Open app

HostDeFi › Is Trezor safe

Is Trezor safe? Open-source custody with a documented 15-minute extraction

Trezor is the ideological opposite of Ledger: fully open-source firmware and hardware schematics, no closed Secure Element — auditable by anyone, which is the entire pitch. It is also the only mainstream hardware wallet with a publicly documented, working seed-extraction attack: in January 2020 Kraken Security Labs demonstrated voltage glitching that pulls the encrypted seed off a Trezor One or Model T in about fifteen minutes with ~$75 of equipment. Both facts are true at once, and the page that respects you holds them together.

Updated September 28, 2026 · By the HostDeFi editorial desk · Sources linked throughout; vendor claims labeled.

What a Trezor device is

Trezor, from SatoshiLabs, shipped the first hardware wallet in 2014 and built its reputation on radical openness: firmware, hardware design, and protocol are all public and independently audited — anyone can verify what the device does with your keys, and no closed chip sits between you and the signing code. Classic models (Trezor One, Model T) ran on a general-purpose STM32 microcontroller rather than a secure element; the newer Safe family (Safe 3, Safe 5) added an EAL6+ Secure Element while keeping firmware open — an architecture shift that exists because of the attack documented below.

Custody is the standard hardware-wallet shape: keys generated on-device, signatures inside, a recovery phrase shown once that restores everything. Trezor additionally pioneered two features the class copied: the BIP39 passphrase (a 25th-word extension that derives a wholly separate wallet — and, critically here, is never stored on the device) and Shamir Backup (SLIP39), which splits recovery into threshold shares. Those two features turn out to be the difference between the documented attack being fatal and being irrelevant.

January 2020: fifteen minutes with a glitcher

On January 31, 2020, Kraken Security Labs published a complete working attack on the Trezor One and Model T — disclosed to SatoshiLabs the previous October. The method: physically open the device, and use voltage glitching (fault injection) on the STM32 microcontroller to re-enable the chip's integrated bootloader; a second glitch bypasses the protection check; the flash contents then read out 256 bytes at a time until the entire encrypted seed is extracted. The seed encryption keys to a 1–9 digit PIN, which brute-forces trivially. Total hands-on time: about fifteen minutes; equipment cost in the hundreds of dollars at research grade, with Kraken estimating a mass-produced glitcher at ~$75.

The unflinching detail: the vulnerability is in the STM32 chip itself — software cannot fix it; SatoshiLabs's own response conceded only a hardware redesign closes it (Ledger's Donjon lab had earlier demonstrated a sibling extraction, ~5 minutes, ~$100 equipment, also unpatchable on those models). What saves the user is the feature that was never stored on the chip: a strong passphrase. The extracted seed without the passphrase opens an empty decoy wallet; the real funds live behind a secret that exists only in your head — which is why Trezor's answer to "is it safe" is "with a passphrase, yes" and why the Safe series now carries a secure element.

The honest trade: open versus sealed

The Ledger-vs-Trezor comparison is usually argued as open-source virtue versus secure-element paranoia, and the record supports a calmer version. Trezor's bet: everything auditable means no hidden firmware path can exist — there is no Ledger Recover-style "the chip can export it" question because all the code is public. The cost: a general-purpose MCU is physically attackable in ways a secure element is engineered against, and that cost was demonstrated, end-to-end, in public.

What the exchange actually produced: Trezor's Safe 3/5 now run an EAL6+ opt-in secure element for the seed while keeping firmware open-source — the first architecture that argues both sides at once. And the counterparty fact: no remote theft, malicious update, or supply-chain key extraction has ever been documented on a genuine Trezor; every demonstrated break requires the device in the attacker's hands, the case opened, and lab equipment — i.e., the threat is theft-plus-lab, not malware.

The breach that wasn't on the device

Like Ledger, Trezor's company-layer incident hit the humans. In January 2024 SatoshiLabs disclosed that an unauthorized actor had accessed its third-party support ticketing system, exposing names and email addresses of up to ~66,000 users who had contacted support since December 2021. No funds, keys, or devices were involved — but a list of confirmed Trezor owners is phishing fuel, and targeted "support" emails followed the same playbook as the Ledger leak: urgent security warnings, firmware-update links, seed-verification traps.

