Skip to content
Research tracker12 min read

Bitcoin Hardware Wallet Security and Support Tracker

Hardware-wallet safety changes after purchase. Models are discontinued, firmware receives security fixes, and recovery guidance changes. This tracker summarizes first-party support and advisory information checked on August 26, 2026; owners should always confirm the linked live source before acting.

Published: August 26, 2026Last checked: August 26, 2026By Kevin Kinnett

Key points

  • COLDCARD owners with seeds generated on affected firmware may need migration; updating alone does not repair an existing seed.
  • Trezor disclosed a sophisticated physical attack against one TROPIC01 layer in Safe 7; the company says the remaining layers and PIN still protect funds.
  • Trezor Model One and Model T are no longer sold by Trezor but retain published maintenance and critical-fix windows.
  • No tracker can replace checking the manufacturer’s current signed firmware and security page immediately before setup or recovery.

Current wallet status at a glance

First-party information checked August 26, 2026
ModelMarket statusSecurity modelCurrent action
Trezor Safe 7CurrentTROPIC01 + EAL6+ Optiga + STM32U5Read the TROPIC01 disclosure; use a strong PIN and current Trezor Suite
Ledger Nano Gen5CurrentSecure Element, Ledger OS, secure touchscreenVerify device authenticity and current Ledger OS before setup
Blockstream Jade CoreCurrentOpen-source hardware/firmware with blind-oracle modelUnderstand the blind-oracle dependency and current app compatibility
Blockstream Jade PlusCurrentSame Jade architecture with QR and removable-media workflowsChoose transfer workflow deliberately and verify addresses on-device
BitBox02 NovaCurrentOpen-source firmware plus EAL6+ Optiga secure chipUse authentic BitBoxApp and verify firmware before wallet creation
COLDCARD Mk4 / Mk5Current and supportedBitcoin-only, dual secure elements, source-available firmwareUse standard firmware 5.6.1; assess whether an existing seed requires migration
COLDCARD QCurrent and supportedBitcoin-only, dual secure elements, source-available firmwareUse standard firmware 1.5.1Q; assess whether an existing seed requires migration
Trezor Model One / Model TDiscontinued from Trezor storeOpen-source legacy architectureKeep firmware current and plan eventual migration without exposing the seed

Advisories that require context or action

  • COLDCARD seed-generation advisory: Coinkite says fixed standard releases begin at Mk4/Mk5 5.6.0 and Q 1.5.0Q, with 5.6.1 and 1.5.1Q currently recommended. Updating fixes future generation but does not repair a seed created on affected firmware.
  • Trezor Safe 7 TROPIC01 disclosure: Trezor reports that Ledger Donjon demonstrated a difficult laser fault-injection attack against TROPIC01. The attack requires possession, chip removal, laboratory equipment, and repetition after power-off. Trezor says it exposes one of several PIN-protection and attestation secrets, not the seed itself.
  • Trezor legacy support: Trezor stopped selling Model One and Model T on January 8, 2026. Its published policy says maintenance continues through at least 2031 and critical security fixes through at least 2036.

What the status labels do and do not mean

“Current” means the manufacturer presents the model as part of its active lineup. It is not a safety certification or an endorsement. “No device-specific advisory located” means the reviewed first-party pages did not show one at the check date; it does not prove that no vulnerability exists.

Security architecture labels also describe tradeoffs rather than winners. An open-source design can be inspected publicly. A secure element can increase resistance to physical extraction. A multisig policy can reduce trust in one device. None of these removes the need for verified backups and careful transaction review.

What owners should check periodically

  1. 1

    Open the official security page

    Use a bookmarked or independently verified manufacturer domain rather than an email or search advertisement.

  2. 2

    Compare installed and recommended firmware

    Check the exact model and release channel. Verify signatures or hashes where the vendor documents that process.

  3. 3

    Read migration language carefully

    Some fixes protect future use but cannot change already-generated keys or backups.

  4. 4

    Confirm recovery compatibility

    Keep the backup format, passphrase, wallet fingerprint, descriptor, and compatible software documented.

  5. 5

    Test before moving a large balance

    Use a small transaction and recovery drill after device replacement or major wallet migration.

Tracker methodology

BitcoinSafe checks manufacturer product pages, support policies, firmware documentation, and public security disclosures. We separate vendor claims from independent conclusions and link the source used for claims that can change. Prices are intentionally excluded because they change by region and promotion.

This is document-based research, not a substitute for hardware teardown, firmware audit, or hands-on recovery testing. Each product profile identifies that limitation explicitly.

Frequently asked questions

Should I update hardware-wallet firmware immediately?

Read the vendor release notes and security notice first, verify the download, confirm your backup, and follow model-specific instructions. Urgent security fixes may justify prompt action, but an unverified or interrupted update creates its own risk.

Is a discontinued hardware wallet unsafe?

Not automatically. The important questions are whether firmware and security fixes continue, whether compatible software remains available, and whether you can migrate without exposing the recovery phrase.

Does a secure element guarantee that a wallet is safe?

No. Secure elements can strengthen physical protection, but wallet safety also depends on firmware, host software, display verification, backup handling, supply chain, and user operation.

Sources and methodology

Claims that can change are checked against the sources below. Product pages report documented features and disclosures; they do not claim hands-on testing unless a test method and evidence are published on the page.

Apply the guidance

Check the complete setup, not one product feature.

Use the local safety audit to review backups, device access, recovery testing, firmware habits, and inheritance without sharing a seed phrase or private key.