Bitcoin Hardware Wallet Security and Support Tracker
Hardware-wallet safety changes after purchase. Models are discontinued, firmware receives security fixes, and recovery guidance changes. This tracker summarizes first-party support and advisory information checked on August 26, 2026; owners should always confirm the linked live source before acting.
Key points
- COLDCARD owners with seeds generated on affected firmware may need migration; updating alone does not repair an existing seed.
- Trezor disclosed a sophisticated physical attack against one TROPIC01 layer in Safe 7; the company says the remaining layers and PIN still protect funds.
- Trezor Model One and Model T are no longer sold by Trezor but retain published maintenance and critical-fix windows.
- No tracker can replace checking the manufacturer’s current signed firmware and security page immediately before setup or recovery.
Current wallet status at a glance
| Model | Market status | Security model | Current action |
|---|---|---|---|
| Trezor Safe 7 | Current | TROPIC01 + EAL6+ Optiga + STM32U5 | Read the TROPIC01 disclosure; use a strong PIN and current Trezor Suite |
| Ledger Nano Gen5 | Current | Secure Element, Ledger OS, secure touchscreen | Verify device authenticity and current Ledger OS before setup |
| Blockstream Jade Core | Current | Open-source hardware/firmware with blind-oracle model | Understand the blind-oracle dependency and current app compatibility |
| Blockstream Jade Plus | Current | Same Jade architecture with QR and removable-media workflows | Choose transfer workflow deliberately and verify addresses on-device |
| BitBox02 Nova | Current | Open-source firmware plus EAL6+ Optiga secure chip | Use authentic BitBoxApp and verify firmware before wallet creation |
| COLDCARD Mk4 / Mk5 | Current and supported | Bitcoin-only, dual secure elements, source-available firmware | Use standard firmware 5.6.1; assess whether an existing seed requires migration |
| COLDCARD Q | Current and supported | Bitcoin-only, dual secure elements, source-available firmware | Use standard firmware 1.5.1Q; assess whether an existing seed requires migration |
| Trezor Model One / Model T | Discontinued from Trezor store | Open-source legacy architecture | Keep firmware current and plan eventual migration without exposing the seed |
Advisories that require context or action
- COLDCARD seed-generation advisory: Coinkite says fixed standard releases begin at Mk4/Mk5 5.6.0 and Q 1.5.0Q, with 5.6.1 and 1.5.1Q currently recommended. Updating fixes future generation but does not repair a seed created on affected firmware.
- Trezor Safe 7 TROPIC01 disclosure: Trezor reports that Ledger Donjon demonstrated a difficult laser fault-injection attack against TROPIC01. The attack requires possession, chip removal, laboratory equipment, and repetition after power-off. Trezor says it exposes one of several PIN-protection and attestation secrets, not the seed itself.
- Trezor legacy support: Trezor stopped selling Model One and Model T on January 8, 2026. Its published policy says maintenance continues through at least 2031 and critical security fixes through at least 2036.
What the status labels do and do not mean
“Current” means the manufacturer presents the model as part of its active lineup. It is not a safety certification or an endorsement. “No device-specific advisory located” means the reviewed first-party pages did not show one at the check date; it does not prove that no vulnerability exists.
Security architecture labels also describe tradeoffs rather than winners. An open-source design can be inspected publicly. A secure element can increase resistance to physical extraction. A multisig policy can reduce trust in one device. None of these removes the need for verified backups and careful transaction review.
What owners should check periodically
- 1
Open the official security page
Use a bookmarked or independently verified manufacturer domain rather than an email or search advertisement.
- 2
Compare installed and recommended firmware
Check the exact model and release channel. Verify signatures or hashes where the vendor documents that process.
- 3
Read migration language carefully
Some fixes protect future use but cannot change already-generated keys or backups.
- 4
Confirm recovery compatibility
Keep the backup format, passphrase, wallet fingerprint, descriptor, and compatible software documented.
- 5
Test before moving a large balance
Use a small transaction and recovery drill after device replacement or major wallet migration.
Tracker methodology
BitcoinSafe checks manufacturer product pages, support policies, firmware documentation, and public security disclosures. We separate vendor claims from independent conclusions and link the source used for claims that can change. Prices are intentionally excluded because they change by region and promotion.
This is document-based research, not a substitute for hardware teardown, firmware audit, or hands-on recovery testing. Each product profile identifies that limitation explicitly.
Frequently asked questions
Should I update hardware-wallet firmware immediately?
Read the vendor release notes and security notice first, verify the download, confirm your backup, and follow model-specific instructions. Urgent security fixes may justify prompt action, but an unverified or interrupted update creates its own risk.
Is a discontinued hardware wallet unsafe?
Not automatically. The important questions are whether firmware and security fixes continue, whether compatible software remains available, and whether you can migrate without exposing the recovery phrase.
Does a secure element guarantee that a wallet is safe?
No. Secure elements can strengthen physical protection, but wallet safety also depends on firmware, host software, display verification, backup handling, supply chain, and user operation.
Sources and methodology
Claims that can change are checked against the sources below. Product pages report documented features and disclosures; they do not claim hands-on testing unless a test method and evidence are published on the page.
Continue your security plan
Trezor Safe 7 Security Model and Tradeoffs
A source-based look at Trezor Safe 7 security, dual secure elements, TROPIC01 disclosure, encrypted Bluetooth, backups, and who should consider it.
Current wallet researchLedger Nano Gen5 Security Model and Tradeoffs
A source-based guide to Ledger Nano Gen5, its secure touchscreen, Secure Element, Bluetooth, NFC, Ledger Recovery Key, software model, and tradeoffs.
Current wallet comparisonBlockstream Jade Core vs Jade Plus
Compare Blockstream Jade Core and Jade Plus security architecture, blind oracle model, QR and removable-media signing, connectivity, and ideal use cases.
Check the complete setup, not one product feature.
Use the local safety audit to review backups, device access, recovery testing, firmware habits, and inheritance without sharing a seed phrase or private key.