full breakdown.

15 min read
9/10

Bitcoin.diy Rating

Our top pick for most people

The Trezor Safe 3 is the hardware wallet we recommend to most people. It's $79, fully open-source, has a proper secure element chip, and offers a Bitcoin-only firmware mode that strips out everything except BTC. That combination doesn't exist anywhere else at this price.

Made by SatoshiLabs in Prague, Czech Republic, Trezor was the world's first commercial hardware wallet back in 2014. They've been at it longer than anyone. And their commitment to open-source hasn't wavered: every line of firmware code, every hardware schematic, is publicly available for anyone to audit.

We tested both the Safe 3 ($79) and the Safe 5 ($169) over several weeks. This review explains why the Safe 3 is our pick, what the Safe 5 adds, and where Trezor still has room to improve.

What Is Trezor?

Trezor is made by SatoshiLabs, a company founded in Prague in 2013. They shipped the first-ever commercial hardware wallet in January 2014. That's over a decade of building security devices for Bitcoin holders.

The idea is the same as any hardware wallet: your private keys live on a physical device, offline, where hackers can't reach them. You sign transactions on the Trezor, confirm on its screen, and the signed transaction goes to the network. Your seed phrase never touches the internet.

What sets Trezor apart is the open-source commitment. The firmware, the hardware schematics, the bootloader, the companion app (Trezor Suite), all of it is published on GitHub. Anyone can read the code, report bugs, or fork it. This matters because in security, "trust but verify" beats "just trust us" every single time.

The current lineup is the Safe 3 ($79) and Safe 5 ($169). Older models (Trezor One and Model T) are still supported but no longer manufactured.

Safe 3 vs Safe 5

Both models share the same security core. The differences are about experience, not protection.

FeatureSafe 3Safe 5
Price$79$169
Secure elementEAL6+ (Optiga Trust M)EAL6+ (Optiga Trust M)
DisplayOLED monochromeColor touchscreen
InputSingle buttonTouchscreen + haptic
ConnectionUSB-CUSB-C
BluetoothNoNo
Bitcoin-only firmwareYesYes
Shamir backupYes (SLIP-39)Yes (SLIP-39)
Open-source100%100%

Our take: The Safe 3 at $79 is the sweet spot. You get the same secure element, the same firmware, and the same security features as the Safe 5. The touchscreen on the Safe 5 is nicer for entering passphrases and verifying addresses, but it's not $90 nicer for most people. If budget isn't a concern and you want the premium experience, the Safe 5 is excellent. For everyone else, the Safe 3.

Setup and Daily Use

Setting up a Trezor Safe 3 takes about 10 minutes. It's one of the simpler hardware wallet setups we've tested.

1

Download Trezor Suite

Get the desktop app from trezor.io. Available for Windows, Mac, and Linux. There's also a web version at suite.trezor.io, but the desktop app is more reliable.

2

Plug In and Update Firmware

Connect via USB-C. Trezor Suite will check for firmware updates and install the latest version. This is also where you choose between universal firmware or Bitcoin-only firmware.

3

Create Your Wallet and Back Up Your Seed

The device generates a 12 or 24-word seed phrase (or Shamir shares if you choose SLIP-39). Write it down on the included cards. Store it somewhere fireproof and offline. This seed is your ultimate backup.

4

Set a PIN

Choose a PIN up to 50 digits long. You'll enter this every time you connect the device. After 16 wrong attempts, the device wipes itself. Your seed backup is your recovery path.

5

Add a Bitcoin Account and Start Receiving

Create a Bitcoin account in Trezor Suite. You'll see a receive address. Always verify on the device screen that it matches. Then send Bitcoin from your exchange to your Trezor address.

Trezor Suite is a solid companion app. It handles portfolio tracking, transaction history, fee estimation, and coin control. It's not as flashy as Ledger Live, but it's clean and functional. And if you prefer a different interface, the Trezor works with third-party wallets like Electrum, Sparrow, and Wasabi too.

Why Open-Source Matters

This is the single biggest reason we recommend Trezor over Ledger.

When a hardware wallet's code is open-source, it means thousands of security researchers, developers, and Bitcoin enthusiasts can inspect it. If there's a bug, someone finds it. If there's a backdoor, someone catches it. Closed-source code relies on one company's internal team to find problems. Open-source has the whole world looking.

Bitcoin itself is open-source. The ethos of "don't trust, verify" runs deep in this community. A hardware wallet that asks you to trust closed-source code is at odds with that philosophy. Trezor aligns with it perfectly.

The practical benefit? When Ledger launched their Recover feature, it proved their closed-source firmware could extract seed phrases from the device. With Trezor, you can read the code yourself and confirm that no such capability exists. That's not theoretical security. That's verifiable security.

Bitcoin-Only Firmware

Trezor offers two firmware options: universal (supports 8,000+ coins) and Bitcoin-only (supports exactly one coin: BTC). You pick which one during setup, and you can switch later.

