Hardware Wallet Reviews 2026: They’re Called Signers Now
Ledger now calls them signers, not hardware wallets, and 2026's hacks reset what a review should test. Here is a device-by-device verdict on Ledger, Trezor, Coldcard, Tangem and the challengers.
Bitcoin was trading just above $77,000 on September 13, jittery ahead of a Federal Reserve meeting where traders were betting heavily on a rate hike (CoinGecko). Every time the price wobbles, more holders pull coins off exchanges and into their own custody, and the device they reach for is a hardware wallet. Except the biggest name in the category will not call it that anymore.
In late 2025, Ledger stopped describing its products as hardware wallets and started calling them signers, arguing that the old word wrongly implied coins live on the device (The Block). It is a marketing decision, but it points at something true: these are not piggy banks, they are key custodians that approve transactions. And in 2026 the reasons to get the choice right kept stacking up. A firmware flaw drained Coldcard users of roughly $116 million in Bitcoin (TRM Labs). A breach at a Trezor shipping partner exposed about 81,000 customers’ names and addresses (BleepingComputer). Ledger was hit with a class action seeking at least $500 million over older breaches (crypto.news). And Ledger’s own security lab knocked layers off two rivals’ chips with a laser (Ledger Donjon).
This is a device-by-device review of the field as it stands now, with a plain verdict for each and a map of which one fits which kind of owner. The short version is not that one wallet wins. It is that the right answer changes completely depending on what you hold, which chains you touch, and who you think is coming for it.
What 2026 changed about buying a signer
For years, hardware wallet reviews turned on spec-sheet trivia: which secure element, how big the screen, whether it has Bluetooth. The events of 2026 moved the important questions somewhere less glamorous. How does the maker generate randomness? How does it sign firmware updates? What does it do with your shipping address? Those are the seams that failed this year, and they barely register on a features grid. Our companion piece works through that idea in detail in Hardware Wallet Reviews 2026: Beyond the Spec Sheet; here we apply it to each device.
Start with the loudest failure. On July 30, attackers began sweeping funds from Coldcard users whose seed phrases had been generated with far too little randomness. A build flag in firmware 4.0.1, shipped back in March 2021, had quietly swapped in a weak software random number generator, cutting seed entropy from 128 bits to as low as 40 bits, low enough to brute-force. The thieves took roughly 1,816 BTC (about $116 million) across several waves; the first sweep alone pulled about 594 BTC from around 500 wallets in 25 minutes (TRM Labs). The chip was never broken. The randomness was.
Then came the data. Trezor disclosed that a breach at its fulfillment partner ShipMonk had exposed customer records, and the count climbed to about 81,000 people, including roughly 67,000 older US orders that ShipMonk had assured Trezor were deleted but had kept anyway (BleepingComputer). No private keys leaked, but names, emails and home addresses did, which is the raw material for phishing and worse. Ledger, meanwhile, was named in a class action filed in late August in the Southern District of New York by a user named Douglas Kim, seeking at least $500 million over its 2020 and December 2023 breaches and alleging that scammers used the leaked data to impersonate Ledger and steal his crypto (crypto.news).
Even the chips took a public beating. Ledger’s Donjon lab used laser fault injection to defeat security layers on both a Tangem card and Trezor’s new Safe 7, in each case needing physical possession and a lab most attackers will never touch, and in each case with no user funds lost (Ledger Donjon). None of this means self-custody is losing. Of roughly 400 million crypto users, only around 30 million hold their own keys, and the hardware wallet market is still forecast to more than quadruple from about $540 million in 2025 to roughly $2.25 billion by 2031, with unit sales up 31% last year (CoinLaw). It means the review criteria grew up.
How to read these reviews
Every verdict below weighs five things, in roughly this order of importance. First, the secure element and, just as important, who is allowed to audit it. Second, the firmware: does the maker publish reproducible builds, and where does the device get its randomness? Third, signing: when you approve a transaction, does the screen show you what you are actually authorizing? Fourth, the company itself: its track record with your personal data and its supply chain. Fifth, your own threat model, which is the one variable no reviewer can set for you.
