Trezor Safe 5 Overview
Additional details
Trezor Safe 5 Screenshots

Trezor Safe 5 Pros and Cons
Pros
- Newer STM32U5 chip resists the Safe 3 attack
- 1.54-inch color touchscreen with haptic feedback
- EAL6+ secure element guards PIN and secrets
- 20-word SLIP-39 default plus Shamir multi-share
- Open, auditable firmware and Suite software
Cons
- $129, a step up in price from the $59 Safe 3
- Signing runs on the MCU, not the secure element
- No Bluetooth, battery, or QR air-gap option
- iOS app is view-only, no transaction signing
- HBAR, SUI, and some chains need other wallets
Who Trezor Safe 5 Is Best For — and Who Should Skip It
The Safe 5 fits a self-custody user on desktop or Android who signs often, wants every sensitive input on the device screen, and will set a passphrase.
- Get it if you found the Safe 3's two-button workflow tedious and sign transactions regularly enough to feel the difference.
- Get it if you want SLIP-39 and Shamir multi-share recovery with the most usable input method Trezor makes.
- Get it if you want to avoid the voltage-glitch exposure the cheaper Safe 3 carries — the Safe 5's newer chip resists it.
- Skip it if you are price-first and will set a passphrase on a Safe 3, which closes most of the gap for $59.
- Skip it if you are iPhone-only, since iOS cannot sign.
What Is Trezor Safe 5 and How Does It Work?

The Trezor Safe 5 is a wired USB-C cold wallet that sits in the middle of Trezor's current three-device line, above the button-driven Safe 3 and below the wireless Safe 7. Its pitch is tactile: a 1.54-inch color touchscreen behind Gorilla Glass 3, haptic feedback Trezor brands as “Trezor Touch,” and every PIN digit, passphrase character, and address confirmation handled on the device itself.
SatoshiLabs, the Prague company behind it, has been building open-firmware hardware wallets longer than almost anyone in the category and has no custody-loss event in its history — it never touches user keys, so there is nothing for the company to lose or freeze. That track record, and the fact that the firmware is public and auditable, is a real trust signal for a device that will hold life-changing sums.
Security and Custody
The Safe 5 is fully non-custodial. Keys are generated on the device, never leave it, and the backup uses the SLIP-39 standard, so recovery does not depend on Trezor existing — any SLIP-39-compatible wallet can restore the seed.
The security architecture has two parts. An EAL6+ certified secure element stores the PIN and secrets, and the device wipes itself after 16 wrong PIN entries. The cryptographic operations — the signing path — run on the microcontroller outside the secure element, which on the Safe 5 is a newer STM32U5, a generation ahead of the chip in the Safe 3.

That distinction is why the March 12, 2025 Ledger Donjon disclosure does not land on the Safe 5 the way it lands on the Safe 3. Donjon showed that the Safe 3's microcontroller can be voltage-glitched by an attacker with physical possession to read its flash and reflash malicious firmware. Trezor's own vulnerability page states plainly that “Trezor Safe 5 is not affected because it uses a more recent microcontroller designed to be more resilient to similar attacks” — the STM32U5. So the Safe 5 shares the architectural shape of the Safe 3, signing outside the secure element, but not the specific weakness Donjon demonstrated.
Keep that in proportion. The demonstrated attack needs physical possession and specialist equipment, and funds are never at remote risk. A passphrase — entered on the touchscreen and never stored on the device — defeats seed-extraction scenarios outright on any hardware wallet, because the seed alone cannot open a passphrased wallet. The takeaway for the Safe 5 is favorable: it keeps the open, auditable stack and the touchscreen while sidestepping the specific flaw that constrains its cheaper sibling.
On transparency, the status is partial and worth stating precisely: the device firmware and the Trezor Suite software are open and auditable, while the secure element itself is closed silicon, as certified SEs are across the industry. That is a better disclosure position than most rivals, and it is exactly how the Donjon finding became public knowledge instead of a private lab note.
Supported Chains and Assets

