Hardware review — Trezor

Trezor review: open firmware, properly certified silicon

Trezor is the answer to the objection people raise against every other hardware wallet: you can read the code. The Safe line pairs that openness with an EAL6+ certified secure element, and the Safe 7 adds a third protection layer that is designed to be audited.

  • EAL6+ Certified secure element across the Safe line
  • 100% Firmware published and reviewable
  • 3 Independent protection layers on the Safe 7
  • ≈NZ$330 Safe 5 landed, indicative

At a glance

A 8.5/10

The best balance of open-source auditability and a screen that non-technical people can actually read.

Best for: Auditable firmware with a modern touchscreen  ·  Maker: Trezor (SatoshiLabs)

Why open firmware is the whole argument

Every hardware wallet asks you to trust something. The interesting question is what. With most devices you are trusting a company's assertion that the code guarding your seed does what they say, backed by a certification lab's assessment of the chip underneath. With a Trezor you are trusting mathematics and public scrutiny, because the firmware is published and anyone with the skills can read the exact code path that touches your recovery phrase.

That distinction used to come at a real cost. Certified secure elements are typically supplied under non-disclosure terms that make publishing the firmware running on them difficult or impossible, which historically forced open-source wallet makers onto general-purpose microcontrollers with far weaker physical protection. Older Trezor models were the textbook example: fully auditable, and demonstrably vulnerable to researchers who could get the device into a laboratory.

The Safe line closed that gap. Every current Trezor pairs open firmware with an EAL6+ certified secure element, and the Safe 7 goes considerably further — the seed is protected by three independent layers: the auditable TROPIC01 chip, an Infineon Optiga element certified to EAL6+, and a separate STM32U5 microcontroller. That is not a marketing arrangement of words; it is a genuine architectural response to the exact criticism the company spent a decade absorbing.

Specifications

Models (Sept 2026) Safe 3 (US$79), Safe 5 (US$169), Safe 7 (US$249)
Secure element EAL6+ certified across the Safe line. Safe 7 adds the auditable TROPIC01 chip plus an Infineon Optiga EAL6+ element and an STM32U5 microcontroller
Source code Fully open — firmware and Trezor Suite are both published
Display Safe 3: mono OLED with two buttons. Safe 5: 1.54" colour touchscreen with haptics. Safe 7: 1.54" AMOLED
Build Safe 3 and 5: polycarbonate. Safe 7: machined aluminium
Connectivity Safe 3 and 5: USB-C. Safe 7: USB-C plus NFC and Bluetooth
Backup BIP39 recovery phrase, optional passphrase; Safe 5 supports Shamir backup, Safe 7 adds an integrated backup system
Physical PIN protection MAC&Destroy mechanism on the Safe 5 — the secure element physically destroys key material after failed attempts
Companion software Trezor Suite — Windows, macOS, Linux; web version available
NZ availability Direct from trezor.io; The Bitcoin Shop (Tauranga) lists Trezor — confirm current stock
Last verified September 2026

Safe 3, Safe 5 or Safe 7

The useful thing about Trezor's range is that the security floor does not move. All three current devices share the EAL6+ certified secure element and the same open firmware, so unlike some competitors you are not being asked to pay more for a better chip. You are paying for the screen and how you interact with it.

The Safe 3 at US$79 is a monochrome OLED with two physical buttons. It is entirely adequate and it is the cheapest way to own genuinely open cold storage. Its weakness is the one we care about most: verifying a long address on a small two-line display is tedious, and tedium is what makes people stop doing it.

The Safe 5 at US$169 is our pick of the range, and the reason is almost entirely the 1.54-inch colour touchscreen with haptic feedback. It sounds like a comfort feature. It is a security feature. When the screen is large enough to show an address legibly and the confirmation is a deliberate tap rather than a button press you have learned to do reflexively, the odds of catching a swapped destination go up substantially. The Safe 5 also carries a physical MAC&Destroy mechanism in the secure element, which destroys key material after repeated failed PIN attempts, and it supports Shamir backup for splitting a seed into shares properly.

The Safe 7 at US$249 is the flagship: a 1.54-inch AMOLED display, machined aluminium body, NFC and Bluetooth, an integrated backup system, and the three-layer TROPIC01 architecture. If you want the most auditable device money can buy and you will use it from a phone, this is it. At the price it competes with a Ledger Flex, and the choice between them is essentially the open-versus-closed argument with a NZ$490 price tag attached.

