
An overview of crypto hardware wallets, testing findings, security considerations, and a note on historical firmware vulnerabilities.
A comprehensive guide comparing crypto hardware wallets such as Ledger, Trezor, BitBox, SafePal, and Coinkite, detailing security features, connectivity options, and historical firmware vulnerabilities.
AI-generated summary
Hardware wallets protect cryptocurrency private keys by keeping transaction signing separate from internet-connected devices.
A hardware wallet is a device designed to protect the private keys used to approve cryptocurrency transactions. In plain terms, your crypto remains on the blockchain, while a hardware wallet holds the keys that let you access it.
The main differences between wallets are which coins they support, how they connect to your phone or computer, and how you check and approve a transaction. This guide explains those differences and what they mean when choosing a wallet.
How we assessed these wallets
Cointelegraph tested Trezor Safe 7, Ledger Stax, Flex, Nano Gen5, Nano X, Nano S Plus and Coinkite’s Opendime. Testing used smartphones and computers running both Linux and macOS operating systems, with both third-party and official software. The Opendime was used as cold storage; the others were used to test both simple transactions and decentralized application interactions. All the other models covered in the article were reviewed based on publicly available information alone.
The review units were supplied to the author of the article free of charge by Ledger, Trezor and Coinkite at our request to be able to review the devices. No compensation or promise of positive coverage was made to any of the companies.
What hardware wallets protect
A hardware wallet keeps transaction signing separate from your phone or computer. This lowers the risk that malware on either device can steal your keys, keeping cybercriminals from accessing your digital assets.
Most hardware wallets also feature a screen, allowing you to verify transaction details on the wallet itself. This means that if the smartphone or computer the wallet is connected to displays incorrect information in order to trick you into signing a malicious transaction, you still have an opportunity to catch the issue before signing the transaction.
However, the protection has limits. The wallet must show enough information for you to understand what you are approving. You can still lose funds by approving a scam transaction, exposing your recovery backup or using vulnerable wallet software.
Your recovery backup needs protection, too. Someone who obtains it may be able to restore your wallet and access the funds.
Hardware wallets for multiple cryptocurrencies
If you hold more than one cryptocurrency, start by checking whether a wallet supports your coins and the networks you use. Also check which features work through the manufacturer’s app and which require another app.
The table below covers the multi-asset versions, and all specifications come from the manufacturer’s documentation.
Ledger’s Stax, Flex, Nano Gen5 and Nano X connect through Bluetooth or USB.
The Stax has a 3.7-inch E Ink touchscreen that curves around the front and one side of the device. The Flex and Nano Gen5 have flat, rectangular 2.8-inch E Ink touchscreens.
The Nano X has a smaller, 1.1-inch OLED screen and two physical buttons. Its folding metal cover gives it a shape similar to a USB flash drive.
During Cointelegraph’s testing of each Ledger device, we found that the Stax — the most expensive option in the lineup — appears to have lag issues, which were confirmed by the manufacturer to be a consequence of the wraparound screen used for the device.
This was perceived as input lag that resulted in repeatedly entering the wrong PIN and having to input the numbers much more slowly than with other devices. For this reason, we advise against this particular device, having found the cheaper touchscreen models to provide a much better user experience.
The Trezor Safe 7 is a color touchscreen hardware wallet with fully open-source software, whereas Ledger uses certified secure element chips that legally prevent Ledger from open-sourcing a portion of its software.
Their practical features are more or less the same, with wide third-party software support, support for thousands of digital assets and dedicated management software for both computer and mobile devices.
The BitBox02 Nova Multicoin is a Bluetooth-capable general-purpose hardware wallet with capacitive controls over an OLED display, compatible with all major platforms. It also allows users to back up private keys onto a microSD card — the first device we discuss to do so. That card needs to be stored securely and separately from the device.
The SafePal X1 stands apart from the others we covered so far with its full keypad, simple monochrome interface and low-cost Bluetooth connectivity. This hardware wallet offers wireless connectivity at a particularly low price while still supporting over 200 blockchains. Usually priced around $70, through Changelly’s wallet marketplace, it’s currently available for $29.99, about 57% below its usual price.
Next come the wired general-purpose hardware wallets. In this category sit Ledger’s Nano S Plus, Trezor’s Safe 5 Universal and Safe 3 Universal, as well as the BitBox02 Multicoin, which connect to supported computers and devices through USB. The Nano S Plus is almost completely identical to the Nano X, but only allows for wired communication.
Trezor’s Safe 5 Universal and Safe 3 Universal are wired hardware wallets, with the former having a colorful touchscreen while the latter has a monochromatic display and two buttons. Both have similar capabilities, but input and output are much less cumbersome on the Safe 5 Universal.
Lastly, the BitBox02 Multicoin is the Swiss company’s wired monochrome touchscreen hardware wallet option. Much like the BitBox02 Nova Multicoin, this model also allows backing up keys on a microSD card.
Wallets that use QR codes
The SafePal S1, S1 Pro and Ngrave Zero exchange transaction data through QR codes shown on their screens and scanned by cameras. This lets users sign transactions without a USB or Bluetooth data connection. These devices still use USB for charging and firmware updates. Users also need to check what they are approving — QR codes alone do not make a transaction safe.
The SafePal S1 and S1 Pro are essentially the same device: a QR code-based hardware wallet with the same color screen, but the Pro is made out of aluminum and glass while the standard version is plastic. The Pro version also has 25% extra battery, but that is the extent of the practical differences between the devices.
The Ngrave Zero is a smartphone-like air-gapped hardware wallet with a color touchscreen and an interface reminiscent of mobile apps. This device also features a fingerprint sensor that is used both for authentication and as a randomness source during key generation alongside its random number generator and ambient light data.
NFC-based wallet cards
Lastly, the Tangem wallet cards are near-field communication (NFC)-based hardware wallets with no dedicated screen, meaning that the wallet will not be able to warn you if your device was compromised and is tricking you into signing a transaction that is different from what is being shown on screen. Users tap the card against the phone to interact with the wallet.
Tangem offers setup with or without a recovery phrase. A wallet created without a recovery phrase generates its key inside the card. When creating a wallet with a recovery phrase, the phone app generates the phrase and transfers the resulting keys to the card.
Bitcoin-only hardware wallets
If you only use Bitcoin, Trezor and BitBox offer Bitcoin-only versions of several wallets covered above. These versions leave out support for other cryptocurrencies. Buyers still need to consider how they will check transactions, protect backups and keep the device’s software updated.
Coinkite’s Coldcard Mk5 is a hardware wallet with a numerical keypad, while the Coldcard Q adds a larger screen, a full keyboard and a camera for scanning QR codes. They work with compatible wallet software, such as Sparrow, to prepare transactions.
In July 2026, Coinkite warned that affected Coldcard firmware could generate wallet keys that were easier for attackers to guess. The issue affected multiple models and software versions.
In an Aug. 24 update, Galaxy Research’s Alex Thorn attributed the theft of about 1,789 BTC from 8,865 addresses to the flaw. The Bitcoin was worth about $114.7 million at the time of the thefts.
Coinkite instructed affected users to install corrected firmware, create a new wallet and transfer their Bitcoin. Updating the firmware does not repair keys already created with the flaw. Users should check the company’s security advisory for affected versions, exceptions and migration instructions.
Coinkite’s Opendime Bitcoin credit chips and button-based hardware wallets Coldcard and Coldcard Q only support Bitcoin. The Opendime brings the cyberpunk concept of credit chips to life by allowing Bitcoin to be stored on it until the seal is broken — much like breaking open a digital piggy bank — to reveal the private key that lets users spend the assets it holds.
Choosing a wallet for your needs
Start with the coins you hold and the phone or computer you plan to use. Then consider how you want to check transactions and recover access if the device is lost. Once you have a shortlist, the Changelly hardware wallet marketplace lets you compare cold wallets side by side and buy them at discounts not offered in public promotions elsewhere.
A screenless NFC wallet can, for instance, be a good cheap option for a multisignature key alongside other keys with stronger checks in place, and a Bitcoin-only device will reduce the attack surface by removing support for coins some users won’t use while being a bad fit for others.
Also, a higher price may buy a better screen, premium materials or added convenience, but does not automatically mean stronger protection. A very important part of owning a hardware wallet is learning to protect your backups, check transaction details and stay informed about security updates to ensure continued safety — remembering that hardware wallets are tools for reducing risk that do not guarantee against loss.

