Which hardware wallets actually stay up
Best measured: Ledger — 9.82/10 on the 100% we could measure.
Runner-up: OneKey — 9.8/10.
Not rankable: 1 of 15 — too little published about them to measure.
Last collection 2026-08-25: probed 252 services, measured 233, over a 90-day window. Collected by our own script, not by hand — the numbers are reproducible, and reproducibly boring.
The ranking
| # | Service | Score | Age | Latency | Median fix | Status feed |
|---|---|---|---|---|---|---|
| 1 | Ledger | 9.82100% | 12.7y | 107 ms | 32 min | statuspage |
| 2 | OneKey | 9.8100% | 7.7y | 351 ms | — | statuspage |
| 3 | Trezor | 8.6682% | 13.7y | 111 ms | — | unknown |
| 4 | NGRAVE | 7.9382% | 8.7y | 622 ms | — | unknown |
| 5 | BitBox | 7.8582% | 11.7y | 91 ms | — | none |
| 6 | Keystone | 7.6182% | 8.7y | 225 ms | — | none |
| 7 | GridPlus | 7.6182% | 9.7y | 221 ms | — | none |
| 8 | Ellipal | 7.6182% | 8.7y | 243 ms | — | none |
| 9 | Cypherock | 7.6182% | 6.7y | 328 ms | — | none |
| 10 | Arculus | 7.6182% | 5.6y | 332 ms | — | none |
| 11 | KeepKey | 7.6182% | 11.7y | 373 ms | — | none |
| 12 | Tangem | 7.1282% | 9.7y | 669 ms | — | none |
| 13 | Coldcard | 7.1282% | 8.7y | 790 ms | — | none |
| 14 | SafePal | 7.1282% | 8.7y | 590 ms | — | none |
Every figure carries the date it was taken, on the service’s card below, linked to its open source. Score is out of what we could measure — the % next to it is coverage.
How we scored this
These weights belong to this category alone. Signature measurement here: Age and status/latency of the companion service — A device in a drawer has no TVL and no uptime; age is the trust signal, plus the reliability of its companion service.
Time the service has been live and continuously operating, from DefiLlama's listing date or the documented launch. Survi…
Median time to first byte from a public endpoint, our own probe, slowest sample discarded, single location. Scored withi…
Whether a public, machine-readable status page exists (statuspage / incident.io / instatus). A service you can audit fro…
Median minutes from published report to published resolution across the incidents a service logged, from its own status …
Latency in this category is timed at the live interface for every service, so the comparison is like-for-like. We never compare latency across categories — a DEX interface and an exchange API are not the same thing, and pretending otherwise would just reward whoever we happened to probe more cheaply.
The brief also defines FEES and UX (0%, 0%). We don’t publish them: we can’t measure them ourselves, and an estimate dressed as a measurement is worse than a gap. Full methodology
The services
Ledger
Live 12.7 yr (since founding (2014), public record). Most failures happen young, so time survived is real signal.
Publishes a machine-readable incident archive (statuspage) — its whole record can be checked by anyone, including against us.
Median 107 ms to first byte from the live interface, our own probe, slowest sample discarded, single location. Compared only within this category.
Median 32 min from published report to resolution across 50 logged incidents. Scored on repair speed, not on how many it logged.
The provider’s feed returns its 50 most recent incidents and no more, which here reaches back 83 days. The remaining 7 are blank because we cannot see them — not because nothing happened.
Over the 83 days the feed covers. Not scored — logging granularity varies between services.
OneKey
Live 7.7 yr (since founding (2019), public record). Most failures happen young, so time survived is real signal.
Publishes a machine-readable incident archive (statuspage) — its whole record can be checked by anyone, including against us.
Median 351 ms to first byte from the live interface, our own probe, slowest sample discarded, single location. Compared only within this category.
No incidents at all in the 90 days its feed covers — we read the feed and it is empty.
Over the 90 days the feed covers. Not scored — logging granularity varies between services.
Trezor
Live 13.7 yr (since founding (2013), public record). Most failures happen young, so time survived is real signal.
A status page exists but publishes no feed we could parse — readable, not auditable. Part of that may be our blind spot (we read three platforms).
Median 111 ms to first byte from the live interface, our own probe, slowest sample discarded, single location. Compared only within this category.
No incident feed we can read, so no repair time to compute.
Status transparency: A status page exists but publishes no feed we could parse — readable, not auditable. Part of that may be our blind spot (we read three platforms).
NGRAVE
Live 8.7 yr (since founding (2018), public record). Most failures happen young, so time survived is real signal.
A status page exists but publishes no feed we could parse — readable, not auditable. Part of that may be our blind spot (we read three platforms).
Median 622 ms to first byte from the live interface, our own probe, slowest sample discarded, single location. Compared only within this category.
No incident feed we can read, so no repair time to compute.
Status transparency: A status page exists but publishes no feed we could parse — readable, not auditable. Part of that may be our blind spot (we read three platforms).
BitBox
Live 11.7 yr (since founding (2015), public record). Most failures happen young, so time survived is real signal.
No public status page found. Nothing about its reliability can be verified from outside — including by us.
Median 91 ms to first byte from the live interface, our own probe, slowest sample discarded, single location. Compared only within this category.
No incident feed we can read, so no repair time to compute.
Status transparency: No public status page found. Nothing about its reliability can be verified from outside — including by us.
Anyone who needs to know when it breaks: no status feed, so you find out it is down by discovering it yourself.
Keystone
Live 8.7 yr (since founding (2018), public record). Most failures happen young, so time survived is real signal.
No public status page found. Nothing about its reliability can be verified from outside — including by us.
