Hardware signers

The many paths
to sovereignty.

Compare the security model, transaction-review experience, backup method, connectivity, and learning curve—not just a feature count.

Shortlist

Nine useful reference points

This is not a winner-takes-all ranking. Each device represents a different balance of transparency, convenience, connectivity, and operator skill.

Feature matrix

Compare security and workflow

Use the checks as a map, not a score. A feature is valuable only when it fits the way you intend to set up, sign, and recover.

Available Optional or model-dependent Not part of the standard workflow
Feature Trezor Safe 7 Bitkey BitBox02 Blockstream
Jade Plus
COLDCARD
Q / Mk5
Foundation
Passport
SeedSigner Krux Ledger
Security and auditability
Publicly reviewable firmware MIT plus Commons Clause Deterministic builds Reproducible builds No third-party audit yet Element OS is closed
Dedicated key-isolation chip TROPIC01, auditable; EAL6+ Optiga alongside Secure MCU; 2-of-3 multisig EAL6+ secure chip Virtual secure element Two, different vendors Stateless design instead Encrypted storage instead EAL5+ / EAL6+
Bitcoin only firmware Separate firmware edition Separate edition, locked at factory Plus Liquid Multi-purpose Multi-asset only
Transaction review on device
Air gap and connectivity
Fully air-gapped signing path USB or Bluetooth only Phone app plus NFC USB, or BLE on Nova QR, SD, USB drive QR on Q; microSD both QR only QR or SD card USB or Bluetooth only
Camera-based QR signing Q only
Removable media for signing Backup only SD or USB drive microSD No microSD on Prime QR only SD card
USB data connection Charging only Off by default Power only Power and flashing
Bluetooth Can be disabled Nova only QuantumLink No radios at all Not Nano S Plus
NFC Main interface Can be disabled Backup Keycards Stax, Flex, Gen5
Backup and operating model
Recovery words supported Multi-share option No seed phrase Plus dice rolls Plus SeedQR Plus dice, SeedQR
Removable-media backup Words only Cloud and social microSD default SD or SeedQR Encrypted microSD Keycards, SeedQR Words or SeedQR Encrypted SD export Words only
Runs without storing a seed Stateless QR signing Temporary seed in RAM Core design Amnesic by default

Every row was cross-checked against each manufacturer's own current documentation on August 6, 2026; where a spec varies by model, the note says which models it applies to. No device is ranked or highlighted here—the marks describe design choices, not scores. A dash does not mean a device is unsafe; it usually means the maker chose a different approach, and a feature only matters if it fits how you actually plan to set up, sign, and recover.

Detailed notes

What each device is really optimizing for

Trezor Safe 7

Trezor Safe 7

Trezor's current premium model is also available as a dedicated Bitcoin-only firmware edition: same hardware as the standard Safe 7—large colour touchscreen, open-source software, a secure element plus a security microcontroller, encrypted Bluetooth, USB-C, wireless charging—with altcoin functionality removed entirely.

Strong fit

  • People who want clear on-device review and a guided companion app.
  • Users who value an open-source design but also want phone connectivity.
  • Bitcoin-only holders who still want a premium touchscreen experience.

Consider

  • A premium device adds features, battery, radios, and complexity that a long-term Bitcoin-only holder may not need.
  • Bluetooth can be disabled; decide whether convenience belongs in your threat model.
Bitkey hardware key

Bitkey

Bitkey is Block's Bitcoin-only wallet: a hardware key, a mobile app, and a Block-held recovery key form a 2-of-3 multisignature wallet by design—no single key can move funds alone. The hardware key has an OLED display, a fingerprint sensor, connects via NFC, and charges over USB-C. Firmware, app, server code, and hardware schematics are published on GitHub under the Commons Clause license, though the firmware cannot be independently rebuilt end-to-end because it depends on a proprietary third-party fingerprint-matching library Block cannot redistribute.

Strong fit

  • People who want multisig-level protection without configuring it themselves.
  • Users who prefer a polished, guided consumer product over a DIY or advanced setup.
  • Anyone comfortable with Block holding one of three keys to help with recovery.

Consider

  • The published code carries a Commons Clause restriction and isn't independently buildable end-to-end—source-available, not fully open source.
  • Recovery leans on the app, encrypted cloud backup, and social recovery rather than a single standard seed phrase.
  • A company-held key is a different trust model than a fully self-contained signer.
BitBox02 hardware wallet

BitBox02

The BitBox02 Bitcoin-only edition combines open-source firmware with a secure dual-chip design, a compact OLED display, touch sliders, USB-C, and a fast microSD backup workflow. The Bitcoin-only firmware edition is locked at the factory and cannot be switched to multi-asset firmware.

Strong fit

  • People who want a compact, approachable Bitcoin-only device.
  • Users who like guided desktop software and microSD recovery.
  • Sparrow, Electrum, Specter, and personal-node users.

Consider

  • Normal use is connected over USB-C rather than camera-based air gap.
  • The original BitBox02 does not work with iPhone/iPad; verify the current Nova model if iOS matters.
Blockstream Jade Plus

Blockstream Jade Plus

Jade Plus is a Bitcoin and Liquid signer with a larger display, camera, physical controls, QR signing, USB-C, Bluetooth, and SD card support. Its hardware and firmware are open source, and its security architecture uses Blockstream's virtual secure element approach.

