Method
A hardware wallet is a small computer that keeps your secret key and refuses to give it to anyone. That's the right instinct. But a device doesn't answer a simple question: what does the manufacturer know about you, and can you verify what the program inside is doing?
We sell none of these devices and we make nothing if you buy one. We have no referral link to any of these manufacturers. This comparison exists because we asked ourselves the question for our own sake. Prices checked on September 5, 2026 in the official shops; every claim links to the page that states it.
July 2026
On July 30, 2026, Coinkite announced that its device, the Coldcard, one of the most respected in the space, had been generating secret keys far weaker than intended.
To understand the incident, you need to know how a Bitcoin key is born: the device randomly draws a very large secret number. There must be so many possible numbers that no one can try them one by one. The target was 128 bits, i.e. about 340 billion billion billion billion possibilities. A flaw in the program reduced that draw to about 72 bits according to the manufacturer's notice.
72 bits isn't “a bit less.” It's thousands of billions of times less. Small enough for a patient attacker to try every combination, offline, without ever touching the device. That's exactly what happened: 1,367.05 bitcoin, about $88.6 million, drained from 4,585 addresses according to the count published by The Record. The flaw had been introduced in March 2021 and sat for five years in public code.
The manufacturer responded correctly: shipments halted, a fix published, and the entire remaining stock made with the old program destroyed, rather than betting on the buyer applying an update still according to The Record. But the hard point remains: updating the device does not fix a key already generated. You need to generate a new one and move the funds.
If you own a Coldcard, the question is relevant today.
Affected are keys generated on Mk2 and Mk3 with versions 4.0.1 through 4.1.9, on Mk4 and Mk5 before 5.6.0, and on Q before 1.5.0Q: the “Edge” branches have their own numbering, 6.6.0X and 6.6.0QX. TAPSIGNER, OPENDIME, and SATSCARD are not affected, as their program differs. A documented exception: if you supplemented the draw with your own dice, at least 50 private rolls were enough to restore 128 bits. All the details are in the manufacturer's security notice, which is the only reference to follow.
The lesson
Publishing your code isn't enough: someone has to read it. After the 2021 rewrite, the Coldcard's in-house math library showed 7 stars and fewer than 20 clones on its repository, versus 512 stars and 212 clones for the one it replaced, as Bitcoin Magazine's analysis notes.
What we take from this
No device is immune. What varies is how quickly a flaw is found, and how honestly it's disclosed. We prefer devices that are heavily reviewed over devices that are heavily marketed.
What we look at
The screen, the size, the number of currencies supported: that's not what interests us here. Here's what we check.
1 · The exact license
Is the program open, and under exactly which license? “Open source” has become a sales pitch. Some manufacturers publish code that the license nonetheless forbids reusing commercially. That isn't dishonest, but it isn't the same thing, and it reduces the number of people who will bother to look at it.
2 · Verifiable at home
Can you rebuild the installed program yourself? This is the decisive criterion, and the least known. Reading the published code doesn't prove that this is the code running in your device. A “reproducible build” lets you recompile the program at home and check that it matches, byte for byte, the one shipped. Without that, you're taking it on faith.
3 · Buying without identity
Paying by card in your name and having it delivered to your home creates a list: “this person, at this address, holds bitcoin.” That list sometimes ends up published. Paying in bitcoin changes the financial side; the delivery address is still almost always needed.
4 · The manufacturer's track record
What has already happened at this company? The past is no guarantee of the future, but it's the only verifiable data. A customer database already published on the internet can't be undone. An incident reported quickly and clearly, on the other hand, speaks well of a company.
A fifth point deserves mention, even though it isn't in the table: does the device need a service from the manufacturer to work day to day? A unit that signs offline, via a photo of an on-screen code or a memory card, talks to no one. This is called full isolation, and it pairs best with your own node.
