Trezor Safe 3:
the cheapest way into Trezor's ecosystem, and the device Ledger's own lab found a real way into.
We tore apart Trezor's entry-level hardware wallet across seven weighted categories; from the first Trezor to ship with a certified EAL6+ secure element, fully open-source firmware, and real Bitcoin-privacy tools like CoinJoin and Tor, to a disclosed March 2025 voltage-glitching attack from Ledger's own security lab against the device's separate microcontroller, and a real, unresolved disagreement across sources over whether the pricier Safe 5 shared the same exposure; and landed on a score the marketing page won't show you.
Our take, up front: launched in October 2023, the Safe 3 was the first Trezor to ship with a certified EAL6+ secure element, and at $59 today (down from $79 at launch), it remains one of the most affordable ways to get real hardware-backed self-custody with fully open-source firmware. It pairs that with genuinely distinctive Bitcoin-privacy tools, CoinJoin and Tor, built directly into Trezor Suite. The real complication: in March 2025, Ledger Donjon, the same competitor security lab behind the separate Trezor Safe 7 finding covered elsewhere in this series, disclosed a voltage-glitching attack against the Safe 3's microcontroller, a chip distinct from the certified secure element itself, which was not compromised. The attack could let someone with physical possession and specialized equipment extract an authentication secret and reprogram the device's firmware. Trezor confirmed no fix exists for already-manufactured units and was refreshingly candid about it publicly. One real, unresolved wrinkle: most sources describe the pricier Safe 5 as sharing the same vulnerable microcontroller, while at least one source states only the Safe 3 was affected. We couldn't fully settle that discrepancy, so we've flagged it rather than guessed. We weighted all of it below.
The Safe 3 was the first Trezor to ship with a certified EAL6+ secure element, launched in October 2023, and its firmware remains fully open-source and independently auditable. In March 2025, Ledger Donjon disclosed a voltage-glitching attack against the device's separate microcontroller (labeled TRZ32F429, a custom-packaged STM32F429 chip), distinct from the certified secure element itself. The attack requires physical possession, desoldering the microcontroller, and precise voltage manipulation to extract flash memory contents, potentially allowing an attacker to bypass a pre-shared authentication secret and reprogram the device's firmware while still passing Trezor's own security checks. Critically, Donjon was unable to extract private keys or PIN codes from the secure element itself; the exposure lives specifically in the separate microcontroller that handles cryptographic operations and user input. Trezor publicly confirmed no firmware fix exists for already-manufactured units and was candid about it: "in cybersecurity, the golden rule is simple: nothing can be completely invulnerable." Real, mitigating context: this is largely a supply-chain-style attack, most realistic against a device tampered with before it reaches a buyer, not a remote exploit, and Trezor states funds remain protected if purchased through official channels. One real, unresolved discrepancy: most sources describe the pricier Safe 5 as sharing the same vulnerable microcontroller; at least one source states the Safe 5 was not affected. We could not fully resolve this from available reporting.
Pros
- First Trezor model with a certified EAL6+ secure element, which itself was not compromised in the disclosed attack
- Fully open-source firmware, independently auditable
- Trezor's public response was candid rather than dismissive
Cons
- Disclosed, unpatchable voltage-glitching vulnerability in the device's microcontroller
- No firmware fix possible for already-manufactured units
- Real, unresolved disagreement over whether the Safe 5 shares the same exposure
The Safe 3 supports 8,000-plus assets through Trezor Suite and third-party apps, the same broad coverage as the pricier Safe 5. Real, distinctive Bitcoin-privacy tools, CoinJoin and Tor, are built directly into Trezor Suite, a genuine differentiator for privacy-focused users that most competitors in this series don't offer at any price.
Pros
- 8,000-plus supported assets, matching the pricier Safe 5
- Real CoinJoin and Tor integration built into Trezor Suite
Cons
- None significant found in our research
A small 0.96" monochrome OLED screen (128×64 pixels) is navigated with two physical buttons; at least one detailed reviewer describes it as "functional but tiny," with long addresses scrolling across the display. There's no touchscreen, Bluetooth, battery, or wireless connectivity at all, a deliberate budget-tier design choice. A real, specific limitation for iPhone users: the Trezor Suite Lite companion app only supports portfolio tracking, buying, and receiving; sending, swapping, setup, and device management all require a desktop computer or an Android device specifically.
Pros
- Simple, hard-to-misuse two-button confirmation flow
- Works fully with desktop and Android
Cons
- Small, monochrome screen where long addresses scroll rather than display fully
- iPhone use is limited to tracking, buying, and receiving; sending and setup require desktop or Android
Tamper-evident, hologram-sealed packaging lets buyers verify their unit wasn't opened before it arrived. The device is compact and lightweight, available in four real color options (Cosmic Black, Solar Gold, Stellar Silver, Galactic Rose). An optional "Keep Metal" kit, sold separately, lets owners permanently engrave their seed phrase into stainless steel for real, physical durability.
