Key points
- A hardware wallet protects your private key from malware on your computer. It does not protect you from signing a malicious transaction yourself, from losing your seed phrase, or from someone forcing you to open the device.
- A secure element is a tamper-resistant chip. EAL5+ and EAL6+ certifications measure how rigorously that chip was evaluated, not the quality of the firmware running on top of it.
- No manufacturer gives you both halves at once: Blockstream Jade ($79) is fully open but drops the physical secure element; Ledger has a certified secure element and closed firmware; Coldcard is source-available, which is not the same thing as open source.
- Ledger suffered a 2020 data leak that exposed roughly 270,000 records including home addresses, and a December 2023 supply-chain attack that drained about $484,000. Neither compromised a single seed phrase.
- At an amortised cost of roughly 30 euros a year for device plus metal backup, the hardware pays for itself once your balance passes a few thousand euros.
Almost everyone starts with the same question: "which is the best hardware wallet?" It is the wrong question, which is why the answers you find are product rankings that leave you no better informed. The right question is: what exactly are you defending against? A device that is excellent against malware can be useless against a home invasion. One that resists a sophisticated physical attack will not save you if your real problem is that you are going to lose the paper you wrote the words on.
Get the order right: define the threat first, then pick the tool. Do it the other way round and you end up with a 400-euro gadget guarding 300 euros, and the seed phrase sitting in your phone's camera roll.
What a hardware wallet actually protects (and what it doesn't)
A hardware wallet is a tiny computer with one job: to generate and hold a private key that never leaves the device, and to sign transactions inside it. When you send bitcoin from a hardware wallet, your computer builds the unsigned transaction, passes it to the device over USB or Bluetooth, the device signs it internally and hands back only the signature. The key never touches an internet-connected system.
That tells you exactly what it covers: malware on your computer or phone (an infostealer that empties your browser finds no key, because the key is not there), exchange breaches — the core of the custody versus self-custody argument — and casual physical extraction, if the device carries a secure element.
And here is what it does not cover, which is where the money actually goes:
- It does not stop you signing a malicious transaction. Connect the wallet to a fraudulent site and approve an unlimited spending allowance on your tokens, and the device will obediently sign: it has done its job correctly. This is the mechanism behind the most common scams, and no wallet solves it for you.
- It does not stop you losing the seed phrase. If the device breaks and you have no seed, the funds are gone. The hardware is replaceable; the seed is not.
- It does not stop coercion. Against someone willing to use violence, the chip is irrelevant. Chainalysis reported a growing link between crypto crime and physical violence in its 2026 data.
- It does not stop address mistakes. Pasting the wrong address has identical consequences with or without a device.
The device is not the system. A hardware wallet is one component. The complete system is: device + seed backup + a verification procedure you follow before signing + an inheritance plan. Most people buy the component and skip the other three.
Pick your threat model before you pick a model number
Write down, in one line, what you are defending against. It changes the purchase completely.
- Malware and phishing (almost everyone's real case): any device with its own screen works, provided it displays the real destination address and amount so you can compare them against what you think you are signing.
- Physical theft of the device: a strong PIN and a secure element. Every serious model covers this.
- Coercion (the "wrench attack"): the defence is a passphrase, not hardware.
- Your own mistakes: the budget goes to a metal backup and a written procedure, not to a more expensive gadget.
- A sophisticated, targeted attacker: you are now in multisignature territory with devices from different manufacturers, and no single product is enough.
Secure elements, EAL5+ and EAL6+: what the labels mean
A secure element is a microcontroller built to resist physical attack: power-consumption analysis, fault injection through voltage glitching, decapping the chip to read it under a microscope. It is the same family of chips used in bank cards and biometric passports.
EAL (Evaluation Assurance Level) comes from Common Criteria and indicates how rigorously the design was evaluated, on a scale from EAL1 to EAL7. It is not a grade for "how secure this is": it is a grade for "how thoroughly this was reviewed". EAL5+ and EAL6+ are high levels, comparable to banking; the "+" marks additional assurance components on top of the base level.
Two caveats absent from the marketing copy. The certification covers the chip, not the firmware running on it, so an EAL6+ secure element with badly written firmware is still vulnerable at the logic level. And physical attack is probably not your real threat: extracting a key from a secure element requires laboratory equipment and physical possession of your device.
