We use technologies like cookies to store and/or access device information. We do this to improve browsing experience and to show (non-) personalized ads. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Техническое хранение или доступ необходимы для законной цели хранения предпочтений, которые не запрошены подписчиком или пользователем.
The technical storage or access that is used exclusively for statistical purposes.
Техническое хранилище или доступ, который используется исключительно для анонимных статистических целей. Без повестки в суд, добровольного согласия со стороны вашего интернет-провайдера или дополнительных записей от третьей стороны информация, хранящаяся или полученная только для этой цели, обычно не может быть использована для вашей идентификации.
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
Trezor Safe 7: review, security and first setup
Launched in October 2025, Trezor Safe 7 is the flagship of the Trezor lineup, which also includes Safe 5 and Safe 3. It is the first Trezor with Bluetooth, a battery and full iPhone support, and the first hardware wallet to use the TROPIC01 security chip, whose architecture is open to independent review.
A hardware vulnerability was discovered in TROPIC01 in January 2026 and publicly disclosed in June. In this Trezor Safe 7 review, we explain what it means for wallet owners, how Bluetooth and post-quantum protection work, and which coins and networks the device supports. We also compare Safe 7 with Safe 5 and Safe 3, then walk through setup and the checks to complete before your first transfer.
Who is Safe 7 for?
Safe 7 is particularly useful if you want to sign transactions from an iPhone: among current Trezor models, it is the only one with full iOS support. Safe 5 and Safe 3 cannot connect to an iPhone. You can use the Trezor Suite mobile app to view accounts you have added from those wallets, buy crypto and receive funds without connecting the device, but setup and transaction signing require a computer or Android phone. Safe 7 also has a larger screen, making it easier to check addresses and review complex DeFi transactions.
If you use a computer or connect your wallet to an Android phone by cable, Safe 5 is worth considering. It costs less than Safe 7 and also uses an OPTIGA Trust M Secure Element and an STM32U5 microcontroller. Safe 3 can be a more affordable first wallet or a backup device, although it has a hardware limitation we discuss in the comparison section.
Which coins and networks does Trezor Safe 7 support?
With its multi-coin firmware, Trezor Safe 7 supports thousands of coins and tokens. Trezor Suite lets you manage Bitcoin (BTC), Ethereum (ETH), Solana (SOL), Cardano (ADA), XRP, Litecoin (LTC) and Dogecoin (DOGE), along with tokens on supported networks.
TRON (TRX) and TRC-20 tokens, including USDT, are already supported in Trezor Suite on Safe 7, Safe 5 and Safe 3. Since the June 2026 update, TRON has been generally available in both the desktop and mobile versions of Suite. The app does not support the older TRC-10 token standard.
When transferring USDT, make sure the sending and receiving networks match. For USDT TRC-20, for example, add a TRON account in Suite and select TRON as the withdrawal network on your exchange. TRC-20 transfers consume the network’s bandwidth and energy resources; if you do not have enough, fees are paid in TRX, so holding USDT alone may not be sufficient. See Trezor’s TRON and TRC-20 guide for the full procedure.
For other assets, check the official list of supported coins and tokens, selecting Safe 7 and the network you need. The list also tells you whether an asset is available in Trezor Suite or requires a compatible third-party app. Support for a token on one network does not mean every network where that token exists is supported.
Inside Safe 7: three chips from three manufacturers
Safe 3 and Safe 5 use two chips: an STM32 microcontroller and an Infineon OPTIGA Trust M Secure Element with CC EAL6+ certification. Safe 7 adds TROPIC01 from Czech company Tropic Square. It uses an STM32U5G microcontroller (ARM Cortex-M33, 160 MHz) and the third version of OPTIGA Trust M. Components from three manufacturers provide independent layers of protection, so compromising one chip should not be enough to access the wallet.
In Safe 7, TROPIC01 enforces the PIN attempt limit in hardware through a mechanism called MAC-and-Destroy: each attempt permanently consumes a one-time slot in the chip, and only the correct PIN produces the required cryptographic result. The chip also stores factory certificates used to authenticate the device and generates random data for wallet creation.
The seed, from which the wallet derives private keys, is stored in encrypted form in the microcontroller’s memory. Its decryption key is never stored in full: after you enter the correct PIN, it is derived from secret data held by several chips, exists briefly in memory, and is then erased. As a result, compromising a single component is not enough to read the seed.
TROPIC01 has an open architecture that independent researchers can inspect. With many Secure Elements, access to technical details is restricted by nondisclosure agreements (NDAs). OPTIGA Trust M documentation is available without an NDA, although the chip itself does not have a fully open architecture. TROPIC01 was designed for open security audits, one of which uncovered the vulnerability discussed below.
