Ledger vs Trezor vs Tangem: Sealed, Open, or Seedless in 2026
Ledger seals its keys in a certified chip, Trezor open-sources everything, Tangem drops the seed phrase. After 2026's laser attacks and breaches, here's which cold wallet fits you.
A hardware wallet has one job: keep your private key off the internet and inside a chip that will not surrender it. In 2026, that job stopped being something anyone could take on faith. Researchers pointed a laser at one brand’s chip and reset its password. A five-year-old software flag drained roughly $116 million from another brand’s users without anyone ever touching their devices. A break-in at a shipping partner spilled the names and home addresses of tens of thousands of buyers into criminal hands. With Bitcoin trading near $77,000 on 11 September as markets braced for fresh US inflation data, per Fortune’s price tracker, the interesting question is no longer which cold wallet has the nicest screen. It is which security model you are actually willing to trust with the keys to your money.
Ledger, Trezor and Tangem are the three names most first-time buyers weigh against each other, and they make three genuinely different bets. Ledger seals its secrets inside a certified, closed chip and asks you to trust the certificate. Trezor open-sources everything it can, now including the secure element itself, and asks you to trust the crowd that can read the code. Tangem throws out the recovery phrase altogether, puts your key on a tap-to-sign card, and asks you to trust a piece of silicon that can never be updated. This guide breaks down what each bet buys you, what it costs, and which kind of holder each one suits, using the hard lessons of 2026 as the stress test.
Three bets on the same problem
The shared problem is easy to state and hard to solve. Your crypto is not stored “in” any wallet; it lives on the blockchain. What a wallet holds is the private key that authorizes moving those coins. A hardware wallet, also called cold storage, keeps that key inside a dedicated offline device and signs transactions internally, so the secret never touches an internet-connected phone or laptop where malware can read it. If you want the longer argument for why a separate device beats a browser extension, our comparison of who really owns your wallet lays out the hot-wallet trade-offs; the short version is that a signing device you can hold is a smaller target than software running next to your email.
Ledger’s chairman and chief executive Pascal Gauthier makes the case for dedicated hardware bluntly. “You cannot ask a general-purpose phone or laptop to protect your most sensitive secrets,” he wrote in a July essay, adding that “everything that is in software is close to impossible to protect.” That premise is one all three brands share. Where they split is on how the key is guarded once it is on the device, and how you get your money back if the device is lost, stolen or destroyed. That single choice, sealed versus open versus seedless, ripples through the price, the attack surface, the recovery story and even how each company reacts when someone finds a hole.
The 2026 lineups and what they cost
Ledger sells four current signers. The Nano S Plus is the entry point at around $79, a compact device with physical buttons, a small screen and no battery. The Nano Gen5, at $179, adds a color touchscreen and is the value pick of the range. The Flex ($249) and the Stax ($399) are the premium touch models, the Stax carrying a curved E Ink screen designed by Tony Fadell, a creator of the iPod. Crucially, all four run the same ST33-series secure element and the same closed-source BOLOS operating system; the extra dollars buy a bigger screen and nicer materials, not stronger key protection.
Trezor’s line climbs from the Safe 3 (around $79) through the Safe 5 (around $169) to the flagship Safe 7, which the company unveiled in Prague in October 2025 and began shipping on 23 November 2025 at $249, according to a detailed CryptoSlate review. The Safe 7 matters more than its price tag suggests: it is the first Trezor built with two secure elements, and the first to carry the TROPIC01 chip that the company spent years developing.
