Trezor Safe 7:
the first auditable secure element, cracked in a lab within months of launch.
We tore apart Trezor's flagship dual-chip hardware wallet across seven weighted categories; from a genuinely novel, fully open-source secure element paired with a certified EAL6+ chip, and a real physical Bluetooth kill switch most competitors only offer in software, to a disclosed laser fault-injection attack from Ledger's own security lab and a real, repeated gap in native TRON/USDT-TRC20 support; and landed on a score the marketing page won't show you.
Our take, up front: the Safe 7 is Trezor's flagship, and it's built around something genuinely unprecedented: TROPIC01, described as the world's first fully open-source, publicly auditable secure element, running alongside a certified EAL6+ chip in a dual-SE design where both must agree before any operation proceeds. That's a real, structural answer to the "trust us, we can't show you the code" problem that closed-source competitors carry. It pairs that with a real physical hardware kill switch for Bluetooth (not just a software toggle), an aluminum unibody with IP67 waterproofing, and honestly-framed "quantum-ready" firmware. The complication: on June 3, 2026, Trezor and Tropic Square disclosed that Ledger Donjon, the security research lab of Trezor's direct competitor, executed a laser fault-injection attack against TROPIC01 under lab conditions back in January 2026, bypassing firmware-signature verification and extracting some secrets from that one component. No funds were at risk, the attack required physical possession plus specialized lab equipment, and it defeated only one of three security layers, arguably the open-security model working exactly as intended. Whether that reads as reassurance or a crack in the pitch is the real judgment call this review has to make. We weighted all of it below.
The Safe 7 is built around a genuinely unprecedented dual-chip architecture: TROPIC01, Trezor's own secure element whose complete hardware design, firmware, and specification are published for public review, running alongside a certified EAL6+ chip, with both required to agree before any operation proceeds. That's a real, structural advantage over closed-source competitors, whose security claims can't be independently verified at all. PIN entry supports 4 to 50 digits with automatic self-wipe after 10 incorrect attempts. Trezor's "quantum-ready" firmware claim is honestly framed: it protects the firmware update chain, device authentication, and secure boot process against future quantum attacks, and Trezor is explicit that it does not make Bitcoin or Ethereum addresses themselves quantum-safe today. Set against this real strength is a real, disclosed finding: on June 3, 2026, Trezor and Tropic Square publicly disclosed that Ledger Donjon, the security research lab of direct competitor Ledger, executed a laser fault-injection attack against TROPIC01 in January 2026 under lab conditions, bypassing firmware-signature verification and extracting some secrets from that one component. No user funds were at risk, the attack required physical possession of the device plus specialized laboratory equipment, it defeated only one of three security layers, and it has never been observed outside the lab.
Pros
- World's first fully open-source, publicly auditable secure element (TROPIC01), paired with a certified EAL6+ chip
- Both secure elements must agree before any operation proceeds, a genuinely novel dual-SE model
- Honest, carefully-framed communication about what "quantum-ready" firmware actually protects
- The disclosed TROPIC01 finding was published transparently, with researchers credited and no evidence of real-world exploitation
Cons
- A real, confirmed laser fault-injection attack extracted some secrets from TROPIC01 under lab conditions
- The vulnerability was found by a direct competitor's own security lab, a real reputational complication regardless of how well it was handled
Native support spans Bitcoin, Ethereum, BNB Smart Chain, Avalanche, Arbitrum, Base, Optimism, Polygon, and Solana, with Solana added through a 2026 Trezor Suite update that removed a previous requirement for third-party bridges or browser extensions. Staking for ETH, SOL, and DOT is available directly through the mobile app, with funds remaining secured on the hardware device throughout. Real, repeatedly-flagged gaps remain: no native TRON (TRX) support, no native TON support, no native USDT on the TRC-20 network specifically, and no native HYPE support, independently confirmed across multiple reviews.