Open firmware versus closed firmware: every vendor's real trade-off
This is where the industry splits, and where marketing distorts the most. The open-source argument is that you, or someone competent acting on your behalf, can verify the firmware does what it claims. The closed-source argument is that secure element manufacturers impose non-disclosure agreements making it impossible to publish the code that talks to the chip. Both are true at once, which is why no vendor offers 100% of both.
Three distinctions worth holding onto:
- Coldcard is source-available, not OSI open source. Its code is published and can be audited, but the licence does not meet Open Source Initiative criteria. The distinction is misreported constantly.
- Blockstream Jade gives up the physical secure element. It is the only device with fully open hardware and firmware, and the price of that openness is that there is no physical SE: it uses a "virtual secure element" that splits the secret with a remote oracle. This is not an oversight, it is a deliberate design trade-off.
- Trezor took years to ship a secure element. The Trezor One and Trezor T had none and were vulnerable to physical extraction by anyone holding the device. The Safe 3/5/7 family fixed that.
Model comparison (prices as of August 2026)
| Model | Price | Secure element | Open source | Bitcoin-only |
|---|---|---|---|---|
| Ledger Nano S Plus | ~€49–79 | Yes (EAL certified) | No, closed firmware | No |
| Ledger Nano X | ~€79–149 | Yes | No | No |
| Ledger Nano Gen5 | €179 | Yes | No | No |
| Ledger Flex | €199 | Yes | No | No |
| Ledger Stax | €399 | Yes | No | No |
| Trezor Safe 3 | $79 | Yes, EAL6+ | Yes | Yes (BTC-only edition) |
| Trezor Safe 5 | $129 | Yes | Yes | Yes |
| Trezor Safe 7 | $249 | Dual auditable SE + post-quantum protection | Yes | Yes |
| Coldcard Mk5 | $189 | Yes (2 SE) | Source-available | Yes, BTC only |
| Coldcard Q | $289 | Yes (2 SE) | Source-available | Yes, BTC only |
| BitBox02 | ~$149 | ATECC608A/B | Yes (Apache 2.0, reproducible builds) | BTC-only edition |
| BitBox02 Nova | ~$203 (BTC-only) | EAL6+, dual chip | Yes | Yes |
| Keystone 3 Pro | $149 | 3 secure elements, EAL5+ | Yes (MIT), reproducible builds | Optional BTC-only firmware |
| Blockstream Jade | $79 | Virtual SE (no physical SE) | Yes, hardware and firmware | Yes, BTC only |
| Blockstream Jade Plus | $149 | Virtual SE | Yes | Yes |
| Tangem (2-card pack) | $54.90 | NXP SE050 EAL6+ | No (audited by Kudelski) | No |
Prices and specifications as of August 2026; check the manufacturer's own site before buying.
The reproducible builds advertised by BitBox and Keystone matter more than they sound. They mean anyone can compile the published source and obtain byte-for-byte the same binary the vendor ships. Without that, open source only proves what could be running on the device, not what is.
The seed, BIP-39 and the passphrase
When you initialise a device, it generates a random number and encodes it as 12 or 24 words using the BIP-39 standard. The words come from a fixed list of 2,048 and the last embeds a checksum, which is why you cannot invent a valid seed by swapping words at random. Every account you will ever hold derives deterministically from that number. The seed is your money; the device merely guards it.
The passphrase (sometimes marketed as the "25th word") is an extra string mixed into the seed. Change one character and you get a completely different, perfectly valid tree of accounts. That enables hidden wallets: the seed alone opens an account with a small, plausible balance, seed plus passphrase opens the real one. It is the only practical defence against coercion, because you can hand over PIN and seed and what appears is a wallet holding 300 euros.
A passphrase has no recovery path. It is not on the device, it is not in the seed, and nobody else knows it. Forget it and those funds are unrecoverable, permanently. Before moving any serious amount into a hidden wallet, run the full rehearsal: send a token amount, wipe the device, restore from seed plus passphrase, and confirm the funds reappear.
The backup: why paper is not enough
Paper gets wet, burns, and disappears in house moves. A metal backup — steel plates you stamp the words into — survives fire and flooding and costs between 30 and 100 euros. It is the line item people cut, and the one they should not. Keep at least two copies in physically separate locations, and if you are separating them geographically, consider a passphrase so that a single stolen copy is not sufficient.
