Skip to main content
btc$85,522-0.24%eth$2,689-0.81%usdt$0.9999+0.00%bnb$779.05-0.93%xrp$1.50-0.02%usdc$0.9999+0.00%sol$120.63+0.44%trx$0.3358-0.20%figr_heloc$1.04-0.60%zec$1,356+1.19%hype$91.65-2.39%doge$0.0937-1.61%xmr$557.99+0.34%link$13.93+0.01%ada$0.2709+1.94%wbt$85.35-0.36%btc$85,522-0.24%eth$2,689-0.81%usdt$0.9999+0.00%bnb$779.05-0.93%xrp$1.50-0.02%usdc$0.9999+0.00%sol$120.63+0.44%trx$0.3358-0.20%figr_heloc$1.04-0.60%zec$1,356+1.19%hype$91.65-2.39%doge$0.0937-1.61%xmr$557.99+0.34%link$13.93+0.01%ada$0.2709+1.94%wbt$85.35-0.36%
CoinPulse

Trezor

Hardware wallet·2014·Czech Republic·trezor.io

Trezor is a hardware wallet made by SatoshiLabs, a company founded in Prague, Czech Republic, in 2014 that shipped the world's first hardware wallet, the Trezor One. Its devices generate and store your private keys offline and sign transactions on the device itself, so the keys never touch an internet-connected computer. Trezor is known for open-source firmware and a range from the classic Model One through the touchscreen Model T to the newer Safe line. Its device keys have never been remotely drained, though it has one notable phishing incident and a documented physical-attack caveat.

Key facts
Founded
2014, Prague; Trezor One was the first hardware wallet2014 · source
Maker
SatoshiLabs, Czech Republic
Devices
Model One, Model T, and the Safe 3 / Safe 5 line
Security model
Keys generated and stored offline; open-source firmware; on-device confirmation · source

Trezor models and how it works

A Trezor is a hardware wallet: it generates and stores your private keys on the device and signs transactions there, so the keys never reach your internet-connected computer or phone. You confirm each transaction on the device's own screen, which is what protects you from malware on the host machine. SatoshiLabs shipped the original Trezor One in 2014 — the first hardware wallet — and the design it introduced (offline keys, a recovery seed, on-device confirmation) is now the template for the whole category.

The line has grown since. The Model One is the compact, button-based classic; the Model T adds a colour touchscreen; and the newer Safe 3 and Safe 5 pair the familiar design with a dedicated secure-element chip. A distinguishing trait across the range is open-source firmware, which lets outside researchers inspect the code that guards your keys.

Is Trezor safe? (and vs Ledger)

Trezor's core promise — that your keys are generated and stored offline and sign on the device — has held: no Trezor device has been remotely drained of the keys it protects. What has gone wrong sat around the device. In 2022 attackers abused a breach at Trezor's third-party newsletter provider to email subscribers a fake Trezor app, a phishing wave the mailing-list breach enabled but which did not itself take funds; it is covered in the incident record below.

There is also a documented physical-attack caveat. Security researchers at Kraken showed in 2020 that an attacker with physical possession of a Trezor and enough time could, using specialist equipment, extract and brute-force the seed — but only when the optional passphrase feature is not set. A strong passphrase mitigates that attack, and it requires having the device in hand; there is no remote drain. This is where a passphrase and buying only from Trezor or an authorised reseller matter.

Compared with Ledger, the trade-off is a familiar one in the category: Trezor leans on open-source firmware that anyone can audit, while Ledger emphasises a certified secure-element chip (Trezor's own Safe line now adds a secure element too). Both keep keys offline and sign on-device; neither has had its device keys remotely drained. The bigger risk for either brand is you being phished into entering your recovery phrase — which no legitimate wallet maker will ever ask for.

Incident record

Mailchimp newsletter breach and phishing wave2022-04

Attackers compromised Trezor's third-party newsletter provider, Mailchimp, and used the stolen subscriber list to email Trezor users a convincing phishing message urging them to download a cloned Trezor Suite app that could steal recovery phrases. The breach exposed newsletter subscriber email addresses and enabled the phishing campaign; it did not itself take funds, and Trezor devices were not compromised. Trezor disabled its newsletter and warned users.

Funds not affectedSource

In our ratings

Where we score Trezor against its peers on open data. The number lives there, not here.

Compare with

Frequently asked

Is Trezor safe?+

Trezor keeps your keys offline and signs transactions on the device, and no Trezor has been remotely drained of its keys. The known caveats sit around the device: a 2022 phishing wave that followed a breach at its third-party newsletter provider (no funds taken by the breach itself), and a documented physical-extraction attack that a strong passphrase mitigates and that requires having the device in hand. Never enter your recovery phrase anywhere but the device.

What is the difference between the Trezor Model One, Model T and Safe?+

All store keys offline and confirm transactions on the device. The Model One is the compact, button-based classic; the Model T adds a colour touchscreen; and the Safe 3 and Safe 5 add a dedicated secure-element chip. For core security they are similar; the differences are the interface, features and the secure element.

Can a Trezor be hacked?+

Not remotely — its device keys have never been remotely drained. Researchers have shown a physical attack that can extract the seed from a device an attacker physically holds, but a strong passphrase mitigates it. The realistic risk for most users is phishing that tricks you into entering your recovery phrase, which Trezor will never ask for.

What changed

  • 2026-09-28Profile created: founding as the first hardware wallet, the model line and security model, the safety picture versus Ledger, and the 2022 Mailchimp phishing incident with a funds-not-affected verdict.