The TROPIC01 vulnerability: what was compromised and what it means for security
Tropic Square commissioned an independent audit of TROPIC01 by Ledger Donjon, the security research team at Trezor’s competitor. In late January 2026, Donjon reported that laser fault injection had allowed it to extract some of the secret data protected by the chip. Building on those findings, Tropic Square engineers found a way to run their own firmware on the chip and obtain a secret used in PIN protection. Trezor published its response on June 3, 2026.
The attack requires physical access to the device, expensive laboratory equipment and specialist knowledge. An attacker must disassemble the wallet, desolder TROPIC01, open the chip package from the back, connect it to a custom board and precisely position the laser. This vulnerability cannot be exploited remotely or through malware on your computer. Trezor also states that it cannot be used to make a counterfeit Safe 7 with malicious firmware that survives a restart, ruling out that route for a supply-chain attack.
According to Trezor, compromising TROPIC01 alone does not give an attacker access to the PIN, funds or wallet backup: the seed is not stored on that chip, and decrypting it requires two other independent layers of protection. A Safe 7 firmware update cannot fully fix the underlying hardware issue. Tropic Square plans to release a revised chip in late 2026, but Trezor has not confirmed whether or when it will use that revision in new Safe 7 devices.
For everyday use, the main risks to watch for are phishing, exposure of your wallet backup and approving malicious transactions. If an attacker with a well-equipped laboratory is a realistic concern for you, factor in the vulnerability in one of the three protection layers: even after compromising TROPIC01, they would still have to defeat OPTIGA and the microcontroller. A strong passphrase provides additional protection when used alongside your backup and stored separately. It is not saved in the device’s persistent memory and is required to access the hidden wallet even if someone has the seed.
Quantum-ready: what is protected?
When Trezor describes Safe 7 as “quantum-ready,” it means post-quantum protection for the boot process, firmware and device authentication. Safe 7 verifies bootloader and firmware signatures using SLH-DSA-128, an algorithm standardized in 2024. Since May 2026, authentication in Trezor Suite has also used a digital signature generated by the microcontroller with the post-quantum algorithm ML-DSA-44. These measures protect against future attacks in which a quantum computer could help forge a conventional digital signature for an update or a device.
The cryptography used for addresses and transaction signatures on Bitcoin, Ethereum and other networks remains unchanged, so these features do not make your coins quantum-resistant. A move to post-quantum cryptography depends on the blockchains themselves; whether Safe 7 could support it through an update will depend on future standards and the device’s resources. When choosing Safe 7 today, consider its screen, connectivity and ease of use: “quantum-ready” describes protection for the device itself.
Bluetooth and connection security
On Safe 7, Bluetooth and USB connections are secured by Trezor Host Protocol (THP), an open-source protocol that encrypts commands and data and protects against interception, tampering and message injection. When first pairing the wallet over Bluetooth, check that the code on its screen matches the one in Trezor Suite. After you install the firmware, Suite asks you to confirm the secure connection using a one-time code shown on Safe 7. The wallet subsequently recognizes approved connections and remains invisible to unknown devices.
If you do not need a wireless connection, you can disable Bluetooth in the settings and use USB-C. You will then be unable to sign transactions from an iPhone, because Safe 7 uses Bluetooth exclusively for this; its USB-C port only supplies power when connected to an iPhone.
Whichever connection you use, always check the recipient address and amount on Safe 7’s screen, as malware on a computer or phone can replace a copied address in the clipboard. The 2.5-inch display makes this easier than the 1.54-inch screen on Safe 5 or the monochrome screen on Safe 3. In September 2026, Trezor introduced Clear Signing for supported contracts on EVM networks, which are compatible with the Ethereum Virtual Machine. When a contract is supported, the device displays a readable description of the action; for other contracts, Suite warns you about blind signing. The feature also works on Safe 5 and Safe 3 with current multi-coin firmware.
Case, battery and water resistance
Safe 7’s case is machined from a solid block of anodized aluminum, with Gorilla Glass 3 protecting the screen and a glass rear panel. It measures 75.4 × 44.5 × 8.3 mm and weighs 45 g, almost twice as much as the 23 g Safe 5. Safe 5 combines a PC-ABS plastic body with an aluminum rear panel, while Safe 3 uses PMMA and an aluminum rear panel.
Safe 7 has an IP54 rating, providing limited dust protection and resistance to splashes from any direction. Do not submerge the device. If a review or older article cites IP67, use the IP54 rating in Trezor’s current documentation as your reference.
