Home › Honest Gear Reviews › Trezor Safe 3
Trezor Safe 3 Review
Open-source firmware combined with a secure element — the most straightforward recommendation for a reader whose priority is being able to verify what the device does.
By the CoinCrafty editorial desk · Updated 25 Jul 2026
Who it is for
Readers who want auditable, open-source firmware without giving up a secure element, and who do not need Bluetooth or a large touchscreen.
The scorecard
| Criterion | Why | Score |
|---|---|---|
Security model 30% weight |
Open-source firmware plus a secure element; the historical physical-extraction weakness of pre-secure-element models is addressed. | 9.0 |
Ease of setup 20% weight |
Well-documented and hard to get wrong, though the two-button entry is slower than touch input. | 8.5 |
Supported assets 15% weight |
Broad coverage of major assets and networks, slightly behind the widest-support devices on long-tail tokens. | 8.5 |
Build quality 15% weight |
Light and compact; plastic construction feels less premium than metal-bodied rivals. | 8.0 |
Value 10% weight |
Strong security posture at a mid-range price, with no meaningful feature you are paying to unlock. | 9.0 |
Support & longevity 10% weight |
Long-established company, thorough public documentation and an active open-source repository. | 8.5 |
Overall weighted |
The weighted average of the six published criteria above, computed rather than chosen. | 8.6 |
Security model
Trezor's firmware is open-source and independently reviewable, which is the single most cited reason people choose the brand. The Safe 3 pairs that openness with a certified secure element, addressing the main historical criticism of earlier Trezor models, which stored secrets in general-purpose microcontroller flash and were shown to be vulnerable to physical extraction by a well-equipped attacker with the device in hand. Transactions are confirmed on the device, and an optional passphrase adds a further layer for readers who understand the risk of forgetting it.
Setup difficulty
Clear and well-documented, with the recovery-phrase confirmation enforced. The two-button interface is slower than a touchscreen but unambiguous. For a device-agnostic walkthrough of doing this properly, see our hardware wallet setup guide and our seed-phrase backup guide.
Pros and cons
Pros
- Open-source firmware that anyone can review
- Secure element closes the historical physical-extraction gap
- Clear, well-documented setup with enforced backup confirmation
- Good security-per-cost for a mid-range device
Cons
- No Bluetooth, so phone use requires a cable
- Small screen and two-button input make long verification slow
- Plastic body feels less durable than metal-cased alternatives
- Long-tail token support trails the widest-coverage devices
Where to buy
Buy direct from Trezor (SatoshiLabs) or an authorised reseller listed on their own site — never second-hand, and never from a marketplace listing, because a pre-initialised device is the most common physical scam in this category. We do not currently run an affiliate link for this device; if that changes, this section will say so plainly and the score will not move. See our affiliate disclosure.
Alternatives
Ledger Nano X — 8.5/10If you want Bluetooth and the widest asset coverage Coldcard Mk4 — 7.6/10If you hold only Bitcoin and want an air-gapped workflowFrequently asked questions
Why does open-source firmware matter?
It lets independent researchers read the code that controls your keys, rather than requiring you to take a company's word for it. It is not a guarantee of safety on its own — code still has to be reviewed — but it removes a whole category of "trust us" from the equation.
Were older Trezor models unsafe?
They were sound against remote attacks, which is what most people face. Their documented weakness was physical: an attacker with the device in hand and specialist equipment could potentially extract secrets. The secure element in the Safe 3 is the direct response to that.
Do I still need a passphrase?
Only if you understand that forgetting it means permanently losing access. It is a genuine defence against someone finding your written recovery words, and a genuine way to lose funds if treated casually.
Sources
Spotted something wrong? Tell us via contact — corrections are logged publicly at corrections.