A device can ace one layer and fail another. Coldcard has excellent hardware and still shipped a randomness bug. Ledger’s chip has never been cracked in the wild while its customer database has been breached more than once. Trezor is the most auditable and still had its buyers’ addresses leaked by a third party. If you want to understand why the badge on the box is not the same as the security you actually get, we made that case separately in Audited by Whom? The Crypto Audit Badge Problem in 2026. With that framing set, here is the field.
| Device | Price (USD) | Coins | Open source | Best for |
|---|---|---|---|---|
| Ledger Nano Gen5 | $179 | Multichain | No | All-round multichain use |
| Ledger Flex / Stax | $249 / $399 | Multichain | No | Same security, premium screen |
| Trezor Safe 5 | $129 to $169 | Multichain | Yes | Best-value open source |
| Trezor Safe 7 | $249 | Multichain | Yes | Auditability, future-proofing |
| Coldcard Q | $249 | Bitcoin only | Yes | Advanced Bitcoin cold storage |
| Tangem (3 cards) | About $75 | Multichain | No | Beginners and gifts |
| Keystone 3 Pro | $149 | Multichain | Yes | Air-gapped QR workflow |
| BitBox02 Nova | About $169 | Multichain | Yes | Understated open source |
| Foundation Passport | $199 (Core) | Bitcoin focus | Yes | Air-gapped Bitcoiners |
| NGRAVE Zero | About $398 | Multichain | No | Highest OS certification |
| SafePal S1 | About $50 | Multichain | No | Budget air-gapped |
Ledger: the Nano Gen5, Flex and Stax
Ledger is the default answer for most newcomers, and in 2026 it is also the company that decided the category name was wrong. Its devices are now signers, its Ledger Live app is now Ledger Wallet, and the pitch has widened from storing crypto to protecting your identity and consent in an era of AI-driven fraud (The Block). The current lineup runs from the keychain-sized Nano S Plus (around $79) through the Nano Gen5 at $179, the Flex at $249 and the Stax at $399. The important thing a buyer should know is that they all share the same ST33-series EAL6+ secure element and the same closed-source BOLOS operating system. The extra money buys a bigger touchscreen and nicer materials, not more security.
The strengths are real. Ledger has sold roughly eight million devices (CoinLaw), supports about as many chains and apps as anyone, and has led the industry push toward clear signing, the readable-transaction standard we return to below. The Nano Gen5 adds Bluetooth, NFC and features like Transaction Check and a Recovery Key. If you hold a spread of assets across many networks and want the widest software support with the fewest rough edges, this is the smoothest option in the field.
The weaknesses are equally real, and they are not about the chip. BOLOS is closed source, so you are trusting Ledger’s word that it does what it claims; the company argues that certified silicon is the point. Chairman and CEO Pascal Gauthier put the philosophy bluntly: “Everything that is in software is close to impossible to protect,” and “A device built to do everything cannot fully protect anything” (Ledger). The harder problem is the company’s data record. Ledger’s chip has never been broken in the field, but its customer database has, in 2020 and again through the December 2023 Connect Kit incident, and those breaches are exactly what the new $500 million class action is about (crypto.news).
Verdict: the best mainstream multichain signer, provided you accept closed firmware and treat every message claiming to be from Ledger as a phishing attempt until proven otherwise. Best for multichain holders who value app support and clear signing over open-source purity.
Trezor: the Safe 5 and the quantum-ready Safe 7
Trezor is the answer for people who would rather verify than trust. Its whole argument is openness, and in 2026 that argument got sharper with the Safe 7, which pairs a new secure element called TROPIC01, the first whose full hardware design and firmware are published for public review, with an Infineon Optiga EAL6+ chip and an STM32U5 processor. At $249 it adds Bluetooth, USB-C, Qi2 wireless charging, a 2.5-inch color touchscreen, and post-quantum firmware signing that Trezor markets as the first quantum-ready wallet (CryptoSlate). One nuance the marketing blurs: the post-quantum part protects firmware updates and device identity, not your on-chain signatures, which remain elliptic-curve like everyone else’s. For most buyers the value pick is the Safe 5 at roughly $129 to $169, with the Safe 3 covering the entry tier near $59 to $79.
Trezor CEO Matej Žák frames the trade-off directly: “We are the most secure because we are the most open-source,” adding that under the old NDA chips, “if we found a problem, we couldn’t warn anyone” (DL News). That openness is not a slogan: when Ledger’s Donjon lab beat one of the Safe 7’s three security layers with a laser in January 2026, Trezor was able to disclose and discuss it in public that June, with no user funds lost (CryptoSlate).
The blemish on Trezor’s year did not come from its hardware at all. The ShipMonk breach leaked the names, emails and addresses of about 81,000 customers through a fulfillment partner, including thousands of older records the partner had promised were deleted (BleepingComputer). Trezor’s one genuinely admirable habit here is a 90-day data-retention policy that limited the recent-order exposure; the company also stressed that the breach does not affect the security of its hardware wallets, which is true, and beside the point for anyone who now has to assume their address is on a phishing list.