Why would you want Bitcoin-only firmware? Less code means less attack surface. Every line of altcoin support is a line that could potentially contain a bug. By stripping everything except Bitcoin, you're running a leaner, tighter piece of software. The firmware binary is smaller, the codebase is simpler, and there are fewer things that can go wrong.

For Bitcoin-only holders, this is a no-brainer. Install the Bitcoin-only firmware and forget about the altcoin world entirely. Your Trezor becomes a pure Bitcoin security device. No Ethereum, no tokens, no distractions.

No other major hardware wallet offers this. Ledger doesn't have a Bitcoin-only mode. Coldcard is Bitcoin-only by design (there's no multi-coin option). Trezor gives you the choice.

Security Features Deep Dive

The Safe 3 packs serious security into a small package. Here are the standout features:

EAL6+ Secure Element

The Safe 3 uses an Infineon Optiga Trust M chip certified to EAL6+. This is a higher certification than Ledger's EAL5+ chip. It stores your private keys in tamper-resistant silicon that's designed to resist physical attacks. And unlike Ledger, the firmware interacting with this chip is open-source, so you can verify how it's used.

Passphrase (25th Word)

Add a passphrase on top of your 24-word seed to create a hidden wallet. Someone who finds your seed but doesn't know the passphrase can't access the hidden wallet. You can even set up a decoy wallet (no passphrase) with a small balance, while your real funds live behind the passphrase. On the Safe 3, passphrase entry happens directly on the device, not on your computer.

Shamir Secret Sharing (SLIP-39)

Instead of backing up one 24-word seed phrase, you can split your backup into multiple shares using Shamir's Secret Sharing scheme. For example, create 5 shares and require any 3 to recover. Store the shares in different locations. No single share is enough to steal your funds. This is far more resilient than keeping a single seed phrase in one place. Learn more in our cold storage guide.

Physical Attack Resistance

Older Trezor models (without a secure element) were vulnerable to a physical seed extraction attack if someone got their hands on the device. The Safe 3's EAL6+ chip fixes this entirely. Even with physical access and lab equipment, extracting the seed from the secure element isn't feasible. If you're upgrading from an older Trezor, this is the biggest reason to switch. If you used a passphrase on your old device, you were already protected, but the secure element adds defense in depth.

Pros and Cons

✓ What Trezor Gets Right

  • 100% open-source. Hardware schematics, firmware, bootloader, companion app. All public, all auditable. This is the gold standard.
  • Bitcoin-only firmware. Strip out every altcoin. Run nothing but Bitcoin. Smaller attack surface, cleaner code.
  • $79 for the Safe 3. Best price-to-security ratio in hardware wallets. EAL6+ secure element at this price is remarkable.
  • Shamir backup. Split your seed into shares for more resilient recovery. No other major wallet does this as cleanly.
  • Passphrase on device. Enter your passphrase directly on the Trezor screen. It never touches your computer.
  • Third-party wallet support. Works with Electrum, Sparrow, Wasabi, and more. You're not locked into Trezor Suite.

✗ Where Trezor Falls Short

  • No Bluetooth. USB-C only. You can't manage your wallet from your phone wirelessly. This is intentional (security over convenience), but it's still a limitation.
  • Safe 3 screen is small. The monochrome OLED works fine, but verifying long addresses on it isn't fun. The Safe 5's touchscreen is a big upgrade here.
  • No air-gap option. The Trezor connects via USB. For true air-gapped signing, Coldcard with MicroSD is the better choice.
  • Single button navigation (Safe 3). Navigating menus and confirming actions with one button takes patience. Not hard, just slow.
  • Not as polished as Ledger Live. Trezor Suite gets the job done, but Ledger Live has a slicker UI and more features like staking and NFT support.
  • Legacy physical vulnerability reputation. Even though the Safe 3 fixes the issue, the old "Trezor can be physically hacked" narrative still follows the brand.

Trezor vs Ledger vs Coldcard

Three philosophies. Same goal. Here's how they compare:

FeatureTrezor Safe 3Ledger Nano XColdcard Mk4
Price$79$149$148
Open-sourceYes (100%)No (firmware)Yes (100%)
Secure elementEAL6+EAL5+ATECC608B
BluetoothNoYesNo
Air-gappedNoNoYes (MicroSD)
Bitcoin-only modeYes (firmware)NoBTC-only by design
Best forMost peopleMobile + multi-coinSecurity maximalists

Our recommendation: For most Bitcoin holders, the Trezor Safe 3 hits the sweet spot of price, security, and usability. If you need Bluetooth and hold many coins, read our Ledger review. If you want maximum air-gapped security and don't mind a steeper learning curve, Coldcard is the top of the line. Check our full hardware wallet comparison for more detail.

The Verdict: 9 out of 10

The Trezor Safe 3 does almost everything right. Open-source hardware and firmware mean you don't have to trust anyone. The EAL6+ secure element fixes the physical vulnerability that plagued older models. Bitcoin-only firmware reduces your attack surface to the absolute minimum. And it costs $79.

