Crypto wallet safety check

Each wallet is scored out of 100 on five factors, and every fact links to its source. A high score means fewer known weak points, not a guarantee: the recovery phrase you write down is still the single most important part of self-custody.

WalletScoreTypeCodeCard
Coinbase Wallet77 Goodsoftware walletPartly open–
MetaMask76 Goodsoftware walletPartly openMetaMask Card
Ledger74 Goodhardware walletPartly openCL Card
Rabby Wallet73 Goodsoftware walletPartly open–
Tangem72 Goodhardware walletClosedTangem Pay
Trezor65 Goodhardware walletOpen source–
Exodus61 Goodsoftware walletPartly open–
Trust Wallet57 Fairsoftware walletPartly open–
Phantom56 Fairsoftware walletClosed–
Bitget Wallet30 Limitedsoftware walletClosedBitget Wallet

Write the recovery phrase on paper or metal, never in a photo or cloud note. Install wallets only from the maker’s own site or the official app store.

How the wallet score works

Five factors add up to 100. The same rules apply to every wallet, and incidents count from the date they happened.

  • Code transparency: 25 points for open source, 15 for partly public code, 0 for closed code.
  • Independent audits: 20 points when the latest published audit of the wallet is under 24 months old, 10 when it is older, 0 with none.
  • Key storage: 20 points for a hardware wallet, 12 for keys kept on a phone or computer.
  • Incident record: Starts at 25. An incident in the last 36 months costs 10 points with user losses, 4 for a breach, 3 for a vulnerability and 1 for phishing. Older incidents cost 5, 2, 1 and 0. Floor 0.
  • Company: 10 points for a named company in an established jurisdiction, 3 for one registered where company licensing involves little supervision.

Bands

Strong ≥ 80, Good ≥ 60, Fair ≥ 40, Limited ≥ 0.

Data rules

  • Facts come from the wallet maker, its public code, the audit firm’s published report, a CVE record or established security press.
  • An incident counts against a wallet when it happened to the wallet’s own software, backups, infrastructure or customer data. Fake apps and phishing that only impersonate a wallet count as the lightest type.
  • Audits of something other than the wallet itself, such as a swap contract or a website, are listed but do not earn points.
  • App store ratings are shown for context and do not affect the score.