The LiFePO₄ (lithium iron phosphate) battery has a capacity of 330 mAh. According to Trezor, it can withstand up to four times as many charge cycles as conventional lithium batteries. It also tolerates a full discharge and retains its charge during long periods of storage. You can charge Safe 7 by cable or with a Qi2-compatible wireless charger. If the battery eventually fails, the wallet will still run on USB-C power and can continue to work with a computer or Android phone. Connecting to an iPhone requires Bluetooth.
The operating temperature range is 0 to +45 °C. If you leave Safe 7 in a freezing car overnight, let it warm to room temperature before using it. Airport X-ray screening does not harm the device.
Safe 7 vs. Safe 5 vs. Safe 3
All three models support passphrases, 12-, 20- or 24-word backups, and Multi-share Backup. The latter splits the backup into several shares and lets you set how many are needed for recovery. Each model supports PINs of up to 50 digits and can act as a FIDO2 security key for two-factor authentication. Trezor Suite for desktop offers Tor and coin control, which lets you manually select Bitcoin’s unspent transaction outputs (UTXOs) for a transaction. You can install Bitcoin-only firmware on any of the three models during setup; the manufacturer also sells dedicated Bitcoin-only editions. The table below compares their differences.
For Safe 3 and Safe 5, Trezor Suite on iPhone lets you view accounts you have added, buy crypto and receive funds without connecting the hardware wallet. You need a computer or Android phone to set up the wallet and sign transactions.
What Safe 7 adds over Safe 5
In everyday use, Safe 7’s main advantages are full iPhone support and cable-free operation over Bluetooth. It also has a battery with wireless charging, a larger screen, an aluminum case and an IP54 rating. TROPIC01 adds a third independent layer of protection, although its known vulnerability limits its effectiveness against laboratory attacks. We would not treat that chip alone as a reason to upgrade from Safe 5: if you use a computer or a wired Android connection and are happy with the smaller screen, there is no need to replace your device.
What Safe 5 offers that Safe 7 does not
Safe 5 supports extra protection using a microSD card containing a random secret, which is required alongside the PIN to unlock the device. Keeping the card and wallet in separate places makes unauthorized access harder, although it does not protect against theft of the backup itself. The feature is enabled through the trezorctl command-line tool, so it is intended for experienced users; Safe 7 does not support it. If the card is lost, you can recover access using your wallet backup. Safe 5 is also lighter and has no battery to wear out over time. If you prefer a wired connection, its lower price and microSD protection may matter more to you than Safe 7’s additional features.
Safe 3: the trade-offs
In March 2025, Ledger Donjon published research on Safe 3 showing that voltage glitching—deliberately disrupting the microcontroller’s power supply—could bypass some authenticity and firmware integrity checks. The attack involves replacing the firmware before the device reaches its owner; the researchers did not demonstrate extraction of a PIN or seed from an initialized, locked wallet. Because the vulnerability lies in the microcontroller hardware, it cannot be fixed with a firmware update. Trezor explains that the attack does not affect Safe 5, which uses the newer STM32U5 microcontroller. Safe 7 also uses a microcontroller from that family.
Buy Safe 3 directly from the manufacturer or an authorized reseller, and complete the checks in Trezor Suite during setup. Pay attention to where the device comes from, since the demonstrated attack bypasses some of those checks. Safe 3 can be a more affordable first wallet or a backup device for the same wallet, provided you are comfortable with two buttons and a small monochrome screen that requires scrolling through long addresses.
Which model should you choose?
If you use an iPhone and want to sign transactions from your phone, whether for DeFi or while traveling, Safe 7 is the only current Trezor model that supports this.
Trezor Safe 7
For use with a computer or a wired Android connection, we recommend Safe 5 if you want a touchscreen. It uses a certified OPTIGA Trust M chip, costs less than Safe 7 and supports extra protection through microSD. It is our choice for most users who do not need to sign transactions from an iPhone.
Trezor Safe 5
9,990.00 UAHOriginal price was: 9,990.00 UAH.7,590.00 UAHCurrent price is: 7,590.00 UAH.Safe 3 works as a more affordable first wallet or a second device for the same wallet, as long as you take its hardware limitation into account and buy from a trusted seller.
Trezor Safe 3
4,590.00 UAHOriginal price was: 4,590.00 UAH.3,590.00 UAHCurrent price is: 3,590.00 UAH.If you only hold bitcoin, you can choose Bitcoin-only firmware during setup to exclude support for altcoins. You do not need a separate device, and the smaller codebase reduces the attack surface. We sell the multi-coin version of Safe 7, which also offers this choice when you install the firmware. You can switch back to Universal firmware, but switching wipes the device, so you will then need to restore your wallet from its backup.
