Both devices will keep your keys off an internet-connected computer, which is the thing that actually matters. Neither is meaningfully more likely to be “hacked” than the other. The real choice is which company you would rather have to trust, and about what — and that is a question with an honest answer that depends on you.
The short version:
- Trezor if you want to be able to verify what the device does, want Shamir backups, or are uneasy about a company holding a file that says you own crypto.
- Ledger if you want the strongest resistance to someone who has physically stolen your device, or you need broad support for a lot of alt-coins and mobile use.
- Neither, yet, if you hold a few hundred dollars of crypto. Skip to the last section.
We do not make or sell hardware wallets, backup plates, or anything else. Some links on this site earn a commission; it does not change what is written here, and the section arguing you may not need either device at all is proof of that.
The 2026 lineups
Prices checked August 2026 and rounded; hardware pricing moves, so confirm before buying.
| Ledger | Price | Trezor | Price |
|---|---|---|---|
| Nano S Plus | ~$79 | Safe 3 | ~$79 |
| Nano X (Bluetooth) | ~$149 | Safe 5 (colour touch) | ~$169 |
| Nano Gen5 (2026, touch/NFC/BT) | ~$179 | Safe 7 (AMOLED, NFC) | ~$249 |
| Flex (2.8″ E Ink touch) | ~$249 | — | — |
| Stax (3.7″ curved E Ink) | ~$399 | — | — |
The entry models are priced identically at about $79, and they are the two devices most people should actually be comparing. Everything above that is screen size, wireless convenience and materials — not security. A larger screen does make verifying transaction details easier, which is a genuine if modest safety benefit, but nobody’s coins have ever been saved by an AMOLED panel.
The secure element question, and two myths to drop
This is where most comparison articles are simply out of date, in both directions.
Myth 1: “Trezor has no secure element.” This was true of the old Model One and Model T. It is not true of the current Safe line — Safe 3, Safe 5 and Safe 7 all ship with a secure element certified to Common Criteria EAL6+, the same assurance class used in passports and SIM cards.
Myth 2: “So they are equivalent now.” Also wrong, and this is the part worth understanding, because the two companies use the chip for different jobs.
- Ledger performs the cryptographic operations inside the secure element. The keys are used where they are stored.
- Trezor Safe uses the secure element to protect the PIN, contribute entropy at wallet creation, and wipe the device after 16 wrong PIN attempts. The actual signing still happens on the general-purpose microcontroller — which remains the component exposed to voltage-glitching attacks.
So Ledger retains a real advantage in one specific scenario: a skilled attacker in physical possession of your device. Trezor has narrowed that gap considerably; it has not closed it.
Worth knowing who found the remaining flaws: Ledger’s own security team, Donjon, published attacks against the Trezor Safe 3 and Safe 5. That is legitimate research and the findings appear sound — and it is also a competitor publishing about a competitor, which is a normal thing in this industry but worth naming rather than presenting as neutral.
The practical weight of all this: physical-extraction attacks require your device, specialist equipment and expertise. If that is your threat model, the answer is a passphrase, not a brand.
Open source versus closed source
Trezor’s firmware is fully open source and auditable by anyone. Ledger’s is not — the secure element firmware is closed, and Ledger’s position is that a secure element vendor’s NDA makes this unavoidable, and that open-sourcing security-critical code has its own risks.
Be clear about what open source does and does not buy you. It does not mean anyone has audited the code you are running, nor that the binary on your device matches the published source. What it does mean is that independent researchers can look, and that the manufacturer cannot quietly change the rules and expect it to go unnoticed.
That distinction stopped being abstract in May 2023.
What Ledger Recover actually proved
Ledger announced an optional subscription service that could back up your recovery phrase by splitting encrypted shards across custodians. The backlash was the largest in the company’s history, and the reason was not the feature itself.
It was that the feature demonstrated the firmware could export seed material at all, given on-device consent. For years the marketing had implied this was architecturally impossible — that keys simply could not leave the secure element. Recover proved that what prevented extraction was the firmware’s policy, not the hardware’s physics.
Two honest framings of that, and you should pick the one that matches how you think:
- Reassuring reading: this was always true of every hardware wallet, including Trezor. Firmware that can sign with a key can be written to export it. Ledger was just the company that made it visible.
- Damning reading: precisely because it was always true, verifiability is the only thing that protects you — and closed firmware means you are trusting a policy you cannot inspect, from a company that has already been shown to describe its own architecture more strongly than the facts supported.