What TROPIC01 actually is

A secure element designed so that its behaviour can be independently verified, rather than accepted on the basis of a certificate and a non-disclosure agreement. On the Safe 7 it sits alongside a conventional EAL6+ Infineon element and a separate microcontroller, so an attacker has to defeat three different things with different properties. It is the most substantive answer anyone in this industry has given to the "certified but unreadable" criticism.

Trezor Suite: honest rather than glossy

Trezor Suite scores 8.6 on our interface axis — very good, half a point behind Ledger Live, and for reasons that are as much about philosophy as execution.

What it does well: firmware updates are clear and verifiable. Address display and confirmation are handled properly, with the device screen as the source of truth. Coin control is available for Bitcoin, which almost no first-party wallet software offers and which matters if you care about the traceability of your holdings. It can connect to your own Bitcoin node. And it is conspicuously free of the commercial surface that has accumulated in competing apps — there are fewer panels trying to sell you a swap.

Where it falls short is mobile. Trezor Suite is a desktop application first, and the Safe 3 and Safe 5 are USB-C devices, so using a Trezor from a phone means an adapter and a third-party wallet app. The Safe 7's Bluetooth and NFC fix this, but only if you buy the most expensive model. If your realistic usage pattern is checking and sending from a phone, that is a legitimate reason to choose differently — and it is one of the few places where we would say Ledger has a clear, practical advantage rather than a marketing one.

Data charts on a screen, representing verifiable open-source security claims
The difference between open and closed firmware is not a difference in security theatre. It is whether an outside party can check the claim at all.

The balance sheet

What we like, and what we don't

Strengths

What it does well

  • Fully open-source firmware — the security claims are verifiable rather than asserted
  • EAL6+ certified secure element across the whole Safe range, including the US$79 Safe 3
  • The Safe 5 colour touchscreen makes address verification something users will actually do carefully
  • Safe 7 layers the auditable TROPIC01 chip with a conventional EAL6+ element and a separate MCU — three independent barriers to the seed
  • Trezor Suite is a clean, honest desktop application with far less commercial clutter than its competitors
  • Official store accepts Monero, which is the only meaningful privacy option at the point of purchase
  • Shamir backup on the Safe 5 splits a seed into shares without the weaknesses of naive manual splitting
Weaknesses

What we hold against it

  • New Zealand stock is unreliable — sources disagree on whether any local reseller carries it, so most buyers import and wait one to three weeks
  • Mobile experience trails Ledger badly on the Safe 3 and Safe 5, which are USB-C only
  • No first-party native staking; delegation means using third-party interfaces
  • Trezor Suite is desktop-first, with no full-featured first-party mobile app
  • Older pre-Safe models had no secure element and were demonstrably vulnerable to physical extraction — relevant if you are buying second-hand, which you should not be
  • Safe 7 pricing puts it level with a Ledger Flex while the practical advantage is mostly philosophical

Getting one in New Zealand — the honest picture

This is the weakest part of the Trezor proposition here, and it is worth being direct rather than optimistic about it.

Cryptocurrency NZ, which maintains a hardware wallet directory for this market, states plainly that no New Zealand reseller currently stocks Trezor and recommends buying direct from trezor.io, quoting roughly NZ$219 for a Safe 5 and NZ$410 to NZ$450 for a Safe 7. The Bitcoin Shop, dispatching from Tauranga, lists Trezor among the brands it carries alongside Blockstream Jade, Coldcard Q and TinySeed. Those two claims are in tension, which most likely reflects intermittent stock rather than an error by either party. The practical advice is to check The Bitcoin Shop's current inventory first, because a domestic dispatch saves you two to three weeks, and fall back to a direct import if the model you want is not there.

Importing is straightforward. Trezor is large enough to be GST-registered for New Zealand sales, so 15% is collected at checkout on goods valued at NZ$1,000 or less and you will not be chased at the border. From 1 April 2026, Customs also applies a Low-Value Goods levy of NZ$2.21 for air freight plus GST per consignment. Expect one to three weeks depending on carrier. Our GST and customs guide works through the totals.

One genuine advantage of buying direct in this case: Trezor's official store accepts Monero. If you would rather your purchase not create a linked record of your name, address and interest in cryptocurrency in a payment processor's database, that option exists and no other major manufacturer offers it. Bear in mind the parcel still goes somewhere, so a collection point or parcel locker does more for your privacy than the payment method does.

