Verified Review
Published Updated

The Safe 3 is Trezor's entry-level cold wallet, a wired non-custodial device covering mainstream coins and the major EVM networks. Its case rests on a pairing few rivals offer anywhere near this price, firmware anyone can audit next to a certified secure element guarding the seed. The complication is where signing actually runs, on a general-purpose chip outside that secure element's protection. How much that architecture concedes, and how cheaply a passphrase buys the ground back, is what the score comes down to.

Andrej Gjorgievski
Reviewed by
George Ong
Fact-checked by

Trezor Safe 3 Overview

Product Name Trezor Safe 3
Release Date 2023
Wallet Type Hardware wallet
Custodial Status Non-custodial
Built-in Swaps Yes
Open-source Partially open-source
Fiat On-ramp Yes

Additional details

Supported Blockchains Bitcoin, Ethereum, BNB Smart Chain, Avalanche, Arbitrum, Base, Polygon, Optimism, Solana
Token Standards ERC-20, BEP-20, SPL
Platforms Android, Desktop (Windows), Desktop (macOS), Desktop (Linux)
Hardware Wallet Support No
Staking Support Limited
Hardware Connection Methods USB

Trezor Safe 3 Screenshots

Trezor Safe 3 Pros and Cons

Pros

  • Open firmware anyone can audit
  • $59 for a certified EAL6+ chip
  • Passphrase fully defeats seed extraction
  • SLIP39 multi-share backup built in
  • No Bluetooth, wired-only attack surface

Cons

  • Signing runs outside the secure element
  • Disclosed 2025 physical extraction path
  • iOS app cannot send transactions
  • Small screen, two-button navigation
  • Closed Infineon SE limits full audit

Who Trezor Safe 3 Is Best For — And Who Should Skip It

Trezor Safe 3 product page showing the hardware wallet, key features, and price
Trezor Safe 3 product page showing the hardware wallet, key features, and price

The Safe 3 fits self-custody users who want a certified-chip cold wallet at the lowest credible price and are willing to run a passphrase.

  • Get it if you hold mainstream coins, use a desktop or Android phone, and want firmware you or anyone else can inspect.
  • Get it if you're moving off an exchange for the first time and want the cheapest serious device from a vendor with a 2014-to-now record.
  • Skip it if your phone is an iPhone and you need to send on mobile.
  • Skip it if you hold amounts you won't protect with a passphrase. In that case pick a device that signs inside the secure element.
  • Skip it if you want a touchscreen or air-gapped QR signing, neither of which exists at this price from Trezor.

What Is Trezor Safe 3 and How Does It Work?

Trezor Safe 3 security features section highlighting open-source design, PIN and passphrase protection, and backup
Trezor Safe 3 security features section highlighting open-source design, PIN and passphrase protection, and backup

The Safe 3 is the entry model in Trezor's current Safe line, sitting under the touchscreen Safe 5 and the flagship Safe 7. It launched in 2023 at $79 and now sells for $59, which makes it the cheapest current-generation hardware wallet with a certified secure element from a first-tier vendor.

SatoshiLabs, the Prague-based company behind it, built the first hardware wallet in 2014 and co-authored the BIP39 seed-phrase standard that nearly every wallet on the market now uses. That track record is a genuine trust signal. The company has never lost customer funds from its own infrastructure, though its brand has been a repeated phishing target, covered below.

Security and Custody

The Safe 3 is fully non-custodial. Keys are generated on the device, never leave it, and every transaction requires physical confirmation on the two hardware buttons. There is no Bluetooth and no battery. The only way in is the USB-C port.

The chip layout is where precision is required. The Safe 3 pairs an Infineon OPTIGA Trust M (V3) secure element, certified CC EAL6+, with an STM32F4 general-purpose microcontroller. The secure element protects the PIN and the seed at rest. Cryptographic operations, including transaction signing, execute on the STM32F4. That split is the source of the device's one disclosed flaw.

