Exchanges
Best Crypto Exchanges Futures Exchanges Options Platforms Derivatives Exchanges Decentralized Exchanges DEX Aggregators Crypto Bridges Memecoin Platforms Binance MEXC Coinbase Bybit
Wallets
Best Crypto Wallets Best Hardware Wallets Best Ethereum Wallets Ledger Trezor
Trading Tools
Best Trading Bots Telegram Trading Bots Best Staking Best Lending Copy Trading 3Commas
Guides
How to Buy Ethereum Day Trading Guide
News Subscribe to newsletter
Share IT
Editorial · Q2 2026 self-custody audit

The 10 best hardware wallets for Bitcoin, reviewed by a custodian who owns each.

Air-gap is the new default. The Bybit $1.5B theft in February 2025 was executed against a connected signing flow, and the market reorganized around it. We benchmarked 10 ranked devices plus 4 honorable mentions on price, secure-element certification, open-source firmware, and two years of incident history.

How we know: every wallet on this list is one we own and have set up at least twice. Prices verified May 27 2026 direct from each vendor’s store; security incidents in the last 24 months disclosed in full. So far 3,420+ holders have bookmarked this guide.
AD This guide contains affiliate links. If you sign up through them, CoinCodeCap may earn a commission at no extra cost to you, and it never affects ranking. Self-custody is your responsibility: lose the seed without a backup and your funds are gone forever. No vendor can recover them.
SELF_CUSTODY.audit — 14 wallets May 27 · 2026
Security index · cert · air-gap · FOSS
NGRAVE Zero $398 = EAL7, the only one · Tangem $55 = NFC tap
Top cert
EAL7
Fully FOSS
6 / 14
Cheapest
$55
Air-gapped
6
Our #1 pick
Ledger Nano X · 9.2
See the full review →
14
Wallets reviewed
10 ranked · 4 honorable
$50–399
Price range
SeedSigner DIY → Stax
EAL7
Highest cert
NGRAVE Zero only
6
Fully open source
Of 14 reviewed
5
Incidents disclosed
Last 24 months
30-second answer — quick picks for 2026
First wallet, <$100
Trezor Safe 3 · $59

Cheapest credible secure-element wallet. Fully open source, two-button UX you’ll learn in 10 minutes.

Buy Trezor Safe 3 →
Multi-chain DeFi
Ledger Nano X · $149

5,500+ direct coins, mobile Bluetooth, the broadest ecosystem. Closed firmware is the trade-off.

Buy Ledger Nano X →
BTC maxi, $10K+
Passport Core · $199

Air-gapped, fully open source, PSBT-native, with a genuinely beautiful keypad UX.

Buy Passport Core →
Gift / non-technical
Tangem 2.0 · $55

NFC card, no seed phrase to lose, 25-year warranty, five-minute setup.

Buy Tangem 2.0 →
Highest security cert
NGRAVE Zero · $398

The only consumer wallet at EAL7. True air-gap, no radios of any kind.

Buy NGRAVE Zero →
Multi-sig / institutional
COLDCARD Q · $249

Dual-vendor secure elements, full QWERTY keyboard, PSBT-native cold signer.

Buy COLDCARD Q →

A hardware wallet keeps your private key on a dedicated, offline device, so even a fully compromised computer can’t sign a transaction without your physical confirmation. The seed never leaves the device. That’s the whole point, and it’s why self-custody beats leaving coins on an exchange.

Most “best hardware wallet” lists rank by affiliate payout. We own every device here and have set each up at least twice. We scored them on secure-element certification, connectivity model, open-source posture and the last 24 months of incidents, including the Ledger Connect-Kit attack and the Cypherock GEEKCON disclosure that other reviews leave out. Below is the ranking, plus the wallet × feature matrix to match a device to your threat model.

01 — Methodology

How we ranked them, with no affiliate weights

Six criteria, equal weight. Every wallet is one we own. Security incidents in the last 24 months affect the score directly; reimbursement and transparency in response affect it positively.