Ledger's real incidents, stated precisely
Ledger is the best-selling manufacturer and also the one with the longest list of documented incidents. It is worth understanding them accurately, because online they get exaggerated and conflated. All four appear in the company's own public incident report, and the 2020 one is catalogued on Have I Been Pwned.
| Incident | Date | What actually happened |
|---|---|---|
| Customer data leak | Breach Jun 2020, public dump Dec 2020 | A misconfigured e-commerce API exposed 1.1 million email addresses and ~270,000 detailed records including home addresses. No funds and no seed phrases were compromised |
| Ledger Recover | May 2023 | An optional, paid recovery service using encrypted key sharding with identity verification. Nothing was stolen |
| Ledger Connect Kit | 14 Dec 2023 | A former employee's NPM account was phished; a drainer was injected into a library used by thousands of dApps. About $484,000 stolen. Patched within hours |
| Global-e exposure | Jan 2026 | Unauthorised access to names and contact details inside payment processor Global-e's system, not Ledger's. No payment data, no seed phrases. Number of people affected not published |
2020 was not a cryptographic failure, it was a personal-data failure — and the consequences were worse than that sounds. Publishing the postal addresses of people known to hold cryptocurrency triggered a wave of highly targeted phishing and physical threats. Hence the standard advice today: avoid giving your home address or primary email when buying a device.
Ledger Recover stole nothing from anyone, and it was still the brand's worst crisis. The reason is conceptual: it demonstrated that the firmware could export key-derived material. The service was opt-in and required explicit consent, but many users had assumed this was physically impossible.
Connect Kit did drain real money — roughly $484,000 by CoinDesk's count — but it never attacked the device. It attacked the JavaScript library websites use to talk to it. Every user who lost funds approved the transaction on their own Ledger: the cleanest illustration that hardware will not save you from signing something malicious.
Worked example: when the device pays for itself
Take a reasonable, complete setup: a Trezor Safe 3 at $79 (roughly €73 at August 2026 rates, plus shipping) and a metal backup plate at €60. Rounded total: €150. These devices comfortably last five years, so amortised that is €30 a year.
Now the other side of the ledger. Chainalysis counted, for 2025, $713 million stolen from personal wallets across 158,000 incidents involving more than 80,000 unique victims. Dividing those two figures gives an average loss per victim of around $8,900 (our own calculation from those numbers). We do not know the size of the exposed population, so there is no clean probability to compute — but you can frame the threshold in reverse:
The device is worth it when
annual probability of compromise × balance > €30.
At a €2,000 balance you need a 1.5% annual probability. At €10,000, a mere 0.3% does it. At €500, you would need a 6% annual chance of your hot wallet being emptied, which is hard to justify if your digital hygiene is decent.
In practice: below roughly €1,000–1,500, your money does more work in a well-managed software wallet with unique passwords and app-based 2FA on a licensed platform. Above that, hardware starts paying for itself; above €5,000, not owning one is hard to defend. The calculation ignores one cost running the other way: the risk that you lose the seed. Hardware without discipline can make your security worse.
Purchase checklist
- Buy only from the manufacturer's own store or a reseller they list themselves. Never from a general marketplace and never second-hand.
- Where possible, use a secondary email address and a pickup point rather than your home. The 2020 Ledger leak is the reason.
- Decide in advance whether you want a Bitcoin-only device (Coldcard, Jade, BitBox02 BTC-only) or a multi-asset one. The firmware attack surface is smaller on the former.
- Check whether the manufacturer publishes reproducible builds: that is what turns "open source" into something verifiable.
- Budget for the metal backup from the start, not as an afterthought.
Setup checklist, step by step
- Inspect the packaging, but do not trust the seal alone: the real control is that the device generates the seed in front of you.
- If it arrives with a seed already written on a card, it is fraudulent. Return it and notify the manufacturer.
- Update the firmware from the official application before generating anything, and confirm the app verifies the device's authenticity.
- Generate the seed on the device itself and write it by hand, with no photos and no keyboard. Verify it using the device's own check procedure.
- Set a long PIN, with no dates and no repeated digits.
- Send a small amount, wipe the device completely, and restore from the seed. Only once the funds reappear should you move the rest.
- Transfer the seed to metal and store two copies in physically separate places.
- If you are going to use a passphrase, repeat the full restore rehearsal with it before depositing anything serious.
- Write instructions for your heirs, without the seed inside the document, and store them separately.
- Never type the seed into a computer, website or app, not even the manufacturer's own: no legitimate tool will ever ask for it.
