Best hardware wallets
Cold-storage devices. We scored 15 of them 0–10 from public data — age and status/latency of the companion service — and ranked the 14 we could measure well enough to place fairly. No affiliate links: the order reflects the evidence, nothing else.
Last collection 2026-08-25: probed 252 services, measured 233, over a 90-day window. Collected by our own script, not by hand — reproducible, and reproducibly boring.
The full ranking
| # | Service | Score | Age | Latency | Median fix | Status feed |
|---|---|---|---|---|---|---|
| 1 | Ledger | 9.82100% | 12.7y | 107 ms | 32 min | statuspage |
| 2 | OneKey | 9.8100% | 7.7y | 351 ms | — | statuspage |
| 3 | Trezor | 8.6682% | 13.7y | 111 ms | — | unknown |
| 4 | NGRAVE | 7.9382% | 8.7y | 622 ms | — | unknown |
| 5 | BitBox | 7.8582% | 11.7y | 91 ms | — | none |
| 6 | Keystone | 7.6182% | 8.7y | 225 ms | — | none |
| 7 | GridPlus | 7.6182% | 9.7y | 221 ms | — | none |
| 8 | Ellipal | 7.6182% | 8.7y | 243 ms | — | none |
| 9 | Cypherock | 7.6182% | 6.7y | 328 ms | — | none |
| 10 | Arculus | 7.6182% | 5.6y | 332 ms | — | none |
| 11 | KeepKey | 7.6182% | 11.7y | 373 ms | — | none |
| 12 | Tangem | 7.1282% | 9.7y | 669 ms | — | none |
| 13 | Coldcard | 7.1282% | 8.7y | 790 ms | — | none |
| 14 | SafePal | 7.1282% | 8.7y | 590 ms | — | none |
Every figure carries the date it was taken, on the service’s card below, linked to its open source. Score is out of what we could measure — the % beside it is coverage.
How we scored hardware wallets
These weights belong to this category alone. Signature measurement here: Age and status/latency of the companion service — A device in a drawer has no TVL and no uptime; age is the trust signal, plus the reliability of its companion service.
How long it has run and survived — time is signal.
Response latency we measure ourselves from a public endpoint.
Whether it publishes a status page anyone can audit.
How fast it resolves incidents, from its own timestamps.
Latency in this category is timed at the live interface for every service, so the comparison is like-for-like. We never compare latency across categories — a DEX interface and an exchange API are not the same thing, and pretending otherwise would just reward whoever we happened to probe more cheaply.
The brief also defines FEES and UX (0%, 0%). We don’t publish them: we can’t measure them ourselves, and an estimate dressed as a measurement is worse than a gap. Full methodology
The services
Ledger
Live 12.7 yr (since founding (2014), public record). Most failures happen young, so time survived is real signal.
Publishes a machine-readable incident archive (statuspage) — its whole record can be checked by anyone, including against us.
Median 107 ms to first byte from the live interface, our own probe, slowest sample discarded, single location. Compared only within this category.
Median 32 min from published report to resolution across 50 logged incidents. Scored on repair speed, not on how many it logged.
The provider’s feed returns its 50 most recent incidents and no more, which here reaches back 83 days. The remaining 7 are blank because we cannot see them — not because nothing happened.
Over the 83 days the feed covers. Not scored — logging granularity varies between services.
OneKey
Live 7.7 yr (since founding (2019), public record). Most failures happen young, so time survived is real signal.
Publishes a machine-readable incident archive (statuspage) — its whole record can be checked by anyone, including against us.
Median 351 ms to first byte from the live interface, our own probe, slowest sample discarded, single location. Compared only within this category.
No incidents at all in the 90 days its feed covers — we read the feed and it is empty.
Over the 90 days the feed covers. Not scored — logging granularity varies between services.
Trezor
Live 13.7 yr (since founding (2013), public record). Most failures happen young, so time survived is real signal.
A status page exists but publishes no feed we could parse — readable, not auditable. Part of that may be our blind spot (we read three platforms).
Median 111 ms to first byte from the live interface, our own probe, slowest sample discarded, single location. Compared only within this category.