Pros
- Tamper-evident, hologram-sealed packaging
- Optional stainless-steel seed-phrase backup kit available
Cons
- No IP-rated waterproofing or premium materials found on pricier competitors
Trezor is built by SatoshiLabs, founded in 2013, which released the first-ever hardware wallet, the Trezor Model One, in 2014. Trezor's public handling of the March 2025 Donjon disclosure was genuinely transparent: the company acknowledged the finding, was explicit that no firmware fix exists for the underlying hardware issue on existing units, and gave honest, unhedged public commentary rather than downplaying the risk. No comparable pattern of customer data breaches was found in our research.
Pros
- Long, established operating history as one of the original hardware wallet makers
- Transparent, candid public disclosure of the March 2025 vulnerability finding
Cons
- No firmware fix possible for the disclosed vulnerability on already-manufactured units
At $59, down from a $79 launch price, this is genuinely one of the most affordable ways to get a certified secure element and fully open-source firmware anywhere in this series. It undercuts the pricier Safe 5 by roughly $70 and the Safe 7 by roughly $190 while running the same core open-source firmware and supporting the same coins; what you give up is screen size and connectivity, not the underlying software. No subscription fee.
Pros
- Price has dropped from $79 to $59 since launch
- Same core open-source firmware and coin support as the pricier Safe 5 and Safe 7
Cons
- None significant found in our research
Real Shamir Backup (SLIP39) support offers flexible 12, 20, or 24-word backup options, with current units defaulting to a 20-word single-share backup. CoinJoin and Tor integration are genuine, distinctive Bitcoin-privacy extras. An optional stainless-steel "Keep Metal" engraving kit adds a real, durable backup option beyond paper.
Pros
- Flexible Shamir Backup options (12/20/24-word)
- Real CoinJoin and Tor privacy tooling built in
Cons
- None significant found in our research
Buy only through Trezor's official store.
Given the disclosed vulnerability is realistically most exploitable via a tampered supply chain, buying direct and checking the hologram seal before setup matters more here than on most devices in this series.
A genuinely excellent entry point into self-custody, with one real, honestly-disclosed asterisk.
As a first hardware wallet, the Safe 3's fundamentals are genuinely strong: real hardware-backed security at $59, fully open firmware you or anyone else can inspect, and Bitcoin-privacy tools most competitors don't bother building in at any price. The March 2025 Donjon disclosure doesn't erase that, but it's a real, permanent asterisk: the device's microcontroller, not its certified secure element, has a confirmed, unpatchable weakness to a specific physical attack, and Trezor was honest about not being able to fix it on units already in the world. For the realistic threat most buyers actually face, someone getting remote access to your funds, this doesn't move the needle. For the narrower, real threat of a tampered supply chain, it's worth taking seriously, and worth buying direct specifically because of it.
The scorecard above is deliberately general. Whether the Trezor Safe 3 is right for you depends heavily on which of these you already are.
The first-time buyer who wants real hardware security at the lowest reasonable price
A certified secure element and fully open firmware for $59 is a genuinely strong entry point into self-custody, especially if you buy direct and aren't a high-value target.
The Bitcoin privacy user who wants CoinJoin and Tor built in
These real, genuine privacy tools are integrated directly into Trezor Suite, a distinctive advantage most competitors don't offer at any price.
The desktop or Android-primary user who doesn't need a touchscreen
You'll get the full feature set without friction; the small screen and two-button flow are a real but manageable trade-off for the price.
iPhone-primary users, or anyone whose threat model includes supply-chain tampering
iOS support is genuinely limited to tracking and receiving, and the disclosed microcontroller vulnerability is realistically most relevant to a device that could have been tampered with before it reached you.
The scorecard covers the headline judgment calls. These four tables cover the specifics we didn't want to bury in prose; the March 2025 Donjon disclosure in plain terms, the real, unresolved question of whether the Safe 5 shared the exposure, the direct Safe 3 vs. Nano S Plus rivalry, and how it compares against the other wallets we've reviewed.
The March 2025 Donjon disclosure, in plain terms
| What happened | |
|---|---|
| Who found it | Ledger Donjon, the same lab behind the separate Trezor Safe 7 TROPIC01 finding covered elsewhere in this series |
| When | Publicly disclosed March 12-13, 2025 |
| What was targeted | The Safe 3's separate microcontroller (TRZ32F429, a custom-packaged STM32F429), not the certified secure element |
| Method | Voltage glitching: precise voltage manipulation during a physical, desoldered attack to force flash memory disclosure |
| What it enables | Extraction of a pre-shared authentication secret, allowing firmware reprogramming that still passes Trezor's security checks |
| Was the secure element compromised? | No; Donjon could not extract private keys or PIN codes from the certified chip itself |
| Patch available? | No fix possible for already-manufactured units, per Trezor's own statement |
| Requirements to replicate | Physical possession, desoldering the microcontroller, specialized equipment, and significant technical expertise |
Trezor states that funds remain protected if the device is purchased through official channels; the realistic risk is a supply-chain attack on a device tampered with before it reaches a buyer, not a remote exploit.
