You’re holding a small plastic device that now stands between years of your income and everyone who’d like to take it. You set it up in ten minutes, wrote twelve words on a card, and felt safe. But a quiet question keeps surfacing at 2am: how do you actually know the firmware inside isn’t keeping a copy of your seed? With most wallets, you don’t. You trusted a company’s word. The Trezor Safe 3 is the rare device that lets you replace that trust with proof.
The short version: The Trezor Safe 3 is a roughly $59 hardware wallet (list price on Trezor’s own shop, often promoted lower) that pairs open-source firmware with an EAL6+-certified Infineon OPTIGA Trust M (V3) Secure Element, supporting Bitcoin, Ethereum, and 9,000+ coins and tokens. Trezor discounts it regularly, so the shop price often sits well below list. Its firmware is auditable line by line and compiled firmware can be verified bit-for-bit against the published source — but the Secure Element itself is a proprietary Infineon part, so “open source” describes the code, not every chip. The trade-offs are real: a small 0.96-inch, 128×64 monochrome screen, no Bluetooth, and — as Ledger’s Donjon lab demonstrated in March 2025 — physical incidents against the Safe 3’s microcontroller that remain possible if you skip the passphrase. Set a BIP39 passphrase (the 25th word), use Shamir Backup for your recovery shares, and this becomes one of the strongest price-to-security ratios on the market. To hold keys off any exchange, an air-gapped wallet like Keystone signs transactions offline so your seed never touches an online device.
Why proprietary wallet firmware is a structural security flaw
Here’s the thing nobody markets to you when you buy a hardware wallet: with closed firmware, your security isn’t cryptographic. It’s reputational.
The 12-point setup for a private, secure, high-output digital life — in one afternoon. No spam, unsubscribe anytime.
In May 2023, Ledger announced Ledger Recover — an opt-in subscription that could split your seed phrase into three encrypted shards and send them to third-party custodians (Coincover, EscrowTech, and Ledger itself) for cloud backup, with identity verification required to restore. The feature being optional wasn’t the part that detonated the community. The detonation was the implication: if firmware could be built to export seed-derived material at all, then the device was never cryptographically incapable of it — users had simply assumed otherwise. Ledger maintained there was no backdoor and that the export required explicit user consent, and security researchers were not able to settle the argument either way — because the Secure Element firmware is closed and nobody outside Ledger could check.
When firmware is closed, you don’t get security — you get a promise, with no audit trail to confirm it. That’s an acceptable deal for headphones. For a device holding your savings, it’s a fault line.
The risk compounds before the box even reaches you. Firmware you can’t inspect can’t be checked at the point of sale, and in 2020 Kraken Security Labs documented supply-chain incidents against the Ledger Nano X — a tampered device whose replaced microcontroller firmware could blank the screen while harmful software on your computer walked you into approving a transaction you never saw. It isn’t the myth of a “pre-loaded seed”; it’s worse in one respect, because the device still looks and behaves like yours. And as the next section shows, this is not a closed-source problem alone — the same class of incident was later demonstrated against the Safe 3.
Where Trezor’s earlier models failed — and why that history matters
An honest review has to confront the Safe 3’s own family tree, because it isn’t spotless.
In December 2018, the Wallet.fail team demonstrated a physical voltage-glitching incident at 35C3 — against the Trezor One (and the Ledger Nano S and Blue by other methods), not the Model T. The Model T was pulled in later: in January 2020 Kraken Security Labs extended the technique to both the Trezor One and Model T, extracting the encrypted seed with about 15 minutes of physical possession, several hundred dollars of gear at first, and an estimated $75 in parts if mass-produced. The method is the same each time: connect to the board and apply precisely timed voltage faults to force the microcontroller to give up its protected flash.
Read that and your stomach drops. Then read the detail that changes everything: if you had set a BIP39 passphrase, the extracted seed was useless — the passphrase is never stored on the device, a mitigation Kraken itself named in its disclosure. Only users relying on PIN and the seed words alone were genuinely exposed.
The root cause was silicon, not software. Those older models used STM32 microcontrollers with no dedicated Secure Element. And that’s the reframe most buyers miss: open-source code protects you from software backdoors and hidden logic. It cannot harden a chip against an incidenter with a soldering iron. Open-source is necessary. It is not, on its own, sufficient. You also need certified physical hardening — the gap the Safe 3 was built to narrow. Narrow, not close: hold that word, because the next section is where this review stops flattering the device.
