Skip to content

Ranked & Reviewed

Best Hardware Wallets

Compare the best hardware (cold) wallets for self-custody, ranked on secure element design, firmware transparency, coin support, and real-world usability.

No money changes hands. This is a non-commercial project: no advertising, no sponsored placements, and no affiliate or referral links. Links to the services below earn us nothing. Every overall score is the plain average of the criteria shown on the page, so you can check the arithmetic yourself — see our rating methodology and how the site is funded.

Dan Reyes

By Dan Reyes · Last checked Jul 24, 2026

Best Hardware Wallets, ranked by score

Rank 1

Keystone 3 ProTop score

Air-gapped signing with the widest asset support

Keystone lists the 3 Pro at $149 with three independent security chips, QR-code and microSD signing that never needs a cable, and both hardware and software published as open source. On the documented facts it is the most complete device in this category.

Price & value
8.0
Secure element
10.0
Open source
10.0
Air-gap & verification
10.0
Asset coverage
10.0

Pros

  • Vendor states three independent security chips
  • Both hardware and software published as open source
  • Fully air-gapped signing over QR codes or microSD
  • Stated support for 5500+ assets across 45+ software wallets

Cons

  • Larger and heavier than a USB-stick form factor
  • Battery-powered devices need periodic charging
  • We have not used the device; scoring is from published specifications
Rank 2

Trezor Safe 5

Best balance of price, certification and asset support

Trezor prices the Safe 5 at $129 with an EAL6+ certified chip, a colour touchscreen and microSD support. It is the cheapest certified-element device here and supports thousands of assets, though the vendor page does not name the chip model.

Price & value
9.0
Secure element
8.0
Open source
8.0
Air-gap & verification
7.0
Asset coverage
9.0

Pros

  • $129 on the official store — lowest price among certified-element devices here
  • EAL6+ certified chip
  • Colour touchscreen with Gorilla Glass 3
  • Vendor states support for thousands of coins and tokens

Cons

  • Chip model is not named on the product page, only its certification level
  • Open-source claim covers design and security but the page does not spell out what is fully published
  • Signing needs a USB-C connection; no QR camera
Rank 3

Coldcard Mk5

Same security model as the Q at a lower price

Coldcard lists the Mk5 at $189 with the same two-vendor secure element design and reproducible open-source firmware as the Q, but without the QR camera — air-gapped signing runs over microSD instead.

Price & value
7.0
Secure element
10.0
Open source
10.0
Air-gap & verification
8.0
Asset coverage
4.0

Pros

  • Same dual secure elements as the Coldcard Q
  • Reproducible open-source firmware
  • $100 below the Q at list price
  • microSD air-gapped signing

Cons

  • No QR camera, so air-gapping depends on microSD
  • Bitcoin only
  • Smaller screen than the Q
Rank 4

Coldcard Q

Maximum-paranoia Bitcoin-only signing

Coldcard lists the Q at $289 with two secure elements from different vendors, reproducible open-source firmware and QR, microSD, NFC and USB connectivity. It is Bitcoin-only by design and the most expensive device here.

Price & value
5.0
Secure element
10.0
Open source
10.0
Air-gap & verification
10.0
Asset coverage
4.0

Pros

  • Two secure elements from different vendors (ATECC608 and DS28C36B)
  • Firmware is open source and reproducible
  • QR, microSD, NFC and USB — full air-gap possible
  • Dual microSD slots for signing workflows

Cons

  • $289 list price, the highest in this comparison
  • Bitcoin only — no support for any other asset
  • Keyboard form factor is bulky compared with a USB signer
Rank 5

BitBox02

Swiss-made simplicity with fully open firmware

Shift Crypto lists the BitBox02 at EUR 124.17 with a dual-chip design, fully open-source firmware and USB-C. A Nova edition at EUR 145.83 adds Bluetooth and a certified EAL6+ secure chip.

Price & value
8.0
Secure element
7.0
Open source
9.0
Air-gap & verification
5.0
Asset coverage
7.0

Pros

  • Firmware is fully open source on both editions
  • Multi and Bitcoin-only editions offered
  • Swiss engineered and manufactured
  • Nova edition adds an EAL6+ certified chip and Bluetooth

Cons

  • Base model's secure chip carries no certification level on the product page
  • USB-C only on the standard edition — no air-gapped workflow
  • Asset list is narrower than the broadest devices here
Rank 6

Blockstream Jade Plus

Fully open-source air-gapped signing for Bitcoin

Blockstream lists Jade Plus at $169.99 and Jade Core at $99, fully open source, with air-gapped transactions and firmware upgrades. It uses a virtual secure element rather than a dedicated chip, which the vendor explains as a deliberate design choice.

Price & value
6.0
Secure element
5.0
Open source
10.0
Air-gap & verification
10.0
Asset coverage
4.0

Pros

  • Fully open source with code published for verification
  • Air-gapped transactions and air-gapped firmware upgrades
  • Camera on Jade Plus for QR workflows
  • Jade Core available at $99

Cons

  • No dedicated physical secure element — the vendor uses a virtual one
  • Bitcoin and Liquid only
  • Jade Plus at $169.99 costs more than devices with certified chips
Rank 7

Ledger Nano Gen5

Named, certified chip and the widest app ecosystem

Ledger gives the Nano Gen5 at roughly $179 with a named ST33K1M5 secure element certified to CC EAL6+, USB-C, Bluetooth 5.2 and NFC, and a Recovery Key in the box. It is the only device here whose firmware is not published for inspection.

