Jump to content

Trezor Wallet

From BitcoinWiki
Trezor hardware wallet
Trezor hardware wallet.

Trezor is a family of hardware wallets developed by the Czech company SatoshiLabs. The devices keep the private keys used to authorize cryptocurrency transactions separate from a general-purpose computer or phone. The first commercial model, now called Trezor Model One, was released on 29 July 2014 and is described by the company as the first commercially available Bitcoin hardware wallet.[1][2]

Operation

A Trezor device derives and stores wallet keys and signs transactions inside the device. The companion Trezor Suite application, or another compatible wallet interface, prepares a transaction; the user checks important details such as the destination address and amount on the device display before approving the signature. This separation reduces the exposure of private keys to malware on the connected host, but it does not make every transaction safe: users can still approve a misleading address or disclose their wallet backup to a phishing site.[3][4]

During setup, the device creates a wallet backup from multiple sources of randomness. Model One and Model T combine randomness from the host with a hardware random-number generator in the device's STM32 microcontroller; Safe 3 and Safe 5 add an OPTIGA secure element, while Safe 7 adds a further TROPIC01 source. The backup, and any optional passphrase, can restore access if the device is lost or damaged. Anyone who obtains the complete backup and passphrase can control the wallet, so neither should be entered into an unsolicited application or website.[5]

Backup formats vary by model and firmware. Model One uses BIP39 word backups, while Model T and the Safe models also support SLIP39 single-share and multi-share backups. A multi-share backup requires a chosen threshold of shares to reconstruct the wallet; one share alone is insufficient. A passphrase-protected wallet requires both the backup and the exact passphrase.[6][7][8]

Models and software

The product line includes Model One, Model T, Safe 3, Safe 5 and Safe 7. Model T began shipping in 2018; Safe 3 was introduced in 2023, Safe 5 in 2024, and Safe 7 in 2025. The Safe models introduced secure elements alongside Trezor's publicly reviewable firmware, and Safe 7 added a second secure element, a touchscreen, Bluetooth connectivity and wireless charging.[9]

On 8 January 2026, SatoshiLabs ended direct e-shop sales of Model One and Model T. It said that both models would receive basic maintenance until at least 2031 and critical security updates until at least 2036, with new-coin support for Model T continuing until at least 2031.[10]

Trezor publishes firmware and software source code in public repositories. The devices support PIN protection, signed-firmware checks and optional passphrases. After repeated incorrect PIN attempts, current devices erase their stored wallet data: Safe 7 does so after ten attempts and the other listed models after sixteen. These controls protect the device, but the separately stored wallet backup remains the ultimate recovery secret.[11][12]

Trezor Suite is the official management application and is available in desktop, web and mobile forms. Asset compatibility varies by device model and interface: some assets are managed directly in Suite, while others require a compatible third-party wallet. Trezor maintains a current compatibility list. All listed models support U2F second-factor authentication; Safe 3, Safe 5, Safe 7 and Model T also support FIDO2 passkeys, while Model One does not.[13][14][15]

Security incidents

On 9 September 2026, an unauthorized actor used access to Brevo, Trezor's third-party newsletter provider, to send phishing email from customer accounts including Trezor's. The message falsely claimed that an STM32 entropy flaw endangered some devices and directed recipients to download software that requested their wallet backup. Trezor said the incident exposed its opt-in newsletter database of about 347,000 email addresses, that no other Trezor system was affected, and that it suspended the Brevo account. Brevo said the wider incident affected 120 customer accounts.[16][17]

The incident did not establish a weakness in Trezor's hardware entropy generation. Its practical risk was social engineering: a recipient who supplied a wallet backup to the malicious application could give the attacker control of the corresponding funds. Trezor advises users to install software only from official sources and states that it does not request wallet backups by email.[18]

See also

  1. Our Story, SatoshiLabs, accessed 15 September 2026.
  2. A decade of pioneering, Trezor, 29 July 2024.
  3. Trezor hardware wallets and their advantages, Trezor, accessed 15 September 2026.
  4. EthClipper: A Clipboard Meddling Attack on Hardware Wallets with Address Verification Evasion, arXiv, 2021.
  5. What is entropy and how does Trezor generate your wallet, Trezor, accessed 15 September 2026.
  6. How to use a wallet backup, Trezor, accessed 15 September 2026.
  7. SLIP39 FAQs, Trezor, accessed 15 September 2026.
  8. What is a passphrase?, Trezor, accessed 15 September 2026.
  9. Trezor fundamentals, Trezor, accessed 15 September 2026.
  10. How long will Trezor Model One and Model T be supported?, Trezor, accessed 15 September 2026.
  11. Trezor source repositories, GitHub, accessed 15 September 2026.
  12. PIN protection on Trezor devices, Trezor, accessed 15 September 2026.
  13. Trezor Suite, Trezor, accessed 15 September 2026.
  14. Supported coins and assets, Trezor, accessed 15 September 2026.
  15. Using your Trezor as a security key, Trezor, accessed 15 September 2026.
  16. Security incident at Brevo, our third-party email provider, Trezor, 10 September 2026.
  17. Bitcoin Wallet Maker Trezor Says Hackers Breached Its Email Provider, Decrypt, 9 September 2026.
  18. Is my device safe to use?, Trezor, accessed 15 September 2026.