How the Safe 3 solves the physical incident problem
The Safe 3 runs a hybrid architecture: open-source firmware paired with the Infineon OPTIGA Trust M (V3), an EAL6+-certified Secure Element that Trezor chose specifically because its documentation is NDA-free and open to public review. That point is unusual. Most Secure Elements are locked behind non-disclosure agreements, so using one normally forces a manufacturer to close part of their stack — defeating the purpose of being open-source in the first place. NDA-free is not the same as open-source, though: the chip itself is still proprietary Infineon silicon running firmware you cannot read. Trezor’s eventual answer to that was TROPIC01, a genuinely open secure element — and it ships in the Safe 7, not here.
Trezor’s implementation sidesteps most of the trap. The Secure Element doesn’t store your private keys. Instead it holds a secret, released only on correct PIN entry, that encrypts the keys held on the main, auditable processor. Core key derivation stays in open code; the Secure Element adds a physical barrier and a real PIN-guessing defence — without ever creating a cryptographic black box you have to trust blindly.
Then comes the part most Safe 3 reviews leave out. In March 2025, Ledger’s Donjon research lab showed the Safe 3 is still glitchable. Its microcontroller, labelled TRZ32F429, is a custom-packaged STM32F429 — the same chip family Wallet.fail and Kraken broke. Because cryptographic operations still execute on that microcontroller and Trezor’s authenticity check at the time verified only the Secure Element, an incidenter with physical access could rewrite the microcontroller firmware and leave no trace the device could report. Trezor confirmed the finding, described it as a supply-chain-incident countermeasure being bypassed rather than a remote misuse, and noted that the Safe 5 uses a newer microcontroller that resists it. The honest summary: the Secure Element hardened PIN handling and key storage. It did not make the Safe 3 immune to fault injection.
So what actually protects you is layered, and the order matters. Buy direct from Trezor or an authorised reseller, so a tampered unit never enters your chain. Run the authenticity check in Trezor Suite and keep firmware current. And set a passphrase — because a passphrase is never written to the device, extraction of the on-device secret still yields nothing usable. The risk surface doesn’t disappear. No device achieves that.
Trezor Safe 3 specifications: what’s actually inside
| Specification | Detail | |—|—| | Secure Element | Infineon OPTIGA Trust M V3 (CC EAL6+, NDA-free) | | Main processor | TRZ32F429 — custom-packaged STM32F429, ARM Cortex-M4 @ 180MHz | | Firmware | Open source (trezor-firmware on GitHub); Secure Element firmware is proprietary Infineon | | Display | 0.96″ monochrome OLED, 128×64px | | Input | Two physical buttons | | Connectivity | USB-C (no Bluetooth) | | Coin support | Bitcoin, Ethereum, and 9,000+ coins and tokens | | Backup | BIP39 12-, 20- or 24-word, plus multi-share Shamir Backup (SLIP39) | | Passphrase | BIP39 passphrase (25th word), on-device entry | | Bitcoin-only firmware | Available as alternative install | | Price | $59 USD list on Trezor’s own shop, frequently promoted lower (checked August 2026) | | Companion software | Trezor Suite (desktop and web), Trezor Suite mobile; also Sparrow, Electrum, MetaMask |
The headline number is the EAL6+ Secure Element at this price. Under $100, that pairing is genuinely hard to find — the closest open-source rivals with a comparably certified chip, like the BitBox02 Nova, sit at roughly double. The specification table above reflects Trezor’s own published specs; note the processor line, because that microcontroller is the component the 2025 Donjon research targeted.
How does the Safe 3 compare to competing hardware wallets?
| Device | Price | Open source | Secure Element | Key strength | Key weakness | |—|—|—|—|—|—| | Trezor Safe 3 | ~$59 | Firmware fully open; Secure Element proprietary | OPTIGA Trust M V3 (EAL6+) | Open firmware + certified SE; lowest price in tier | Small screen; microcontroller glitching shown in 2025; passphrase does the heavy lifting | | Ledger Nano X | ~$149 | Partial (SE firmware closed) | ST33 (EAL5+) | Bluetooth; wide app ecosystem | Closed SE firmware; Recover controversy; higher price | | Coldcard Mk5 | ~$189 list, often ~$170 | Source-available (Commons Clause), not freely redistributable | Dual ATECC608 + DS28C36B; no published Common Criteria rating | Air-gapped; advanced Bitcoin signing | Bitcoin-only; steep learning curve; licence is not true open source | | BitBox02 / BitBox02 Nova | ~$149 / ~€175 | Firmware fully open | ATECC608 (BitBox02); OPTIGA Trust M V3 EAL6+ (Nova) | Minimalist; strong open-source ethos; Nova adds iOS | Limited coins on Bitcoin edition; smaller community |
Under $100, the Safe 3 remains the cheapest route to open firmware plus a certified Secure Element. But two corrections to the folklore are owed here. First, the Coldcard does not have stronger open-source credentials: Coinkite ships its firmware under a Commons Clause licence, so you may read and build it but not freely redistribute it — readable is not the same as open. Second, the BitBox02 Nova now pairs fully open firmware with the same EAL6+ OPTIGA Trust M V3, so the Safe 3’s architecture is no longer unique — only its price is. The Coldcard still wins on air-gapped Bitcoin signing for people who want that discipline. For most people who want verifiable trust without a second mortgage, the Safe 3 wins on math.