Verdict: the best choice if auditability is your top priority, and the Safe 5 is the value sweet spot of the whole market. Best for users who want to inspect what they run and do not mind a slightly less polished app than Ledger’s.
Coldcard: the Bitcoin-only air-gap after the entropy hack
Coldcard, made by Coinkite in Canada, is the connoisseur’s Bitcoin signer: Bitcoin only, dual secure element, fully air-gapped over microSD or QR, with paranoid features like duress PINs and decoy wallets. The Q model ($249) adds a full keyboard and larger screen; the Mk4 (around $178) is the cheaper classic. For a certain kind of Bitcoiner it has long been the reference device.
Then came the worst hardware-wallet loss of the year, and the cruel part is that it was not a hardware failure. The July exploit traced to that build flag in firmware 4.0.1 from March 2021, which substituted a weak software random number generator and dropped the entropy of any seed generated under it from 128 bits to as low as 40 bits. Attackers brute-forced those seeds and swept about 1,816 BTC, roughly $116 million, and crucially a firmware update cannot heal a seed that was already created weakly; even a passphrase did not save affected users (TRM Labs).
The lesson for a buyer is not that Coldcard is a bad wallet; it is that a top-tier, security-obsessed device with real secure elements was undone by the least glamorous component in the whole system, its randomness. Current firmware and freshly generated seeds are not affected, and the truly careful move on any Coldcard is to add your own dice-roll entropy at setup so you never have to fully trust the device’s generator in the first place.
Verdict: still the reference air-gapped Bitcoin signer for advanced users, on the condition that you generate a fresh seed on current firmware. Best for Bitcoin-only holders who want maximal, verifiable cold storage and will read the manual. Not the device for a multichain beginner.
Tangem: the seedless card and the laser
Tangem is the outlier that makes the most people comfortable and the most experts nervous. It is a smartcard you tap against your phone over NFC, and there is no seed phrase by default. The private key is generated on a Samsung S3D232A EAL6+ chip and, only at setup, cloned to one or two backup cards. A two-card pack runs about $54.90, a three-card pack about $75, and there is a Ring version near $150. It has been audited by Kudelski, Riscure and Cure53, and it has no firmware-update mechanism whatsoever.
That last point became the story in July, when Ledger’s Donjon lab published a laser fault-injection attack: a nanosecond pulse faults a single check in the card’s SetPin routine, resetting the access password without the original password or a backup card, after which a held card can be drained. It requires physically holding your card, a laboratory worth around $250,000, roughly two hours per card and real expertise, and because Tangem cannot push firmware, it cannot be patched. No user has ever lost funds to it (Ledger Donjon).
Tangem co-founder Andrey Kurennykh pushed back hard, and his argument is worth weighing: “LFI attacks are not scalable, and for everyday users, the practical risk is virtually non-existent,” and “there have been no known real-world losses from laser fault-injection attacks on any hardware wallet to date.” He frames the non-updatable firmware as a deliberate feature of the seedless design rather than a bug, and concludes that the product is fully safe against real-world attack scenarios (Tangem). Both things are true at once: the attack is real, and it is not a threat to a normal person whose card is not in an attacker’s hands.
Verdict: the easiest genuine cold storage for newcomers and the best device to hand a non-technical relative, with two honest caveats: you can never patch it, and if you lose all your cards there is no seed to restore from, so the spare cards are your only backup. Best for beginners, gifts and phone-native users who value simplicity over auditability.
The open-source challengers and the outliers
Beyond the big four, several devices deserve a place on any serious shortlist, and two of them sit at the price extremes.
- BitBox02 Nova (about $169): a Swiss, fully open-source signer with a dual-chip design including an EAL6+ secure element and a clean companion app. It is the quiet, well-engineered pick for people who want Trezor-grade openness in a different package. Best for privacy-minded Europeans.
- Keystone 3 Pro ($149): three Infineon secure elements, fully air-gapped over QR codes only, with a large touchscreen and open-source firmware. It marries air-gapped security with a phone-friendly workflow at a mid-tier price. Best for buyers who want air-gap without the Coldcard learning curve.
- Foundation Passport (Core $199, Prime $349): a polished, open-source, Bitcoin-focused device with a camera-and-microSD air-gap. Note that the pricier Prime adds NFC and Bluetooth and is therefore not air-gapped, an important distinction the name does not make obvious. Best for Bitcoiners who want a refined air-gapped experience.
- NGRAVE Zero (about $398): the most locked-down and the most expensive, built on an EAL7-certified operating system and fully air-gapped, but closed source. Best for high-value holders who prize the highest certification and do not mind paying for it.