Tangem breaks the mold on both form and price. Instead of a gadget you charge and cable up, you buy a set of NFC smartcards, or a ring. A two-card set costs about $55 and a three-card set about $75, with the Tangem Ring around $150. There is no screen, no battery and no cable. You tap the card against your phone to sign a transaction, and the app on the phone is the interface.
| Brand | Model | Price (USD) | Form factor | Secure element / OS | Notes |
|---|---|---|---|---|---|
| Ledger | Nano S Plus | ~$79 | USB stick, buttons | ST33 (EAL5+/6+), closed BOLOS | Entry model, no battery |
| Ledger | Nano Gen5 | $179 | Touchscreen | ST33 (EAL6+), closed BOLOS | Best value in the range |
| Ledger | Flex | $249 | E Ink touch | ST33 (EAL6+), closed BOLOS | NFC, wireless |
| Ledger | Stax | $399 | Curved E Ink touch | ST33 (EAL6+), closed BOLOS | Fadell-designed premium |
| Trezor | Safe 3 | ~$79 | Buttons + screen | Optiga (EAL6+), open firmware | Entry secure-element model |
| Trezor | Safe 5 | ~$169 | Touchscreen | Optiga (EAL6+), open firmware | Color touch |
| Trezor | Safe 7 | $249 | Touchscreen | TROPIC01 + Optiga (EAL6+), open | Two secure elements, Bluetooth, Qi2 |
| Tangem | 2-card set | ~$55 | NFC card | Samsung (EAL6+), closed firmware | Seedless, tap to sign |
| Tangem | 3-card set | ~$75 | NFC card | Samsung (EAL6+), closed firmware | Extra backup card |
| Tangem | Ring + 2 cards | ~$150 | NFC ring | Samsung (EAL6+), closed firmware | Wearable form |
Ledger: the sealed, certified vault
Ledger’s whole philosophy rests on two pillars: a certified secure element and a locked-down operating system. Its ST33-series chips carry Common Criteria certifications as high as EAL6+, the same grade of evaluation used for electronic passports and bank cards, and the BOLOS operating system that runs on them is closed source. You cannot read Ledger’s firmware or independently audit the chip; instead you trust the certification, the internal Donjon security lab and the company’s decade-long track record. Gauthier is unapologetic about the trade-off, writing that “the safest place to store value is Bitcoin on a Ledger” in a threat environment where, as he put it, “hackers are winning.”
The closed model carries a reputational cost, and Ledger has paid it in public more than once. In mid-2020, a breach of the company’s e-commerce and marketing database exposed roughly 1.1 million email addresses and about 272,000 records that included names, phone numbers and physical home addresses, data later dumped on a hacker forum and fed into years of phishing and extortion, as BleepingComputer documented. In December 2023, attackers phished a former employee’s software-registry account and pushed malicious code into Ledger’s widely used Connect Kit library, draining more than $600,000 from users of many different dapps before a clean version shipped within about 40 minutes, TechCrunch reported. And in 2023 the launch of Ledger Recover, an opt-in subscription that shards your recovery phrase across three custodians after an identity check, set off a backlash precisely because it proved a closed device many owners assumed could never export a key could, by design, be built to do exactly that.
None of those incidents cracked the secure element itself, which is Ledger’s point: the chip held, the humans and the surrounding software did not. But each one also illustrated the cost of a model where users cannot verify what the device is doing and have to take the company’s word for it.
Trezor: open source down to the chip
Trezor, built by the Czech company SatoshiLabs, makes the opposite wager. Its firmware has always been open source, and with the Safe 7 the company extended that principle to the one component the whole industry had treated as an unavoidable black box: the secure element. Chief executive Matej Žák frames openness as the security feature. “We are the most secure because we are the most open-source,” he told DL News. “In the past, we used chips under NDA, and if we found a problem, we couldn’t warn anyone, even if competitors using the same flawed chip attacked us for being insecure.”
The Safe 7’s answer is TROPIC01, a secure element co-designed through a sister venture, Tropic Square, and billed as the first auditable secure element on the market, with its code, SDK and documentation published on GitHub. It does not stand alone: the Safe 7 pairs TROPIC01 with a conventional Infineon Optiga secure element certified to EAL6+ and an STM32U5 microcontroller, so two independent secrets must be combined with your PIN to decrypt the wallet, an arrangement Trezor describes as designed to prevent access after any single component fails. “The Trezor Safe 7 is generally more secure because it’s our first device with two secure elements,” Žák said. “Crucially, one of these is auditable.”
