Trezor Safe 7 Tested: An Open-Source Hardware Wallet

Bitcoin Magazine

Trezor Safe 7 Review: The FOSS Self Custody Hardware Wallet

Some hardware wallets strive to create air-gapped devices that end users can assemble by hand, or customize for industry professionals within a free and open-source framework. Others keep their source code proprietary, aiming to act as the Apple or Macintosh of hardware wallets by enforcing user guardrails through design. Trezor appears to have struck a middle ground with the Safe 7.

The device feels reminiscent of a modern iPhone, featuring a metal exterior, a wide screen extending to the edges of the device, and tactile feedback specifically engineered to provide user satisfaction. In a way that most other wallets fail to achieve, the Safe 7 successfully conveys the impression and experience that Bitcoin is a tangible, physical entity.

Trezor also bridges the divide between Bitcoin and broader crypto users quite effectively. It achieves this by offering two distinct firmware stacks and designs: a standard multi-coin version available in black and green, and a Bitcoin-only orange edition. Users can freely switch back and forth regardless of which version they originally purchase, though Bitcoiners who know what they want can choose the orange model to avoid any off-path firmware upgrades. Both user types can transition to the alternative firmware option if desired, regardless of the device’s color.

This choice does come with certain implications, however. Many firmware updates focus on coins other than Bitcoin, leaving the Bitcoin-only firmware much leaner. Trezor’s support documentation states clearly: “Added advantages of running Bitcoin-only firmware include fewer regular updates (compared to the Universal firmware) and reduced risk of bugs or security issues.”

Trezor Safe 7 Review: The FOSS Self Custody Hardware Wallet

The Magic Words

For anyone with Bitcoin experience who has never used a Trezor, the first notable feature is the length of the word list. The Safe 7 utilizes 20 words for its wallet backup rather than the standard 12 or 24 used by most competitors, continuing a security design choice Trezor has developed over many years.

Introduced by Trezor in 2019 alongside the Shamir backup feature, this 20-word standard is known as SLIP-39. Shamir allows users to divide their wallet’s backup seed words into multiple shards. A specified threshold of these shards is required to recreate the Bitcoin wallet, while any single shard alone remains insufficient.

Consider a two-of-three Shamir setup: users write down three separate lists of 20 words and store them across distinct physical locations such as a bank, home, and office. If a thief steals one list, or a fire and flood destroys another, the loss is not catastrophic. A single shard cannot grant access to the wallet, while the remaining two shards allow the owner to regain control and transfer coins to a new wallet setup. This quality, often called redundancy, is also accomplished by multi-signature wallets, albeit with different trade-offs such as onchain transaction costs. Shamir backups derive from a well-established cryptographic scheme called Shamir Secret Sharing, for which Trezor built its own implementation.

Trezor Safe 7 Review: The FOSS Self Custody Hardware Wallet

Compared to the more common 12-word standard, these additional words do not provide extra entropy; Trezor clarifies that users receive the same 128 bits of entropy found in 12-word seeds. Nevertheless, Trezor notes that the word list utilized in SLIP-39 is carefully curated to eliminate confusing or phonetically similar words.

Furthermore, SLIP-39 enables functionality that BIP-39 does not: extendability into Shamir. Users who initially set up a single 20-word seed backup on a Trezor device can later generate a redundant set of Shamir shares, such as a three-of-five configuration. Because these shares recreate the identical wallet, users do not need to execute onchain transactions to move funds. They should, however, consider destroying their original 20-word single seed, as it alone can still restore the associated wallets.

Interested users can consult a comprehensive FAQ provided by Trezor. Although SLIP-39 enjoys much lower adoption rates than its predecessor, it is supported by alternative wallets like Sparrow and Electrum.

Trezor Safe 7 Review: The FOSS Self Custody Hardware Wallet
Review example of a single seed SLIP-39 Trezor Safe 7 wallet recovered into Electrum wallet.

Top of the Line User Experience

The Safe 7 highlights a deep commitment to design and user experience through a series of subtle yet memorable features. The most iconic encountered during testing was the device’s response to critical approval decisions, such as signing a transaction or updating a security PIN. When a user presses and holds a digital button at the bottom of the screen, an internal gyroscope causes the device to gently vibrate while two green light trails flow outward from the button around the display’s borders. As the lights meet at the top, the gyroscope accelerates to produce an escalating mechanical sound and tactile sensation in the hand. The sequence culminates when the entire screen frame illuminates alongside a small green LED at the top, signaling that the action is complete. Though this entire process takes only a second or two, it grounds the digital and abstract experience of moving bitcoin in a tangible reality.

