Prices: CoinGecko

Hardware wallet comparisons: how to choose a device that fits you

Compare Ledger, Trezor, COLDCARD, BitBox, Keystone, Tangem and more on security, open source, connectivity, backups and price, as of October 2026.

Beginner13 min readUpdated October 4, 20268 sources
On this page
  1. What a hardware wallet does (and doesn't) protect against
  2. How to choose: the features that matter
  3. Comparison table: current models as of October 2026
  4. Which device fits which kind of user
  5. How to buy a hardware wallet safely
  6. Setup checklist
  7. The bottom line

Key takeaways

  • A hardware wallet keeps your private keys offline and asks you to confirm every transaction on its own screen, but it cannot protect a seed phrase you type into a website.
  • Compare devices on firmware openness, secure chip design, screen quality, connectivity, coin support and backup options rather than on marketing claims.
  • Every major maker has had incidents, mostly customer-data leaks and phishing; in July 2026 a COLDCARD firmware bug weakened seed generation, so update firmware before creating a seed.
  • Buy only from the manufacturer or an authorized reseller, and never use a device that arrives with a seed phrase already set up.

A hardware wallet is a small device that keeps your crypto keys offline and makes you approve every transaction on its own screen. This guide compares the main models sold as of October 2026 and helps you match one to how you actually use crypto.

What a hardware wallet does (and doesn't) protect against

Your crypto lives on a blockchain, not on the device. What the device holds is your private key, the secret that authorizes spending. A hardware wallet creates that key, stores it, and signs transactions internally, so the key never touches your computer or phone.

That design protects you well against several common threats:

  • Malware on your computer or phone. Even if your laptop is infected, the attacker cannot copy a key that never leaves the device.
  • Silent transaction tampering. You check the address and amount on the device's own screen before approving. Malware can change what your computer shows, but not what the device shows.
  • Casual theft of the device. A PIN locks the device, and most models wipe themselves after too many wrong guesses.

It does not protect you from everything:

  • Giving away your seed phrase. If you type your recovery words into a website, app or form, anyone holding them can rebuild your wallet. This is the most common way hardware wallet owners lose funds.
  • Approving a bad transaction. If you sign a malicious token approval or send to a scammer's address, the device will faithfully do what you approved.
  • Losing your backup. If the device breaks and you have no backup, the funds are gone. No company can recover them for you unless you opted into a recovery service.
  • Physical coercion or a careless hiding place. Someone who finds your written backup does not need your device at all.

How to choose: the features that matter

Marketing pages are full of superlatives. These are the questions that actually separate one device from another.

Open-source firmware

Firmware is the software running on the device. When it is open source, anyone can read the code and researchers can look for flaws. Trezor, BitBox, Keystone, Foundation and Blockstream publish their firmware. Ledger publishes its apps and companion software but not its full secure-chip operating system. COLDCARD's code is public but licensed with a "Commons Clause" restriction, so it is better described as source-available. Tangem's firmware is closed but has been audited by outside firms.

Secure element

A secure element is a tamper-resistant chip, similar to those in bank cards, designed to resist lab attacks that try to pull secrets out of the hardware. Older Trezor models without one were vulnerable: in 2020, Kraken Security Labs showed it could extract the seed from a Trezor One or Model T with about 15 minutes of physical access and specialized equipment, a risk Trezor users could reduce with a passphrase. All current Trezor models now include a secure element. Blockstream's Jade takes a different approach, a "virtual secure element" that splits protection between the device and a Blockstream server.

Screen and input

A bigger, clearer screen makes it easier to check long addresses and to read what a DeFi contract is asking you to sign. Touchscreens are friendlier; two-button devices are cheaper. Tangem cards have no screen at all, so you rely on your phone to display what you are signing.

Connectivity: USB, Bluetooth, NFC or air-gapped

Every connection is a possible attack surface, but the key never leaves the device on any of them. Air-gapped devices such as the Keystone 3 Pro and NGRAVE ZERO pass data only through QR codes or memory cards, which some people prefer for peace of mind. Bluetooth models are more convenient with phones, especially iPhones, which do not support USB data with some wallets.

Coin support

Multi-chain devices manage Bitcoin, Ethereum, Solana and thousands of tokens. Bitcoin-only devices strip out other code, which narrows what can go wrong. Trezor and BitBox sell Bitcoin-only editions of their regular devices.

Passphrase and multisig support

A passphrase adds an extra word to your seed and opens a separate hidden wallet, so a found seed phrase alone is not enough. Multisig requires several keys, often on devices from different makers, to approve a transaction. Most devices here support passphrases; COLDCARD, Passport, Jade, BitBox, Keystone and Trezor are commonly used in multisig setups.

Backup options

The standard backup is a 12- or 24-word BIP-39 seed phrase, which you can restore on many brands. Trezor now defaults to a 20-word SLIP-39 backup and can split it into Shamir shares. BitBox adds a microSD backup. Tangem is "seedless" by default, using two or three cloned cards. Ledger offers an optional paid service, Ledger Recover. Our seed storage comparison covers how to store any of these safely.