The March 2025 Donjon Disclosure

Ledger's in-house security team showed that an attacker who physically obtains a Safe 3, desolders the microcontroller, and applies voltage glitching with specialist equipment can extract the seed, because the signing path runs on the STM32F4 outside the secure element's protection. Trezor confirmed the finding and shipped a firmware mitigation, but because signing runs on the microcontroller the exposure is architectural, not something firmware fully removes on this hardware. Three things keep it from sinking the device. First, it requires possession of the unit, so remote funds are never at risk. Second, it takes lab-grade gear and skill, not a screwdriver. Third, an optional passphrase defeats it completely, since the extracted seed alone opens nothing. The practical consequences are two: set a passphrase, and buy directly from Trezor so a tampered unit never reaches you.

Earlier Trezor marketing, and plenty of reviews echoing it, framed the Safe 3 as a device that cuts no corners on security. That framing does not survive the disclosure. The accurate statement is that the Safe 3 has a well-built at-rest security model and a signing path with a known, physically-gated, passphrase-mitigated extraction attack.

Open-source

Trezor's firmware and hardware designs are published and independently auditable, which remains the company's core differentiator against Ledger's closed operating system. The OPTIGA secure element, however, is a proprietary Infineon component. The correct label is partially open: open firmware on the MCU, closed silicon in the SE. It is worth noticing that the open chip is the one where the flaw was found and the closed one is where it wasn't, which cuts against the reflex that open automatically means safer at the silicon level.

Company Incident History

Trezor has never suffered an on-chain loss of user funds, but its support channels have been breached twice. In 2022, attackers used a compromised MailChimp account to send convincing phishing emails to Trezor's newsletter list. In January 2024, a support-portal breach exposed the names and email addresses of roughly 66,000 users. Neither incident touched keys or devices. Both feed the same realistic threat for Trezor owners: emails impersonating Trezor support asking for your seed. The device will never need your seed typed anywhere but its own screen flow, and no legitimate support message will ask for it.

Versus Ledger

Trezor wins on transparency, and Ledger's own record includes the 2020 e-commerce database breach and the 2023 Recover backlash. But Ledger's architecture runs cryptographic operations inside its certified secure element, so on the specific axis the Donjon attack exposed, Ledger's design is the more resistant of the two. Buyers should weigh open, auditable firmware against in-SE signing and decide which risk model fits them. Neither vendor gets a clean sweep.

Supported Chains and Assets

Trezor Safe 3 in Trezor Suite app section showing portfolio management and supported coins and tokens
Trezor Safe 3 in Trezor Suite app section showing portfolio management and supported coins and tokens

Native support covers Bitcoin, Ethereum, Solana, Cardano, XRP, Litecoin, Dogecoin, Bitcoin Cash, Zcash, and Ethereum Classic, plus EVM networks including Polygon, BNB Smart Chain, Arbitrum, Base, and Optimism. Token standards span ERC-20, BEP-20, and SPL. Trezor markets “1000s of coins and tokens,” and the named-chain list above is the honest version of that claim. For a multi-chain holder with mainstream assets, coverage is complete. Users deep in newer ecosystems should check the Trezor supported-assets list before buying.

Usability and Recovery

Setup runs through Trezor Suite, which sets the bar for polish in this category on desktop. Windows, macOS, and Linux get the full experience, Android gets full functionality over USB-C, and iOS is the weak spot: the iPhone app can track balances, buy, and receive, but cannot send. A web version runs in Chromium browsers only.

The hardware itself is deliberately minimal. A small monochrome screen and two physical buttons handle everything, including PIN entry and address verification. It works, and address checking on-device is the point of a hardware wallet, but scrolling a long address two characters at a time is the price of the $59 tag.

Recovery options run deeper than the price suggests. Standard 12, 20, or 24-word BIP39 backups are joined by SLIP39 multi-share backup, which splits recovery across multiple shares so no single piece of paper is a single point of failure. The optional passphrase adds a hidden-wallet layer on top of the seed, and after the Donjon disclosure it should be treated as part of the standard setup, not an advanced extra. Sixteen wrong PIN attempts wipe the device.