Pros
- Native support across all major chains including a recently-added, genuine Solana integration
- Direct in-app staking for ETH, SOL, and DOT with funds remaining on-device throughout
Cons
- No native TRON (TRX) or USDT TRC-20 support, independently confirmed by multiple reviewers
- No native TON or HYPE support
A 2.5" OLED touchscreen handles setup, PIN entry, and transaction verification. Bluetooth enables wireless mobile signing, and unlike most Bluetooth-equipped competitors that rely on a software toggle, the Safe 7 includes a real physical hardware kill switch, a genuine, concrete answer to the common "Bluetooth means a bigger attack surface" concern. Qi2 wireless charging rounds out the convenience features. At least one independent reviewer offers a real, specific counterpoint worth including rather than assuming universal praise: "the touchscreen isn't as user-friendly as we'd like it to be."
Pros
- Physical hardware kill switch for Bluetooth, not just a software toggle
- 2.5" OLED touchscreen for on-device transaction verification
- Qi2 wireless charging
Cons
- At least one independent review specifically flags the touchscreen as less user-friendly than expected
This is a real, substantial step up from Trezor's own Safe 5: an aluminum unibody replaces the Safe 5's PC-ABS plastic, and the Safe 7 adds IP67 waterproofing, a genuinely meaningful upgrade for anyone who travels with their device or risks occasional exposure to moisture. Gorilla Glass 3 protects the touchscreen, and the device uses LiFePO4 battery chemistry, a real, safety-conscious choice for a battery that sits in a wallet meant to last years.
Pros
- Aluminum unibody construction, a real upgrade over plastic-bodied competitors
- Genuine IP67 waterproofing
- Gorilla Glass 3 display protection and safety-conscious LiFePO4 battery chemistry
Cons
- None significant found in our research
Trezor is built by SatoshiLabs, a long-established Czech company and one of the original hardware wallet makers in the category. Our research turned up no comparable pattern of customer data breaches, the kind that has affected some competitors more than once. The company's handling of the TROPIC01 disclosure, publishing the finding, crediting the researchers, and providing real, concrete mitigating context, reflects well on its crisis-communication practices specifically, even though the incident itself is real.
Pros
- Long, established operating history as one of the original hardware wallet makers
- No comparable pattern of customer data breaches found in our research
- Transparent, well-credited public disclosure of the TROPIC01 vulnerability finding
Cons
- The TROPIC01 disclosure is recent enough that its longer-term reputational impact isn't fully settled
At $249, the Safe 7 sits at the premium end of the category, and multiple independent reviewers are candid that Trezor's own Safe 5, at $129 to $169 depending on the source, delivers essentially the same core firmware security for meaningfully less if you don't need wireless features, the aluminum build, or the dual-SE architecture specifically. Ledger's Nano X at $149 undercuts it further, though without the open-source firmware or dual-chip design.
Pros
- The price premium buys real, substantive hardware extras, not just cosmetic differences
Cons
- Trezor's own Safe 5 offers comparable core firmware security for $80-120 less
- Cheaper competitors exist for users who don't need wireless or premium build features
Shamir backup offers a genuinely advanced seed-splitting recovery model beyond a standard single recovery phrase. Quantum-ready firmware provides a real, honestly-framed future-proofing path. The physical Bluetooth kill switch and Qi2 wireless charging add further, real convenience-with-security features, and native in-app staking for ETH, SOL, and DOT rounds out a genuinely feature-dense package for this category.
Pros
- Shamir backup for advanced, split-based recovery
- Quantum-ready firmware with honest, accurate framing of what it does and doesn't protect
- Native in-app staking for ETH, SOL, and DOT
Cons
- None significant found in our research
Buy only through Trezor's official store.
Buying direct is the only way to be confident your device hasn't been tampered with before it reaches you. Confirm you're on Trezor's own site before entering any payment details.
The most structurally honest security model in this category, tested and found real within months.
