Independent DeFi security desk · Status: operationalMethodology & corrections · Submit an incident
Wallet Guides · Compared 2026-09-29

Hardware wallets compared: Ledger, Trezor and BitBox02

A hardware wallet does one job: keep the signing key somewhere a browser cannot reach, and make you confirm each signature on a screen the computer does not control. This table compares the main options on that job and on the practical questions around it - setup, backup, companion app and price band.

Who this is for: Readers holding more value than they are comfortable leaving in a browser wallet.

Short answer

Pick the device whose confirmation screen you will actually read and whose companion app you will actually keep updated. The differences between the main vendors matter less than buying from a legitimate source and treating the recovery phrase as the real asset.

Some outbound links on this page may become partner links if a commercial agreement is signed. Partner status never changes which products are listed, the order of the table, or the notes underneath it. We do not accept payment to remove a warning. See the affiliate disclosure for details. Affiliate disclosure →

The comparison

3 options
Option Form factorSigning confirmationCompanion softwareFirmware accessBackup modelCost band
Ledger USB and Bluetooth devices, with and without a screenOn the device screen, with a physical button pressLedger Live plus a large set of supported third-party walletsVendor-distributed firmware; the secure element is not fully open sourceRecovery phrase written by you; some models also support on-device backup featuresEntry-level to premium, rises with screen size and features
Trezor USB, touchscreen or button-operated devicesOn the device screenTrezor Suite, with third-party wallet supportOpen-source firmware, publicly reviewableRecovery phrase written by youEntry-level to premium, depending on model
BitBox02 Compact USB-C device with touch sensorsOn the device, with touch gesturesBitBoxApp, plus third-party integrationsOpen-source firmware with a documented build processRecovery phrase, or a microSD backup cardMid range

Cells marked with a dash mean we could not verify the detail from public documentation at the review date.

Why each option is in the table

More in Wallet Guides →

Ledger

Why it is here
The widest third-party wallet support, so it slots into most existing DeFi workflows without changing how you operate.

What to watch
Buy directly or from an authorised reseller. Never accept a pre-initialised device, and never enter a recovery phrase that a device or a website displays for you.

Trezor

Why it is here
Open-source firmware is the reason many security-focused readers choose it: the signing logic can be read by anyone.

What to watch
The cheapest model is not equivalent to the higher models in physical protections. Compare model against model, not brand against brand.

BitBox02

Why it is here
Fewer features and a smaller supported-chain list, which for some readers is a feature rather than a limitation: less surface area to reason about.

What to watch
Narrower dapp support than the two larger vendors. Check that your specific chains and workflows are supported before buying.

Common questions

What is the biggest risk with a hardware wallet?

Not the device - the recovery phrase. Anyone who reads those words can move the funds without touching your device. Store them offline, never photograph them, never type them into a website, and never let a support conversation ask for them.

Can a hardware wallet be drained without a signature?

Not through the signing key. Losses attributed to hardware wallets almost always trace back to a phrase that was exposed, a device bought from a compromised seller, or an approval granted in a software wallet that shares the same address.

Do I still need to revoke approvals with a hardware wallet?

Yes. The device controls how a transaction is signed, not which permissions already exist on-chain. Approvals granted in the past remain active regardless of what signs for the address today.

Method. We build each table from vendor documentation and, where possible, a hands-on test of the flow described in the row. We do not rank products by revenue, and we do not publish return, yield or profit claims. Interface details, chain support and fees change often: treat every cell as a starting point and confirm it on the vendor's own documentation before you rely on it.

Related reading

All topics →

BNB Chain crosses $1B in tokenized stocks, ETFs as market hits $3.7B

Tokenized stocks and ETFs on BNB Chain reached $1.1 billion as the broader market climbed to $3.7 billion, putting the network’s share at roughly 30%.

SMBC Nikko partners with Uniswap on Japan-compliant DeFi gateway targeted for mid-2027

This partnership could pave the way for integrating DeFi into regulated markets, potentially transforming financial systems globally.

Aave founder says V3 unaffected after third-party adapter exploit drains $305K

Aave founder Stani Kulechov said Aave v3 was unaffected after an attacker exploited a third-party adapter to drain about $305,000 from two Safe multisig wallets.

Spot bitcoin ETFs log $2.7 billion in September inflows as institutional demand holds

US spot bitcoin ETFs recorded $2.65 billion in net inflows in September, their second-largest monthly inflow since October 2025.

Aave v3 exploit drains up to $310K after Safe module attack

The exploit highlights the critical need for rigorous security audits of third-party modules in DeFi, as vulnerabilities can lead to significant financial losses.

NEAR Intents says its identified the hacker, gives 48-hour ultimatum

“We have identified you, sir,” NEAR Intents general manager Alex Shevchenko said on Friday after the protocol was hacked for $3.8 million.

Sponsor this page

Put your product next to this decision.

Sponsored placements are labeled and never change the table, the order, or the warnings. Send your product, destination and placement.

View advertising options →