Company track record

Every long-running maker has had incidents. What matters is what was exposed and how the company responded:

  • Ledger, 2020: a breach of its e-commerce and marketing database exposed about one million email addresses, and detailed names, home addresses and phone numbers for about 272,000 customers, and the leaked data has fueled phishing ever since, including altered devices mailed to customers as fake "replacements." No funds were taken from devices directly.
  • Ledger Recover, 2023: Ledger announced an optional, identity-verified service that encrypts your key, splits it into three fragments and stores them with Coincover, Ledger and EscrowTech. Critics objected that firmware able to export key material, even encrypted, broke a long-standing promise. The service remains opt-in.
  • Ledger, December 2023 and January 2026: a compromised Ledger Connect Kit code library briefly injected wallet-draining code into apps that used it, and in January 2026 Ledger's payment processor Global-e reported a leak of customer names, contact details and order information.
  • Trezor, 2024 and 2026: a January 2024 breach of a third-party support portal exposed contact details of about 66,000 customers, and the September 2026 Brevo incident exposed about 347,000 newsletter email addresses. BitBox newsletter subscribers were targeted in the same Brevo attack.
  • COLDCARD, July 2026: Coinkite disclosed a firmware bug that weakened seed generation across several models, and attackers stole funds from some affected wallets. Fixed firmware is available, but updating does not repair an existing seed; affected users need to move funds to a new seed.

Comparison table: current models as of October 2026

Hardware wallets compared (official list prices in USD, checked October 2026)
ModelList priceFirmwareSecure chipConnectivityCoinsDefault backup
Ledger Nano S Plus$69Partly openYesUSB-CMulti-chain24-word BIP-39
Ledger Nano X$99Partly openYesUSB-C, BluetoothMulti-chain24-word BIP-39
Ledger Nano Gen5$179Partly openYes (EAL6+)USB-C, Bluetooth, NFCMulti-chain24-word + Recovery Key card
Ledger Flex$249Partly openYes (EAL6+)USB-C, Bluetooth, NFCMulti-chain24-word + Recovery Key card
Ledger Stax$399Partly openYesUSB-C, Bluetooth, NFCMulti-chain24-word + Recovery Key card
Trezor Safe 3$59OpenYes (EAL6+)USB-CMulti-chain or BTC-only20-word SLIP-39
Trezor Safe 5$129OpenYes (EAL6+)USB-CMulti-chain or BTC-only20-word SLIP-39
Trezor Safe 7$249OpenYes (two chips)USB-C, BluetoothMulti-chain or BTC-only20-word SLIP-39
COLDCARD Mk5$219Source-availableYes (two chips)USB-C, NFC, microSDBitcoin-only24-word BIP-39
COLDCARD Q$319Source-availableYes (two chips)USB-C, NFC, microSD, QRBitcoin-only24-word BIP-39
BitBox02EUR 149*OpenYesUSB-CMulti-chain or BTC-onlymicroSD + 24-word
BitBox02 NovaEUR 175*OpenYes (EAL6+)USB-C, BluetoothMulti-chain or BTC-onlymicroSD + 24-word
Keystone 3 Pro$149Open (per maker)Yes (three chips)QR, microSD, optional USB-CMulti-chain24-word or Shamir
Tangem (3 cards)$69.90Closed, auditedYes (EAL6+)NFCMulti-chainSeedless cards
NGRAVE ZERO$398Partly openYesQR onlyMulti-chain24-word or steel plate
Foundation Passport Prime$349OpenYesBluetooth, NFC, USB-C, QRBitcoin-onlyEncrypted Magic Backup
Blockstream Jade Plus$149OpenVirtual (server-assisted)USB-C, Bluetooth, QRBitcoin-only12/24-word BIP-39

*BitBox's official shop lists euro prices; the US checkout price was not confirmed. COLDCARD and NGRAVE prices were shown as reductions from higher list prices, and the NGRAVE ZERO was marked sold out when checked. Trezor stopped selling the Model One and Model T on January 8, 2026, though both still receive security updates. COLDCARD's Mk4 has been replaced by the Mk5.

Which device fits which kind of user

There is no single "best" hardware wallet. These pairings describe fit based on features, not an endorsement. Any device from a reputable maker, set up carefully, is far safer than keeping keys on an exchange you do not control or in a phone note.

First-timers

Look for a clear screen, a simple companion app and a standard backup. The Trezor Safe 3 and Ledger Nano S Plus are the lowest-cost options from the two largest makers. If reading small text worries you, the Trezor Safe 5 or Ledger Nano Gen5 add touchscreens. People who find writing down words stressful sometimes choose Tangem cards, accepting a closed-source design and no device screen in exchange.

Bitcoin-only holders

The COLDCARD Mk5 and Q, Foundation Passport Prime, Blockstream Jade Plus, and the Bitcoin-only editions of Trezor and BitBox all suit this profile. COLDCARD offers the deepest advanced features but has a steeper learning curve and the July 2026 incident to weigh. Jade Plus is the lowest-cost QR option, with a server-assisted security model you should understand first.