The Safe 7's core pitch, an auditable secure element paired with a certified chip, both required to agree, is a genuine, structural answer to the closed-source trust problem competitors ask you to simply accept. That the flagship chip was then attacked in a lab by a direct competitor's own research team, and that Trezor published the result rather than burying it, is close to the best-case outcome that model could produce: a real flaw, found and disclosed, not exploited in silence. Combined with genuinely premium build quality, a physical Bluetooth kill switch, and an honestly-framed quantum-ready roadmap, this is a device whose approach to trust is more substantive than most. The real gaps, a premium price that Trezor's own cheaper Safe 5 partly undercuts, and a persistent lack of native TRON/TRC-20 support, keep it from a clean top score.
The scorecard above is deliberately general. Whether the Trezor Safe 7 is right for you depends heavily on which of these you already are.
The security-first holder who wants independently verifiable firmware
Open-source code you (or researchers you trust) can actually inspect is a real, structural priority for you, and you're willing to pay a premium for a dual-chip architecture built around that principle.
The traveler who wants a genuinely durable, waterproof device
The aluminum unibody and real IP67 waterproofing matter if your wallet leaves a drawer regularly, a genuine upgrade over plastic-bodied competitors.
The mobile-first user who wants wireless signing without a soft toggle
A physical Bluetooth kill switch gives you a real, concrete way to disable wireless entirely, not just a settings menu you have to trust.
TRON/TRC-20 USDT holders, or anyone who just wants core security cheaply
Native TRON and TRC-20 support are genuinely absent, and Trezor's own Safe 5 delivers comparable core firmware security for meaningfully less if you don't need the extras.
The scorecard covers the headline judgment calls. These four tables cover the specifics we didn't want to bury in prose; exactly what the TROPIC01 disclosure did and didn't mean, what "quantum-ready" actually protects, the Safe 7 against Trezor's own cheaper Safe 5, and how it compares against the other hardware wallets we've reviewed.
The TROPIC01 disclosure, in plain terms
| What happened | |
|---|---|
| Who found it | Ledger Donjon, the security research lab of direct competitor Ledger |
| When | Attack executed January 2026; publicly disclosed June 3, 2026 |
| Method | Laser fault-injection attack under lab conditions |
| What was bypassed | Firmware-signature verification on the TROPIC01 chip specifically |
| Requirements to replicate | Physical possession of the device plus specialized laboratory equipment |
| Layers defeated | One of three security layers in the dual-SE design |
| User funds at risk? | No |
| Seen outside the lab? | No, never observed in the wild |
Trezor disclosed this publicly and credited the researchers, consistent with the open-security model's core promise: real flaws get published and fixed rather than sitting undiscovered.
What "quantum-ready" actually protects
| Protected today | Not protected today | |
|---|---|---|
| Firmware update chain | Yes, quantum-resistant verification | |
| Device authentication / secure boot | Yes | |
| Bitcoin / Ethereum addresses (ECC-based) | Not quantum-safe; requires protocol-level changes to the blockchains themselves |
Trezor is explicit about this distinction in its own marketing, a real, appreciated contrast to vaguer "quantum-proof" claims elsewhere in the industry.
Trezor Safe 7 vs. Trezor Safe 5
| Safe 7 | Safe 5 | |
|---|---|---|
| Price | $249 | $129-$169 |
| Secure element | Dual: TROPIC01 (open-source) + EAL6+ | Single EAL6+ |
| Body material | Aluminum unibody, IP67 | PC-ABS plastic |
| Wireless | Bluetooth (hardware kill switch) + Qi2 charging | None |
| Quantum-ready firmware | Yes | Not specified |
If you don't need wireless features or the dual-SE architecture specifically, the Safe 5 delivers comparable core security for meaningfully less.