If you hold a substantial balance, plan how you will store your backup and recover access. A metal backup, a strong passphrase stored separately and a tested recovery plan help preserve access if the device is lost or damaged. The 24-word Trezor Keep Metal is designed for a 24-word BIP39 backup. If you keep Safe 7’s default 20-word SLIP39 backup, choose a metal backup that supports that format; the 24-word Keep Metal version is not designed for it.
Trezor Keep Metal — 24 word
Where to buy Safe 7 in Ukraine
We sell the multi-coin version of Trezor Safe 7 with delivery across Ukraine, a 12-month warranty and help with setup.
If you choose another seller, check that they appear on Trezor’s official reseller list and inspect the device when it arrives. When ordering from trezor.io, allow for international shipping and any applicable customs charges.
Avoid used or repackaged devices and offers with no verifiable origin, including listings on OLX and other marketplaces. A hardware wallet’s supply history matters even if it looks new.
Setting up Safe 7 for the first time
The steps below cover the main setup process. Menu labels may change as Suite is updated, so refer to the official “Get started with the Trezor Safe 7” guide as you work through them.
What to check when your device arrives
Before connecting it for the first time, inspect the device and box contents, whether you bought directly from trezor.io or from a reseller. If you notice signs of tampering or anything that differs from the official description, contact the seller before starting setup.
Frequently asked questions
Is Trezor Safe 7 safe after the TROPIC01 vulnerability disclosure?
The published attack targets one chip and requires physical access, disassembly and specialist laboratory equipment. According to Trezor, even a successful compromise of TROPIC01 does not by itself expose the PIN, seed or funds, because two other independent protection layers remain. If a laboratory attack is a realistic concern for you, take the TROPIC01 vulnerability into account and use a strong passphrase stored separately from your backup.
Does Safe 7 work with iPhone?
Yes, through Bluetooth and the Trezor Suite mobile app. Safe 7 is the only current Trezor model that lets you sign transactions from an iPhone. When connected to an iPhone, USB-C is used only for charging.
Can I use Safe 7 without Bluetooth?
Yes. Disable Bluetooth in the settings and use USB-C with a computer or Android phone. You cannot sign transactions from an iPhone without Bluetooth.
What happens when the battery wears out?
If the battery no longer holds a charge, connect Safe 7 to a computer or Android phone by cable. The device will continue to work on USB-C power. Signing transactions from an iPhone still requires Bluetooth.
Is Safe 7 waterproof?
No. Its current IP54 rating covers limited dust protection and resistance to splashes. The device is not designed to be submerged, so use IP54 as your reference even if a review cites IP67.
Can I move my wallet from Safe 5 or Safe 3 to Safe 7?
Yes. Choose wallet recovery during Safe 7 setup and enter the words from your existing backup on the device’s screen. Safe 7 supports the same formats as Safe 3 and Safe 5. If you used a hidden wallet, you will also need the same passphrase. Once you have confirmed that recovery was successful, you can keep the old device as a backup or reset it to factory settings.
Does quantum-ready protect my bitcoin from quantum computers?
No. Safe 7’s post-quantum cryptography protects the boot process, firmware updates and device authentication. The quantum resistance of your coins depends on when and how their blockchains adopt post-quantum cryptography.
Further reading
Related Posts
Trezor Safe 7 vs Ledger Flex: Which One to Choose in 2026
When comparing Trezor Safe 7 vs Ledger Flex, the differences go deeper than screen size or weight: both hardware wallets have a touchscreen, Bluetooth, and a battery, but they protect private keys and handle recovery in different ways. Before choosing a model, it’s worth understanding how its security works and how easy it will be …
Crypto cards in Ukraine: availability, fees and limits
Crypto cards in Ukraine in 2026 let you pay for purchases without first withdrawing funds to a bank card. Whether you can get one depends on where you live and whether you pass identity checks; what you ultimately pay depends on conversion rates and fees. We compare providers that explicitly list Ukraine as a supported …
Ledger Flex setup: step-by-step guide from unboxing to your first transaction
Ledger Flex setup is best done step by step, from checking the box contents to completing your first test transaction. If you have just received a Ledger Flex, this guide will walk you through installing Ledger Wallet, running Genuine Check, creating a new wallet, writing down your Secret Recovery Phrase, and setting up your recovery …
Keystone 3 Pro setup: step-by-step guide from unboxing to your first transaction
Keystone 3 Pro setup should start with verifying the device and checking a few basic security settings. In this guide, we walk through the entire process step by step, from inspecting the box to signing your first transaction. We based the instructions on Keystone’s official documentation and kept menu labels exactly as they appear on …