It is worth being precise about one marketing claim. The Safe 7 introduced post-quantum cryptography, but for verifying firmware updates and proving device identity (using schemes such as SLH-DSA and ML-DSA), not for signing your blockchain transactions, which still use the same elliptic-curve signatures every wallet uses. Trezor’s history also carries a caution: the older Model One and Model T shipped with no secure element at all, just a general microcontroller, which left them exposed to physical seed-extraction attacks if a thief had the device in hand. The Safe series exists to close exactly that gap.
Tangem: a wallet with no seed phrase
Tangem’s bet is the most radical of the three: get rid of the recovery phrase entirely. There is no twelve or twenty-four word backup to write down, photograph by accident or lose in a house fire. Instead, when you set up a Tangem set, the secure element on each card generates a private key internally and clones it across the two or three cards (or the ring) in your set over an encrypted NFC link, one time, at setup. Each card is then a full, independent copy of your wallet. You keep them in different places; lose one, and the others still work.
The cards use a Samsung secure element certified to EAL6+, generate keys on-card and sign by NFC tap. Tangem has published three external security reviews over the years, by Kudelski Security in 2018, Riscure in December 2023 and Cure53 in 2026, the last covering its mobile SDK. The defining design decision, and the source of its biggest controversy in 2026, is that Tangem cards have no firmware update mechanism at all. The company presents this as a feature: nothing can be changed after manufacture, so nothing can be tampered with remotely or slipped in through a malicious update. The flip side is that a flaw baked into the silicon can never be fixed. That trade-off moved from theory to headline in July.
The laser-lab argument that split the industry
In 2026, Ledger’s Donjon lab did something unusual: it turned its fault-injection rig on both of its main rivals and published the results. The findings, and the very public arguments that followed, are the clearest window into what “sealed,” “open” and “seedless” actually mean when someone attacks them.
Against Tangem, Donjon described a laser fault-injection attack on the card’s Samsung S3D232A secure element. By firing a single, precisely timed nanosecond laser pulse at one location on the chip’s die, the researchers could flip a single conditional check inside the SetPin handler in Tangem’s closed firmware, making the card accept a new access password without the legitimate recovery steps ever running. In other words, an attacker in physical possession of your card could reset its password and drain it. Donjon disclosed the flaw to Tangem on 10 February 2026 and published it on 9 July. The catch, in both directions, is severe: the lab setup costs around $250,000, each card takes roughly two hours of hands-on work, and because Tangem cards cannot receive firmware updates, the flaw can never be patched. Donjon reported no real-world losses; this was a laboratory result.
Tangem pushed back hard, and the exchange became a rare public fight between two wallet makers. Co-founder Andrey Kurennykh argued that “LFI attacks are not scalable, and for everyday users, the practical risk is virtually non-existent,” and that “the gap between a successful laboratory attack and actual harm to users is an abyss.” He also reframed the non-updatable design as a deliberate consequence of going seedless: a seed-based wallet can be built to wipe its keys if it detects tampering, but in a seedless architecture, he wrote, “that same response risks locking the user out of their own funds in case of rare false-positive sensor alerts.” Tangem’s bottom line, in its official reply: “Our product is fully safe against real-world attack scenarios, and this article doesn’t change that.”
Trezor did not escape the same lab. On 3 June 2026, Donjon published research on the Safe 7’s TROPIC01 chip, showing it could bypass signature verification and run unauthorized firmware on chip samples, again only with physical access and specialized equipment, per CryptoSlate’s review. Here the open, layered design told a different story: Donjon’s initial tests left the chip’s separate “MAC-and-Destroy” secret storage intact, and Trezor argued the research “does not demonstrate recovery of a complete Safe 7 wallet” because the PIN and the second secure element still stand in the way. No user funds were lost. The contrast Trezor drew was less about the specific chip than about the model: because the design is open, the attack could be discussed, verified and reasoned about in public, rather than argued over from behind an NDA.