The structural lesson both hardware vendors taught: buying the device de-links your keys from the internet, and buying it as a registered customer re-links your identity to "owns crypto hardware." Trezor's advice mirrors the honest rule: they never ask for your recovery phrase or send unsolicited firmware links — every message that does is the leak working.

What actually protects a Trezor

The checklist the attack record implies, in order of consequence: use a passphrase — it is the difference between a stolen Trezor being a $75 extraction job and a dead end, and it costs you one more secret to hold; buy only from trezor.io — a resold or pre-seeded device defeats everything else; treat physical custody as the threat model — the documented breaks need the device, the case opened, and lab gear, which means your real exposure is theft, coercion, and "lost" luggage, not remote malware; and Shamir or steel for the backup — the phrase is the other half of custody and it gets no chip at all.

And the standard disclaimer the open-source model earns: auditable code is verification, not armor — it tells you there is no hidden path, and the 15-minute attack tells you the visible one exists on the classic chips. A Trezor behind a strong passphrase, bought direct, on the Safe series is about as hardened as consumer self-custody gets; a Trezor One without a passphrase in a checked bag is a different answer.

Frequently asked questions

Can a Trezor be hacked?

Physically, yes — it is the only mainstream hardware wallet with a fully documented working extraction. Kraken Security Labs (Jan 2020) pulled the encrypted seed off the Trezor One and Model T in ~15 minutes via voltage glitching on the STM32 chip — needs the device, an opened case, and ~$75-class equipment; the 1–9-digit PIN then brute-forces trivially. Unpatchable on those models (chip-level flaw). Two counters: a strong passphrase (never stored on-device — extraction then yields nothing) and the newer Safe series' EAL6+ secure element. No remote or supply-chain key theft has ever been documented on a genuine device.

Is Trezor safe without a passphrase?

Against remote attack, yes — there is no remote vector into a genuine Trezor. Against the documented physical attack, no — on a Trezor One or Model T, an attacker who steals the device can extract the PIN-encrypted seed and brute-force the PIN. The passphrase is a separate secret that never touches the chip, so an extracted seed opens an empty decoy while real funds stay behind it. If physical theft is in your threat model — travel, shared housing, coercion — the passphrase is the load-bearing defense.

Is Trezor safer than Ledger?

It is a real trade, not a ranking. Trezor: fully open-source firmware — anyone can audit what the device does, no hidden export path can exist; but the classic STM32 models have a documented 15-minute physical extraction (mitigated by passphrase; the Safe series adds an EAL6+ element). Ledger: certified Secure Element with no documented extraction — but closed firmware, the 2020 customer-data breach (272K buyers' addresses), and Ledger Recover proving firmware can export the seed. Verdict: trust auditable code + passphrase → Trezor Safe; trust certified silicon → Ledger.

Did Trezor have a data breach too?

Yes — same shape as Ledger's, smaller. January 2024: SatoshiLabs disclosed unauthorized access to its third-party support ticketing system — names and email addresses of up to ~66,000 users who had contacted support since December 2021. No keys, funds, or devices touched; the exposure is phishing fuel — confirmed owners get "urgent security" mail with seed-verification traps. SatoshiLabs's standing rule covers it: support never asks for your recovery phrase, and no unsolicited firmware link is legitimate.

What is Trezor Shamir Backup?

SLIP39 — instead of one 24-word phrase, your recovery secret splits into multiple shares (e.g., 3-of-5): any threshold subset restores the wallet, one share alone is useless. It solves the two failure modes of a single phrase — theft of the paper and loss of the paper — at the cost of more objects to manage. On the classic models it also composes with the passphrase story: distributed backup plus an unstored passphrase means neither the device nor any single backup artifact is a complete attack.

Which Trezor model is safest?

The Safe series (Safe 3, Safe 5): they add an EAL6+ Secure Element that holds the seed — the direct response to the STM32 voltage-glitching attacks — while keeping firmware open-source, which no other vendor combines. On the legacy One/Model T the answer is "safe with a strong passphrase, physically attackable without one." Whichever model: buy only from trezor.io — a pre-seeded or tampered marketplace device defeats every protection on this page.

HostDeFi is an educational risk tool, not financial advice. On-chain data can be incomplete or manipulated; a clean check is a dated snapshot, not a guarantee. Always do your own research. Free · no signup · a HostDeFi product