Compared to earlier Trezor models tested, such as the Model T and the classic Trezor One, the conscious effort dedicated to making cryptographic money comfortable to use is clear. For instance, the on-screen buttons are significantly larger than those on the Model T, mitigating frequent mistyping errors that could lead to severe consequences—such as wiping the device memory after consecutive incorrect PIN entries. Larger finger-sized digital buttons help eliminate that unnecessary stress. Additionally, the metal casing undoubtedly gives the Safe 7 a mature feel, moving past the plastic shells characteristic of older iterations.

A curious interface feature included on the device is the “Wipe PIN,” a specialized code that deletes all user data when entered during login. Trezor’s public documentation explains its function but leaves its specific purpose vague: what exact risk or threat is it meant to solve? Hyper-paranoid Bitcoiners have historically requested features like this to counter low-likelihood, high-impact threats such as the infamous “wrench attack,” where an assailant coerces a user into opening their wallet.

The limitation of Trezor’s Wipe PIN implementation is that it makes it immediately obvious the wallet contents have been erased—an outcome unlikely to satisfy a hostile attacker. At least one competing hardware wallet features a more sophisticated iteration that erases the primary user wallet while silently opening a secondary “decoy” wallet without tipping off the UI. For security-conscious users, a more advanced wipe PIN mechanism would be welcomed.

The Safe 7 also incorporates Bluetooth connectivity and an internal battery compatible with Qi2 wireless chargers. It can operate over a USB-C connection with Bluetooth toggled off in the settings. This alternative operating mode frees users from physical cables—another subtle yet powerful design choice that relieves stress during transaction signing, where Bitcoin’s immutable nature makes every final decision high stakes. For heightened paranoia, a physical hardware switch for the Bluetooth antenna would also be a welcome addition.

The Airgap Principle

Prior to the Safe 7, no Trezor model included an internal battery or Bluetooth capabilities. Adding these elements represents a significant design choice that satisfies broader consumer expectations for modern hardware while introducing distinct potential risks.

Internal batteries in devices ranging from smartphones to hardware wallets are known to degrade over time, potentially swelling and breaching their casings to become hazards that can destroy device memory or usability. Trezor addresses this by employing LiFePO₄ batteries, noting that their “chemistry is more stable and safer than common lithium-ion batteries” and claiming in documentation that “swelling is extremely unlikely.”

Meanwhile, integrating Bluetooth requires a largely closed-source software and hardware stack that allows long-range interaction, challenging the air-gapped principles of cold storage. To mitigate this, manufacturers like Trezor isolate the Bluetooth antenna to transmit strictly end-to-end encrypted messages. Trezor accomplishes this via the Trezor Host Protocol, which encrypts data in transit to a computer and is equally applied to USB-C cable connections, ensuring unencrypted data is trusted neither over USB nor Bluetooth.

Nonetheless, this wireless capability arguably shifts the Safe 7 away from traditional air-gapped cold storage and closer to a high-security warm wallet configuration, contrasting with standard hot wallets operating on internet-connected computers or servers holding private keys.

Hardware Overview and Entropy

If the Coldcard security incident demonstrated anything, it is that cold storage lacks meaning without robust entropy. Entropy provides the random, unpredictable inputs required to generate cryptographic secrets, such as recording the results of 100 consecutive dice rolls. These randomized outputs pass through algorithms to produce public and private key pairs, commonly referred to as seed words.

Trezor maintains an in-depth explanation outlining how it generates and utilizes entropy to form wallet key pairs. For the Safe 7, the system draws on four separate entropy sources:

  • Entropy provided by the host computer or phone.
  • A hardware True Random Number Generator (TRNG) embedded within the STM32 microcontroller.
  • The Optiga secure element, serving as the second computer chip on the hardware.
  • The TROPIC01, representing their latest independently auditable secure element chip.

These four independent sources combine during wallet generation, driven by GPL 3 open-source logic handling the underlying operations.

Presently, Trezor does not incorporate user-generated entropy inputs into wallet creation. Manual dice rolling is omitted, though users can append a passphrase or “25th word” to existing accounts and key pairs to serve a similar function.