Median 225 ms to first byte from the live interface, our own probe, slowest sample discarded, single location. Compared only within this category.
No incident feed we can read, so no repair time to compute.
Status transparency: No public status page found. Nothing about its reliability can be verified from outside — including by us.
Anyone who needs to know when it breaks: no status feed, so you find out it is down by discovering it yourself.
GridPlus
Live 9.7 yr (since founding (2017), public record). Most failures happen young, so time survived is real signal.
No public status page found. Nothing about its reliability can be verified from outside — including by us.
Median 221 ms to first byte from the live interface, our own probe, slowest sample discarded, single location. Compared only within this category.
No incident feed we can read, so no repair time to compute.
Status transparency: No public status page found. Nothing about its reliability can be verified from outside — including by us.
Anyone who needs to know when it breaks: no status feed, so you find out it is down by discovering it yourself.
Ellipal
Live 8.7 yr (since founding (2018), public record). Most failures happen young, so time survived is real signal.
No public status page found. Nothing about its reliability can be verified from outside — including by us.
Median 243 ms to first byte from the live interface, our own probe, slowest sample discarded, single location. Compared only within this category.
No incident feed we can read, so no repair time to compute.
Status transparency: No public status page found. Nothing about its reliability can be verified from outside — including by us.
Anyone who needs to know when it breaks: no status feed, so you find out it is down by discovering it yourself.
Live 6.7 yr (since founding (2020), public record). Most failures happen young, so time survived is real signal.
No public status page found. Nothing about its reliability can be verified from outside — including by us.
Median 328 ms to first byte from the live interface, our own probe, slowest sample discarded, single location. Compared only within this category.
No incident feed we can read, so no repair time to compute.
Status transparency: No public status page found. Nothing about its reliability can be verified from outside — including by us.
Anyone who needs to know when it breaks: no status feed, so you find out it is down by discovering it yourself.
Arculus
Live 5.6 yr (since founding (2021), public record). Most failures happen young, so time survived is real signal.
No public status page found. Nothing about its reliability can be verified from outside — including by us.
Median 332 ms to first byte from the live interface, our own probe, slowest sample discarded, single location. Compared only within this category.
No incident feed we can read, so no repair time to compute.
Status transparency: No public status page found. Nothing about its reliability can be verified from outside — including by us.
Anyone who needs to know when it breaks: no status feed, so you find out it is down by discovering it yourself.
KeepKey
Live 11.7 yr (since founding (2015), public record). Most failures happen young, so time survived is real signal.
No public status page found. Nothing about its reliability can be verified from outside — including by us.
Median 373 ms to first byte from the live interface, our own probe, slowest sample discarded, single location. Compared only within this category.
No incident feed we can read, so no repair time to compute.
Status transparency: No public status page found. Nothing about its reliability can be verified from outside — including by us.
Anyone who needs to know when it breaks: no status feed, so you find out it is down by discovering it yourself.
Tangem
Live 9.7 yr (since founding (2017), public record). Most failures happen young, so time survived is real signal.
No public status page found. Nothing about its reliability can be verified from outside — including by us.
Median 669 ms to first byte from the live interface, our own probe, slowest sample discarded, single location. Compared only within this category.
No incident feed we can read, so no repair time to compute.
Status transparency: No public status page found. Nothing about its reliability can be verified from outside — including by us.
Anyone who needs to know when it breaks: no status feed, so you find out it is down by discovering it yourself.
Coldcard
Live 8.7 yr (since founding (2018), public record). Most failures happen young, so time survived is real signal.
No public status page found. Nothing about its reliability can be verified from outside — including by us.
Median 790 ms to first byte from the live interface, our own probe, slowest sample discarded, single location. Compared only within this category.
No incident feed we can read, so no repair time to compute.
Status transparency: No public status page found. Nothing about its reliability can be verified from outside — including by us.
Anyone who needs to know when it breaks: no status feed, so you find out it is down by discovering it yourself.
SafePal
Live 8.7 yr (since founding (2018), public record). Most failures happen young, so time survived is real signal.
No public status page found. Nothing about its reliability can be verified from outside — including by us.
Median 590 ms to first byte from the live interface, our own probe, slowest sample discarded, single location. Compared only within this category.
No incident feed we can read, so no repair time to compute.
Status transparency: No public status page found. Nothing about its reliability can be verified from outside — including by us.
Anyone who needs to know when it breaks: no status feed, so you find out it is down by discovering it yourself.
Who we left out, and why
We looked at 15, ranked 14, and could not measure 1.
| Service | Status feed | Why it isn’t ranked |
|---|---|---|
| Blockstream Jade | unknown | 1 of 4 criteria measurable, 22% of this category’s weight — under the 25% a place in the ranking needs. Left unranked on purpose: the less we measure, the fewer criteria there are to dock points on, so a thinly-measured service drifts upward for no reason but our ignorance. |
Head to head
Questions
Why isn’t the biggest name at the top?+
Because we rank on whether a service works and can be checked, not on how big it is. Size is not a criterion here — a large service that publishes no status feed cannot demonstrate its reliability to anyone, and it scores accordingly.
What does "62% measured" mean under a score?+
It is the share of our criteria weight we actually measured for that service. The rest is n/a — we did not measure it, so its weight was redistributed across what we did measure rather than counted as zero. A high score at low coverage is a narrower claim than the same score at high coverage, and we would rather show you that than hide it.
Where do the incident numbers come from?+
From each provider's own status page, which several publish as a machine-readable feed. We compute repair time from their published report and resolution timestamps, and link the source on every figure so you can check it. It is their record — we just do the arithmetic and refuse to round it in their favour.
No affiliate links or paid placements in this section. How this is funded · Methodology