Skip to content

Ledger vs Trezor: An Honest Comparison

Both are reputable hardware wallets with genuinely different philosophies. The secure element versus open source trade-off, the controversies on both sides, and which suits which user.

Last reviewed 2026-09-14

The core difference

Ledger uses a certified secure element — a tamper-resistant chip of the type used in bank cards — and keeps its firmware closed source. Strong physical security; you are trusting code you cannot audit.

Trezor publishes everything, hardware and firmware. Fully auditable; the older models use a general-purpose microcontroller that a skilled attacker with physical access can extract keys from. The Safe line adds a secure element while keeping the firmware open.

That is the entire trade-off: verified physical security you cannot inspect, versus inspectable code with a weaker physical guarantee.

What happened on each side

Ledger, 2020. A marketing database breach exposed roughly 270,000 customer names, addresses and phone numbers. No funds were taken, but the list circulated for years and produced targeted phishing and credible physical threats against named holders.

Ledger, 2023. Ledger Recover, an optional paid service that splits an encrypted seed backup across three custodians, was announced without warning. The functional objection was not the service but what it proved: firmware could be written that extracts the seed. The device had been marketed as making that impossible. Ledger has since committed to open-sourcing more of the stack.

Trezor, ongoing. Physical extraction attacks on the Model One and Model T are demonstrated and documented. They require the device in hand and specialist equipment. A strong passphrase mitigates them; Trezor has never disputed the limitation.

Choosing

Ledger if you want the strongest physical security, the widest coin support, and a polished mobile experience — and you accept trusting a closed firmware.

Trezor if verifiability matters more than physical hardening, or if the Recover episode changed how you weigh vendor trust. The Safe 3 and Safe 5 close most of the physical gap.

Either beats leaving a meaningful balance on an exchange. The gap between these two is much smaller than the gap between both of them and a hot wallet.

Buying and setting up

  1. Buy direct from the manufacturer. Never from a marketplace reseller. Supply-chain tampering is real, and a pre-configured device is the most common way beginners lose everything.
  2. Generate the seed on the device. If a device arrives with a seed phrase already written on a card, it is compromised. Destroy it.
  3. Test the recovery with a small amount before transferring anything substantial.
  4. Consider a passphrase. A 25th word creates a hidden wallet. It is also unrecoverable if forgotten — and no one can help you.

What a hardware wallet does not protect you from

It secures the key. It does not stop you signing something harmful: a drainer approval signed on a hardware wallet empties it just as effectively. It does not stop you sending to the wrong address or the wrong network. And it cannot help if the seed phrase is lost.

The device removes one category of risk. The rest is still yours.

Related tools

← All guides