Eight devices
“Not documented” means we didn't find the answer on the manufacturer's official pages. We'd rather say so than guess.
| Device | Open program | Verifiable at home | Purchase in bitcoin | Customer data leak | Price |
|---|---|---|---|---|---|
| Blockstream Jade and Jade Plus |
Yes: the whole under GPLv3, some components under their own license | Yes: official procedure, manufacturer signature excluded from the comparison | Yes: own shop, bitcoin and Liquid accepted | Yes, indirect, October 2023, at a carrier: emails confirmed, phone numbers and addresses not ruled out, volumes never published | 67 $ · 169 $ |
| Coldcard Mk4, Mk5, Q |
No in the strict sense: MIT plus the “Commons Clause”, which removes the right to sell a derivative | Yes in practice: independent rebuild of version 5.6.0 matching every byte | Yes: gift cards payable only in bitcoin | No customer database published. Automatic erasure after 120 days, but suspended until further notice since the July 30, 2026 incident | Mk4 and Q in the shop |
| Trezor Safe 3, Safe 5 |
Yes: GPLv3 and LGPLv3 depending on the parts; the secure chip is not presented as open | Yes: official procedure via container, signature zeroed out for comparison | Yes: bitcoin and Lightning via a provider, 15 minutes to pay | Yes: January 2024, at a support provider: up to 66,000 contacts (name or username and email), no postal address | 59 $ · 129 $ |
| Ledger Nano S Plus, Nano X, Flex, Stax |
Partially: the manufacturer claims “95%”; the chip's low-level code stays closed under agreement with its foundry | Not documented: no rebuild procedure found | Yes: bitcoin via payment providers | Yes, the worst in the industry: June 2020: about one million emails; database published in plain text on December 20, 2020 with about 272,000 records of name, postal address, and phone number | 59 $ → 399 $ |
| BitBox02 and Nova |
Yes, without reservation, Apache 2.0, commercial use included | Yes: consumer-friendly procedure, fingerprint comparison explained step by step | Yes: bitcoin and Lightning directly, with an announced discount; delivery address required | Yes, indirect, July 2022, leak at its email delivery platform; volumes not specified | 173 $ · 203 $ |
| Foundation Passport Core, Prime |
Yes: a patchwork of open licenses, the whole to be considered copyleft due to the GPLv3 | Yes: official procedure, plus independent reproducibility reviews | Yes: bitcoin via a payment server hosted by the manufacturer itself | Not documented | 99 $ · 349 $ |
| SeedSigner assemble it yourself |
Yes, without reservation, MIT license, operating system included | Yes: byte-for-byte reproducible images since version 0.7.0, with a signature to verify | Not applicable: no company: you buy generic components | Not applicable: no company, so no customer database | under $50 in parts |
| Keystone 3 Pro | Partially: MIT license, but one library is shipped already compiled, and a manufacturer admission: secure chip and system not fully open | Yes: official procedure, the device itself displays the fingerprint to compare | Yes: bitcoin via providers; address cannot be changed after ordering | Not documented. Shipping data retention reduced to 180 days, deletion possible on request | 149 $ |
Prices are those shown by the official shops on September 5, 2026, in the currency they display, excluding shipping and local taxes. They change often: check before ordering.
In a few lines
What struck us about each one, from the standpoint of what the manufacturer learns about you.
Published code, an acknowledged rebuild procedure centered on bitcoin. The friction point isn't the purchase but the use: by default, unlocking goes through a Blockstream server, said to know neither you, nor your wallet, nor your actual PIN. Anyone who refuses this link can host that server themselves, or unlock directly with their own barcode backup.
There is no manufacturer: you assemble a small generic computer and install a fully open, reproducible, and signed program on it. No order, no name, no address, so no customer database that could leak. The device doesn't even keep your key: you re-enter it every time you use it, and it signs offline via photo.
Apache 2.0 with no restrictive clause, and a verification procedure written to be followed by someone who isn't a developer, which is rare. Payment directly in bitcoin and Lightning, with no intermediary provider, with an announced discount. The first setup goes through the manufacturer's app, after which the device can be used with software of your choice.
