We moved our own coins to Trezor in 2023, so we have a stake in the answer and we have tried to write it as if we did not. This guide is for anyone about to buy a Trezor, or holding one after the 2026 data leak headlines, who wants the full record rather than a sales page. It covers what the devices protect against, every serious attack that has been published, the customer data leaks, and the handful of habits that close most of the remaining risk.

Disclosure: we earn affiliate commission from Trezor and Ledger through links in our videos, and Trezor invited us to its Safe 3 and Safe 7 launches. Trezor did not see this article. This is education, not personalised security advice. Facts were checked on 17 September 2026.

Is Trezor safe? The short answer

Yes, with one caveat that has nothing to do with the device. Trezor hardware has never had customer funds taken through a remote hack, and every published attack on it has needed the device in hand, lab equipment and, on current models, an attack that has since been fixed or that cannot reach your keys. The weak point has been Trezor's suppliers leaking customer names, emails and addresses, which scammers then use.

ThreatHow well a Trezor Safe model holds up
Malware on your computer or phoneStrong. Transactions are shown and confirmed on the device screen
Someone steals the deviceStrong. PIN, secure element and a wipe after repeated wrong PINs; a passphrase adds a second secret
Lab attack with the device in handStrong on Safe models; weaker on the older Model One and Model T without a passphrase
Weak randomness when creating the walletStrong. Several independent sources are mixed together
Phishing using leaked customer dataDepends entirely on you. This is where Trezor owners actually lose money

How does a Trezor protect your coins?

By keeping the keys on a device that never goes online and making you approve everything on its own screen. Your computer or phone only sees public addresses and unsigned transactions, so malware there can propose a payment but cannot approve one.

  • Open firmware. Everything running on the device is published, and Trezor documents reproducible builds so anyone can confirm the official release matches the public code.
  • A certified secure element. The Safe 3, Safe 5 and Safe 7 use an EAL6+ certified Infineon OPTIGA chip to guard the PIN and protect the wallet backup, as Trezor's secure element page explains.
  • A second secure element on the Safe 7. It adds TROPIC01, a secure element whose design can be audited, so no single chip holds everything.
  • Mixed randomness. New wallets combine randomness from the device, the connected computer and, on Safe models, the secure element, so one failing source does not weaken your seed.
  • Nothing leaves the device. Trezor offers no service that sends your seed or shares of it to anyone, which is the main reason we chose it over Ledger. Our guide to Ledger Recover explains the difference.

Has a Trezor ever been hacked?

Not remotely. Researchers have broken older models with physical access, and have found flaws in newer chips that Trezor either fixed or showed could not reach funds.

Record of published attacks on Trezor devices from 2020 to 2026, all needing physical access, alongside four customer data leaks from 2022 to September 2026 that exposed contact details but no seeds or devices

Top half: the device, which has held up. Bottom half: is customer data held by suppliers, which is what scammers use.

  • 2020, Model One and Model T. Kraken Security Labs extracted seeds by voltage glitching in about 15 minutes with the device in hand. Neither model has a secure element, so a firmware update cannot fully fix it. A strong passphrase defeats the attack.
  • 2023, Model T. The recovery firm Unciphered showed another physical extraction. The same defence applies.
  • 2025, Safe 3. Ledger's security lab, Donjon, glitched the Safe 3's main processor in a way that could help tamper with a device before it reaches a buyer. Trezor fixed it and said seeds protected by the secure element were not exposed.
  • 2026, Safe 7. In June, Ledger Donjon and Tropic Square disclosed a laser fault-injection attack on the TROPIC01 chip. It needs the device taken apart and specialist equipment, and it cannot be fixed by a firmware update. Trezor's response says keys and the backup are not stored on that chip, so funds are not at risk.

Every attack that actually extracted a seed targeted a model without a secure element. The findings on Safe models were published and dealt with before anyone reported a loss, which is the point of hardware that outside researchers can examine.

What about the Trezor data breaches?

They are real and they matter, even though none exposed seeds, PINs or devices. The information leaked lets scammers write convincing emails, send fake letters and, in the worst cases, know where a holder lives.

  • 2022: Trezor's newsletter list was exposed through its email provider, and fake Trezor emails pushed a malicious app.
  • January 2024: a breach of a third-party support ticket system exposed about 66,000 names and email addresses.
  • August to September 2026: the shipping provider ShipMonk was breached, exposing names, emails, phone numbers and addresses of about 81,000 customers, including orders from 2019 to 2021 that Trezor says the shipper had confirmed deleting, as BleepingComputer reported.
  • September 2026: attackers who breached the email platform Brevo used Trezor's account to send a fake "hardware microcontroller vulnerability" alert to about 347,000 newsletter subscribers. About 2,500 people clicked before the site was taken down, according to BleepingComputer. The link led to an app that asked for the wallet backup.

Ledger's record here is worse in scale, with a 2020 breach of about 272,000 customers' home addresses. Neither brand has solved this, so protect yourself: use a delivery address that is not your home where you can, and treat every unexpected message about your wallet as an attack. Our guide to fake crypto support scams shows how the approaches are written.