- Do not store it in photos, notes, email, cloud storage or a password manager.
- Do not split 24 words into three chunks of 8 thinking you have multiplied your security: you have drastically shrunk the search space for whoever finds one chunk. If you want to split a secret, use a scheme designed for that.
- Do not buy a device that a seller has "already set up for you".
Where things stand in 2026
Two changes define the year. The first is regulatory. Across the European Union, MiCA — Regulation (EU) 2023/1114 — now governs crypto-asset service providers, and national transition periods closed during 2026; in Spain, for example, the grandfathering window ended on 1 July 2026, after which only firms holding a CASP licence from the national authority or passporting one from another member state may offer custody. That constrains exchanges and professional custodians, not you: self-custody remains legal and requires no registration anywhere in the EU. In the United States, a joint SEC and CFTC interpretation published on 17 March 2026 set out a token taxonomy and acknowledged that most crypto-assets are not themselves securities; holding your own keys is not a regulated activity there either.
Tax is where people over-generalise. Owning a device creates no filing obligation by itself, but disposals — selling, swapping, spending — are generally taxable events, and treatment varies enormously by jurisdiction: how gains are characterised, which forms apply, and whether self-custodied balances must be declared at all. Do not apply a rule you read about one country to yours; check your national tax authority or a professional.
The second change is commercial: manufacturers have started selling post-quantum resistance (the Trezor Safe 7 advertises it). That addresses a future risk, not a present one — no known quantum computer today threatens Bitcoin or Ethereum signatures. Do not let it drive your purchase.
One closing note on where the money actually goes. The FBI's IC3 report covering 2025 recorded more than $11 billion in cryptocurrency fraud across 181,565 complaints. The overwhelming majority of those losses did not come from keys extracted from chips. They came from people persuaded to transfer funds voluntarily. No hardware wallet fixes that. What fixes it is reading the real destination address and amount on the device screen, every single time, before you press confirm.
Frequently asked questions
Can I use a second-hand hardware wallet?
No. The seller may have initialised the device with a seed they already know and shipped it to you with a pre-written "recovery" card. If a device arrives with 24 words already printed on paper, it is a scam: a legitimate device generates the seed in front of you the first time you power it on. Buy only from the manufacturer's own store or a reseller they list themselves.
What happens if the manufacturer goes out of business?
Nothing, as long as you wrote down the seed phrase. Seeds follow the BIP-39 standard and are interoperable: you can restore a Ledger seed on a Trezor, a Trezor seed on a BitBox, and so on. What may not travel cleanly is the derivation path for less common coins and, above all, passphrases implemented in proprietary formats. Verify compatibility before you depend on it.
Does a passphrase replace the seed phrase?
No, it stacks on top. A passphrase is an extra word or sentence that, combined with your 12 or 24 words, derives a completely different set of accounts. Forget it and the funds in that hidden wallet are gone even though you still hold the seed. Lose the seed and the passphrase alone is worth nothing.
Is EAL6+ twice as secure as EAL5+?
No. Common Criteria measures how rigorously a design was evaluated, not resistance on a linear scale. EAL5+ implies a semiformally verified design; EAL6+ adds semiformal verification of the design plus further checks. Both are high levels, the kind used in bank cards and passports. Against a realistic attacker the practical difference is small.
Sources and references
- Ledger — Security incident report
- Have I Been Pwned — Ledger breach
- CoinDesk — Ledger exploit drained $484K
- Chainalysis — 2026 Crypto Crime Report
- Chainalysis — Crypto hacking and stolen funds 2026
- FBI — Cryptocurrency and AI scams bilk Americans of billions (IC3 2025)
- SEC — Staff clarifies application of federal securities laws to crypto assets
- CNMV — Crypto-asset regulation under MiCA (example of a national register)
Related guides
Custodial vs non-custodial wallets: who actually holds your keys
The precise technical difference, what happened at Mt. Gox, FTX and Celsius, the $713M stolen from personal wallets in 2025, and what MiCA really protects.
Security · 13 minThe most common crypto scams in 2026 and how to spot them
Pig butchering, drainers, address poisoning and fake support explained from the inside, with the Chainalysis and FBI numbers and what to do if you have already been hit.
Security · 15 minHow to choose an exchange: licences, fees and the small print
In the EU the number one criterion is no longer the fee, it is the MiCA licence. Public registers, the Binance case, the spread trap and the real cost of buying €1,000.
Security · 14 min