Is Trezor safe?
Short answer
Trezor scores 65/100 (Good). It is a self-custody hardware wallet made by Trezor Company s.r.o. (Czech Republic). Its code is open source, no independent audit of the wallet has been published, and 5 security incidents are on record, none with user losses through the wallet itself.
How Trezor scores
Safety score
65/100
Good
Write the recovery phrase on paper or metal, never in a photo or cloud note. Install wallets only from the maker’s own site or the official app store.
The wallet code is public under an open-source licence, so anyone can check how keys are handled.
No independent audit of the wallet itself has been published.
Keys are created and kept on a dedicated device, away from the phone or computer you browse with.
5 incidents on record, 5 in the last three years. Recent incidents and losses weigh more.
Run by Trezor Company s.r.o., a named company in Czech Republic.
Trezor at a glance
- Type: hardware wallet
- Available on: hardware device, desktop, web, iOS, Android
- Key storage: Recovery phrase. Wallet backup (single or multi-share) generated on the device and never leaves it; Safe 3/5/7 add a secure element, while Model One and Model T have none.
- Networks: EVM chains, Bitcoin and Solana. Coins page lists Ethereum on "44 networks"; Solana only on "some Trezor models". No overall network count published.
- Company: Trezor Company s.r.o. (Czech Republic)
- Open source: Firmware and the Trezor Suite app are public. The third-party secure element chips in Safe models are not Trezor code. GitHub
- App ratings: App Store: 4.7 from 1,557 ratings; Google Play: 4.7 from 3,786 ratings
Has Trezor been hacked?
- August 2026 · Breach
Shipping provider ShipMonk was breached through a Metabase zero-day. Trezor says 80,689 customers were affected: 13,689 from May-August 2026 orders plus about 67,000 US customers from 2019-2021 orders that ShipMonk had failed to delete. Names, emails, phones and addresses exposed; Trezor's systems and devices not compromised. Source - June 2026 · Vulnerability
Ledger Donjon extracted a subset of secrets from the TROPIC01 secure element in Trezor Safe 7 using a lab laser fault-injection attack. Trezor says PINs, backups and funds are not exposed because keys are not stored on that chip; hardware flaw, not fixable by firmware. Source - June 2025 · Phishing
Attackers abused Trezor's support contact form so that automatic replies from help@trezor.io carried phishing subject lines asking for wallet backups. Source - March 2025 · Vulnerability
Ledger Donjon reused a known physical attack to bypass some supply-chain tamper checks on older Trezor Safe 3 units. No keys or PINs extracted; Trezor said Safe 5 uses a different chip. Source - January 2024 · Breach
Unauthorized access to Trezor's third-party support ticketing portal exposed names/usernames and emails of about 66,000 people who contacted support since December 2021; the data was used in seed-phishing emails. Source
Trezor security audits
We found no published independent audit of Trezor.
Crypto cards that work with Trezor
No card in our database spends directly from Trezor. These self-custody cards work with a wallet you control:
Other wallet safety checks
Frequently asked questions
Is Trezor safe?
Has Trezor ever been hacked?
Is Trezor open source?
Is there a crypto card for Trezor?
Sources
- Trezor security page and bug bounty · checked September 29, 2026
- Trezor supported coins · checked September 29, 2026
- trezor-firmware repository · checked September 29, 2026
- trezor-suite repository · checked September 29, 2026
- Recent customer data exposed in shipping provider incident · checked September 29, 2026
- Trezor response: TROPIC01 chip disclosure · checked September 29, 2026
- BleepingComputer: Trezor's support platform abused in phishing attacks · checked September 29, 2026
- The Block: Trezor discloses vulnerability in older Safe 3 wallets · checked September 29, 2026
- BleepingComputer: Trezor support site breach exposes 66,000 customers · checked September 29, 2026