Affiliate disclosure: buying through links on this page may earn us a commission at no extra cost to you (details). Nothing here is investment advice.
Verdict up front: the Trezor Safe 7 is the most interesting hardware wallet of 2026 — not because of its (excellent) screen or its aluminum body, but because it’s the first wallet whose secure element you don’t have to take on faith. If verifiability is why you chose self-custody, this is currently the high-water mark. At $249 $209, it earns its flagship price — with two honest caveats we’ll get to.
Check current Safe 7 price at trezor.io →
Quick specs
| Display | 2.5″ color touchscreen, 520×380, 700 nits, Gorilla Glass, haptic feedback (62% larger than the Safe 5’s) |
| Body | Machine-anodized aluminum unibody, IP54 dust/splash rated, 75.4 × 44.5 × 8.3 mm, 45 g |
| Security chips | Three, from three different vendors: TROPIC01 (auditable SE) + Infineon Optiga (EAL6+, NDA-free) + STM32U5 MCU |
| Connectivity | USB-C, plus open-source encrypted Bluetooth; Qi2 wireless charging |
| Battery | LiFePO₄ — roughly 4× the charge-cycle life of standard lithium cells, holds charge in storage for years |
| Firmware | Open source; optional Bitcoin-only build; post-quantum signatures on updates, authentication, and boot |
| Price | |
| Our verifiability score | 8 / 10 — methodology here |
The headline: a secure element you can actually audit
Every serious hardware wallet uses a secure element — a hardened chip that guards your keys against physical attack. And for years, every one of them has come with the same asterisk: secure elements are closed silicon, wrapped in NDAs, and you simply trust the manufacturer. It’s the one opaque box in an otherwise open-source stack, and it’s the main reason no Trezor or Ledger has ever scored a 10 in our verifiability methodology.
The Safe 7’s TROPIC01 is the first mainstream attempt to remove that asterisk: an auditable secure element whose protection mechanisms can be independently inspected. You don’t have to accept “trust us” — researchers can check. That is a genuinely new thing in this product category, and it’s why the Safe 7 matters beyond its spec sheet.
Smartly, Trezor didn’t bet the house on the new chip. The Safe 7 runs three independent chips from three different vendors — the TROPIC01, a conventional EAL6+ Infineon Optiga (notably licensed without an NDA), and an STM32U5 microcontroller. A compromise of any single component doesn’t compromise your keys. The firmware layer adds another first: post-quantum cryptography protecting firmware updates, device authentication, and the boot chain. Nobody’s quantum computer is stealing coins today — but firmware you install in 2026 may still be guarding your keys in 2036, and this is the right decade to start.
The honest part: it’s already been attacked in a lab
In June 2026, Ledger’s security research team (the Donjon) demonstrated a laser fault-injection attack against the TROPIC01. We cover this in our firmware & security tracker, and we rate it LOW severity: lab-only. Here’s the plain-English version: the attack requires physically possessing your device, decapping work, and laboratory equipment — and even then it defeats only one of the Safe 7’s three security layers. Your PIN, passphrase, and the other two chips still stand between an attacker and your coins.
Two things can be true at once: this finding does not meaningfully change the security of your bitcoin, and it’s exactly what “auditable” looks like in practice — rival researchers probing a chip that’s open enough to probe. Closed secure elements get attacked too; you just don’t get to read about it. We’d rather own a device whose failures are published than one whose failures are secret.
Living with it: the screen, the battery, the Bluetooth question
The 2.5-inch, 700-nit touchscreen is the best display Trezor has shipped — verifying a receive address no longer feels like reading a pager. The aluminum unibody feels like a premium object rather than a plastic fob, and the IP54 rating means a splash won’t end your self-custody journey. The battery choice is quietly clever: LiFePO₄ chemistry trades a little energy density for roughly four times the charge-cycle lifespan, and it holds charge through long storage — the right trade for a device that may sit in a drawer or safe for months between uses. Qi2 wireless charging means the USB-C port can stay untouched for years.
Now the controversial bit: Bluetooth. Air-gap purists will bristle, and we understand why — every radio is attack surface. Three things soften it here: the Bluetooth stack is open-source and encrypted end-to-end (auditable, like the rest of the device), the radio is optional — you can use USB-C exclusively and never pair it — and critically, transaction signing still happens on-device: Bluetooth only carries data a compromised phone could see anyway, never your keys. If wireless still offends your threat model, turn it off — or buy the air-gapped Coldcard Q instead. For everyone else, signing a transaction from your phone without hunting for a cable is the kind of convenience that keeps people actually using cold storage instead of leaving coins on exchanges.
Safe 7 vs Safe 5 vs the competition
The Safe 5 ($129 $109) remains the sensible pick for most people: same Trezor Suite experience, same open-source firmware with a Bitcoin-only option, proven track record. What $249 $209 buys on the Safe 7 is the auditable-chip architecture, the three-vendor redundancy, quantum-ready firmware signing, the bigger screen, metal build, and wireless. Against Ledger’s Flex and Stax: Ledger’s hardware is polished and its screens are lovely, but its secure element remains fully closed and its firmware partially so — which is precisely the philosophical gap the Safe 7 was built to widen. Our full comparison table puts them side by side.
Who should buy it — and who shouldn’t
- Buy it if: you hold enough that flagship-grade hardware is cheap insurance; you care about verifiability as a principle (it’s why you’re on this site); you want the best screen-and-build Trezor has made; or you’ll actually use the wireless workflow.
- Skip it if: you’re starting out — the Safe 3 (
$89$49) secures your first coins with the same firmware; you demand a true air gap — that’s the Coldcard Q’s territory; or you bought a Safe 5 recently — the security delta doesn’t obsolete it.
FAQ
What happens when the battery eventually dies?
The device works over USB-C regardless of battery state, and your keys live in the secure elements, not the battery. LiFePO₄’s 4× cycle life pushes that day far out anyway.
Can I run it Bitcoin-only?
Yes — like the rest of the Safe line, Trezor offers a Bitcoin-only firmware build that shrinks the attack surface to the one chain that matters.
Is the June 2026 security finding a reason to wait?
In our judgment, no. It’s a lab-only attack on one of three layers, requiring physical possession and specialist equipment. Track it (we do, in the tracker), but a thief with your device still faces your PIN, your passphrase, and two more chips.
Bottom line
The Safe 7 is Trezor arguing, in hardware, that “trust me” isn’t good enough — and backing it with a chip anyone can audit, two more chips in case that one fails, and firmware signed against a quantum future. That’s the most verifiability ever shipped in a consumer wallet, and it’s why this is the new reference point at the premium end.
Get the Trezor Safe 7 at trezor.io (current price: $249 $209) → Always buy direct from the manufacturer — never marketplace resellers.