No incident feed we can read, so no repair time to compute.
Status transparency: A status page exists but publishes no feed we could parse — readable, not auditable. Part of that may be our blind spot (we read three platforms).
NGRAVE
Live 8.7 yr (since founding (2018), public record). Most failures happen young, so time survived is real signal.
A status page exists but publishes no feed we could parse — readable, not auditable. Part of that may be our blind spot (we read three platforms).
Median 622 ms to first byte from the live interface, our own probe, slowest sample discarded, single location. Compared only within this category.
No incident feed we can read, so no repair time to compute.
Status transparency: A status page exists but publishes no feed we could parse — readable, not auditable. Part of that may be our blind spot (we read three platforms).
BitBox
Live 11.7 yr (since founding (2015), public record). Most failures happen young, so time survived is real signal.
No public status page found. Nothing about its reliability can be verified from outside — including by us.
Median 91 ms to first byte from the live interface, our own probe, slowest sample discarded, single location. Compared only within this category.
No incident feed we can read, so no repair time to compute.
Status transparency: No public status page found. Nothing about its reliability can be verified from outside — including by us.
Anyone who needs to know when it breaks: no status feed, so you find out it is down by discovering it yourself.
Keystone
Live 8.7 yr (since founding (2018), public record). Most failures happen young, so time survived is real signal.
No public status page found. Nothing about its reliability can be verified from outside — including by us.
Median 225 ms to first byte from the live interface, our own probe, slowest sample discarded, single location. Compared only within this category.
No incident feed we can read, so no repair time to compute.
Status transparency: No public status page found. Nothing about its reliability can be verified from outside — including by us.
Anyone who needs to know when it breaks: no status feed, so you find out it is down by discovering it yourself.
GridPlus
Live 9.7 yr (since founding (2017), public record). Most failures happen young, so time survived is real signal.
No public status page found. Nothing about its reliability can be verified from outside — including by us.
Median 221 ms to first byte from the live interface, our own probe, slowest sample discarded, single location. Compared only within this category.
No incident feed we can read, so no repair time to compute.
Status transparency: No public status page found. Nothing about its reliability can be verified from outside — including by us.
Anyone who needs to know when it breaks: no status feed, so you find out it is down by discovering it yourself.
Ellipal
Live 8.7 yr (since founding (2018), public record). Most failures happen young, so time survived is real signal.
No public status page found. Nothing about its reliability can be verified from outside — including by us.
Median 243 ms to first byte from the live interface, our own probe, slowest sample discarded, single location. Compared only within this category.
No incident feed we can read, so no repair time to compute.
Status transparency: No public status page found. Nothing about its reliability can be verified from outside — including by us.
Anyone who needs to know when it breaks: no status feed, so you find out it is down by discovering it yourself.
Live 6.7 yr (since founding (2020), public record). Most failures happen young, so time survived is real signal.
No public status page found. Nothing about its reliability can be verified from outside — including by us.
Median 328 ms to first byte from the live interface, our own probe, slowest sample discarded, single location. Compared only within this category.
No incident feed we can read, so no repair time to compute.
Status transparency: No public status page found. Nothing about its reliability can be verified from outside — including by us.
Anyone who needs to know when it breaks: no status feed, so you find out it is down by discovering it yourself.
Arculus
Live 5.6 yr (since founding (2021), public record). Most failures happen young, so time survived is real signal.
No public status page found. Nothing about its reliability can be verified from outside — including by us.
Median 332 ms to first byte from the live interface, our own probe, slowest sample discarded, single location. Compared only within this category.
No incident feed we can read, so no repair time to compute.
Status transparency: No public status page found. Nothing about its reliability can be verified from outside — including by us.
Anyone who needs to know when it breaks: no status feed, so you find out it is down by discovering it yourself.
KeepKey
Live 11.7 yr (since founding (2015), public record). Most failures happen young, so time survived is real signal.
No public status page found. Nothing about its reliability can be verified from outside — including by us.
Median 373 ms to first byte from the live interface, our own probe, slowest sample discarded, single location. Compared only within this category.