How to set up and secure your Trezor Safe 3
The good news: the first move is almost embarrassingly easy, and each step closes a real incident path.
- Verify authenticity in software, not stickers. Trezor ships with a holographic seal, but treat that as a basic tamper hint, not proof. The real check happens when you open Trezor Suite — it performs cryptographic attestation against Trezor’s public-key infrastructure. If that check fails, the device is counterfeit. Stop there.
- Generate the seed on the device. During setup the Safe 3 creates your recovery seed on its own screen — never on your computer. Trezor supports 12-, 20- and 24-word backups, so don’t be alarmed if Suite offers you twelve words rather than twenty-four; entropy at that length is still far beyond brute force. Write it on the included card in pen. Don’t photograph it, don’t type it anywhere, don’t drop it in a password manager. This card is your only backup independent of the hardware.
- Use Shamir Backup to kill single points of failure. The Safe 3 supports SLIP39 multi-share backup, which splits your seed into shares with a threshold. A practical layout: 3-of-5 — store two shares at home, hand one to a trusted person with sealed instructions, place two off-site. Now one fire, one theft, or one bad actor can’t sink you.
- Set a BIP39 passphrase (the 25th word). This is the layer people skip and shouldn’t, and after the 2025 glitching research it is no longer optional in spirit. The passphrase generates an entirely separate wallet from the same seed and is never stored on the device — you enter it each time you open that wallet. So physical extraction without it reaches only your standard wallet, not the holdings behind the passphrase. The cost: forget it and you’re locked out permanently. Test access to your passphrase wallet monthly.
- Switch to Bitcoin-only firmware if that’s all you hold. Fewer features mean less code, and less code means a smaller risk surface. You can flip between standard and Bitcoin-only firmware anytime by wiping and restoring from your seed.
Of all five, the passphrase is the one that turns a stolen device from a disaster into a shrug.
Why does open-source firmware actually protect you?
The value isn’t that you’ll personally read the trezor-firmware repository — most owners never will. The value is structural.
Because anyone can read the code, security researchers, cryptographers, and adversarial reviewers do. Vulnerabilities they find get reported, patched, and publicly disclosed. Trezor publishes each one on its own vulnerability pages — including the ones that don’t flatter it, like the Donjon evaluation of this very device, and the 2026 laser-fault-injection finding against the Safe 7’s TROPIC01 chip. That is the cycle working: open code, adversarial review, public disclosure, improvement. It is worth noting the reviewers here were Ledger’s own lab — openness invites scrutiny from competitors too, which is a feature.
Trezor reinforces it with deterministic builds. Compile the published source in the published build environment and the resulting binary is bit-for-bit identical to the firmware Trezor distributes. That addresses the “trusting trust” problem — the chance that a compiler itself slips in malicious code. Trezor is not alone in offering it: Coldcard, BitBox and Keystone publish reproducible builds too, and any review claiming Trezor is unique here is selling you something. What separates Trezor from Ledger is not reproducibility as such — it is that Ledger’s most security-critical layer, the Secure Element firmware, cannot be reproduced or read at all.
What are the real limitations of the Safe 3?
Let’s be honest, because the version of this review that pretends it’s all upside isn’t worth reading.
The screen is small. At 128×64 on a 0.96-inch monochrome OLED, verifying long Ethereum contract addresses means patient scrolling. For anyone regularly handling complex DeFi transactions, the Coldcard’s larger display or the Nano X’s wider screen are meaningfully more comfortable. Two-button navigation is fine for Bitcoin and simple transfers; it gets fiddly fast for heavy on-chain work.
There’s no Bluetooth, and mobile support is partial rather than absent. Trezor now ships a mobile Suite app: on Android you can connect the Safe 3 by USB and use it properly, while on iOS you get portfolio tracking and receiving but not full functionality — only the Bluetooth-equipped Safe 7 is fully usable on iPhone. If you transact mostly from an iPhone, that’s genuine friction, and the experience is still built for a desk.