Multi-chain and DeFi users

If you sign smart-contract transactions often, screen size and clear transaction details matter most. The Ledger Flex and Stax have large E Ink screens and support many chains. The Trezor Safe 7 offers a large color screen with open-source firmware. The Keystone 3 Pro signs over QR codes and connects to wallets such as MetaMask. Before connecting to any app, read our guide to sending crypto safely.

Mobile-first users

Choose a device that works with your phone. Bluetooth options include the Ledger Nano X, Nano Gen5, Flex and Stax, the Trezor Safe 7, and the BitBox02 Nova (which uses Bluetooth for iPhone and iPad). Tangem works by tapping cards to your phone over NFC. QR-based devices like Keystone also pair well with phone wallets.

Maximum security and multisig

For larger balances, many experienced holders use a 2-of-3 multisig with devices from different makers, so one company's bug or breach cannot cost them everything. Air-gapped devices such as the COLDCARD Q, Keystone 3 Pro and Passport Prime are popular in these setups. Multisig adds complexity, so practice recovery with a small amount first.

How to buy a hardware wallet safely

A hardware wallet is only as trustworthy as the path it took to reach you. Scammers have shipped tampered devices and fake replacements to people whose addresses leaked.

  • Buy direct or from an authorized reseller. Type the maker's web address yourself or use a reseller listed on the maker's own site. Avoid marketplace sellers you cannot verify.
  • Never buy used. A secondhand device could be modified or could have its key recorded by the previous owner.
  • Reject any pre-initialized device. If the box contains a recovery card with words already filled in, or the device asks you to "use the seed provided," it is a scam. A genuine device always makes you create your own seed or restore your own backup.
  • Check the packaging and seals. Each maker describes its tamper-evident packaging. Contact support through the official site if anything looks off.
  • Verify the device and firmware. Use the official app's genuine-device check and install firmware updates only through that app or the maker's documented process.
  • Ignore unexpected "replacement" devices or alerts. After the 2020 leak, criminals mailed altered devices to some Ledger customers. A device you did not order should never be used.

Setup checklist

  1. Download the companion app only from the maker's official site or your phone's official app store, and double-check the publisher name.
  2. Update the firmware before creating a seed. This is now essential for COLDCARD owners.
  3. Set a strong PIN that is not your phone or bank PIN.
  4. Create a new wallet on the device. Write the recovery words by hand on the supplied card, in order, and double-check the spelling.
  5. Never photograph, type, scan or upload the words. No cloud notes, password managers or screenshots.
  6. Complete the device's backup check, then plan a durable copy using our seed storage guide.
  7. Decide whether to add a passphrase. If you do, back it up separately; forgetting it means permanent loss.
  8. Send a small test amount, verify the receive address on the device screen, then practice a recovery on a spare or reset device before moving larger sums.
  9. Write down your device model and backup type for your heirs, without the words themselves. Our wallet recovery guide explains what to do if something goes wrong.

The bottom line

The device matters less than the habits around it. Pick a model whose screen you can read, whose app you will actually use, and whose backup format is a standard you can restore elsewhere. Buy it from the source, create your own seed on updated firmware, store the backup well, and never type those words anywhere else. If you are still deciding between self-custody and other options, start with our explainer on how crypto wallets work and our scam and security hub.

Frequently asked questions

Do I need a hardware wallet?

If you hold crypto yourself and the amount would hurt to lose, a hardware wallet is a common way to keep keys off an internet-connected computer or phone. If you keep everything on an exchange, you are trusting the exchange instead, which is a different risk.

Is open-source firmware always safer?

Not automatically, but public code can be reviewed by independent researchers, which makes hidden flaws harder to keep secret. Closed designs rely more on audits and certifications that you cannot check yourself.

Is Bluetooth on a hardware wallet dangerous?

Bluetooth adds a wireless link, but your keys still stay on the device and you still approve each transaction on its screen. If you do not need it, most Bluetooth models let you switch it off.

What happens if the company behind my wallet goes out of business?

If your device uses a standard backup such as a BIP-39 seed phrase, you can restore your funds on another compatible wallet. Check that your chosen device uses an open standard before you buy.

Can I buy a hardware wallet on Amazon or eBay?

Only buy from the manufacturer's own store or a reseller the manufacturer lists as authorized. Avoid secondhand devices and marketplace sellers you cannot verify.

Sources

  1. Compare Trezor Hardware Wallets — Trezor
  2. Hardware wallets comparison — Ledger
  3. Coldcard Security Advisory — Coinkite
  4. E-commerce and Marketing data breach - FAQ — Ledger Support
  5. Ledger Recover FAQs — Ledger Support
  6. Security incident at Brevo, our third-party email provider — Trezor
  7. Kraken Identifies Critical Flaw in Trezor Hardware Wallets — Kraken
  8. Introducing BitBox02 Nova — BitBox

Updated October 4, 2026 by The Crypto Guide editorial team. Educational content, not financial, legal or tax advice. Spot an error? Request a correction.