
Ledger vs Trezor is the wrong question if the only thing you weigh is a feature checklist. Both brands ship hardware wallets that sign transactions offline. The real split is how each company has handled its worst days, and what that says about the trust profile you are actually buying. This piece runs the numbers.
Key Takeaways
- Ledger runs a proprietary Secure Element chip certified up to EAL6+ across its Flex and Stax lineup, and a closed-source operating system that has been at the center of the 2023 Ledger Recover backlash.
- Trezor runs an EAL6+ Secure Element on its Safe 3 and Safe 5 and adds a TROPIC01 auditable Secure Element with post-quantum crypto on the Safe 7, alongside a fully open-source firmware.
- Ledger’s headline incident is the 2020 breach that exposed roughly 1 million email addresses and 272,000 physical addresses; Trezor’s headline incident is the April 2022 MailChimp phishing wave, followed by a January 2024 support-site breach and a June 2025 support-form abuse.
What each brand actually sells today
Ledger’s current lineup covers the Nano S Plus (entry level, cable-only, no iOS), the Nano X (adds Bluetooth BLE 5.2 and a 128 x 64 pixel OLED screen), the Flex (2.8 inch E Ink touchscreen, EAL6+), the Stax (3.7 inch curved E Ink touchscreen, EAL6+) and the newer Nano Gen5. Every model ships with a proprietary Secure Element chip, either the ST33K1M5 or the ST33J2M0 depending on tier. The Ledger Wallet app manages more than 500 coins directly and provides pass-through access to a wider catalog of tokens.
Trezor’s current lineup is anchored on the Safe 3 at $59, the Safe 5 at $129 and the Safe 7 at $249, each also available as a Bitcoin-only firmware variant. The older Model T is officially discontinued, though Trezor has committed to software updates for it until at least 2031. The Model One remains available at entry level. Trezor says it supports “1000s of coins and tokens” across networks including Bitcoin, Ethereum, Solana, Base, Arbitrum One and Cardano, and claims more than 2 million users worldwide.
The chip story matters, because it is the physical basis of what you are trusting. Ledger uses closed Secure Elements from STMicroelectronics under CC EAL5+ and EAL6+ certifications, but Ledger’s firmware sits on top of a proprietary operating system that is only partially open. Trezor’s Safe 3 and Safe 5 also use EAL6+ Secure Elements, and the Safe 7 pairs a certified Optiga chip with the TROPIC01, described as the world’s first auditable Secure Element, plus a post-quantum SLH-DSA-128 signature scheme for firmware updates and device boot. Trezor firmware is publicly reviewable.
This is the first fork in a Ledger vs Trezor decision. Ledger optimizes for a certified black-box supply chain. Trezor optimizes for verifiable code you can audit. Both approaches have merits. Neither is a security guarantee on its own. What separates them in practice is how the two companies have handled the days when things went wrong.

Where security stopped being theoretical
Ledger’s July 2020 breach is the reference point for anyone considering the brand. On July 14, 2020, a researcher flagged unauthorized access to Ledger’s e-commerce and marketing database via an exposed API key. The initial access dated to June 25, 2020. About 1 million customer email addresses were stolen, plus detailed contact information for 9,532 customers at first count, later expanded to roughly 272,000 customers when the full database dump was published on a forum on December 20, 2020. No payment information or credentials were exposed, but the physical-address leak triggered a documented wave of phishing and physical extortion attempts against Ledger customers.
The 2023 Ledger Recover episode is more nuanced. On May 16, 2023, Ledger announced a $9.99-per-month backup service that encrypts a pre-BIP39 version of the private key, splits it into three fragments and distributes them to Coincover, Ledger and an independent backup provider, with 2-of-3 reconstruction back to the device. The community objected that the mere existence of the pathway broke the “keys never leave the device” promise. Ledger postponed the release on May 23, 2023, committed to accelerating open-sourcing of core OS components, and shipped Recover on October 24, 2023 anyway. The trust cost of that sequence is still priced into the Ledger vs Trezor conversation today, particularly for buyers who trace the self-custody preference that grows every time institutional Bitcoin flows leave IBIT and FBTC.
Trezor’s headline event is the April 2022 MailChimp campaign. MailChimp discovered unauthorized access to an internal tool on March 26, 2022, and Trezor customers were phished via fake trezor.us and xn--trzor-o51b.com domains on April 3, 2022. The investigation identified 319 MailChimp accounts viewed, 102 of them with audience data exported, focused on the cryptocurrency and finance industries. Trezor took the phishing domain offline, suspended newsletter communications and warned users not to open Trezor emails until further notice.
The story did not stop there. On January 17, 2024, a third-party support ticketing portal was accessed without authorization, exposing names, usernames and email addresses of 66,000 users who had interacted with Trezor Support since December 2021. Trezor confirmed 41 cases where the exposed data was exploited via phishing messages asking users to disclose their 24-word seed under the pretext of “firmware validation.” No user funds were compromised, per Trezor. Then in June 2025, attackers abused Trezor’s automated support form by submitting tickets with phishing content in the subject line, causing [email protected] auto-replies to echo the phishing content back to victims.
The pattern reads like this. Ledger’s incidents are heavier in blast radius (physical-address leaks, extortion) and touch the brand’s own database and product decisions. Trezor’s incidents are more numerous but consistently rooted in third-party channels (email, support portal) rather than the device itself. Neither profile is comfortable. Both are worth understanding before buying.
Which one fits your profile
For a long-term Bitcoin HODLer with no interest in DeFi, staking or NFTs, a Trezor Safe 3 at $59 in Bitcoin-only firmware is a hard bundle to beat. It gives you the EAL6+ Secure Element, publicly reviewable code and the tightest possible attack surface. The device does one thing, and it does it with the fewest moving parts. This is the profile that historically has cared most about firmware transparency, and Trezor is still the reference here.
For a multi-chain user active on Solana, Base, Arbitrum, staking positions and NFT signing, both brands work, but the ergonomics diverge. Ledger’s Live app has a wider integration catalog and better mobile experience, particularly on iOS. Trezor’s Suite is desktop-first and does not yet cover as many chains at parity. A user living daily on the wider crypto stack that has moved twice as fast as Big Tech in this cycle will feel the difference more on Ledger than on Trezor.
For a user who does not want to touch a centralized exchange after seeing Japan’s crypto exchange consolidation accelerate at the SBI-Bitbank level, the deciding factor is code you can inspect. Trezor’s fully open-source firmware and, on the Safe 7, the auditable TROPIC01 Secure Element with post-quantum firmware signing, is the harder answer to give up.
For an EU-based buyer worried about the residual data risk from the 2020 Ledger dump, the calculus is more personal than technical. Trezor, based in the Czech Republic, has not published a Ledger-scale physical-address leak. That fact alone shifts the balance for some users, independent of chip specs.
The verdict on Ledger vs Trezor is that neither brand is universally better. Ledger buys you the widest software ecosystem and premium industrial design on Flex and Stax. Trezor buys you code transparency, cheaper entry, and the current frontier on auditable Secure Elements with the Safe 7. Pick the one whose failure mode you can live with.
More to come.