No incident feed we can read, so no repair time to compute.
Status transparency: No public status page found. Nothing about its reliability can be verified from outside — including by us.
Anyone who needs to know when it breaks: no status feed, so you find out it is down by discovering it yourself.
Tangem
Live 9.7 yr (since founding (2017), public record). Most failures happen young, so time survived is real signal.
No public status page found. Nothing about its reliability can be verified from outside — including by us.
Median 669 ms to first byte from the live interface, our own probe, slowest sample discarded, single location. Compared only within this category.
No incident feed we can read, so no repair time to compute.
Status transparency: No public status page found. Nothing about its reliability can be verified from outside — including by us.
Anyone who needs to know when it breaks: no status feed, so you find out it is down by discovering it yourself.
Coldcard
Live 8.7 yr (since founding (2018), public record). Most failures happen young, so time survived is real signal.
No public status page found. Nothing about its reliability can be verified from outside — including by us.
Median 790 ms to first byte from the live interface, our own probe, slowest sample discarded, single location. Compared only within this category.
No incident feed we can read, so no repair time to compute.
Status transparency: No public status page found. Nothing about its reliability can be verified from outside — including by us.
Anyone who needs to know when it breaks: no status feed, so you find out it is down by discovering it yourself.
SafePal
Live 8.7 yr (since founding (2018), public record). Most failures happen young, so time survived is real signal.
No public status page found. Nothing about its reliability can be verified from outside — including by us.
Median 590 ms to first byte from the live interface, our own probe, slowest sample discarded, single location. Compared only within this category.
No incident feed we can read, so no repair time to compute.
Status transparency: No public status page found. Nothing about its reliability can be verified from outside — including by us.
Anyone who needs to know when it breaks: no status feed, so you find out it is down by discovering it yourself.
Who we left out, and why
We looked at 15, ranked 14, and could not measure 1.
| Service | Status feed | Why it isn’t ranked |
|---|---|---|
| Blockstream Jade | unknown | 1 of 4 criteria measurable, 22% of this category’s weight — under the 25% a place in the ranking needs. Left unranked on purpose: the less we measure, the fewer criteria there are to dock points on, so a thinly-measured service drifts upward for no reason but our ignorance. |
Head to head
How to choose hardware wallets
Cold-storage devices — and the honest truth is that no single ranking fits everyone. Our scores tell you what is best-evidenced on public data: age and status/latency of the companion service. Use them as a shortlist, not a verdict.
Start at the top of the table, then open the full breakdown for any service you are considering. Read the coverage figure beside its score — a high number on thin coverage is a narrower claim than the same score fully measured. Check the “where we docked points” and “who it’s not for” notes on each card; the service that scores highest overall is not always the one that fits your specific need. And remember what these scores deliberately leave out — fees and support quality — which you should weigh yourself before committing.
Hardware wallets ratings — FAQ
How are hardware wallets ranked on this page?+
Each service is scored 0–10 from public data — age and status/latency of the companion service — weighted for what matters in this category, plus our own latency and status checks. 14 of 15 are ranked; the rest we could not measure enough to place fairly. Every figure is dated and links to its source.
What is the best hardware wallet?+
On the data we could measure, Ledger scores highest at 9.82/10, ahead of OneKey (9.8/10). "Best" here means best-evidenced, not most advertised — open each service below for the full breakdown and decide what fits your needs.
Why isn’t the biggest name at the top?+
Size is not a criterion. A large service that publishes no audits or status page cannot demonstrate its safety from the outside, so it scores below a smaller one that can — even if it is perfectly sound. We rate what is verifiable, not what is famous.
What does the "% measured" figure under a score mean?+
It is the share of this category's criteria weight we could actually fill for that service. Anything we could not measure is marked n/a and its weight is redistributed across the rest — never counted as zero — so the percentage tells you how complete the verdict is.
Do you earn money from these rankings?+
No. There are no affiliate links, no paid placements and no sponsored entries anywhere in the ratings section. That is what lets this list put a smaller, audited service above a bigger, opaque one.
No affiliate links, paid placements or ads anywhere on this site. How this is funded · Methodology