Three questions to ask about any hardware wallet
Most comparisons argue about chips. Three duller questions tell you more:
Does an outside firm test it, and can you read the report? Anyone can claim their device is secure. Paying researchers to attack it and then publishing what they found, including the unflattering parts, costs money and stings.
Do they pay for bugs? A bounty gives someone who finds a flaw a reason to report it rather than sell it, and gives skilled researchers a reason to go looking at all.
Can those researchers see the code? Closed firmware still gets attacked. Fuzzing over USB or QR is routine, and reverse engineering has got cheaper as models have got better at reading disassembly. Source code does not make an audit possible, it makes it cheaper, so more people attempt more of it. Open source beats source available too, because code under a real licence gets reused, and the developers reusing it (sometimes) read it.
All three
Passport publishes firmware under GPL and hardware under CERN-OHL-S v2, complete enough to build one from the files. Outside audits are online with the fixes. The bounty covers the device, though the amount is decided case by case.
Keystone also has all three, with the best evidence that its bounty works: outside researchers found a real firmware flaw and got paid. Audits from two firms, reproducible builds, schematics and secure element firmware published. One catch is theirs alone: researchers are asked not to disclose without written approval, with no time limit.
Two of three
Trezor publishes firmware and hardware and runs the best funded bounty, up to $100,000. No commissioned audit report, but the secure element in its newest device was tested externally and the flaw disclosed publicly.
Ledger pays well and its in house team does serious offensive work, including on rivals. Firmware and OS are closed, so every finding costs more effort. The chips are lab certified, but you only see the certificate.
Open and nothing else
Jade and Bitkey publish firmware, Bitkey with reproducible builds. No audits or bounties, so the code waits for volunteers. Sometimes they turn up: Jade's serious 2025 flaw was found and reported for free.
SeedSigner is as open as anything here and built from off the shelf parts, but there is no company; an audit or bounty was never on offer.
This measures how a company behaves, not how the device is built. Still, between two similar devices, take the one that publishes its code and pays people to break it.
Most comparisons argue about chips. Three duller questions tell you more:
Does an outside firm test it, and can you read the report? Anyone can claim their device is secure. Paying researchers to attack it and then publishing what they found, including the unflattering parts, costs money and stings.
Do they pay for bugs? A bounty gives someone who finds a flaw a reason to report it rather than sell it, and gives skilled researchers a reason to go looking at all.
Can those researchers see the code? Closed firmware still gets attacked. Fuzzing over USB or QR is routine, and reverse engineering has got cheaper as models have got better at reading disassembly. Source code does not make an audit possible, it makes it cheaper, so more people attempt more of it. Open source beats source available too, because code under a real licence gets reused, and the developers reusing it (sometimes) read it.
All three
Passport publishes firmware under GPL and hardware under CERN-OHL-S v2, complete enough to build one from the files. Outside audits are online with the fixes. The bounty covers the device, though the amount is decided case by case.
Keystone also has all three, with the best evidence that its bounty works: outside researchers found a real firmware flaw and got paid. Audits from two firms, reproducible builds, schematics and secure element firmware published. One catch is theirs alone: researchers are asked not to disclose without written approval, with no time limit.
Two of three
Trezor publishes firmware and hardware and runs the best funded bounty, up to $100,000. No commissioned audit report, but the secure element in its newest device was tested externally and the flaw disclosed publicly.
Ledger pays well and its in house team does serious offensive work, including on rivals. Firmware and OS are closed, so every finding costs more effort. The chips are lab certified, but you only see the certificate.
Open and nothing else
Jade and Bitkey publish firmware, Bitkey with reproducible builds. No audits or bounties, so the code waits for volunteers. Sometimes they turn up: Jade's serious 2025 flaw was found and reported for free.
SeedSigner is as open as anything here and built from off the shelf parts, but there is no company; an audit or bounty was never on offer.
This measures how a company behaves, not how the device is built. Still, between two similar devices, take the one that publishes its code and pays people to break it.
349❤️14❤️3👍2🤙2❤1🌻1