Is the Trezor Safe 3 or Safe 5 as secure as a Ledger?

Yes, and in one respect more so. The Safe 3 and Safe 5 use an EAL6+ certified secure element, the same certification level as the Ledger Nano S Plus, Flex and Stax, and higher than the EAL5+ chip in the Ledger Nano X. On top of that, Trezor's firmware is fully open, while Ledger's secure element software is only partly published.

Where Ledger still leads is coin coverage and multi-coin staking in one app. Where Trezor leads is verifiability and the absence of any seed export service. We compare the two in full in Trezor vs Ledger, and the Safe 7 has its own Trezor Safe 7 review.

Was Trezor affected by the Coldcard hack?

No. From 30 July 2026, an attacker drained thousands of Bitcoin wallets created on Coldcard devices, whose firmware had been generating seeds with far too little randomness since 2021. Reported losses ran into tens of millions of dollars and kept rising as more wallets were swept. Trezor confirmed its devices do not share that code and that every model generates at least 128 bits of randomness by default.

One warning applies to Trezor owners too. If you created your words on an affected Coldcard and later restored them onto a Trezor, you are still exposed, because the weakness is in the words themselves. Create a new wallet on the Trezor and move your coins. We covered the whole incident in this video.

Our August 2026 breakdown of the Coldcard flaw: the one-character bug, how the attacker found the wallets, who escaped, and what to do if you are affected. Watch it on our CryptoTips channel.

Are the older Trezor Model One and Model T still safe?

Safe enough with a passphrase, and worth replacing for larger sums. Trezor stopped selling both in its shop on 8 January 2026 and says it will provide critical security fixes until at least 2036, according to its support timeline. Neither has a secure element, which is why the physical attacks above worked. With a strong passphrase that is stored separately, a thief with lab equipment still cannot open your main wallet.

How do you use a Trezor safely?

  1. Buy direct from trezor.io or an authorised reseller, never a marketplace, and download Trezor Suite only from trezor.io.
  2. Let Suite check the device. It verifies the device is genuine before installing firmware. Stop if anything looks wrong.
  3. Create a new wallet on the device and write the words on paper or metal. Never photograph them or type them into a computer or phone.
  4. Add a passphrase and store it apart from the words. On Safe models you enter it on the device.
  5. Consider multi-share backup so no single piece of paper can empty your wallet. Our seed phrase guide explains the options.
  6. Check every address on the device screen before you approve, and send a small test amount first.
  7. Ignore every unsolicited message. Trezor will never ask for your words, and no firmware alert will ever need them.

Read how to use a cold wallet for the full walkthrough, and for larger holdings, spread keys across makers with our multisig operational playbook. Once your coins sit in several wallets, the members' Portfolio Tracker shows them together from public addresses, with no keys involved. More guides are in the Wallets and Custody hub.

Frequently asked questions

Is Trezor safer than Ledger?

For most people, yes, though the hardware is now close. Trezor Safe models and most Ledgers use EAL6+ certified secure elements, and neither brand has lost customer funds to a remote device hack. Trezor's advantage is fully open firmware and no seed export service, while Ledger offers Ledger Recover and keeps its secure element software only partly published. Both have leaked customer data.

Can a Trezor be hacked remotely?

No remote hack of a Trezor device has ever been published. Transactions must be confirmed on the device itself, so malware on your computer can suggest a payment but cannot approve it. The published attacks all needed physical possession and lab equipment. Remote losses among Trezor owners come from phishing, where people are tricked into typing their recovery words somewhere.

Was my data in the 2026 Trezor breach?

Possibly, if you ordered a Trezor in the United States between late 2019 and 2021 or bought one recently. Trezor disclosed the ShipMonk breach in August 2026 and widened it in September to about 81,000 customers. The separate Brevo incident exposed newsletter email addresses. Either way, assume your contact details are known and treat every unexpected Trezor message as a scam.

Is the Trezor Safe 7 still safe after the TROPIC01 disclosure?

Yes, according to Trezor. The June 2026 laser attack on the TROPIC01 chip needs the device taken apart and specialist lab equipment, and Trezor says your keys and wallet backup are not stored on that chip. The Safe 7 also has a certified secure element and a main processor as separate protections. A passphrase adds a second secret the attacker would also need.

Does Trezor have access to my recovery phrase?

No. Your recovery words are created on the device and shown only on its screen, and Trezor offers no cloud or custodian backup that sends them anywhere. The firmware is open source, so independent developers can check that behaviour. Anyone claiming to be Trezor who asks for your words is a scammer, whatever the message says.

Is Trezor Suite safe to download?

Yes, from trezor.io. Scammers have circulated fake Trezor apps through phishing emails, including after the 2022 and 2026 email breaches. Type the address yourself rather than clicking a link. Trezor Suite checks that your device is genuine and installs signed firmware, and it will never ask you to type your recovery words.

Keep learning