Features

Trezor Suite includes partner-powered buy and sell, staking for ETH, ADA, and SOL, and swaps through integrated partners plus DEX access via WalletConnect. Staking is delegated through the Suite interface while keys stay on the device, so self-custody is preserved. Buying and selling through fiat partners can require KYC depending on the provider and amount. DEX swaps require none. None of these features are unique to Trezor, but none of them compromise the custody model, which is the standard that counts.

Cost

Trezor Safe 3 hardware wallet security diagram showing the secure element and physical shield
Trezor Safe 3 hardware wallet security diagram showing the secure element and physical shield

The device is $59, down from its $79 launch price, and that is the entire cost of ownership. There is no subscription and no charge for Trezor Suite. Swap and on-ramp partners take their own fees and spreads per transaction, disclosed at quote time, and they are the same class of third-party cost every hardware wallet passes through. At $59, the Safe 3 undercuts the Ledger Nano S Plus ($79) while matching its EAL6+ secure-element certification, and nothing else from a first-tier vendor touches its price.

Trezor Safe 3

Final Verdict

The value case is real: $59 buys a non-custodial device with an EAL6+ secure element, open firmware, SLIP39 backup, and staking that never surrenders keys, from the company that invented the category. The deductions are equally real: a publicly disclosed physical extraction path on the signing MCU that firmware mitigations raise the bar against without fully closing, a partially rather than fully open stack, and an iOS experience that stops short of sending. The passphrase converts the headline flaw from a risk into a checkbox, which is why the score holds in the mid-7s instead of falling further. Buy it direct, set the passphrase during setup, and the Safe 3 is the best sub-$100 cold wallet decision available in 2026.

Trezor Safe 3
Overall Score
7.5 / 10
Very Good

Made by the original hardware-wallet maker, Vendor co-authored the BIP39 standard, Seed restores on any BIP39 wallet

Why it stands out

  • Open firmware anyone can audit
  • $59 for a certified EAL6+ chip
  • Passphrase fully defeats seed extraction
  • SLIP39 multi-share backup built in
  • No Bluetooth, wired-only attack surface

What to consider

  • Signing runs outside the secure element
  • Disclosed 2025 physical extraction path
  • iOS app cannot send transactions
  • Small screen, two-button navigation
  • Closed Infineon SE limits full audit
Affiliate Disclosure

Disclaimer: CryptoSlate may receive a commission when you click links on our site and make a purchase or complete an action with a third party. This does not influence our editorial independence, reviews, or ratings, and we always aim to provide accurate, transparent information to our readers.

FAQ

Is the Trezor Safe 3 safe?

Yes, with one setup step. A March 2025 disclosure by Ledger’s Donjon team showed the seed can be extracted from a physically captured device using voltage glitching on its STM32F4 microcontroller. The attack needs possession, desoldering, and lab equipment, and an optional passphrase defeats it entirely. Remote attacks against funds have never been demonstrated.

Has Trezor been hacked?

No Trezor infrastructure has ever lost user funds. The company’s support channels have been breached: a 2022 phishing campaign sent through a compromised MailChimp account, and a January 2024 support-portal breach that exposed around 66,000 names and email addresses. The realistic threat to Trezor owners is phishing email impersonating support, not the device.

Is the Trezor Safe 3 open-source?

Partially. The firmware and hardware design are open and auditable, which is Trezor’s main differentiator against Ledger. The OPTIGA Trust M secure element is a closed, proprietary Infineon chip.

Trezor Safe 3 vs Ledger Nano S Plus, which is safer?

They fail differently. Trezor offers open firmware and a cleaner marketing record, while Ledger signs transactions inside its certified secure element, which makes it more resistant to the specific physical-extraction attack disclosed against the Safe 3. A Safe 3 with a passphrase closes most of that gap at $20 less.

Does the Trezor Safe 3 work with iPhone?

Only partially. The iOS app tracks balances, buys, and receives. Sending requires desktop (Windows, macOS, Linux) or Android over USB-C.

Does the Trezor Safe 3 support staking?

Yes. ETH, ADA, and SOL staking run through Trezor Suite with keys remaining on the device.