No radio, no wireless of any kind: a camera and a memory card slot, nothing else. The device physically cannot talk to the network, so it talks to no one. The program rebuild is documented, and the manufacturer itself points to independent third-party verifications, which is the sign of a company comfortable with scrutiny.
The industry's oldest and most scrutinized code, with an official rebuild procedure. The Safe models' secure chip is presented as certified and documented without a non-disclosure agreement, but the manufacturer does not call it open. Usable with the in-house software or with another, which leaves you in control.
An excellent device on paper: full offline signing, no manufacturer software required, purchase payable only in bitcoin via gift card. But two serious caveats. The license isn't open in the strict sense: it forbids selling a derivative, which in practice reduced the number of people reviewing its code. And the July 2026 incident tells the rest of the story.
Offline signing via photo, a documented rebuild procedure, and the device itself displays the fingerprint to compare, well thought out. The license is permissive, but one library ships already compiled, and the manufacturer states plainly that its secure chip and part of its system are not open, so you cannot verify how randomness is produced there. After the Coldcard incident, that statement is worth reading twice.
This is the most widely used device, and the one whose customers have suffered the most. In June 2020, the sales database was siphoned off; on December 20, 2020, it was published in plain text, with about 272,000 records containing name, postal address, and phone number. These records still circulate today and feed physical mail scams and fraudulent visits. On the technical side, the manufacturer acknowledges that its chip's core stays closed, and we found no procedure to rebuild the installed program.
Whichever device
The best hardware wallet in the world is worthless if buying it put your name and address in a file that ends up published. Five steps, in order of importance. And if you don't have bitcoin yet to pay for the device, we compared fifteen apps on their real ability to let you get your funds out.
Pay in bitcoin
Every manufacturer in this comparison accepts it, some directly and without an intermediary. This removes your name and your bank from the equation. Coinkite goes further: its gift cards can only be bought with bitcoin.
Have it delivered somewhere other than your home
A pickup point, an office, a PO box, a relative's address. This is the most useful step, because it's the postal address that turns a data leak into a physical risk. Careful: several shops refuse any refund for a wrong address, and some forbid changing it after ordering.
Buy in person if you can
A new, sealed unit, bought from someone you meet in person, leaves no commercial trace. It's the cleanest solution, and the rarest.
Ask for your data to be erased
Some manufacturers erase it on their own after a few months, others do it on request. Write to them. The worst case remains the company with no policy at all: the data then stays indefinitely.
Never second-hand, never a device that's already been set up.
A second-hand device may have been tampered with to strip you of your funds, and a unit shipped with a key already written on a card is a known scam: whoever printed it knows it. The rule allows no exception: you generate your key yourself, on an up-to-date device, and no one else ever sees it. The Coldcard incident adds a nuance: updating before generating your key isn't an administrative formality, it's the act that protects you.
A last word on the link between this page and our service. A hardware wallet protects your key; it doesn't protect what your wallet tells the network. Every time it checks your balance, it asks a computer, and that computer learns which addresses belong to you. That's the second problem we address, by giving you your own node. The two are complementary, and neither replaces the other.
Our caveats
A comparison with no empty box is a comparison where the gaps were papered over. Here are ours.
We did not test all eight devices
This comparison covers what manufacturers publish and documented incidents, not hands-on testing of each device. We use the Jade; the others are judged on the record.
We're missing three leak volumes
Neither Blockstream nor Shift Crypto has published the number of people affected by the incidents at their providers. So we write “volumes not published” rather than cite a second-hand figure.
The absence of a leak is not proof
For Foundation and Keystone, we found no documented leak. That may mean there wasn't one, or that it wasn't disclosed. We cannot decide, and we won't.
We recommend only one device, and we tell you which
We mention the Jade because it's the one whose program we verify ourselves. This is neither a ranking nor investment advice, and we have no agreement with any of these manufacturers. Our business is the node and the network exit, not reselling devices.
The hardware wallet keeps the secret. The node avoids having to ask a stranger for your balance.
We ask you to be wary of manufacturers' customer databases: it would be poor form not to hold ours to the same standard. Here, field by field, is what ours contains.