
Buy it direct from the manufacturer's own website, not from a marketplace listing. That one rule does more for your security than the difference between any two devices on this page. A sealed box from a third-party seller tells you nothing. A device that arrives with a seed phrase already printed on a card is a scam, every time, no exceptions.
Prices move, so check before you order, but the shape of the market is stable: entry-level units land somewhere around $50 to $80, mainstream models with a screen and Bluetooth sit near $150, and the specialist Bitcoin-only devices run from about $65 up past $200. You're not buying computing power. You're buying a chip that holds a secret and a screen that tells you the truth about what you're signing.
What the device actually does
Your private key generates signatures. A hardware wallet keeps that key in a chip that never hands it to your laptop, and signs transactions inside the device. Your computer sends over an unsigned transaction. The device shows you the destination address and amount on its own screen. You press a physical button. The signed transaction goes back out.
That screen is the whole point. Malware on your PC can swap a copied address for the attacker's. It can't change what your Trezor shows you. Which is why devices with tiny, low-resolution screens are a real downside and not a cosmetic one, because you will get lazy about checking a 42-character address on a display the size of a postage stamp.
The three dividing lines
Almost every argument in this space comes down to one of three things.
Secure element or not. A secure element is a tamper-resistant chip designed to resist physical extraction. Ledger has used one from the start. Trezor's older models, including the Model One and Model T, didn't, and researchers demonstrated seed extraction from them with physical access and lab equipment. Trezor addressed this with the Safe 3 in 2023 and the Safe 5 in 2024, both of which pair their open firmware with a secure element chip.
Open source or not. Secure elements ship with vendor NDAs, which historically meant closed firmware. Ledger's device firmware isn't fully open. In May 2023 Ledger announced Recover, an optional service that splits an encrypted version of your seed across custodians. The service is opt-in. The uproar was about something else: it proved the firmware could be made to move seed material off the device, which cut against years of messaging. If that bothers you, it's a legitimate reason to buy something else.
Air-gapped or plugged in. Coldcard, Keystone and Blockstream Jade can operate without ever touching a USB data cable, passing transactions by microSD card or QR code through a camera. It's slower. It also removes an entire attack surface. For a small stack it's overkill. For a serious one it's the correct trade.
The devices, briefly
Ledger (Nano S Plus, Nano X, Flex, Stax). The broadest coin support by a distance, a polished app, and the Nano X adds Bluetooth for phone use. If you hold a long tail of altcoins and NFTs, this is often the only device that supports all of them. The closed firmware and the Recover episode are the cost of admission.
Trezor (Safe 3, Safe 5). Open firmware, a secure element, and Shamir backup on the Safe 5, which splits your recovery into shares so no single piece of paper ruins you. Good desktop software. Coin support is solid but narrower than Ledger's. If I were handing a device to someone who wants one thing that works and isn't a philosophical project, it'd be a Safe 3.
Coldcard (Mk4, Q). Bitcoin only. Full air gap by microSD, PSBT workflow, duress PIN, and a "brick me" PIN that destroys the secure element. The Q has a full keyboard. It's not friendly. You'll read the documentation twice. For a serious Bitcoin holding, especially in multisig, it's the standard.
BitBox02. Swiss-made, comes in a Bitcoin-only edition or a multi edition, backs up to a microSD card as well as to words. Genuinely pleasant setup. Fewer coins than Ledger.
Blockstream Jade. Cheap, open source, has a camera for QR air gap, Bitcoin only. The least painful way to try air-gapped signing without committing $200.
Keystone 3 Pro. QR-only air gap, big touchscreen, fingerprint, broad chain support. Good middle ground if you want air gap without going Bitcoin-only.
What actually goes wrong
Almost nobody loses funds because someone broke their secure element. They lose funds these ways.
They wrote the seed phrase into a notes app, or photographed it. Cloud backup did the rest.
They signed something they didn't read. A drained wallet after "claiming" an airdrop is usually a token approval the owner authorised with their own device. The hardware worked perfectly. It signed exactly what was asked.
They used a passphrase, told nobody, and died. A BIP39 passphrase creates a completely separate wallet on top of your 24 words. It's strong protection against someone finding your seed. It's also an extra thing to lose, and it won't be in your will unless you put it there.
They never tested the backup. This is the big one.
Test your recovery before you fund it
Set the device up. Write the words on the card. Send a small amount, something you'd shrug at losing. Then wipe the device to factory settings and restore it from your written words.
If the balance comes back, your backup works. If it doesn't, you've learned that for the price of coffee instead of everything. Do this before you move real money, and do it again if you ever change your backup arrangement.
Write the words in pencil or a decent pen on the supplied card, then move them to steel if the amount justifies it. House fires and burst pipes are far more common than burglars who know what a seed phrase is. A stamped steel plate costs less than most of these devices.
Where the advice breaks down
If you're holding a few hundred dollars and actively trading, a hardware wallet may just add friction you'll route around. You'll leave funds on the exchange anyway. Be honest about that rather than buying a device that ends up in a drawer with nothing on it.
And if the amount is genuinely large, a single device is the wrong answer regardless of brand. Multisig, two or three devices from different manufacturers, keys stored in different physical places. It's more work. It also means no one theft, fire or manufacturer failure ends you. Tax treatment of any of this varies by where you live, and that's a question for an accountant, not a forum.
Pick one. The Trezor Safe 3 if you want it simple, the Coldcard if you're serious about Bitcoin, the Ledger if you need the coin support and you've made peace with the firmware.
Then go and do the restore test. The device is the easy part.
Ray Okonkwo
Money & Business
Former commercial banker turned small-business owner. Covers salary, credit, margins and the arithmetic nobody does before signing.
Watch
Worth an hour of your evening
More from Crypto.
From channels we rate. Plays on YouTube.
Read next