Native coverage runs through Bitcoin, Ethereum and its major L2s (Arbitrum, Base, Optimism, Polygon), Solana, BNB Chain, and Avalanche, with token support across the ERC-20, BEP-20, and SPL standards — thousands of assets in practice through Trezor Suite.
The gaps are specific: chains such as Hedera (HBAR) and Sui are not supported, and holding an unsupported asset means pairing the device with a third-party wallet or not using the Trezor for that position at all. Check your exact portfolio against Trezor's supported-assets list before buying, because the device is excellent for the majors and simply absent for some newer ecosystems.
Usability and Recovery

The touchscreen is the reason this device exists. PIN entry, passphrase entry, and address verification all happen on the 240×240 color display with haptic confirmation on each touch, which removes the button-scrolling workflow of the Safe 3 and keeps every sensitive input off the connected computer. For someone signing transactions weekly, the difference is the product.
Recovery defaults to a 20-word SLIP-39 backup, with classic 12/24-word seeds supported for compatibility and Advanced Multi-share available for users who want a Shamir scheme — splitting the backup into multiple shares so no single piece of paper is a total-loss point. The passphrase adds a second factor that exists only in your head.
Platform support is uneven. Trezor Suite is full-featured on desktop (Windows, macOS, Linux) and on Android over USB-C. On iPhone the app is view-only: you can watch balances but not sign, so iOS-first users should treat the Safe 5 as a desktop-companion device or look elsewhere.
Features
Trezor Suite handles the day-to-day: partner-powered fiat buy and sell, staking for ETH and SOL, and swaps through integrated partners plus dApp access over WalletConnect. Staking and swapping keep keys on the device throughout, which is the correct model for a cold wallet.
Connectivity is deliberately minimal — USB-C wired only, a microSD slot for encrypted storage extras, and no Bluetooth, no battery, and no QR-based air-gap mode. That reads as a limitation next to air-gapped rivals, and it is one, but a wired-only device also carries no wireless attack surface. Users who want wireless convenience are the Safe 7's audience.
Cost

The list price is $129 in all three finishes. Trezor Suite is free, there is no subscription, and the device price is the entire cost of ownership.
The value question is the family ladder. The $59 Safe 3 shares the EAL6+ secure element and the Suite features, but not the microcontroller: the Safe 5 moves to the newer STM32U5 that Trezor says resists the Donjon voltage-glitch the Safe 3 is exposed to. So the $70 premium buys the touchscreen, the haptics, and a harder signing chip, not the screen alone. The $249 Safe 7 goes further still, adding the auditable TROPIC01 layer on top of the same STM32U5.
Final Verdict
With 7.5/10 Trezor Safe 5 sits below the Safe 7 (7.8) and, in our current scoring, level with the Safe 3 — a tie the Donjon finding actually calls into question, because the Safe 5's newer STM32U5 microcontroller resists the voltage-glitch attack the Safe 3 is exposed to. On the security pillar the Safe 5 is the better protected of the two, and that gap is under review for the final score. Its touchscreen is a genuine usability gain, set against a real price premium. The Safe 5 earns the "recommendable" band cleanly. Non-custodial done properly, a modern recovery stack, honest partial-open-source status, and a maker with a clean custody record are all in the plus column. The old reservation — that it inherited the Safe 3's glitchable chip — turns out not to apply: Trezor's newer microcontroller resists that attack. Signing still runs outside the secure element, so a passphrase remains the right habit for any hardware wallet, but the Safe 5 is a safer vault than an earlier read of this device suggested.
Made by the original hardware-wallet maker, Restores on any SLIP-39-compatible wallet, Vendor co-authored the BIP39 standard
Why it stands out
- Newer STM32U5 chip resists the Safe 3 attack
- 1.54-inch color touchscreen with haptic feedback
- EAL6+ secure element guards PIN and secrets
- 20-word SLIP-39 default plus Shamir multi-share
- Open, auditable firmware and Suite software
What to consider
- $129, a step up in price from the $59 Safe 3
- Signing runs on the MCU, not the secure element
- No Bluetooth, battery, or QR air-gap option
- iOS app is view-only, no transaction signing
- HBAR, SUI, and some chains need other wallets
Disclaimer: CryptoSlate may receive a commission when you click links on our site and make a purchase or complete an action with a third party. This does not influence our editorial independence, reviews, or ratings, and we always aim to provide accurate, transparent information to our readers.