Compare sixteen hardware wallets by price, secure element, open firmware and Bitcoin-only support. Manufacturer data as of August 2026, with no affiliate links.
Updated 28 August 2026
Almost every hardware wallet comparison in this industry is written by someone earning a commission on each sale. This one is not: there is not a single affiliate link here, and no manufacturer has paid to appear or to be placed higher in the table.
The data comes from the manufacturers' own pages and their authorised resellers, collected on 28 August 2026. Prices are shown in dollars as illustrative figures rather than live conversions, and they move with promotions and import duties: check them before you buy.
Model
Price
Secure element
Open firmware
Bitcoin-only
How to read this table
"Secure element" is a trade-off, not a tick box. A secure element is a chip built to resist physical attack and to hold the key without ever exposing it. The EAL5+ and EAL6+ certifications describe how rigorously that design was evaluated. The catch: the companies making these chips impose non-disclosure agreements, so a device with a secure element can almost never be fully open.
That tension defines the whole category. Blockstream Jade gives up the physical secure element — it uses a "virtual secure element" model backed by a remote oracle — in exchange for being the only device with both hardware and firmware fully open. That is a deliberate design decision, not an oversight, and working out which of the two risks bothers you more is what actually decides your purchase.
"Source-available" is not "open source". Coldcard's firmware can be read, but its licence does not meet the OSI definition of open source. It is a distinction that gets reported wrong constantly, which is why the table keeps the two apart.
Ledger has the secure element and does not have open firmware. That is, quite literally, the argument its critics make, and it became concrete in May 2023 with Ledger Recover: an optional recovery service which demonstrated that the firmware could export key material under certain conditions. No funds were stolen; what happened was a crisis of confidence about the threat model.
Bitcoin-only: a choice, not a limitation
Firmware that only understands Bitcoin contains less code. Less code means less attack surface and fewer updates. If bitcoin is all you plan to hold, the Bitcoin-only build of the same device is strictly safer than the multi-coin one, at no extra cost.
Nearly every manufacturer in the table offers that variant, and on Trezor, BitBox and Keystone it is an alternative firmware you can flash onto the same device.
What none of these boxes will save you from
Signing a malicious transaction. If you approve a transfer on the device's screen having misunderstood it, the wallet signs without complaint. That is exactly what happened with the Ledger Connect Kit drainer in December 2023.
Losing the seed phrase. The device is replaceable; the 12 or 24 words are not.
Someone forcing you to open it. The defence there is a passphrase opening a secondary wallet with a small balance, not the chip.
An unofficial seller. Always buy from the manufacturer or an authorised reseller. Never second-hand, and never a device that arrives with a seed already written down.
A warning that does not appear on any product page. In December 2020 Ledger's customer database was published: 1.1 million email addresses and roughly 270,000 records including physical addresses. Not a single fund was compromised, but for years afterwards the people on that list received phishing campaigns and threats. Buying a hardware wallet means handing your details to someone: use a dedicated email address and, if the manufacturer allows it, a pickup point rather than your home.