Strong fit

  • People who want camera-based air-gapped signing with a modern screen.
  • Users who prefer auditable hardware and firmware.
  • Sparrow, Nunchuk, Specter, and Blockstream App workflows.

Consider

  • Learn how PIN unlock, genuine check, and stateless recovery work before deciding on a backup plan.
COLDCARD Q and Mk5 hardware wallets

COLDCARD Q / Mk5

COLDCARD Q and Mk5 are Bitcoin-only signers with dual secure elements from different vendors, publicly reviewable and reproducible firmware, and some of the deepest transaction-policy controls available on a consumer signer, while still working for someone building their first air-gapped setup.

Strong fit

  • People who want one device that scales from a first air-gapped wallet to advanced multisig and policy rules.
  • Users who value dual, independently-sourced secure elements and open, reproducible firmware.
  • Anyone who wants microSD, NFC, and (on the Q) QR/camera air-gap options in a single signer.

Consider

  • Read the docs to get the most out of its more advanced features.
  • Choosing between Q and Mk5 comes down to keyboard-and-camera versus a smaller, simpler form factor.
Foundation Passport Prime hardware device

Foundation Passport

Passport Prime is Foundation's current device, and it is a significant change of direction from the earlier Bitcoin-only Passport. It keeps the open-source approach, the camera for QR-based air-gapped signing, and SeedQR import and export, but it is now a multi-purpose security device: alongside the Bitcoin wallet, its KeyOS firmware also handles 2FA codes, FIDO security keys, and encrypted file storage. It pairs a security processor with a secure element, adds QuantumLink Bluetooth and NFC backup Keycards, and drops the microSD slot the older model used.

Strong fit

  • People who want camera-based QR air-gapped signing with a large, modern touchscreen.
  • Anyone who wants one device for Bitcoin plus 2FA codes, security keys, and encrypted files.
  • Envoy companion-app workflows, including Magic Backups and Keycard recovery.

Consider

  • No longer Bitcoin-only—the extra apps and radios add capability but also attack surface a single-purpose signer avoids.
  • Backup moves to NFC Keycards and SeedQR rather than the microSD workflow the earlier Passport used.
  • If you specifically want the older Bitcoin-only Passport, check availability first—Foundation's shop currently lists Passport Prime.
SeedSigner open-source hardware wallet

SeedSigner

SeedSigner is open-source, Bitcoin-only firmware that you build yourself from off-the-shelf parts—typically a Raspberry Pi Zero, a camera module, and a small screen—into a fully air-gapped, QR-code-based signer. It has no secure element and, by design, does not persist your seed on the device: you re-enter it each session from words, dice rolls, or a SeedQR.

Strong fit

  • People who want a fully inspectable, DIY Bitcoin-only signer built from cheap, replaceable hardware.
  • QR-based single-sig and multisig workflows, including stateless "amnesic" use.
  • Users comfortable assembling hardware and flashing firmware themselves.

Consider

  • No secure element—encryption and process-level protections are a different trust model than a certified chip.
  • Built on commodity consumer electronics rather than purpose-built security hardware.
  • Re-entering your seed each session is deliberate, but means you need a reliable physical backup.
Krux running on a Yahboom K210 touchscreen device

Krux

Krux is open-source, Bitcoin-only firmware that turns off-the-shelf Kendryte K210 devices—such as the Yahboom K210 module or M5StickV—into air-gapped signers using QR codes or an SD card. It has no secure element; protection relies on encryption. Krux was built amnesic-first—by default it holds nothing between sessions and you load your key each time—with optional encrypted storage on the device or an SD card if you want persistence.

Strong fit

  • People who want a fully inspectable, DIY Bitcoin-only signer.
  • QR-based single-sig and multisig workflows.
  • Users comfortable flashing firmware and sourcing their own hardware.

Consider

  • The project states it has not yet been formally audited by a third party.
  • No secure element—encryption-based protection is a different trust model than a certified chip.
  • Built on commodity consumer electronics rather than purpose-built security hardware.
Ledger Stax hardware wallet

Ledger

Ledger's current lineup (Nano S Plus, Nano X, Flex, Stax, and the touchscreen Nano Gen5) pairs a certified secure element—EAL5+ on the older Nano models, EAL6+ on the newer touchscreen devices—with the Ledger Live companion app. The individual apps you install are open source, but the underlying secure element operating system, BOLOS, is closed source, so the core security boundary can't be independently reviewed the way a fully open design can. Devices are multi-asset by default rather than shipping a dedicated Bitcoin-only firmware edition.

Strong fit

  • People who want a widely used, certified-hardware signer with a polished companion app.
  • Users who hold multiple assets, not just Bitcoin, on one device.
  • Anyone prioritizing a large ecosystem of supported apps and integrations.

Consider

  • The secure element OS is closed source—you're trusting Ledger's certification, not auditing the code yourself.
  • No dedicated Bitcoin-only firmware edition, and no air-gapped (QR or SD card) signing path.
  • Ledger Recover, an opt-in cloud/social seed-backup service, has drawn criticism; it's optional and can be ignored if you self-custody your own backup.

Product details checked against COLDCARD, Trezor, Krux, Blockstream, Bitkey, BitBox, SeedSigner, Foundation, Ledger. Features, availability, and pricing can change. Links checked August 6, 2026.