| Dimension | Ledger | Trezor | Tangem |
|---|---|---|---|
| Source model | Closed (BOLOS) | Open source, incl. TROPIC01 SE | Closed firmware |
| Secure element | ST33 series, EAL5+/6+ | Optiga EAL6+ (+ TROPIC01 on Safe 7) | Samsung EAL6+ |
| Firmware updates | Yes | Yes | None by design |
| Recovery model | Seed phrase (opt-in Recover) | Seed phrase, Shamir backup | Seedless, backup cards |
| 2026 lab finding | Chip uncracked; software/humans breached | Chip fault-injection, full wallet not recovered | Laser resets password, unpatchable |
| Who can audit it | Ledger plus certifier | Anyone | Contracted auditors |
The Coldcard hack: when the entropy is the enemy
The scariest hardware wallet story of 2026 involved none of the three. Beginning on 30 July, attackers started draining Bitcoin from users of Coinkite’s Coldcard, a popular Bitcoin-only signer, and TRM Labs put confirmed losses at 1,816 BTC, roughly $116 million, across more than 5,200 addresses. What makes it the defining lesson of the year is how it worked: not a laser, not a phishing email, but a build-configuration error in a firmware release from March 2021 that caused some devices to generate seeds using a weak software random number generator instead of the hardware entropy source. The result collapsed the effective strength of those keys from a designed 128 bits to as little as 40 bits on older devices, low enough to brute force remotely. No attacker ever needed to touch a victim’s device.
The Coldcard episode reframes what a wallet buyer should worry about. A tamper-proof chip is worthless if the randomness that generates your key is predictable, and a flaw in a build flag can sit dormant for years before someone works out how to exploit it at scale. It puts a premium on reproducible builds (so the shipped firmware provably matches the public source), on high-quality on-chip entropy, and on a company’s ability to respond, migrate users and recover, the same messy after-the-fact work we covered in our look at Halborn and crypto’s recovery race. For the three wallets here, it is a reminder that “secure element” is a necessary claim, not a sufficient one; how the key is born matters as much as where it is stored.
Blind signing, clear signing, and what you actually approve
A hardware wallet only helps if you understand what you are approving on its screen. For years, most on-chain approvals were “blind”: the device showed an unreadable blob of hexadecimal, and the user tapped confirm because the alternative was not transacting at all. Blind signing has been blamed for some of the largest thefts in the industry, and it is exactly the failure mode that clear signing sets out to end by rendering transactions in structured, human-readable language.
The standard behind it, ERC-7730, began at Ledger, but in a notable move on 12 May 2026 the company handed stewardship of it to the Ethereum Foundation, so that no single vendor controls the registry of contract descriptions. The Foundation’s announcement lists Ledger, Trezor, MetaMask, WalletConnect, Fireblocks and others as ongoing stewards, which means the two hardware rivals in this comparison are on the same side of this particular fight. In practice, the payoff of a larger touchscreen (the Ledger Flex and Stax, the Trezor Safe 7) is not vanity: more screen means more room to show a legible summary of what a transaction will do before you sign it. Tangem, which relies on the paired phone for its interface, inherits both the convenience and the risk of that phone’s display. The broader question of which wallets can actually stop a malicious approval is one we tackled head-on in our drainer test of MetaMask, Phantom and Rabby; the hardware layer is only as safe as the screen where you confirm.
The warehouse breach: ShipMonk and your address book
The most instructive incident of 2026 for hardware wallet owners was not a chip exploit at all. In August, Trezor disclosed that a breach at ShipMonk, a third-party fulfilment partner, had exposed customer data. The first disclosure, on 13 August, covered 13,689 people, of whom 11,742 had their full name, email, phone number and shipping address exposed. Then it grew. By early September, Trezor confirmed the incident reached roughly 81,000 customers after an additional 67,000 US buyers, who had ordered between November 2019 and August 2021, were found to be affected, The Hacker News reported. The sting in the tail: Trezor said it had “repeatedly requested and received written assurance confirming the deletion” of that older data, which had nonetheless persisted in ShipMonk’s systems. The root cause was a critical SQL-injection vulnerability (CVE-2026-72898) in an analytics tool, exploited by an extortion group.
