Buy
Market
🔥
Prediction Market

Trezor Safe 7 Review: Open-Source Hardware Wallet for Self-Custody

A review of the Trezor Safe 7, covering its design, dual firmware, SLIP-39 backup, and user experience.

28/09/2026 14:4631 min read

Some hardware wallets aim for an air-gapped design that users can assemble themselves or that suits professionals following an open-source philosophy. Others keep their source closed and strive to become the Apple or Macintosh of hardware wallets, guiding users through design. Trezor appears to have found a middle ground with the Safe 7.

With a metal exterior, a large screen that extends to the device's edges, and tactile feedback designed to please users, the Safe 7 feels like a contemporary iPhone. It conveys the sense that Bitcoin is tangible and physical, something many other wallets fail to achieve.

Trezor also manages the split between Bitcoin-centric and crypto users effectively. It does so by offering two firmware stacks: a standard multi-coin variant in black or green, and a Bitcoin-only version in orange. Users can toggle between them freely no matter which they ordered, though Bitcoiners can choose the orange version to avoid extra firmware updates. Any user can switch firmware types later if desired, irrespective of the device's color.

The decision carries implications: most firmware updates concern non-Bitcoin coins. Therefore, the Bitcoin-only firmware is more streamlined. Trezor's support materials state: “Added advantages of running Bitcoin-only firmware include fewer regular updates (compared to the Universal firmware) and reduced risk of bugs or security issues.”

The Magic Words

Users familiar with Bitcoin but new to Trezor will first notice the word list size. The Safe 7 uses 20 words for wallet backups, instead of the common 12 or 24. This is a security choice Trezor has refined over years. The SLIP-39 standard, which uses 20 words, was debuted by Trezor in 2019 alongside the Shamir backup feature. Shamir allows splitting seed words into shards; a threshold of shards can reconstruct the wallet, but any single shard is useless. In a two-of-three Shamir setup, for instance, users create three 20-word lists stored in separate places (bank, home, office). Losing one to theft or disaster is not catastrophic because that shard alone cannot access the wallet, while the other two allow recovery. This 'redundancy' is also achieved by multi-signature wallets, but with trade-offs like onchain transaction fees. Shamir backups derive from Shamir Secret Sharing, a classic cryptographic scheme that Trezor implemented.

The additional words compared to the common 12-word scheme do not increase entropy; Trezor states that both offer 128 bits of entropy. However, the SLIP-39 word list is, per Trezor, deliberately chosen to prevent confusion between similar words.

SLIP-39 provides an ability that BIP-39 lacks: expandability into Shamir. Users starting with a single 20-word seed on a Trezor can later generate a redundant set of Shamir shares, such as three-of-five. These shares recreate the same wallet, avoiding onchain transfers. Users should destroy the original 20-word seed, as it alone can still restore the wallet. Trezor offers a detailed FAQ for further reading. SLIP-39 is also supported by wallets like Sparrow and Electrum, but its adoption is much lower than BIP-39.

Top of the Line User Experience

The Safe 7 shows significant investment in design and UX through subtle but memorable touches. The most notable during testing was the approval response for actions like signing transactions or changing the PIN. The user presses and holds a digital button at the screen's bottom. The device vibrates slowly via an internal gyro, while two green lights flow from the button around the screen edges. When the lights meet at the top, the gyro accelerates, creating a rising mechanical sound and feel. The screen frame fully illuminates and a small green LED at the top confirms completion. The sequence lasts a second or two but makes moving bitcoin feel tangible.

Compared to earlier Trezor models like the Model T and Trezor One, the ergonomic design is clear. Screen buttons are larger than those on the Model T, reducing mistyping errors that could have serious consequences, like wiping the device after a wrong PIN. The larger, finger-sized buttons ease that anxiety. The metal casing adds a feeling of maturity over the plastic of older models.

A notable interface feature is the 'Wipe PIN', a special code that erases user data upon login. Trezor's public documentation describes its function but not its purpose: what threat does it counter? Some security-conscious bitcoiners have sought such features for rare but severe scenarios like a 'wrench attack', where a thief compels the victim to unlock the wallet.