The physical attack question, and why the Safe line exists

Trezor's history here is instructive and the company deserves credit for how it handled it.

The original Trezor One and Model T had no secure element. Their seeds were held in a general-purpose microcontroller, and security researchers demonstrated that with physical possession of the device and laboratory equipment, key material could be extracted. Trezor did not dispute this — the threat model was explicit from the start, and the trade was open firmware in exchange for weaker physical protection. For a remote-attack threat model it was a perfectly reasonable position. For anyone worried about a stolen device, it was not.

The Safe line is the answer. An EAL6+ certified secure element now holds the seed, the Safe 5 adds a physical MAC&Destroy mechanism that destroys key material after repeated failed PIN attempts, and the Safe 7 layers three independent protections. The company closed its own most-cited weakness without abandoning the openness that made it worth choosing.

Two practical consequences. First: never buy a second-hand Trezor, and be particularly wary of older Model One and Model T units appearing cheaply on marketplaces — the physical extraction concern applies to exactly those devices. Second: if you hold more than about NZ$20,000, enable a passphrase. It creates a separate hidden wallet from the same seed, so anyone who obtains your written words gets an empty or decoy wallet. It also destroys your funds permanently if you forget it, which is why we cover it carefully in the backup guide.

From our testing notes

Something we did not expect: the Safe 5's touchscreen changed tester behaviour in a measurable way. On two-button devices, people learned within a few transactions that confirmation meant "press both buttons" and stopped reading the screen — it became a reflex. On the touchscreen, where confirmation is a deliberate tap on a specific area, they kept looking. That is a small interface detail with a direct security consequence, and it is exactly the kind of thing a spec-sheet comparison cannot capture.

Trezor Safe 5 FAQ

Trezor Safe 5 — questions New Zealanders ask

How much does a Trezor cost in New Zealand?

Trezor's own published RRP is US$79 for the Safe 3, US$169 for the Safe 5 and US$249 for the Safe 7. Landed in New Zealand that works out to roughly NZ$160, NZ$330 and NZ$490 including GST and shipping — indicative estimates, not quotes, and the exchange rate moves. Local stock is inconsistent: Cryptocurrency NZ has stated that no New Zealand reseller currently carries Trezor and recommends buying direct, while The Bitcoin Shop in Tauranga lists Trezor among its stocked brands. Check both before assuming either.

Which Trezor should I buy — Safe 3, Safe 5 or Safe 7?

All three share the same EAL6+ certified secure element and the same fully open firmware, so this is a screen and input decision rather than a security one. The Safe 3 at US$79 gives you a monochrome OLED and two buttons. The Safe 5 at US$169 adds a 1.54-inch colour touchscreen with haptic feedback, which makes address verification something people will actually do properly — that is why we grade it as the pick. The Safe 7 at US$249 adds an AMOLED display, a machined aluminium body, NFC and Bluetooth, and the auditable TROPIC01 chip as a third protection layer.

Is Trezor fully open source?

Yes, and this is its defining advantage. Trezor publishes the firmware for its devices and the source for Trezor Suite, which means independent researchers can read the code that handles your seed rather than taking a company's word for it. The Safe 7 pushes further with the TROPIC01 secure element, which is designed to be auditable — historically the sticking point, because certified secure elements usually come with non-disclosure obligations that made full openness impossible. That is a genuinely meaningful engineering achievement, not marketing.

Can a Trezor be hacked?

Not remotely, and that is the part that matters. Older Trezor models without a secure element were shown to be vulnerable to physical key extraction by researchers with laboratory access to the device — which is precisely why the Safe line added an EAL6+ certified element. What no version protects against is you entering your recovery phrase into a phishing site, or approving a malicious transaction; those are the mechanisms behind almost all real losses and no hardware fixes them. A PIN plus an optional passphrase covers the realistic physical-theft scenario.

Does Trezor work with a phone?

Partially, and less smoothly than Ledger. The Safe 7 adds Bluetooth and NFC, which improves mobile use considerably. The Safe 3 and Safe 5 are USB-C devices, so phone use means an adapter and a third-party app rather than a first-party mobile experience — Trezor Suite is primarily a desktop application. If your wallet needs to live in your pocket and be used from a phone regularly, that is a genuine argument for a Ledger with Bluetooth or for the Safe 7.

Next in this cluster

Keep reading