25%
01

Secure element + firmware

Certified SE chip (EAL5+ min, EAL6+ preferred, EAL7 noted), firmware transparency, reproducible builds, audit history.

15%
02

Connectivity model

USB only, USB+BLE, NFC, or QR-only air-gap. Bybit’s Feb 2025 attack made QR-only the new gold standard.

15%
03

Open-source posture

Full source (firmware + app), partial, or closed. Bitcoin-first users treat fully open as a hard requirement.

20%
04

Incidents, 24 months

Connect-Kit, Recover backlash, support-portal phishing, supply-chain demos. Score adjusts for what happened and the response.

10%
05

Coin coverage

Bitcoin-only is a feature for many threat models. Multi-chain adds attack surface but unlocks DeFi.

15%
06

Setup & daily use

Setup time, companion-app quality, mobile parity, and partner-software support (Sparrow, Specter, Nunchuk, MetaMask).

02 — Wallet × feature

Match a device to your threat model

Pick the row that matches what you actually need. Tap a posture below to filter the list to wallets that satisfy it.

All wallets Air-gapped Fully open source Bitcoin-focused Under $120 Bluetooth
Wallet Price Air-gap Open source Secure element Bluetooth Coins
Prices verified May 27 2026 direct from vendor stores. “Air-gap” = device cannot exchange data without QR codes or microSD. EAL = Common Criteria Evaluation Assurance Level (higher is better).
03 — The concepts

6 self-custody concepts you actually need

Skip the 30-page manuals. These six decide whether a hardware wallet is actually protecting you.

🔐

Secure element

“A chip built to resist physical key extraction”

Tamper-resistant chip that stores the key and signs in isolation from the main MCU. Certified EAL5+ minimum, EAL6+ standard, EAL7 in one device.

Used by · every credible wallet except SeedSigner
📶

Air-gap signing

“QR codes and microSD only — no USB, no radios”

Device physically incapable of data exchange. Transactions pass via QR or microSD, eliminating the Bybit-style connected-signing attack class.

Used by · NGRAVE, Passport, Keystone, COLDCARD
📜

Open-source firmware

“Source on GitHub, builds are reproducible”

Firmware auditable by anyone; reproducible builds prove the running binary matches public source. Bitcoin-first users treat it as mandatory.

Fully open · Trezor, BitBox, Passport, COLDCARD, Jade
🧩

Shamir backup

“Split the key across N cards, need K to recover”

The key is split across multiple physical shares; recovery needs a quorum (e.g. any 2 of 5). No single point of failure — no 24-word seed to protect.

Used by · Cypherock (5-card), Tangem, Trezor SLIP-39
📋

PSBT

“A standard for wallets that don’t trust each other”

BIP-174 lets multiple wallets cooperate to sign without sharing keys. The foundation of multi-sig and air-gapped Bitcoin signing.

Supported by · every BTC-only wallet here + Sparrow, Specter
🪪

Passphrase / 25th word

“An optional secret on top of the seed”

An extra string you remember, added to the seed to derive a separate wallet. Forget it and the wallet is gone; use it and a physical seed extraction is useless without you.

Supported by · all here except Tangem & SeedSigner stateless
04 — Full comparison

All 10 ranked wallets, side by side

Filter by posture, or tap any column header to sort. Default order is our overall score.

All wallets Air-gapped Open source Bitcoin-focused Multi-chain
Wallet Score Price Air-gap Open source Best for

Score weights: security/SE 25%, incidents 20%, open source 15%, air-gap 15%, coins 10%, UX 15%. Buy links are AD · sponsored.

05 — Incident disclosure

Five incidents every buyer should already know

Every wallet with a material exploit, breach or controversy in the last 24 months is disclosed below. Two belong to ranked wallets (Ledger, Cypherock); the score reflects each.

