This guide is not about why. Freedom. That's all I'll say about why. This guide is about how.
Freedom and our digital shields
Satoshi's discovery of absolute digital scarcity has given us immense freedom: freedom from bankers, politicians and powerful institutions that might infringe on our property. Every satoshi represents a slice of freedom that can't be taken away by anyone.
The downside to that freedom is the responsibility that comes with it. Today we have numerous tools to protect our digital property from bad actors or loss. These tools are our digital shields. But security is not just about owning the right tools, it's about using them correctly.
The goal of this guide is to give an experience-based overview of hardware wallets that may help you decide which tools are a good fit for protecting your freedom.
Who this is for
This is for people looking for the best bitcoin hardware wallet without having to try them all themselves.
Bitcoin basics
These basic inner workings of bitcoin help us understand how to work with bitcoin and decide on the right tools.
Bitcoin ownership: keys and signatures
Bitcoin ownership boils down to keys, which come in pairs: public and private. A public key is like a bank account: all anyone can do with it is send money there. The corresponding private key is like the password to that account, which lets you actually move the money.
A private key lets you move bitcoin by signing a transaction, which is only valid if it includes a signature. Anyone can create a transaction that moves any bitcoin, even all of Satoshi's, but without a signature that transaction is incomplete. You need the corresponding private key to provide a valid signature.
Bitcoin transactions are usually created on a device connected to the internet, like a mobile or laptop (we call this hot). We then pass that transaction to our hardware wallet, which views and verifies the details and confirms the transaction with a signature. Once a transaction is signed, it can be broadcast to a bitcoin node so miners can include it in a block and append it to the blockchain.
Hot device creates transaction > sends to cold device > cold device provides signature > hot device broadcasts the signed transaction.
Hardware wallets: storing keys, not bitcoin
There are never actually any bitcoin on any of the devices we'll be discussing. All bitcoin are stored publicly on the blockchain, on every full node on the planet (a full node is a computer that keeps a full copy of the blockchain, a long list of every bitcoin transaction that has ever taken place). The hardware wallets we'll talk about only exist to hold the private key needed to sign transactions, so we can move our bitcoin.
Hardware wallets vs signing devices
A hardware wallet stores the private key used to sign bitcoin transactions, so every hardware wallet is a signing device. But there are also stateless devices that don't store a bitcoin private key permanently and are still able to sign transactions. A device like the popular Seedsigner requires you to load a private key onto it before it can create signatures. Some devices can work both ways.
From seed to address: the cryptographic chain
The final basic to understand is the relation between a seed phrase, private key, public key and addresses. Your seed phrase is your starting point: human-readable words, usually 12 or 24. It's not a key itself but a master blueprint that deterministically (reproducibly) derives the rest.
- Your seed phrase produces a private key.
- The private key generates a public key, mathematically linked to it but irreversible.
- A public key spawns addresses, which are practically unlimited.
Seed phrase > private key > public key > addresses. The seed phrase is therefore the most important part of your setup. You can lose the hardware wallet that holds your private key, as long as you have your seed phrase backup.
Air gaps
Air gaps are security measures where a device like a hardware wallet is never connected to another, internet-facing device. This significantly reduces exposure to compromise. Instead of transferring transactions over USB or Bluetooth, air-gapped signing devices use QR codes or SD cards. QR codes have become a popular workflow for signing bitcoin transactions.
Air gaps are mostly praised for their added security, but that might be overrated: connecting over USB is not, by itself, a security issue that has caused real-life theft of user funds. Air gaps might be overrated for their security but underrated for their usability. The ability to simply scan a QR code is a much preferred workflow for many, and rightfully so.
Methodology
Approach and focus
When evaluating hardware wallets, several things matter: security, usability, durability, compatibility and value. Security comes first: if a wallet is insecure, its ease of use or price tag is irrelevant. But here's the reality: none of the devices in this guide are insecure in any real sense. There appear to be zero documented instances of a device's inherent security being breached and funds being stolen as a result. There are documented instances of white-hat hackers getting into devices, but none of those resulted in stolen user funds, and that's not just down to the manufacturers: they stand on the shoulders of cryptographic giants, Satoshi being just one of them.
Bitcoin does get stolen, but it seems to always come down to user error, phishing, loss, physical theft or extortion. Given that strong security baseline, I'm assessing these hardware wallets mainly through a practical, usability lens. The devices themselves are secure in any practical sense; it's the user who is always the weakest link. Overall usability, and how smoothly a device guides users to proper use, is one of the best differentiating security features any device can have. Usability is security. Security is not just about owning the right tools, it's about using them correctly.