Was the Safe 5 also affected? Sources disagree
| Claim | Source pattern |
|---|---|
| Safe 5 shared the same vulnerable microcontroller | The majority of detailed technical sources we found describe both the Safe 3 and Safe 5 as using the same TRZ32F429 chip and both as affected |
| Safe 5 was not affected | At least one source states only the Safe 3 was affected, with the Safe 5 using a different, unaffected chip |
We could not fully resolve this discrepancy from available reporting; if you own a Safe 5 and want certainty, check Trezor's own current, official statement on the matter directly.
Direct rivals: Trezor Safe 3 vs. Ledger Nano S Plus
| Trezor Safe 3 | Ledger Nano S Plus | |
|---|---|---|
| Launch price | $79 | $79 |
| Current price | $59 | $79 |
| Firmware | Open-source | Closed-source |
| Philosophy | Open code, Bitcoin privacy tools, Shamir Backup | Secure Element model, closed ecosystem, wider app support |
| Disclosed vulnerability | March 2025 microcontroller voltage-glitching (unpatchable) | None specific to this device found in our research |
Multiple sources frame this as a genuine philosophy choice as much as a spec comparison: open, inspectable code versus a closed but differently-architected security model.
How it compares to other hardware wallets we've reviewed
| Wallet | Price | Firmware | Notable trade-off |
|---|---|---|---|
| Trezor Safe 3 | $59 | Open-source | Disclosed, unpatchable microcontroller vulnerability (physical attack only) |
| Ledger Nano S Plus | $79 | Closed-source | No iOS support; same Recover/breach history as other Ledgers |
| Trezor Safe 5 | $59-$129 (sources vary) | Open-source | Real, unresolved disagreement over shared exposure to the Safe 3 finding |
| Trezor Safe 7 | $249 | Open-source | Separate, disclosed lab-conditions TROPIC01 vulnerability |
This is now the second Ledger Donjon disclosure against a current Trezor product covered in this series, a real, notable pattern of one company's security lab publicly testing a direct competitor's entire lineup.
We don't just want to hand you our number; we want to show you how it sits next to what other review desks and comparison sites have published. Coverage here is largely 2026-dated and mostly focused on value and everyday usability, with less direct engagement with the March 2025 Donjon disclosure than we've given it. One source (Cypherock) sells a competing product and explicitly pitches it as an upgrade, which we've flagged as a real, mild bias to weigh accordingly.
Our score lands modestly below the aggregated industry average; most sources lead with the genuine value and open-source story without weighting the disclosed, unpatchable microcontroller vulnerability as heavily as we do, even accounting for how narrow its realistic exploitation window is.
| Source | Score | Type |
|---|
Scores compiled by our editorial team from publicly available reviews as of August 2026. "Editorial estimate" means the outlet didn't publish a single numeric score, so we converted their published verdict and sentiment into a comparable 100-point figure. Verify current figures directly with each source before citing them elsewhere.
The vulnerability requires an attacker to have physical possession of your device, desolder its microcontroller, and use specialized equipment. This is realistically a supply-chain risk, most relevant to a device tampered with before you received it, rather than a remote or software-based threat. Trezor states funds remain protected if you purchased through official channels.
No. Trezor confirmed no firmware fix is possible for the underlying hardware flaw on units already manufactured, since the vulnerability lives in the physical microcontroller itself, not in software that can be patched remotely.
Sources genuinely disagree. Most detailed technical reporting describes the Safe 5 as sharing the same vulnerable microcontroller as the Safe 3; at least one source states only the Safe 3 was affected. We couldn't resolve this discrepancy from available reporting, so check Trezor's own current, official statement if you own a Safe 5 and want certainty.
The Safe 3 uses a two-chip design: a certified EAL6+ secure element that handles PIN protection, and a separate microcontroller that handles cryptographic operations and user input. Donjon's attack targeted the microcontroller specifically; the secure element itself resisted extraction of private keys or PIN codes.
Only partially. The Trezor Suite Lite iOS app supports portfolio tracking, buying, and receiving. Sending, swapping, initial setup, and device management all require a desktop computer or an Android device.
$59 as of mid-2026, down from a $79 launch price in October 2023.
Beyond similar pricing and both lacking Bluetooth, it's largely a philosophy difference: the Safe 3 offers fully open-source firmware and built-in Bitcoin privacy tools (CoinJoin, Tor); the Nano S Plus offers Ledger's closed-source Secure Element model and a wider third-party app ecosystem.
Only through Trezor's own official store, and check the tamper-evident hologram seal before setup. This matters more here than on most devices in this series, given the realistic threat model for the disclosed vulnerability is a compromised supply chain.
More Reviews
BitBox02 – Hardware Wallet Review
Score: 71/100. Swiss-made, open-source, and genuinely clever, but sources disagree on whether multisig still works.
Read MoreLedger Flex – Hardware Wallet Review
Score: 76/100. Best chip Ledger makes, but closed-source firmware, the Recover controversy, and two breaches still linger.
Read MoreNGrave Zero – Hardware Wallet Review
Score: 62/100. The "EAL7 wallet" is real, but the actual secure element underneath is a lower EAL5+ chip.
Read MoreTrezor Safe 7 – Hardware Wallet Review
Score: 78/100. Fully auditable TROPIC01 chip, undercut by a real Ledger Donjon laser fault-injection disclosure.
Read More