SlowMist investigation reveals attackers linked to Bitget's $388 million theft exploited a zero-day vulnerability in a third-party security product, using custom withdrawal tools and forged risk-control parameters to drain hot wallets.

US President Donald Trump and tech executives from Google, Anthropic, Meta, OpenAI, Nvidia, and xAI signed a voluntary accord to ensure AI models behave as intended, emphasizing internal controls, external audits, and board oversight amid concerns over frontier AI safety and US-China competition.

Aztec Labs has relaunched zk.money, a self-custodial Ethereum layer-2 wallet enabling private stablecoin transfers via zero-knowledge proofs, three years after its initial shutdown. The wallet allows users to send USDC, USDT, or DAI without revealing transaction details, though deposits from Ethereum remain public and are subject to $2,500 per-transaction and $50,000 daily deposit limits. The relaunch coincides with growing Ethereum community interest in privacy enhancements, including fee-paying privacy pools for the upcoming Hegotá upgrade.

A public PS5 jailbreak named Relapse works on firmware versions 7.00 through 13.60 via a simple DNS change and User Guide exploit, enabling homebrew and game backups, while Sony faces a class-action lawsuit alleging misleading 'Buy Now' buttons that imply ownership of digital games, which Sony denies by citing license terms stating software is licensed, not sold.

At DevDay 2026 in San Francisco, OpenAI unveiled over 20 new products including 'Dots' — always-on AI agents with dedicated cloud computers — GPT-6.1 Sol, a cost-efficient model, ChatGPT Space for human-AI document collaboration, and tools like Ultrafast speed tiers, Decisions API, and Private Intelligence for secure enterprise use, following the cancellation of GPT-6.1 Astra due to safety concerns.

The Zano blockchain team is planning a recovery process for users affected by an emergency chain rollback that erased a month of transactions. The team intends to use developer and contributor funds to cover losses, though specific claim rules remain pending.