Trezor was quick to stress that “the breach does not affect the security of the company’s hardware wallets,” and that is true in the narrow sense: no keys were exposed. But it misses why buyers should care. A leaked list of confirmed hardware wallet owners with home addresses and phone numbers is a targeting database. It feeds convincing phishing (fake “your Trezor is compromised” emails), bogus support calls and, at the extreme, it points criminals at the front doors of people known to hold crypto. Ledger’s own 2020 breach followed the identical arc, from database leak to phishing to physical extortion letters. The lesson is uncomfortable and brand-agnostic: the manufacturer’s data handling is part of your threat model, so buy from official channels, consider a shipping address that is not your home, and treat any unsolicited “wallet security” contact as hostile.
The $5 wrench: the physical threat model
Security researchers have a name for the attack no chip can stop: the “$5 wrench attack,” where someone simply coerces you into unlocking your own wallet. In 2026 it stopped being a joke. Chainalysis counted 46 violent, crypto-related incidents through late June, with about $30 million stolen in successful attacks (and more than $107 million targeted when you include attempts). Kidnappings featured in 52% of incidents and home invasions in 37%, and France emerged as a striking hotspot with at least 30 publicly known cases. The one hopeful number: only 26% of attempts succeeded in extracting a payment, down from 49% in 2025, suggesting more holders are learning not to keep everything reachable from a single device.
This is where a leaked address book (see the ShipMonk breach above) and a physical threat model meet, and it is where the three wallets diverge in a way that matters. Ledger and Trezor both support passphrase-protected hidden wallets: a secret word, never stored on the device, unlocks a separate account, so a coerced owner can hand over a decoy wallet holding a small balance while the real funds stay invisible. That plausible-deniability option is a genuine defense against coercion. Tangem’s seedless model makes hidden-wallet setups less straightforward, and its physical cards, which look innocuous, cut both ways: harder to identify as a wallet, but with no self-destruct if taken. For anyone whose holdings, or whose public profile, make them a plausible target, the practical takeaways are old-fashioned: keep the bulk of funds behind a passphrase, split holdings across devices, and never advertise them.
Backups, recovery, and inheritance
Losing access is a far more common way to lose crypto than being hacked, which makes the recovery model the least glamorous but most consequential difference between these three. Trezor offers the most robust options: a standard seed phrase, or Shamir backup, which splits the secret into multiple shares (say, three of five) so that no single sheet of paper is a single point of failure and a partial loss is survivable. Ledger uses a standard seed phrase by default and, for those who want it, the opt-in Ledger Recover subscription that shards an encrypted copy across three custodians, retrievable after identity verification, a convenience that trades some self-custody purity for a safety net.
Tangem’s seedless model is the sharpest trade-off of all. Because there is no seed phrase, there is nothing to steal from a drawer, nothing to phish and nothing to fat-finger, which eliminates whole categories of user error. But there is also nothing to write down and hand to an heir. Your backup is the physical set of cards; inheritance means making sure a trusted person can find and use one of them, ideally with the access code, when you are gone. That is arguably easier to explain to a non-technical heir than a 24-word phrase, but it is only as good as the physical custody plan behind it. Whichever model you choose, the failure to plan for succession is its own risk, and no secure element addresses it.
Where the rules stop: self-custody and the SEC
One thing all three wallets have in common is that, in the United States, the Securities and Exchange Commission does not regulate the device in your hand. The SEC’s crypto enforcement, which remains active into 2026 as we detailed in our piece on its whistleblower and enforcement machine, targets exchanges, issuers and intermediaries that hold customer assets or sell securities, not the act of holding your own keys. A hardware wallet you control is not a regulated custodian, and moving your coins to one is not a reportable event.
That distinction is the whole point of self-custody, and it cuts both ways. There is no help desk, no chargeback and no regulator to appeal to if you get phished or lose your backup; the responsibility is entirely yours. It also sits inside a shifting compliance backdrop: anti-money-laundering rules such as the FATF Travel Rule, which we examined in the context of stablecoins and money-laundering rails, apply to the exchanges and licensed providers you buy from and cash out to, not to the wallet itself. In practice that means your on-ramp and off-ramp are the regulated choke points; the wallet in the middle is yours alone, for better and worse.