How it compares to other hardware wallets we've reviewed
| Wallet | Firmware | Secure element | Price | Notable trade-off |
|---|---|---|---|---|
| Trezor Safe 7 | Open-source | Dual: TROPIC01 (auditable) + EAL6+ | $249 | Disclosed lab-conditions TROPIC01 vulnerability; no native TRON/TRC-20 |
| Ledger Flex | Closed-source | CC EAL6+ (ST33K1M5) | $249 | Recover controversy, two customer data breaches |
| Trezor Safe 5 | Open-source | Single EAL6+ | $129-$169 | No wireless features, no dual-SE architecture |
| Coldcard MK4 | Open-source | Dual secure elements | $157 | Bitcoin-only; no altcoin support |
At the same $249 price point, the Safe 7 and Ledger Flex represent genuinely different trust models: verifiable open-source code with one disclosed lab-conditions flaw, versus closed-source code with a cleaner practical track record but no way to independently check it.
We don't just want to hand you our number; we want to show you how it sits next to what other review desks and comparison sites have published. This includes our own real, published score for the Safe 7, marked accordingly below. Coverage ranges from strongly enthusiastic to genuinely mixed depending on how much weight each outlet gives the TROPIC01 disclosure and the premium price relative to the Safe 5.
Our score lands modestly below the aggregated industry average; several sources lead with the genuinely novel dual-SE architecture and quantum-ready roadmap without weighting the real, disclosed TROPIC01 vulnerability or the TRON/TRC-20 gap as heavily as we do.
| Source | Score | Type |
|---|
Scores compiled by our editorial team from publicly available reviews as of August 2026. "Editorial estimate" means the outlet didn't publish a single numeric score, so we converted their published verdict and sentiment into a comparable 100-point figure. Verify current figures directly with each source before citing them elsewhere.
The disclosed attack requires physical possession of the device plus specialized laboratory equipment, and it has never been observed outside a lab setting. No user funds were at risk, and it defeated only one of the device's three security layers. It's a real, confirmed finding, but not a practical, real-world threat to a device in your own possession.
It's described as the world's first secure element whose complete hardware design, firmware, and specification are published for public review. Every standard EAL6+ chip on the market, including those in Ledger devices, older Trezor models, and OneKey wallets, has a closed-source internal architecture you can't independently verify.
No, and Trezor is explicit about this. The quantum-ready firmware protects the device's own firmware update chain, authentication, and secure boot process against future quantum attacks. It does not make Bitcoin or Ethereum addresses themselves quantum-safe; that would require changes to those blockchains' own protocols.
No, native TRON (TRX) and TRC-20 USDT support are both absent, independently confirmed across multiple reviews. If you regularly hold or transfer USDT specifically on TRON, this is a real, practical gap to weigh before buying.
Yes. Most Bluetooth-equipped hardware wallets rely on a software toggle in the firmware settings, meaning Bluetooth can be disabled but the hardware itself doesn't guarantee it's inactive. The Safe 7's kill switch is a physical hardware control, a more concrete guarantee.
If you don't need wireless features, the dual-SE architecture, or the aluminum/IP67 build, multiple independent reviewers note the Safe 5 delivers comparable core firmware security for $80 to $120 less. The Safe 7 makes the most sense if those specific extras matter to you.
A recovery method that splits your seed into multiple shares, requiring a subset of them to restore your wallet, rather than relying on a single 24-word phrase. It's a genuinely more advanced backup option than most competitors offer.
Only through Trezor's own official store. Buying direct is the only way to be confident you're receiving a genuine, untampered device rather than one intercepted through a third-party marketplace.
More Reviews
BitBox02 – Hardware Wallet Review
Score: 71/100. Swiss-made, open-source, and genuinely clever, but sources disagree on whether multisig still works.
Read MoreLedger Flex – Hardware Wallet Review
Score: 76/100. Best chip Ledger makes, but closed-source firmware, the Recover controversy, and two breaches still linger.
Read MoreNGrave Zero – Hardware Wallet Review
Score: 62/100. The "EAL7 wallet" is real, but the actual secure element underneath is a lower EAL5+ chip.
Read MoreTrezor Safe 5 – Hardware Wallet Review
Score: 76/100. Confirmed unaffected by the Safe 3's chip flaw, but skips native TRON support at a real price premium.
Read More



