87 / 691CZ·02

Trezor

Czech hardware wallet for self-custody and verification outside a general-purpose computer

Trezor is SatoshiLabs' hardware-wallet brand: its devices keep and use private keys apart from the host computer, while bitcoin remains on the blockchain and safety still depends on transaction checks, backups and the threat model.

Marek Palatinus and Pavol Rusnák began the prototype after meeting at brmlab in 2011, opened preorders in 2013 and shipped Trezor Model One in 2014. Trezor is neither a custodian nor an impenetrable vault: an exposed seed, wrong passphrase, unchecked address or physical attack can bypass its protection.

Trezor is a hardware wallet for self-custody: under normal signing the private key stays on the device, while coins and history exist on the blockchain. A valid backup can recover from device loss; disclosure of that backup defeats the benefit of hardware isolation. [Trezor — what is a hardware wallet]

SatoshiLabs says Marek Palatinus and Pavol Rusnák met at Prague's brmlab in 2011, opened preorders in 2013 and shipped Model One in 2014; Model T followed in 2018. Safe 3, Safe 5 and the 2025 Safe 7 later expanded the line. Model One and Model T left direct sale in January 2026, but critical updates are promised through at least 2036. [SatoshiLabs — our story] [Trezor — company] [Trezor — Model One and Model T support] [Trezor — Safe 7 announcement]

The host application constructs a transaction and the device displays what the user must approve before signing. Malware may replace an address on the computer screen, so recipient and amount must be checked on Trezor's display; the device cannot infer human intent or identify a fraudulent counterparty. [Trezor — threats and device verification]

A wallet backup restores funds independently of the particular device. Depending on the model, Trezor supports BIP39 and SLIP39 formats with 12, 20 or 24 words; formats and word counts are not interchangeable. The backup should never be photographed, cloud-stored or entered into a website. [Trezor — wallet backup formats]

A PIN restricts use of a stolen device, the wallet backup restores keys, and an optional passphrase derives a separate wallet. Trezor does not store or recover the passphrase: a typo opens another valid wallet, and losing the exact text makes funds inaccessible even with the correct backup. [Trezor — threats and device verification] [Trezor — wallet backup formats]

Trezor Suite is the application interface and Trezor Connect lets third-party apps integrate; both sit before the device's signing boundary. Exporting an XPUB cannot spend but exposes an account's addresses, balances and history, so it is a substantial privacy disclosure tied to account, derivation path and passphrase. [Trezor — XPUB privacy] [Trezor Connect — integration documentation]

Trezor publishes firmware and Suite source code and signs official firmware. Public repositories enable inspection and reproducible claims, but prove neither flawlessness, an independent audit of every release nor a safe supply chain; installing unofficial firmware also wipes the device and triggers a warning. [Trezor firmware — public repository] [Trezor Suite — releases]

Safe 3, Safe 5 and Safe 7 use secure elements, but their architectures differ. In 2026 Trezor described a difficult physical attack on Safe 7's TROPIC01 that can extract one PIN-protection secret and attestation material; the company says it is not remote seed extraction, yet one of three physical barriers is weakened. An auditable chip is not an invulnerable chip. [Trezor — TROPIC01 vulnerability disclosure]

Safe 7's quantum-ready label describes a future firmware-verification upgrade path, not post-quantum Bitcoin signatures today. A sufficiently capable quantum computer would threaten current cryptography, but Bitcoin's ecosystem must adopt any new signature scheme; Trezor says an urgent email demanding a quantum upgrade now is a scam. [Trezor — Safe 7 announcement] [Trezor — quantum computing and Bitcoin]

In August 2026 Trezor disclosed a ShipMonk incident: 11,742 customer records were fully and 1,947 partly exposed. Trezor says its systems, devices, seeds and funds were not breached, but names, contacts and delivery addresses raise targeted phishing and physical-attack risk. Key security is not security of all operational data. [Trezor — ShipMonk customer-data incident] [Financial Times — Trezor shipping-data breach]

For the clearest picture, read this entry together with Bitcoin, SatoshiLabs, Hardware Wallet, Self-custody, Private Key, Seed Phrase. The reverse links also lead from BIP 39, Hardware Wallet, Prague Bitcoin ecosystem, SatoshiLabs.

DOC · 001Trezor — what is a hardware walletDocumentationDOC · 002SatoshiLabs — our storyPrimaryDOC · 003Trezor — companyPrimaryDOC · 004Trezor — threats and device verificationDocumentationDOC · 005Trezor — wallet backup formatsDocumentationDOC · 006Trezor — XPUB privacyDocumentationDOC · 007Trezor Connect — integration documentationDocumentationDOC · 008Trezor firmware — public repositoryDocumentationDOC · 009Trezor Suite — releasesDocumentationDOC · 010Trezor — Model One and Model T supportPrimaryDOC · 011Trezor — Safe 7 announcementPrimaryDOC · 012Trezor — TROPIC01 vulnerability disclosurePrimaryDOC · 013Trezor — quantum computing and BitcoinDocumentationDOC · 014Trezor — ShipMonk customer-data incidentPrimaryDOC · 015Financial Times — Trezor shipping-data breachDocumentation
Reviewed 1 August 2026Source-first · No investment advice