🔴
Ledger Connect-Kit · npm supply-chain attack
December 14, 2023
−$600K
A former Ledger employee was phished; the attacker pushed malicious versions of the Connect-Kit npm package loaded by dozens of dApps (Zapper, SushiSwap, Phantom, Balancer). Visitors in the ~40-minute window saw a fake drainer modal. The Ledger hardware was not compromised — the attack sat at the JavaScript-library layer. Ledger patched within ~40 minutes and reimbursed victims.
Funds: reimbursed in full · signing process overhauled
Why Ledger Nano X is still #1: the hardware and secure element worked exactly as intended. The failure was in employee access controls and npm signing, both since restructured publicly.
🟡
Ledger Recover · seed-exfiltration controversy
May 2023 announce · Oct 2023 launch
Opt-in
Ledger announced an optional paid service that splits an encrypted copy of the seed across three custodians for ID-verified users. The backlash was immediate: critics argued the firmware capability to extract the seed should not exist at all. A class action followed in 2024; the service remains opt-in.
No funds lost · lasting reputational hit with purists
Why it still matters: Recover didn’t change security for users who don’t enable it, but it set a precedent that firmware can exfiltrate seed material. Bitcoin-first buyers who treat that as disqualifying choose Trezor, BitBox or Foundation.
🟡
Trezor support-portal phishing · twice
January 2024 + June 2025
~66K records
In Jan 2024 a third-party ticket portal Trezor used was breached, exposing ~66,000 names and emails. No seed material was extracted. In June 2025 attackers abused the ticket auto-reply system to send phishing emails from Trezor’s own support address. The hardware was untouched; the social-engineering surface is the lesson.
No funds lost via hardware · data leak is a phishing vector
Why Trezor is still #2: the wallet is fully open source with an EAL6+ secure element. Support-portal hygiene is an operations issue, not an architecture one. Trezor published post-mortems and migrated off the affected portal.
🟡
Cypherock GEEKCON 2025 · supply-chain demo
GEEKCON 2025, Shanghai
Demo only
Research collective DARKNAVY chained vulnerabilities to simulate a supply-chain attack on the Cypherock X1 — firmware tamper plus secure-boot bypass to capture mnemonics on a compromised device. Cypherock pushed patches to GitHub silently rather than running a coordinated disclosure, and the security community criticized the response.
No real-world theft · researcher engagement criticized
Why Cypherock is still ranked (at #9): the distributed-key Shamir model is a legitimate contribution and the patches landed. But the response damaged trust, and that matters for a category where the threat model is “vendor competence under attack.”
🔴
Ledger Nano X · $214K retail-fraud drain
January 2025
−$214K
A user bought a Nano X from a fake “Ledger Thailand” Lazada storefront. The device shipped pre-configured with an attacker-controlled seed; the user funded the wallet and the attacker drained it. Ledger’s hardware was correct — the failure was buying from a third-party marketplace instead of direct.
Funds: total loss · counterfeit vendor + user error
Why it still affects the score: distribution-channel hygiene is a known attack vector. Box-seal integrity, Genuine Check at first boot, and direct-only distribution all matter — buy from the vendor’s own site, never a marketplace.
🟢
The other 7 ranked wallets
24-month scoring window
Clean
NGRAVE Zero, BitBox02, Tangem, COLDCARD Q, Foundation Passport Core, Keystone 3 Pro and Blockstream Jade Plus have clean records across the window. (Two minor technical disclosures: a Trezor Safe 3 vuln found by Ledger Donjon in March 2025, patched promptly; and snail-mail phishing campaigns targeting customers by name — data weaponization, not hardware compromise.)
Takeaway: a clean 24-month record is the baseline. The incidents that matter are the ones a vendor handles badly, not the ones it handles fast.
06 — The reviews

Our top picks, reviewed in full

#02 · Best FOSS
Trezor Safe 5
Best fully open-source touchscreen
✓ Owned & set up twice
9.1/10

SatoshiLabs, Prague (2013) · Optiga Trust M EAL6+ secure element · 1.54″ color touchscreen + haptics, Gorilla Glass 3 · USB-C only · fully open source firmware and apps

The first Trezor with a true secure element, and the most polished companion app on this list. The color touchscreen is responsive, the haptics are genuinely useful, and SLIP-39 Shamir Backup is supported natively. If Bluetooth is a hard no, this is the FOSS answer to the Nano X.

