At a glance
| Attribute | Ledger | Trezor |
|---|---|---|
| Security chip | Secure Element (EAL5+/6+) | Open MCU (+ SE on Safe 3/5) |
| Firmware | Closed-source | Fully open-source |
| Coins supported | 5,500+ | ~1,800 |
| Entry-level price | Nano S Plus — $79 | Safe 3 — $79 |
| Top-of-line price | Stax $399 / Flex $279 | Safe 5 — $169 |
| Companion app | Ledger Live (desktop + mobile) | Trezor Suite (desktop + web) |
Security architecture
Ledger: Secure Element, closed firmware
Every Ledger device stores your seed inside a Secure Element — the same class of tamper-resistant chip used in passports and payment cards. Physical attacks like voltage glitching, side-channel analysis or chip decapping are dramatically harder against an SE than against a general-purpose MCU. The trade-off is that Ledger cannot open-source the SE firmware because the chip is under NDA with its manufacturer. You are trusting Ledger not to ship a malicious firmware update.
Trezor: open MCU, auditable firmware
Trezor devices historically stored the seed on a general-purpose STM32 microcontroller. The advantage: every line of firmware is public and reproducibly built. The disadvantage: with the device in hand, researchers have repeatedly extracted seeds via voltage glitching (Kraken Security Labs on the One, and Unciphered on the Trezor T). The newer Safe 3 and Safe 5 add a Secure Element to close that gap while keeping the firmware open.
Security incident history
Neither device has ever been remotely hacked — the incidents that hit each brand tell you what the realistic risk actually looks like.
- Ledger (2020): e-commerce database breach leaked ~1M customer emails and ~270K physical addresses, kicking off years of targeted phishing and even wrench-attack threats. The devices themselves were not compromised.
- Ledger (2023): Connect Kit supply-chain attack drained ~$600K from dApp users via a compromised npm package — a software integration issue, not a device compromise.
- Ledger Recover (2023): optional key-shard backup service triggered a major community backlash over the principle that a firmware update could, in theory, expose the seed to third parties.
- Trezor One (2020): Kraken Security Labs demonstrated a voltage-glitching attack that extracts the seed in ~15 minutes with physical access.
- Trezor T (2023): Unciphered publicly extracted a seed from a Trezor T via physical voltage glitching.
Which one should you pick?
Pick Ledger if…
- • You hold a broad long-tail portfolio (XRP, SOL, ADA, thousands of tokens).
- • Your threat model is physical theft, not a malicious vendor update.
- • You want the largest ecosystem of dApps and mobile Bluetooth support.
Pick Trezor if…
- • Open-source firmware you can independently audit is non-negotiable.
- • You mostly hold BTC and majors, and want the lowest-risk vendor model.
- • You prefer a company with no history of customer-data breaches.
Compare every wallet side by side
See how Ledger and Trezor stack up against BitBox, Coldcard, OneKey and the rest.
Open the full comparison table