And physical incident resistance is improved, not absolute — which the March 2025 Donjon work put beyond argument for this specific model. The Safe 3 is not air-gapped like a Coldcard, its microcontroller is a known-glitchable STM32F429 derivative, and an incidenter with physical possession and lab equipment can still attempt fault injection. The Secure Element raises the bar for PIN and key extraction. It doesn’t erase the risk. Your passphrase, and buying from a source you trust, remain the real defences against physical theft and tampering.
One more thing an honest review shouldn’t skip, because it isn’t about the device at all. In January 2024 an incidenter gained access to Trezor’s third-party support ticketing portal and reached the contact details of up to 66,000 customers who had contacted support since December 2021 — names or nicknames and email addresses. No funds or devices were compromised, but 41 users were emailed directly and asked for their recovery seeds. The lesson generalises: your wallet’s cryptography can be flawless while the vendor’s customer-service vendor leaks the list of people worth impersonation scam. Nobody from Trezor will ever ask for your seed. Nobody.
Frequently asked questions
Is the Trezor Safe 3 safe if someone physically steals it?
If you set a BIP39 passphrase, yes — practically. A thief who extracts what is on the device reaches only your standard wallet, not the passphrase-protected one, because the passphrase is never stored there. Without a passphrase you’re relying on the Secure Element and PIN alone, and on the Safe 3 that is a real but bounded defence: Ledger’s Donjon lab showed in 2025 that the device’s microcontroller can be glitched by someone with physical access and the right equipment. Set the passphrase.
Do I need to be technical to use it?
No. Trezor Suite walks you through setup, and the day-to-day workflow is three buttons and a screen. The open-source advantage works for you whether or not you read code — the global research community audits it on your behalf. You only need technical confidence for advanced moves like compiling firmware to verify a deterministic build.
Trezor Safe 3 vs Ledger Nano X — which should I pick?
For verifiable trust at the lowest price, the Safe 3 at around $59 against the Nano X at around $149. For Bluetooth and a wider app ecosystem on mobile, the Nano X — but you accept closed Secure Element firmware and the trust model the Ledger Recover episode exposed. If auditability is your priority, the Safe 3’s open firmware and deterministic builds are the deciding factor. If physical-tamper resistance is your priority, be aware that neither device is untouched by published research, and step up to the Safe 5 or Safe 7 rather than assuming the Safe 3’s Secure Element settles it.
What happens if I forget my passphrase?
You lose access to that wallet permanently — there is no recovery, by design. The passphrase is never stored anywhere. Treat it with the same care as the seed itself: memorize it or store it securely and separately, and test access to the passphrase-protected wallet monthly so you catch a problem while you still can.
The authority verdict on the Trezor Safe 3
| Dimension | Score | Rationale | |—|—|—| | Security architecture | 80/100 | EAL6+ SE meaningfully hardens PIN and key storage over earlier models, but the 2025 Donjon research showed the microcontroller is still glitchable — the passphrase, not the chip, is the load-bearing defence | | Open-source trust | 92/100 | Fully auditable firmware, deterministic builds, published vulnerability disclosures — best-in-class transparency, with the Secure Element the honest exception | | Usability | 79/100 | Trezor Suite is polished; small screen and two buttons create real friction for complex transactions | | Value | 93/100 | Around $79 for an EAL6+ Secure Element with open-source firmware is the strongest price-to-security ratio available | | Sovereignty fit | 91/100 | BIP standards keep the wallet portable; Shamir Backup removes single points of failure; passphrase enables plausible deniability |
You started with a quiet 2am question — how do you know the thing guarding your money isn’t quietly betraying you. With the Safe 3, the answer stops being “because they said so.” It becomes “because the code is open, the builds are reproducible, and the world has checked” — including a rival’s security lab, which found something real and got it published rather than buried. That’s the difference between owning a security device and renting a promise. It is not a promise that no incident exists. Set the passphrase, buy from a source you trust, split your backup, and the small screen stops mattering. You’re not trusting a company with your money anymore. You’re verifying it yourself — which is the whole point of holding your own keys.
The Signal - free dispatch
One practical email that makes your digital life calmer. Checklists, tool cautions, plain-English decisions. No noise.
Free. No spam. Unsubscribe any time.
Join the Inner Circle
Weekly dispatches. No algorithms. No surveillance. Just sovereign intelligence.
Zero spam · Fully private · Sovereign by design.