Ledger Recover is opt-in. Nobody’s keys were taken. The question it left behind is whether “opt-in” is a property you can verify or one you have to believe.
The factor almost nobody weights properly: who knows you own crypto
In June–July 2020, Ledger’s e-commerce and marketing database was breached. Roughly 1.1 million email addresses and about 272,000 records containing full names, phone numbers and home addresses were exposed and later dumped publicly.
What followed is the part that matters for your threat model. Victims received phishing emails and texts impersonating Ledger support and asking them to “update” their wallet or confirm a recovery phrase. Others received extortion letters demanding $700–$1,000 in Bitcoin under threat of doxxing or violence. There were attempted home invasions.
A hardware wallet protects your keys. It does not protect the fact that you bought one. A public file mapping “this person owns cryptocurrency” to “this is their front door” is a different category of harm entirely, and it is not fixed by any secure element. Ledger customers have since been notified of a further exposure through a third-party e-commerce processor, so this is a live consideration rather than a closed chapter.
The lesson generalises past brand choice: buy direct, never from a marketplace reseller, and give the minimum information required. Where practical, have it delivered somewhere that is not your home. This applies whichever device you choose.
Shamir backup: a real Trezor advantage
Every Trezor Safe model supports SLIP-39 Shamir backup: your seed is split into shares with a threshold, so that (say) any 2 of 3 shares reconstruct the wallet and any single share reveals nothing.
This is the correct way to split a secret, and it is the direct answer to the naive “write six words on each card” idea that quietly guts your security. It is genuinely useful for inheritance planning and for anyone spreading backups across locations. If that describes you, it is a strong reason to pick Trezor and not a small one.
Post-quantum signatures on the Safe 7
Trezor markets the Safe 7 as the first hardware wallet with post-quantum cryptography, using SLH-DSA-128 — the hash-based signature scheme standardised by NIST as FIPS 205.
This is real cryptography and a genuinely forward-looking choice, and it should not be oversold. Hash-based signatures are the conservative corner of post-quantum design, so the engineering is sound. But Bitcoin and Ethereum transactions are still signed with elliptic-curve cryptography — the chains do not accept post-quantum signatures, so this cannot protect your BTC or ETH today. It protects device-level operations and positions the hardware for a future the networks have not reached.
Do not buy a Safe 7 believing it makes your coins quantum-safe. It does not, and no wallet can, because the exposure lives on the chain rather than in your pocket. We cover what a quantum computer could and could not actually break in quantum.
So which one
Choose Trezor if you value being able to verify the firmware, you want Shamir backup, you are planning for inheritance, or the 2020 breach and its aftermath sit badly with you.
Choose Ledger if physical theft of the device is your primary worry, you hold a wide range of alt-coins, or you want the more mature mobile experience.
At the $79 entry point — Safe 3 against Nano S Plus — the Safe 3 is the better default for most people, because open firmware and Shamir backup are usable advantages today, while the secure-element gap only matters to an attacker holding your device.
When you should buy neither
If you hold a few hundred dollars of crypto, a $79 device is a large fraction of your holdings to spend on a threat you are unlikely to face. You are far more likely to lose that money to a bad backup, a phishing site, or forgetting the wallet exists.
Spend the effort on the free things first: a reputable software wallet, a recovery phrase written on metal and stored in two buildings, and a tested restore. Those cost almost nothing and eliminate the failures that actually happen. A hardware wallet is worth buying when the amount at stake exceeds the cost of the device by a comfortable margin — and it is worth buying before that point only if you already have the backup discipline to use it properly.
Whichever you choose: the device is not the security. The backup is. Neither company can help you if the phrase is wrong, and neither will ever ask you for it — nor will we.
Sources
- Trezor: Secure Elements in Trezor Safe devices — what the EAL6+ element does, and that signing remains on the microcontroller
- Ledger: Addressing the July 2020 e-commerce and marketing data breach — the company’s own account
- Have I Been Pwned: Ledger breach record — independent record of the exposed data
- CoinDesk: Ledger’s PR struggle reveals uncomfortable trade-offs — contemporaneous coverage of Ledger Recover
- SLIP-39 — the Shamir threshold backup scheme
- NIST FIPS 205 (SLH-DSA) — the post-quantum signature standard cited for the Safe 7