Hardware crypto wallets
Who holds the keys, whether the code is open, whether development is alive. The score is ours and made only of things that can be checked.
Keys live on a separate device that is not online. 10 entries
| Name | Score | Code | Last update | Code reviews | Keys |
|---|---|---|---|---|---|
| BitBox02 | 8/10 | Apache-2.0 | August 28, 2026 | — | With the user |
| Coldcard | 8/10 | Open | August 25, 2026 | — | With the user |
| Keystone | 8/10 | Open | August 25, 2026 | — | With the user |
| Ledger | 8/10 | MIT | August 30, 2026 | — | With the user |
| OneKey | 8/10 | Open | August 30, 2026 | — | With the user |
| Tangem | 8/10 | Open | August 27, 2026 | — | With the user |
| Trezor | 8/10 | Open | August 30, 2026 | — | With the user |
| Ellipal | 2/10 | Closed | — | — | With the user |
| NGRAVE | 2/10 | Closed | — | — | With the user |
| SafePal | 2/10 | Closed | — | — | With the user |
How this kind works
The keys sit in a separate device that never goes online. Signing happens inside it: the computer hands over an unsigned transaction and gets a signed one back, while the key itself never leaves. Malware on the computer has nothing to intercept. Other worries take its place: devices get lost and broken, and you must buy from the maker rather than second-hand, because a tampered device knows your key from the start. The real secret is not the device but the recovery phrase written down at first use: it restores the wallet on a new device, and it hands the wallet to anyone else who reads it.
What the score is made of
Wallet: open code 3, development in the past three months 3 (within a year 1), code review 2, keys with the user 2.
A low score means «we could check little», not «this one is a bad choice». Closed code offers nothing to look at — that is an absence of proof, not an accusation.
Open code and development from GitHub, code reviews and networks from DefiLlama. The list itself is ours.