15 services rated

Best Hardware Wallets

Signing devices ranked on secure element, firmware openness and recovery design.Every score below is the weighted mean of the rubric marks, not an editor's gut feel.

How we score this category

Full methodology →
Key isolation
Secure element or equivalent, whether keys can ever leave the device, and resistance to physical extraction.
25%
Firmware openness
How much of the stack is open source and reproducibly buildable, and whether independent researchers can audit it.
20%
Recovery design
Seed standards, passphrase support, backup options, and whether recovery ever requires trusting the vendor.
20%
Asset coverage
Chains and applications supported natively and through third-party wallets.
15%
Vendor conduct
Supply-chain controls, breach history, and how the company behaves when it makes a mistake.
10%
Usability
Whether a careful non-expert can set it up, verify a transaction and recover it without help.
10%
8.9
Rank 1 · Strong

Swiss-made, fully open, dual-chip, and the easiest of the serious devices to actually live with.

Key isolation
9.0
Firmware openness
9.5
Recovery design
9.0
Asset coverage
7.0
Vendor conduct
9.5
Usability
9.0
8.8
Rank 2 · Strong

The most open device in the category, and the first Trezor whose secure element closes the gap that dogged its predecessors.

Key isolation
8.5
Firmware openness
10.0
Recovery design
9.0
Asset coverage
8.0
Vendor conduct
8.0
Usability
9.0
8.7
Rank 3 · Strong

Three secure elements, QR-only communication, and broad chain support — the strongest air-gapped device that is not Bitcoin-only.

Key isolation
9.5
Firmware openness
8.0
Recovery design
8.5
Asset coverage
9.0
Vendor conduct
8.0
Usability
8.5
8.7
Rank 4 · Strong

The Safe 5's security at half the price, with a smaller screen and buttons instead of touch.

Key isolation
8.5
Firmware openness
10.0
Recovery design
9.0
Asset coverage
8.0
Vendor conduct
8.0
Usability
8.0
8.5
Rank 5 · Strong

Ledger-class chain coverage with open firmware — undermined slightly by a vendor still building its track record.

Key isolation
8.5
Firmware openness
9.0
Recovery design
8.0
Asset coverage
9.0
Vendor conduct
7.5
Usability
8.5
8.3
Rank 6 · Strong

The most paranoid Bitcoin device on the market: dual secure elements, true air-gap, and no interest in making things easy.

Key isolation
10.0
Firmware openness
9.0
Recovery design
9.5
Asset coverage
4.0
Vendor conduct
9.0
Usability
6.0
8.2
Rank 7 · Strong

Fully open hardware and firmware, assembled in the United States, with a phone-like interface that makes air-gapping bearable.

Key isolation
9.0
Firmware openness
9.5
Recovery design
8.5
Asset coverage
4.0
Vendor conduct
9.0
Usability
8.5
8.0
Rank 8 · Strong

The best screen in the category, which matters more than any other feature when you sign contract calls all day.

Key isolation
8.5
Firmware openness
7.0
Recovery design
8.0
Asset coverage
8.5
Vendor conduct
7.5
Usability
8.5
8.0
Rank 9 · Strong

The most physically hardened device on the market, at a price and openness level that narrow its audience sharply.

Key isolation
9.5
Firmware openness
6.0
Recovery design
8.5
Asset coverage
7.5
Vendor conduct
8.0
Usability
7.5
7.9
Rank 10 · Solid

The cheapest credible open-source device, using a clever blind-oracle design instead of a secure element.

Key isolation
7.5
Firmware openness
9.5
Recovery design
8.5
Asset coverage
4.5
Vendor conduct
9.0
Usability
8.0
7.6
Rank 11 · Solid

The most capable device by coverage, from the vendor with the worst record on trust in the category.

Key isolation
9.0
Firmware openness
5.0
Recovery design
7.0
Asset coverage
10.0
Vendor conduct
5.5
Usability
9.0
7.6
Rank 12 · Solid

You build it from commodity parts and it stores nothing — the purest answer to supply-chain risk, for people who enjoy that answer.

Key isolation
7.5
Firmware openness
10.0
Recovery design
8.0
Asset coverage
4.0
Vendor conduct
9.5
Usability
5.5
7.6
Rank 13 · Solid

A bank card with a secure chip: astonishingly easy, at the cost of the backup model everyone else uses.

Key isolation
8.5
Firmware openness
6.5
Recovery design
6.0
Asset coverage
8.5
Vendor conduct
7.5
Usability
9.5
7.1
Rank 14 · Solid

Wide coverage and a real air gap for fifty dollars, with closed firmware and a Binance-adjacent ownership story.

Key isolation
7.5
Firmware openness
4.5
Recovery design
7.5
Asset coverage
9.0
Vendor conduct
6.5
Usability
8.0
7.0
Rank 15 · Solid

A sealed metal slab with no ports at all — strong on physical security, weak on everything you would need to verify it.

Key isolation
8.0
Firmware openness
4.0
Recovery design
7.0
Asset coverage
9.0
Vendor conduct
6.5
Usability
8.0

How OBOL rates hardware wallets

A signing device has one job: keep a private key somewhere software cannot reach it, and show you honestly what you are about to sign. Key isolation therefore carries the most weight, followed by firmware openness — because a security claim nobody outside the company can check is a marketing claim.

Recovery design is weighted equally with openness for a simple reason: far more crypto is lost to bad backups than to attackers. We favour standard seed phrases you can restore on any compatible device, and we mark down schemes that make the vendor a necessary party to getting your funds back.

The blind-signing problem

Most losses involving hardware wallets are not extraction attacks. They are users approving a transaction whose meaning the device could not display. Devices with larger screens and proper transaction decoding get credit here, and devices that show you a hash and ask for confirmation do not.

What a hardware wallet does not protect you from

It will not save you from signing a malicious approval, from a compromised recipient address, or from writing your seed into a phone. It protects the key, not the decision. Every score in this category assumes you still verify addresses on the device screen.

FAQ

Open source or secure element — which matters more?
Both, and the strongest devices now combine them. A secure element resists physical extraction; open firmware lets researchers verify there is no backdoor. Devices that give up one entirely score lower here.
Is an air-gapped device meaningfully safer?
It removes an attack surface — no USB or Bluetooth stack to exploit — at the cost of convenience. For large, rarely moved holdings, that trade is usually worth it.
Does the vendor ever need to be involved in recovery?
With a standard BIP39 seed, no: any compatible device restores it. Be cautious with proprietary recovery services, which reintroduce exactly the third party the device exists to remove.