Price & value
7.0
Secure element
9.0
Open source
3.0
Air-gap & verification
5.0
Asset coverage
9.0

Pros

  • Names both the chip (ST33K1M5) and its certification (CC EAL6+)
  • Ledger Recovery Key and three recovery sheets included
  • USB-C, Bluetooth 5.2 and NFC
  • Vendor states support for thousands of cryptocurrencies

Cons

  • Firmware is not published for public inspection on the pages we checked
  • No QR or microSD path, so no fully air-gapped workflow
  • Price is given only as approximate and varies by region

At a glance

Best Hardware Wallets: score and best use per service
ServiceScoreBest for
Keystone 3 Pro9.6Air-gapped signing with the widest asset support
Trezor Safe 58.2Best balance of price, certification and asset support
Coldcard Mk57.8Same security model as the Q at a lower price
Coldcard Q7.8Maximum-paranoia Bitcoin-only signing
BitBox027.2Swiss-made simplicity with fully open firmware
Blockstream Jade Plus7.0Fully open-source air-gapped signing for Bitcoin
Ledger Nano Gen56.6Named, certified chip and the widest app ecosystem

What is a hardware wallet?

A hardware wallet is a physical device that stores the private keys to your cryptocurrency offline and signs transactions inside the device, so the keys never touch an internet-connected computer. You approve or reject each transaction on the device itself. Because the signing happens in isolated hardware, malware on your phone or laptop cannot extract the keys or move funds without your physical confirmation.

How does a hardware wallet keep keys safe?

Three mechanisms do the work. A secure element is a tamper-resistant chip, often certified to a Common Criteria assurance level such as EAL5+ or EAL6+, that stores the seed and resists physical extraction. A seed phrase — usually 12 or 24 words following the BIP39 standard — is the human-readable backup from which every key is derived; whoever holds it controls the funds. On-device verification means the receiving address and amount are shown on the device's own screen, so a compromised computer cannot swap in an attacker's address without you seeing it.

What should you check before buying one?

  • Secure element and certification: whether a dedicated chip is present and the assurance level it is certified to. Some designs use two independent chips; a few deliberately use none and rely on a different model.
  • Open source: whether firmware, hardware design, or both are published, and whether builds are reproducible so the code can be shown to match what runs on the device.
  • Verification method: how a transaction reaches the device — QR code, microSD, USB or Bluetooth — and whether a fully air-gapped workflow, with no cable to a computer, is possible.
  • Asset coverage: which chains are supported. Bitcoin-only devices reduce attack surface by design; multi-asset devices trade some of that for breadth.

Custodial versus self-custody

A hardware wallet is self-custody: you hold the keys and bear full responsibility for the seed backup. There is no password reset and no support line that can recover a lost seed. That is the point — no third party can freeze, seize or lose your funds — but it places the burden of secure backup entirely on you. Store the seed phrase offline, never type it into a website or app, and treat anyone who asks for it as an attacker.

How we score this category

A hardware wallet is a security product, and almost everything that matters about one is published: the chip inside it, the certification that chip carries, whether the code can be inspected, and how a transaction is verified. That makes the category unusually checkable, so it is scored strictly on documented facts rather than on impressions — every figure below traces to a vendor page listed at the foot of each review.

Every service in this ranking is scored 0–10 against the same 5 criteria, each carrying equal weight (20% apiece). The overall score is their plain average, rounded to one decimal place, and each review prints the individual numbers and the arithmetic so you can reproduce the result yourself.

What each criterion covers

Price & value20% of the score
Recommended retail price at the vendor's own store, what ships in the box, and whether a backup or recovery accessory is included or sold separately. We use the published price, not a promotional one.
Secure element20% of the score
Whether a dedicated secure element is present, its chip model where the vendor names it, and the Common Criteria assurance level it is certified to. Designs using more than one independent chip, or deliberately using none, are described as such rather than penalised for not matching a single template.
Open source20% of the score
How much can actually be inspected: firmware, hardware design, or both, and whether builds are reproducible so the code published can be shown to match the code running. Vendor claims are counted only where a public repository is linked.
Air-gap & verification20% of the score
How a transaction reaches the device and how it is verified before signing — QR camera, microSD, USB or Bluetooth — and whether a fully air-gapped workflow is possible without connecting the device to a computer at all.
Asset coverage20% of the score
Assets and networks the vendor states are supported, and third-party wallet compatibility. Bitcoin-only devices score lower here by definition; the review text says plainly when that is a deliberate design decision to reduce attack surface rather than a shortcoming.

What does not affect a score

Nothing commercial, because there is nothing commercial to affect it. This is a non-commercial project: no advertising, no sponsored placements, and no affiliate or referral links anywhere on the site. Links to the services above earn us nothing, so no provider can buy a score, a rank, or an entry in this list. Where two services finish level, they are listed alphabetically rather than ordered silently.

The process across all categories, including how often we re-check, is set out in our ratings methodology.

Frequently asked questions

What is a hardware wallet and how does it protect crypto?

A hardware wallet is a physical device that stores your private keys offline and signs transactions internally. Because the keys never leave the device or touch an internet-connected computer, malware and phishing sites cannot extract them, which is why cold storage is considered the strongest self-custody option.

Is a secure element necessary in a hardware wallet?

A certified secure element resists physical extraction and side-channel attacks, adding meaningful protection if the device is lost or stolen. Some wallets instead use open microcontrollers with open-source firmware for verifiability. Both models can be sound; the trade-off is closed hardware certification versus fully auditable code.

Can I recover my funds if my hardware wallet is lost or broken?

Yes, provided you backed up the recovery seed phrase generated at setup. That BIP39 seed lets you restore your keys on any compatible wallet. Store it offline, never digitally, and never share it. Losing both the device and the seed means the funds are unrecoverable.

Rankings are editorial. Nothing here is financial advice. Editorial policy · How we score · How we're funded.