+What worked
  • True EAL6+ secure element
  • Fully open, reproducible builds
  • Native SLIP-39 Shamir
What didn’t
  • No Bluetooth, no air-gap mode
  • iPhone support read-only
  • Support-portal phishing history
Price
$169
SE
EAL6+
Coins
9,000+
Source
Full
Buy Trezor Safe 5 → Open source · reproducible builds AD Sponsored. Buy from the vendor only. Self-custody at your own risk.
#03 · Highest certification
NGRAVE Zero
Highest security cert (EAL7)
✓ Owned & set up twice
8.9/10

Brussels, Belgium (2018) · 4″ touchscreen, fingerprint, IP55 · EAL7 secure element (only consumer device at this level) · fully air-gapped — QR only, no USB data, no radios

True air-gap with no radios of any kind, and the best build quality on this list. The included GRAPHENE stainless-steel seed backup is the cleanest physical-storage solution money can buy, and the EAL7 certification is the highest tier any consumer device has achieved. The catch is closed firmware at $400.

+What worked
  • Only EAL7 consumer device
  • True air-gap, zero radios
  • GRAPHENE steel seed backup
What didn’t
  • Closed firmware at $400
  • BTC tooling lags Passport
  • ~1,500 coins, not 5,500+
Price
$398
SE
EAL7
Coins
~1,500
Air-gap
QR only
Buy NGRAVE Zero → GRAPHENE steel backup included AD Sponsored. Buy from the vendor only. Self-custody at your own risk.
07 — Get started

Your first hardware wallet, in 5 steps

Never set one up before? This is the safest cold-start. Works the same on Ledger, Trezor, BitBox, Foundation, Keystone, Jade and Tangem.

1

Order direct from the vendor

ledger.com, trezor.io, bitbox.swiss, foundationdevices.com — never a marketplace. Verify the tamper seal; if anything looks disturbed, refuse the package.

2

Run Genuine Check at first boot

Every wallet here has a vendor-side check that verifies the device is genuine and the firmware unmodified. Skip it and you risk a counterfeit.

3

Generate the seed on the device

Write all 12 or 24 words on the recovery card. Never type it on a phone or computer, never photograph it, never store it in a password manager.

4

Send a small test transaction first

Deposit $20–50, then withdraw it back to an address you control. Confirm both on the device screen. If setup is wrong, you find out at $50, not $50,000.

5

Store the seed in two separate places

Paper in a fire-resistant safe plus a stainless-steel backup at a second location. Most losses aren’t theft. They come from losing the device and seed in the same disaster.

08 — Honorable mentions

Four wallets for specific niches

$399 · PREMIUM
Ledger Stax

Curved 3.7″ E-Ink touchscreen designed by Tony Fadell, ST33K1M5 EAL6+, Qi wireless charging, USB-C + BLE + NFC. Same security tier as a Nano X in a premium chassis, aimed at aesthetic-driven multi-chain users.

$59 · ENTRY
Trezor Safe 3

The cheapest secure-element Trezor — 0.96″ OLED, two buttons, 14g, EAL6+, fully open source, BTC-only firmware variant. Best entry-point for first-time buyers on a tight budget.

~$50 · DIY
SeedSigner

Raspberry Pi Zero v1.3 + camera + LCD, fully air-gapped, stateless (no persistent key storage), BTC-only via PSBT. Cannot be “drained” because nothing is stored. For sovereignty enthusiasts and multi-sig co-signers.

~$160 · WEARABLE
Tangem Ring

Zirconia-ceramic wearable with embedded NFC, no screen, no battery, no firmware lifecycle. Same 81 chains as Tangem 2.0, EAL6+, 25-year lifespan. The first production wearable cold wallet, though ring size is fixed at purchase.

09 — Don’t buy new

Five wallets to avoid buying in 2026

These still function if you already own one, but they shouldn’t appear on a 2026 shopping list.

Ledger Nano S

2016 model, end-of-life June 2025. No further firmware updates or new app integrations. Rotate to Nano S Plus or Nano X.