Which wallet for which user
There is no single winner here, because the three brands are not really answering the same question. The right pick depends on what you hold, how you transact and what you are most afraid of. The matrix below maps common holder profiles to the strongest fit.
| Holder profile | Best fit | Why |
|---|---|---|
| Multichain / DeFi power user | Ledger Flex or Stax | Broad asset support, large screen for clear signing, mature app ecosystem |
| Open-source purist | Trezor Safe 7 | Auditable firmware and secure element, Shamir backup, verifiable claims |
| First-timer / mobile only | Tangem 3-card set | No seed to lose, tap-to-sign simplicity, lowest price |
| Bitcoin-focused saver | Trezor Safe 5 or a Bitcoin-only signer | Simple, open, strong backup; single-chain focus |
| Inheritance-minded holder | Trezor (Shamir) or Ledger (Recover) | Structured, shareable recovery for heirs |
| Plausible wrench target | Ledger or Trezor plus passphrase | Hidden-wallet decoy defends against coercion |
If you want the widest ecosystem and the polish of a modern touchscreen, Ledger is hard to beat, provided you are comfortable trusting a certificate you cannot read. If you want to verify rather than trust, Trezor’s Safe 7 is the most open device the category has produced, and its handling of the Donjon research showed the value of daylight. If you want self-custody without the ceremony of a seed phrase, Tangem is the simplest on-ramp, as long as you accept a card that can never be patched. The one bet none of them can make for you is the discipline: buy from official channels, understand what you sign, plan for the wrench and plan for your heirs. In 2026, those habits protected more coins than any secure element did.
Frequently Asked Questions
Which is the safest hardware wallet in 2026: Ledger, Trezor, or Tangem?
There is no single safest choice, because each makes a different trade-off. Ledger relies on a certified but closed secure element, Trezor on fully open source down to an auditable chip, and Tangem on a seedless card that cannot be updated. All three keep keys offline, and none suffered real-world losses from the 2026 laboratory attacks. The safest wallet is the one whose security model you understand and whose recovery plan you will actually follow.
Can a hardware wallet really be hacked with a laser?
In a laboratory, yes. In 2026, Ledger’s Donjon team used laser fault injection to reset a Tangem card’s password and to bypass part of the Trezor Safe 7’s chip protections. But both attacks required physical possession of the device, roughly $250,000 of equipment, and hours of expert work, and neither produced any real-world theft. For everyday users, phishing and malware are far more likely threats than a laser.
Is Tangem safe if its cards can never be updated?
Tangem argues that its seedless, non-updatable design removes the biggest everyday risks: there is no seed phrase to phish or lose, and no update channel to poison. The downside is that a flaw baked into the firmware can never be patched, as the 2026 laser research showed. For typical holders, Tangem considers the practical risk minimal, while buyers who fear a targeted physical attack may prefer a device with a passphrase-protected hidden wallet.
What was the Coldcard hack, and does it affect Ledger, Trezor, or Tangem?
The Coldcard hack drained about $116 million in Bitcoin from July 2026, caused by a 2021 firmware flag that made some devices generate weak, guessable keys with no physical access needed. It did not affect Ledger, Trezor, or Tangem devices directly, but it is a warning for all of them: a secure chip cannot save you if the randomness that creates your key is predictable. It raised the value of reproducible builds and strong on-chip entropy.
Does the SEC regulate hardware wallets in the United States?
No. The SEC regulates exchanges, token issuers, and custodians that hold other people’s assets, not a self-custody device you control. Moving crypto to your own hardware wallet is not a reportable event, and the wallet is not a licensed custodian. The regulated points are the exchanges you use to buy and sell, where rules such as the FATF Travel Rule apply; the wallet itself is your responsibility alone.
Yuki Tanaka is HOGE Wire’s wallets and self-custody correspondent, covering hardware security, exchanges and on-chain safety.