- SafePal S1 (about $50): a capable air-gapped, QR-based multichain signer at a fraction of the price of the others. It is the value entry point, with the fewest independent guarantees about its internals. Best for cost-sensitive users who understand that trade-off.
| Device | Secure element | Source model | Firmware updatable | Air-gap | Notable 2026 event |
|---|---|---|---|---|---|
| Ledger Nano Gen5 | ST33-series, EAL6+ | Closed (BOLOS) | Yes | No | $500M breach class action |
| Trezor Safe 7 | TROPIC01 (open) + Infineon EAL6+ | Open | Yes | No | ShipMonk data breach; lab bypass of 1 of 3 layers |
| Coldcard Q | Dual secure element | Open | Yes | Yes | $116M entropy exploit (old firmware) |
| Tangem | Samsung S3D232A, EAL6+ | Closed | No (by design) | Card / NFC | Donjon laser reset (lab only) |
| BitBox02 Nova | Dual-chip incl. EAL6+ | Open | Yes | No | None reported |
| Keystone 3 Pro | Three Infineon SEs | Open | Yes | Yes | None reported |
| Foundation Passport | Air-gapped, open firmware | Open | Yes | Yes (Core) | None reported |
| NGRAVE Zero | EAL7-certified OS | Closed | Yes | Yes | None reported |
Blind signing is still what drains you
Here is the failure mode that costs more than any cracked chip: a user approving a transaction they could not read. Blind signing is when the device shows an unintelligible payload and you tap approve anyway, trusting that the interface built it correctly. Ledger CTO Charles Guillemet has warned for years that a blind-signed transaction is “not intelligible by default. It’s a digital payload,” which is why his rule is “don’t trust, verify” (Cointelegraph).
The fix is clear signing, where the screen tells you in plain language that you are sending a specific amount to a specific address or granting a specific approval. The standard that makes this work is ERC-7730, which Ledger co-developed and then handed to the Ethereum Foundation as steward in May 2026, alongside Trezor, MetaMask, WalletConnect and others; blind signing has been implicated in billions of dollars of losses, including the Bybit hack (Ethereum Foundation).
This is about to matter even more. As AI agents begin initiating transactions on people’s behalf, the screen where a human verifies what is really being signed becomes the last line of defense, a point security researchers keep hammering; we covered the agent-security angle in When the AI Agent Breaks Out: Trail of Bits on Crypto Security. The practical takeaway for this review: a signer that forces you to blind-sign for the chains and apps you actually use is a downgrade, no matter how good its chip or how nice its screen.
The $5 wrench and the leaked address book
Two threats never appear on a spec sheet, and both got worse in 2026. The first is physical coercion, the so-called wrench attack, where someone simply forces you to unlock your own wallet. Chainalysis counted about $30 million in confirmed thefts from such attacks in the first half of 2026 (roughly $107 million including attempts) across 46 known incidents, with kidnappings featuring in 52% of them and home invasions climbing from 14% to 37% of cases; France was a particular hotspot (Chainalysis). As the firm put it, “Criminals have recognized that crypto holders are high-value targets because they possess wealth in an instantly and irreversibly transferrable form.”
The defenses here are behavioral more than technical: keep your holdings quiet, do not advertise them, and use features built for exactly this, like Coldcard’s duress PIN that opens a decoy wallet, or a modest hot balance held separately from your real stack. This is also the argument for multisig on larger holdings, since no single coerced signature moves the funds.
The second invisible threat is the maker’s own data. Your device can be flawless and your home address can still leak through the vendor’s shop or a fulfillment partner, as Ledger’s 2020 breach and Trezor’s ShipMonk incident both showed. Leaked contact data turns into targeted phishing, and in the worst cases it feeds the physical attacks above. That is why a company’s data practices belong in a hardware review at all: buy through official channels, give the least information you can, and treat every unsolicited message claiming to be from Ledger or Trezor as hostile.
Which signer for which buyer
Because there is no single winner, the honest way to end a roundup is with a map from who you are to what you should buy.
| If you are… | Your main risk | Recommended signer |
|---|---|---|
| New to self-custody, modest multichain holdings | Phishing and mistakes | Tangem or Ledger Nano Gen5 |
| Bitcoin only, larger holdings | Firmware, entropy, coercion | Coldcard Q (fresh seed) or Foundation Passport |
| Active multichain DeFi user | Blind signing, malicious dApps | Ledger Nano Gen5 or Trezor Safe 5 |
| Open-source purist | Trusting closed firmware | Trezor Safe 7 or BitBox02 Nova |
| High-net-worth, long horizon | Single point of failure | Multisig across two brands (e.g. Coldcard plus Trezor) |
| Buying for a non-technical relative | Losing the seed phrase | Tangem |
Backup, inheritance and the day the company dies
Here is the fact that reframes every review above: the device is disposable, the seed is everything. Almost every reputable signer hands you a standard BIP39 seed phrase, usually 12 or 24 words, that restores your coins on any compatible wallet from any maker. If Ledger, Trezor or Coinkite vanished tomorrow, your funds would be untouched as long as you held those words. That portability is itself a buying criterion, and it is the reason a vendor going bankrupt is not the catastrophe people fear.
