Hardware Wallet Comparison

A good Bitcoin hardware wallet should verify transactions on its own screen, sign without a live computer connection, protect the seed with secure elements, let you add your own entropy, use open standards, and avoid remote-validation servers. Use this table to compare devices against those security requirements.

Our 8 non-negotiable criteria, applied to seven current devices. Linked notes point to primary product documentation and public security research.

Last updated: September 6, 2026

How we compare wallets

This is an opinionated security comparison, not a neutral survey of every feature or use case. We prioritize independent transaction verification, offline signing, protected key storage, mixed user-and-device entropy, reproducible firmware, open standards, and recovery without permanent dependence on a vendor. A product may be well engineered and still fail one of these criteria because it uses a different trust model.

✅ = meets this guide's criterion ⚠️ = material dependency or trade-off ❌ = does not meet this guide's criterion

Ratings describe documented capabilities as of the review date. They are not guarantees that a product is secure or free from undiscovered vulnerabilities. Objective ratings should be supported by linked product documentation or public research. Material corrections update the review date.

Feature COLDCARD Q COLDCARD Mk5 Trezor Safe 7 BitBox02 Ledger Nano X Jade Plus Bitkey
Open-source firmware ✅ ✅ ✅ ✅Firmware and bootloader source ❌OS not fully open ✅ ⚠️Code published; noncommercial license
Fully air-gapped ✅QR or microSD ✅microSD ❌USB + Bluetooth ❌USB-C ❌USB + BT ✅QR / SD option ❌NFC
Bitcoin-only firmware ✅ ✅ ✅Optional BTC-only firmware ✅Dedicated Bitcoin-only edition ❌Multi-coin ❌+ Liquid ✅
Secure element ✅Dual SE ✅Dual SE ⚠️Dual SE; TROPIC01 laser-fault disclosure ✅ATECC608B ✅ST33J2M0 ❌Blind oracle / stateless ✅Secure enclave
Bring your own entropy ✅Required physical input: key timing, dice, or coins ✅Required physical input: key timing, dice, or coins ⚠️Suite supplies and checks host entropy; no physical-input setup ⚠️Optional dice seed replaces device RNG ❌Device secure-element TRNG only ⚠️Client API can add bytes; no physical-input setup ❌No documented user-entropy flow
Reproducible builds ✅ ✅ ✅Build guide ✅Build verification ❌ ✅Build guide ❌App builds documented, not device firmware
Nonce-exfiltration defenses ✅RFC 6979 ECDSA + signed, reproducible firmware ✅RFC 6979 ECDSA + signed, reproducible firmware ✅RFC 6979 ECDSA + signed, reproducible firmware ✅Anti-Klepto with a compatible client for ECDSA; not Taproot/Schnorr ⚠️RFC 6979 in the Bitcoin app; OS not reproducible; no host-verified Anti-Exfil ⚠️Anti-Exfil in the sign_tx ECDSA flow; not current PSBT/QR or Taproot signing ❌No documented host-verified Anti-Exfil; device firmware not reproducible
No remote servers ✅ ✅ ✅ ✅Own node or external wallet ✅Recover is optional ⚠️Oracle by default; self-host/stateless option ❌Server key + recovery services
On-device screen ✅Large color ✅OLED ✅Touch ✅OLED + touch controls ✅OLED ✅Color ✅OLED touch
External PSBT workflow ✅ ✅ ✅ ✅Sparrow / HWI ✅BIP-174 signing ✅ ❌No external PSBT workflow
Multisig ✅ ✅ ✅ ✅On-device registration ✅ ✅ ⚠️2-of-3 only
Duress / secondary PIN ✅5 types ✅5 types ⚠️Wipe code ⚠️Hidden passphrase wallets; no duress PIN ⚠️Hidden passphrase wallet ⚠️Wallet-erase PIN ❌
SeedXOR ✅ ✅ ❌ ❌ ❌ ❌ ❌
QR code signing ✅ ❌ ❌ ❌ ❌ ✅ ❌
Advertised price (USD) $289 $189 $249 $171 $79 From $149 $250
Security notes Security architecture Security architecture TROPIC01 disclosure2026 customer-data breach Severe USB / bootloader exploit Recover architecture Blind-oracle model 2-of-3 server-key modelRelationship-enrollment RNG bug

Bring your own entropy: This guide gives a full checkmark only when the normal setup mixes private physical input from the owner with independently generated device entropy. Host-supplied randomness, optional APIs, and importing a complete dice seed use different trust models. Never invent seed words or use an online generator.

Nonce-exfiltration scope: Dark Skippy assumes malicious signing firmware. RFC 6979 plus signed, reproducible firmware is an appropriate defense: it avoids accidental ECDSA nonce failures and helps keep changed code off the device or make it detectable. Anti-Klepto/Anti-Exfil adds host verification where supported; its coverage depends on the device, host software, signature scheme, and signing workflow. Bitcoin Core also uses RFC 6979 for ECDSA and reproducible Guix builds.

Prices are the advertised US prices observed on August 30, 2026, before tax and shipping; promotions and currency conversion can change. A checkmark means the device supports the row's capability, not that it has no security tradeoffs or undiscovered vulnerabilities.

Detailed comparisons: vs Ledger · vs Trezor · vs Bitkey · vs Jade · Q vs Mk5

Read Choosing a Hardware Wallet for why these criteria matter.