It loses one point for the lack of Bluetooth (some people genuinely need mobile access) and the small screen on the Safe 3 that makes address verification tedious. These are minor complaints for a device that nails the fundamentals this well.

If you're looking for your first hardware wallet, or upgrading from an exchange account or mobile wallet, the Trezor Safe 3 is where you should start. It's the best balance of security, transparency, and price on the market right now.

9/10

Our Top Pick for Most People

Fully open-source, Bitcoin-first mindset, best price-to-security ratio. The Safe 3 at $79 is the hardware wallet we recommend to almost everyone. The closed-source chip debate ends here.

Frequently Asked Questions

Is the Trezor Safe 3 safe for storing Bitcoin?

Yes. The Safe 3 stores your private keys in an EAL6+ certified secure element chip that never exposes them to your computer or phone. All transaction signing happens on the device. The firmware and hardware are 100% open-source, meaning security researchers worldwide can audit the code. No private keys have ever been compromised on a Trezor device with a passphrase enabled.

What is Bitcoin-only firmware and should I use it?

Bitcoin-only firmware is a special build of Trezor's software that strips out all altcoin support entirely. No Ethereum, no tokens, no other chains. Just Bitcoin. This reduces the attack surface (less code means fewer potential bugs) and is preferred by Bitcoin maximalists. You can switch between universal and Bitcoin-only firmware at any time through Trezor Suite.

Should I buy the Safe 3 or the Safe 5?

The Safe 3 ($79) and Safe 5 ($169) offer the same level of security. The Safe 5 adds a color touchscreen with haptic feedback, making it easier to verify addresses and navigate menus. If you want the best experience money can buy, get the Safe 5. If you want the best value for solid security, the Safe 3 is the right choice. We recommend the Safe 3 for most people.

What is Shamir Secret Sharing (SLIP-39)?

Shamir Secret Sharing splits your seed backup into multiple shares. For example, you can create 5 shares and require any 3 to recover your wallet. This means no single backup location holds enough info to steal your funds, and you can lose up to 2 shares without losing access. It's a more resilient backup method than a single 24-word seed phrase. Trezor is one of the few wallets that supports it.

What is the passphrase (25th word) feature?

A passphrase is an extra word or phrase you add on top of your 24-word seed. It creates an entirely separate hidden wallet. Even if someone finds your seed phrase, they can't access funds protected by a passphrase without knowing it. It also means you can have a decoy wallet (no passphrase) with a small amount, and a real wallet (with passphrase) holding your main stack. The Safe 3 enters the passphrase directly on the device screen for safety.

Was there a vulnerability with older Trezor models?

Yes. Older Trezor models (One and Model T) without a dedicated secure element were vulnerable to a physical seed extraction attack. An attacker with physical access and specialized equipment could read the seed from the device's memory chip. The Safe 3 fixes this with its EAL6+ secure element, which is resistant to these physical attacks. Using a passphrase also protected against this vulnerability on older models.

Does the Trezor Safe 3 have Bluetooth?

No. Trezor deliberately chose not to add Bluetooth. Wireless connectivity introduces a potential attack vector, and Trezor prioritizes security over convenience. The Safe 3 connects via USB-C only. If mobile access matters more than anything else, the Ledger Nano X is the only major hardware wallet with Bluetooth.

How does Trezor compare to Ledger?

The biggest difference is philosophy. Trezor is 100% open-source (hardware and firmware). Ledger uses a closed-source secure element. Trezor offers Bitcoin-only firmware. Ledger doesn't. Ledger has Bluetooth. Trezor doesn't. Ledger supports more coins out of the box, but Trezor supports 8,000+ with universal firmware. For Bitcoin-focused users, Trezor wins. For multi-coin mobile users, Ledger wins.

Can I use Trezor with third-party wallets?

Yes. Trezor works with many popular Bitcoin wallets including Electrum, Sparrow, and Wasabi. You don't have to use Trezor Suite if you prefer a different interface. This flexibility is one of the advantages of open-source hardware. You can pair your Trezor with whichever software wallet fits your workflow best.

What happens if Trezor (SatoshiLabs) goes out of business?

Because Trezor is fully open-source, the community could maintain the firmware independently. Your seed phrase works with any BIP-39 compatible wallet, so you can always recover your Bitcoin elsewhere. The open-source nature is actually an insurance policy: even if the company disappears, the code and hardware designs live on. Your coins are safe as long as you have your seed phrase.

Affiliate Disclosure: Bitcoin.diy may earn a commission if you sign up through our links. This doesn't affect our review or recommendations. We only recommend products we've tested and believe in. Our editorial opinions are our own, and we'll always tell you the honest downsides alongside the positives. Your trust matters more than any commission.

Ready to Secure Your Bitcoin?

The Trezor Safe 3 is our top pick. But don't take our word for it. Compare all the options.