The practical rules follow from that. Write the seed on metal rather than paper so it survives fire and water, keep copies in separate locations, and consider a passphrase (a 25th word) so a found backup is not enough on its own. For inheritance, the low-tech version still works best for most people: sealed written instructions, held by a lawyer or in a safe, that explain where the seed is and how to use it. Multisig and time-locked recovery services add resilience for larger estates. This is the same trust-versus-control question that runs through custody generally, which we mapped in Bitcoin L2s After the Liquid Hack: Where the Trust Lives.
Tangem is the deliberate exception. With no seed phrase, your backup is the spare cards you created at setup, which is wonderfully simple until you realize that losing all of them means there is no restore path. Keep them physically apart, and treat the loss of the last card the way everyone else treats losing their seed words.
Self-custody and the SEC: the device is yours, the rules are not
A hardware wallet sits deliberately outside the part of the financial system regulators can reach. It holds your private keys; no company can freeze or seize the coins, and no agency licenses the signer in your hand. The Securities and Exchange Commission regulates exchanges, broker-dealers and issuers, not self-custody, and its own investor education now walks retail investors through the choice between holding coins on a platform and holding your own keys (Investor.gov).
That freedom is the whole point, and it cuts both ways. There is no support line that can reverse a mistaken transaction, no chargeback, no password reset. Lose the seed and the coins are simply gone. Where the broader rulebook is heading, who must register and what counts as a regulated intermediary, is a live fight we track in DeFi Compliance in 2026: The Rulebook Goes to the Senate, but none of it changes the basic bargain of a signer: you take on the responsibility an exchange would otherwise carry, in exchange for control an exchange can never give you.
Frequently Asked Questions
What is the best hardware wallet in 2026?
There is no single best signer; the right one depends on what you hold and what you are defending against. For broad multichain use with readable transactions, the Ledger Nano Gen5 and the Trezor Safe 5 lead. For Bitcoin-only cold storage, the Coldcard Q with a freshly generated seed and the Foundation Passport stand out. For beginners and gifts, Tangem’s seedless card is the simplest, and high-value holders should spread keys across two brands in a multisig rather than trust any single device.
Are hardware wallets still safe after the 2026 Coldcard and Trezor incidents?
Yes, with context. The Coldcard losses came from a weak-randomness firmware flag, not a broken chip, and only affected seeds generated under old firmware; fresh seeds on current firmware are not exposed. The Trezor breach leaked customer names and addresses through a shipping partner, not private keys, so no coins were at risk from it. A signer that keeps your keys offline is still far safer than leaving coins on an exchange, as long as you buy from official channels and back up your seed.
Why does Ledger call its devices signers now?
In late 2025 Ledger stopped using the term hardware wallet and began calling its products signers, arguing that coins never actually live on the device; the device only holds your private keys and signs transactions. The company also renamed its Ledger Live app to Ledger Wallet and framed the change around protecting digital identity as AI-driven fraud grows. The word changed, but the job of guarding keys and approving transactions offline did not.
Do I need a hardware wallet if I only hold Bitcoin?
If your Bitcoin is worth more than you would be comfortable losing to a phone or laptop compromise, yes. A Bitcoin-only air-gapped signer such as the Coldcard or the Foundation Passport keeps your keys off any internet-connected device and lets you verify every transaction on a trusted screen. For smaller amounts any reputable signer works; the point is moving keys off exchanges and hot wallets into something you control.
What happens to my crypto if the wallet maker goes out of business?
For almost every hardware wallet, nothing: your coins live on the blockchain, and your seed phrase, usually 12 or 24 BIP39 words, restores them on any compatible wallet from any maker. That portability is why the seed backup matters more than the brand. The exception is Tangem, which has no seed phrase by design, so its backup is the spare cards you set up at the start; keep them in separate places.
Yuki Tanaka is a senior wallets and exchanges correspondent at HOGE Wire, covering self-custody, key management and the security of the tools crypto holders rely on.