Process and approach
Who in their right mind buys fifteen-plus hardware wallets? You only need one. If you're looking at multi-sig and need to manage multiple keys, maybe two or three, and even then several signing devices can do multi-sig entirely by themselves (Seedsigner, Passport, Jade and Jade Plus, Coldcard, Specter).
I do have them all lying around, but the point of this guide isn't to review every bitcoin hardware wallet and throw together the unboxing photos and setup steps. You can find extensive unboxings and reviews elsewhere, and I'll link to the best of those so this guide can serve as an anchor point for further reading. An AI agent could quite simply scrape and summarise the reviews of all these devices into one massive article.
The approach here is experience-based: a wider, holistic view of where a specific model fits within the broader ecosystem, not just a feature comparison, but a report on real usage with real bitcoin. When you first buy a hardware wallet you're excited and proud, and you should be. Starting the journey of self-custody is a big step toward self-sovereignty.
Picking holes
When the umpteenth device hits your hands and a core feature doesn't work properly, you get critical. There's no other way around it, not for me. You can't un-know what you know: if another device at a similar or lower price does the same thing instantly, you can't help but wonder why this one can't. Those experiences have been the source of several frustrations you'll read about here.
As an official reseller for most of the brands discussed in this guide, and in direct contact with many customers, I believe I'm well positioned to review these cold storage tools as part of a whole. Some will find me overly critical. My harshness is deliberate: it's by relentless testing that we forge resilience, and I'll be pointing out the weak spots so the industry can raise the bar and onboard the next billion users.
Compatibility
An often overlooked feature is compatibility: how well a hardware wallet plays with other tools in the bitcoin ecosystem. Bitcoin is a protocol, a set of rules, and hardware and software have to follow those rules for different components to work smoothly together. Bad things happen when companies don't follow the rules.
Compatibility is about making sure your wallet speaks the same language as your software, backups and recovery methods. Hardware wallets use standards like BIP-39 (seed phrases) and BIP-44 (derivation paths) to generate keys and addresses, but not every wallet implements them the same way. Get this wrong and you might not be able to find your bitcoin again. If you set up a wallet with device A on its default settings, lose it, then try to recover with a different device, and some setting like the derivation path differs, your funds can seem to vanish. They're still there, just invisible to the new device: not lost, hiding behind a compatibility gap.
Hardware wallets, reviewed so far
Blockstream Jade
It makes sense to start with the cheapest device. A lot of newcomers are budget conscious, and the Jade's low price point is appealing to that audience. Before writing this section I looked at what others are saying, out of curiosity, and there's a lot of content on the Jade out there: Privacy Pros lists it as a 9.3/10 device, Athena Alpha rates it 4.3/5, BlockDYOR gives it 92/100, MaterialBitcoin is the first to mention real downsides like battery life and build quality, HardwareWallets.net rates it 90% and beginner-friendly, and HeyApollo rates it 4.5/5 across 73 reviews.
It doesn't make much sense to do yet another unboxing and setup article about how it has a camera, is open source, has USB-C and supports Liquid. I'm swimming against the tide here, not to be contrarian, but to give my honest opinion, and I hate to say what I'm about to say, because Blockstream really is an OG bitcoin company pushing the space forward. I love bitcoin and every company doing its part.
But I think the Blockstream Jade is a rough device. It screams low build quality. The camera struggles. The jog wheel feels like it's going to give out if you nudge it too hard. The overall experience makes the case for self-custody feel weaker than it should.
It's the people who love their Jade, like the reviewer on HeyApollo who called it "the best cold wallet for beginners, very user friendly," who will push back on this, and that's fair. This is about fixing the world, not about getting likes. In a world where anyone can generate another five-hundred-word positive review in five seconds with AI, experience-based insight becomes more valuable, not less.
It also strikes me that I'm being unfair here. This is a budget device meant to onboard as many new users as possible, and a low price point is crucial for that. But it saddens me that the Blockstream Jade has been the first cold storage experience for so many people. That people do like it is genuinely interesting, and we'll see the same pattern with some of the other wallets in this guide: a mix of confirmation bias and not knowing any better. Every experienced bitcoiner I know has similar thoughts.
Score: 2/10. Who should buy this in 2025? Almost no one. It would be a 1 if it weren't still somewhat usable over USB. If you want a budget device, look at the Cardware instead.