The issue is that Trezor's Wipe PIN is obvious; the attacker would see that the wallet was wiped, which could escalate the situation. Another hardware wallet offers a more advanced version that deletes the main wallet but opens a decoy wallet without UI hints. For the paranoid, a better wipe PIN would be appreciated.

The Safe 7 includes Bluetooth and an internal battery that supports Qi2 wireless charging. Users can also connect via USB-C with Bluetooth turned off in settings. Cable-free operation reduces stress during transaction signing, which is high-stakes due to Bitcoin's irreversibility. Some would prefer a physical switch to disable the Bluetooth antenna.

The Airgap Principle

Previous Trezor models lacked an internal battery and Bluetooth. Adding them is a major decision, offering benefits that modern consumers expect, but also introducing risks.

Internal batteries in devices like hardware wallets and phones can degrade, swell, and rupture over time, posing hazards and damaging memory. Trezor says it selected LiFePO₄ batteries because their "chemistry is more stable and safer than common lithium-ion batteries," and claims "swelling is extremely unlikely."

Bluetooth integration adds largely closed-source software and hardware, enabling remote interaction and undermining cold storage's air-gap. Trezor isolates the Bluetooth antenna and uses encrypted end-to-end messaging via its Trezor Host Protocol, which also encrypts USB-C connections. The company does not send unencrypted data over USB or Bluetooth.

Still, the wireless feature arguably shifts the Safe 7 from cold storage towards a high-security warm wallet, as hot wallets are internet-connected computers holding keys.

Hardware Overview and Entropy

The Coldcard hack demonstrated that cold storage is useless without quality entropy. Entropy is a random, unpredictable input for cryptographic secrets, like rolling dice 100 times. Dice outputs feed algorithms to generate key pairs and seed words.

Trezor details its entropy generation in a dedicated article. The Safe 7 employs four entropy sources:

  • Entropy from the host computer or phone.
  • A hardware TRNG inside the STM32 microcontroller, one of Trezor's chips.
  • The Optiga secure element, the second chip in the Trezor hardware.
  • The TROPIC01, Trezor's newest "independently auditable" secure element chip.

These four sources combine during wallet generation. The firmware is GPL 3 open source. Trezor does not allow user-entered entropy for wallet creation; no dice rolls. Users can add a passphrase or '25th word' to existing keypairs, which serves a similar purpose.

Trezor CTO Tomas Susanka said in a talk with Efrat Fenigson that user entropy is only useful if the code incorporates it. The Coldcard bug was not due to poor hardware entropy but because the firmware did not use the good entropy correctly.

Danny Sanders, Trezor CCO, agreed but said user entropy had been "discussed a lot" and "it’s not a hard no." However, Trezor's user base, which he says is "multiples" that of Coldcard, "cannot be asked to throw dice." He noted they already have "mental overload with just writing down words" for the 20-word seed. The security gains from user entropy are marginal if machine entropy sources are used correctly.

Shipping, Phishing and Wipe Codes

Purchasing a hardware wallet online and having it shipped home is becoming less appealing. Trezor, like Ledger, suffered a database hack via its shipping partner ShipMonk. Earlier this month, 67,000 U.S. customer records were exposed from ShipMonk databases; Trezor says most should have been deleted. This raises the risk of targeted harassment, particularly in countries like France where Bitcoin users are already targeted by organized crime.

From an opsec standpoint, a P.O. Box is now almost necessary for crypto purchases. No large entity can be fully trusted with personal data, as internet history shows. Users can buy wallets at conferences with cash or bitcoin to avoid shipping. Trezor teased an "Anonymous delivery" service in response to the breach. Sanders told Bitcoin Magazine it will launch in the E.U. "in a matter of weeks" and the U.S. soon after. Public data shows Trezor still uses ShipMonk.

Concluding Thoughts

After years of using older Trezors like the Model T and Trezor One, the Safe 7 feels like a major product evolution and a solid choice for self-custody, especially in multi-vendor multisig or as a daily warm wallet. Its Shamir backup is also suitable for advanced self-custody.

Share to

Disclaimer: this article comes from third-party media and is provided for reference only. It does not constitute investment advice. Crypto and other financial products carry significant price volatility risk, so please make your own decisions carefully.

Related articles