Trezor Model One

2014 hardware, removed from the e-shop Jan 8 2026. Maintenance patches continue, but no new units — buy a Safe 3 or Safe 5.

Trezor Model T

Removed from the e-shop Jan 8 2026 in favor of the Safe 5. Same support timeline as Model One.

KeepKey

Stagnant under post-ShapeShift-DAO stewardship. Last meaningful hardware refresh was 2017; ecosystem support has thinned.

Original Jade (non-Plus)

Superseded by Jade Plus with a 66% larger screen and integrated camera. No reason to buy the original over the Plus.

10 — Which one?

Skip the rankings — find your row

1
New BTC holder, $500–5K
Cheap, well-documented setup → Trezor Safe 3
2
DeFi power user, multi-chain
5,500 coins + best mobile → Ledger Nano X
3
Bitcoin maximalist, $50K+
Air-gapped, fully open source → Passport Core
4
Multi-sig / co-signer
Dual-vendor SE + QWERTY → COLDCARD Q
5
Non-technical family gift
Tap-to-sign, no seed to lose → Tangem 2.0
6
Highest certification
EAL7, true air-gap → NGRAVE Zero
!
Red flags — walk away
Buy from the vendor’s own site, never Amazon, Lazada or eBay. Marketplaces are the #1 source of pre-configured tampered devices. A legitimate wallet generates the seed on-device at first boot; if yours ships with a printed seed, return it. No vendor will ever email or mail you asking to “verify” your seed phrase. That is always fraud.
11 — FAQ

Hardware wallets — common questions

Which hardware wallet is best for Bitcoin in 2026?
For new holders on a budget: Trezor Safe 3 ($59) or Jade Plus ($149). For Bitcoin maximalists with $10K+: Foundation Passport Core ($199) or COLDCARD Q ($249) — both fully air-gapped, fully open source, PSBT-native. For multi-chain users who hold BTC alongside ETH and Solana: Ledger Nano X.
What was the Ledger Connect-Kit hack — is Ledger safe?
On Dec 14 2023, a phished former employee let an attacker push a malicious Connect-Kit npm package, draining ~$600,000 from users of dApps like Zapper and SushiSwap. Ledger patched in ~40 minutes and reimbursed victims. The Ledger hardware itself was not compromised — the attack was at the JavaScript-library layer between dApp and wallet.
Is air-gapped really safer than USB or Bluetooth?
For most threat models, yes. Air-gapped wallets sign via QR codes or microSD only — no USB data path, no Bluetooth, no wireless. That eliminates entire attack categories, including the Bybit-style compromise where a malicious UI was injected into a connected signing flow in February 2025.
What is EAL6+ and EAL7, and does it matter?
EAL is the Common Criteria certification scale for the chip inside the wallet. EAL5+ is the entry tier (Ledger Nano X), EAL6+ the modern standard (Trezor Safe 5, Tangem, Cypherock), and EAL7 ships in only one consumer device — NGRAVE Zero. In practice the gap between EAL6+ and EAL7 is marginal; supply-chain hygiene and software design matter more.
Are hardware wallets actually open source?
Some are, most partially. Fully open firmware and app: Trezor Safe 5, BitBox02, Foundation Passport Core, COLDCARD Q, Blockstream Jade Plus and SeedSigner. Partial: Keystone 3 Pro, Cypherock X1. Closed: Ledger Nano X/Stax and NGRAVE Zero.
GA
Gaurav Agarwal
Editor · CoinCodeCap

Gaurav has covered self-custody since 2017 and owns every wallet in this guide. For this audit he set up each device at least twice, verified prices direct from vendor stores, and reconciled 24 months of incident reporting against BleepingComputer, Decrypt, DARKNAVY and each vendor’s own reports.

𝕏 @coincodecapView all reviews →
The CoinCodeCap brief

We test the wallets so you don’t trust the wrong chip with your keys.

One email a week — new reviews, incident disclosures, and the occasional blunt warning. No hype, no paid placements.

Free. Unsubscribe anytime. We never sell your data.
Share IT
Gaurav
Gaurav

Get Daily Updates

Crypto News, NFTs and Market Updates