Blockstream Jade Plus
The upgraded Jade Plus is a different story: build quality is solid now, screen quality is good, and menu navigation is clear and smooth. The camera might be the best of all the devices tested. It's a genuinely usable standard hardware wallet, and like the base Jade it has no secure element, which several other reviewers list as a con but which I think is actually a significant pro: not having to trust a black-box secure element is a real win.
If you want to use it as a stateless signing device, loading a seed via QR code, you're going to have a bad time. I tried loading a seed QR onto the device for several minutes straight without success. Every other device capable of this (Foundation Passport, Seedsigner, Specter, Krux) does it instantly, sub-second. The first-open experience was genuinely solid, which made the failed seed QR load more frustrating: this would be a near-perfect device if they'd nailed that too.
Score: 7/10. Who should buy this in 2025? Anyone who wants to avoid a secure element and wants a simple, solid airgapped device. Works well as part of a multi-sig setup.
Bitbox
The BitBox02 has earned attention for its security, usability and price. Being Swiss-made helps its popularity. It's a beautiful piece of tech: you can't tell what it is just by looking at it, since it has no physical buttons.
The trade-off is capacitive touch instead of physical buttons, and it doesn't work as smoothly as simple, physical clicking with tactile feedback. Entering a six-letter word for the first couple of times can take a full minute; compare that to entering a six-digit PIN on a touchscreen like the Keystone, or with buttons like the Passport, and the difference is night and day.
This has become the device's biggest downside, and a fairly critical one. The BitBox app makes up for a lot of it: it's genuinely one of the best companion apps out there, and the Pocket Bitcoin integration for buying straight to your cold storage BitBox is close to perfect. Personally, I can't get past the un-usability of plugging it in and entering a password with dozens of careful touches, compared to switching on a battery-powered device and pushing six digits, which is at least ten times faster.
Trezor Safe 5
The Trezor Safe 5 is SatoshiLabs' latest hardware wallet release. A key security feature is its EAL6+ certified Secure Element, which is NDA-free: notable, since most secure element chips in other hardware wallets exist under NDA and require a degree of trust.
In real-life first use, the packaging is straightforward: basic cardboard, two small stickers and a short 50cm USB-C to USB-C cable. Functional, but underwhelming for a premium security device. On setup, the wallet defaults to SLIP39 rather than the more familiar BIP39 word list, and finding the "classic" BIP39 option takes extra digging, which could frustrate anyone expecting BIP39 by default.
Verifying the seed phrase means picking the right word from a three-word multiple-choice list, which is secure but cumbersome, and slow for new users given the small, somewhat unresponsive screen. An accidental tap on the wrong word forces a full reset to factory defaults, erasing all progress, which is a real hassle given it's also unfamiliar for new users to go from seeing 24 words to selecting them from a list rather than swiping through. The touchscreen can be error-prone generally: even entering the PIN at unlock sometimes fails because the numbers are easy to mis-tap.
Cardware
Disclosure: a sample alpha device was provided by Cardware for testing.
The Cardware wallet is a fully air-gapped budget hardware wallet. It has no internal battery and is powered via USB-C with only power connections active, so no data transmission is physically possible. This is visually verifiable through its transparent casing and circuit board.
It combines an EAL6+ certified secure element with hardware-level read/write protection against physical tampering, and, in an industry first, can use a video stream as entropy for key generation, alongside supporting dice rolls. That combination of features at a bargain price should give the Blockstream Jade real competition as the preferred budget bitcoin hardware wallet.
Build quality: given the price, it feels surprisingly solid. It's clearly a budget device, but the large buttons give it a good tactile feel. The camera feed is low quality but scanning QR codes still works.
Missing: there's no support for loading a seed QR, so you can't use the device statelessly. That's a real gap.
Non-upgradeable firmware: since the device has no SD card slot, its firmware can't be upgraded. This is presented as a security feature, but I'd call it security theatre: an ultra-secure design choice that doesn't solve a real security problem. Devices like the Foundation Passport and BitBox have had valuable firmware updates over the years that keep paying off for long-term holders.
Features: air gap, power-only USB-C, EAL6+ secure element, dice entropy, web wallet integration. What sets it apart: transparent casing and circuit board, non-upgradeable firmware, hardware-level read/write protection, and high-entropy key generation from a hashed video stream.
This guide is a work in progress. Keystone 3 Pro, OneKey Pro, Coldcard Mk4, Coldcard Q and Foundation Passport are reviewed next, along with the DIY category (Specter, Krux, Seedsigner, airgapped computer), a full comparison table and a conclusion. None of that is written yet, so it isn't published here.