During a discussion with Efrat Fenigson, Trezor CTO Tomas Susanka emphasized that user-generated entropy only matters if the software implementation actually makes use of it. He noted that the Coldcard vulnerability stemmed not from flawed hardware entropy generation, but from a bug that prevented the firmware from utilizing that high-quality entropy properly.

Echoing this perspective, Trezor CCO Danny Sanders told Bitcoin Magazine that while user-added entropy is a topic “discussed a lot,” it is “not a hard no.” However, because Trezor’s user base is “multiples” larger than Coldcard’s, Sanders explained that users “cannot be asked to throw dice,” noting that “they already have a mental overload with just writing down words” in reference to the 20-word backup process. When machine-based entropy sources function correctly, the security advantages of user-supplied entropy remain marginal.

Shipping, Phishing and Wipe Codes

Acquiring a crypto hardware wallet online and having it delivered directly to a home address is becoming an increasingly precarious proposition. Trezor recently joined Ledger as major hardware providers whose user databases suffered breaches through shipping partners—in Trezor’s case, via ShipMonk. Earlier this month, 67,000 U.S. customer records were compromised from ShipMonk databases, despite expectations that these records were scheduled for deletion by the shipping vendor. This exposes users to heightened risks of targeted harassment, particularly in jurisdictions like France where crypto holders are frequent targets for organized crime.

From an operational security standpoint, utilizing a P.O. Box for crypto-related acquisitions has effectively become mandatory, as history consistently demonstrates that neither major corporations nor governments can safeguard personal data indefinitely. Alternatively, users can purchase hardware wallets in person using cash or Bitcoin at large conferences to bypass shipping risks entirely.

Addressing this concern, Trezor teased an upcoming “Anonymous delivery” option in the wake of the breach. Sanders informed Bitcoin Magazine that the service will launch in the E.U. within weeks and expand to the U.S. shortly thereafter, though public records indicate the company still relies on ShipMonk for fulfillment in the interim.

Concluding Thoughts

Having relied on older Trezor models like the Model T and Trezor One for years, the Safe 7 emerges as a meaningful evolution of the product line and a solid enhancement for self-custody frameworks. It fits particularly well within multi-vendor multisig setups or as a daily-use warm wallet, while its Shamir backup implementation secures a well-deserved place among advanced self-custody tools.

FAQ

What is the Trezor Safe 7? It is a FOSS (Free and Open-Source Software) self-custody hardware wallet featuring a metal exterior, wide display, internal battery, and Bluetooth connectivity.

What is a SLIP-39 backup? It is Trezor’s 20-word backup standard that supports Shamir Secret Sharing, allowing users to split seed phrases into multiple redundant shards.

Does the Trezor Safe 7 support Bitcoin-only firmware? Yes, users can choose or switch between a standard multi-coin firmware or a leaner, Bitcoin-only orange firmware version.

Can the Safe 7 be used via Bluetooth? Yes, it features Bluetooth connectivity and Qi2 wireless charging, though it can also be operated strictly over a USB-C cable with Bluetooth disabled.

spot_imgspot_img

Latest News

Belarus Grants Approval to Nation’s Initial Crypto Banks

Bitcoin Magazine Belarus Approves the Country’s First Crypto Banks: Report  Belarus earlier this year signed a legal framework for crypto banks in the country. This post Belarus Approves the Country’s First Crypto Banks: Report  first appeared on Bitcoin Magazine and is written by Mathew Di Salvo.

Breez SDK Launches New Stablecoin Conversion Tool

Bitcoin software provider Breez has launched a new stablecoin conversion tool within its SDK, enabling users to receive USDT and USDC payments from over 30 different blockchain networks directly into their bitcoin or dollar balances.

Samourai Dispatch #7: Dispatches From Within

In Samourai Dispatch #7, the author details the harrowing and traumatic 30-day BOP transit process from FPC Morgantown to FCI McKean, involving flights, buses, and difficult conditions.

Per Bylund on How Artificial Intelligence Sparks Universal Entrepreneurship

Austrian economist Per Bylund discusses artificial intelligence, explaining why AI functions as a statistical engine that enhances efficiency rather than replacing the human entrepreneur in a shifting economy.

Bitcoin Nears Crucial Valuation Milestone Relative to Gold

Bitcoin approaches a major valuation milestone relative to gold, with its 90-day correlation hitting a six-year high and sitting just 3 percent away from turning positive for 2026.
spot_imgspot_img

LEAVE A REPLY

Please enter your comment!
Please enter your name here