NewsCryptoTrezor Safe 7 Review: The FOSS Self-Custody Hardware Wallet

Trezor Safe 7 Review: The FOSS Self-Custody Hardware Wallet

Author: Bitcoin Magazine·

Key Takeaways

  • •The Safe 7 uses a 20-word SLIP-39 backup standard that can be extended into Shamir secret sharing, letting users split their seed into shards stored in separate locations with no onchain transactions needed to migrate funds.
  • •It is the first Trezor to ship with Bluetooth and internal LiFePO4 battery, a combination that arguably moves the device out of strict air-gapped cold storage and closer to a high-security warm wallet.
  • •The wallet combines four independent entropy sources — the host computer, an STM32 microcontroller TRNG, the Optiga secure element, and the TROPIC01 chip — under GPL 3 open-source firmware that independent researchers can verify.
  • •Trezor offers two firmware stacks, a Bitcoin-only version and a multi-coin universal version, with the company stating that Bitcoin-only firmware requires fewer updates and carries a reduced risk of bugs or security issues.
  • •A breach at Trezor's shipping partner ShipMonk exposed 67,000 U.S. customer records, prompting Trezor to build an 'Anonymous delivery' service that will launch in the E.U. within weeks and expand to the U.S. soon after.
Trezor Safe 7 Review: The FOSS Self-Custody Hardware Wallet

Some hardware wallets pursue fully air-gapped designs that end users can assemble by hand, or devices tailored to industry professionals under a free and open-source ethos. Others close their source code and aspire to become the Apple or Macintosh of hardware wallets, competing through tightly engineered user guardrails. With the Safe 7, Trezor appears to have found a middle ground between the two approaches.

A hardware wallet's core job is narrow but critical: keep the private keys that control bitcoin in offline isolation and sign transactions on-device, so those secrets never sit on an internet-connected computer. How much of the software and hardware around that job is open to public inspection is the divide separating the industry's two camps.

The device feels closer to a modern iPhone than to a conventional bitcoin accessory: a metal exterior, a wide screen that reaches the borders of the chassis, and tactile feedback clearly engineered to satisfy the user. In a way most other wallets do not, the Safe 7 creates the impression that bitcoin is a real, physical thing.

Trezor also navigates the divide between Bitcoin and broader crypto users by shipping two firmware stacks and two designs: a standard multi-coin version in black and green, and a Bitcoin-only version in orange. Users can switch between firmware types at will regardless of which colorway they order, but Bitcoiners who already know what they want can buy the orange edition and skip any off-path firmware upgrade.

The choice does carry consequences. Many firmware updates revolve around coins other than bitcoin, which makes the Bitcoin-only firmware leaner. Trezor's support documentation puts it plainly: "Added advantages of running Bitcoin-only firmware include fewer regular updates (compared to the Universal firmware) and reduced risk of bugs or security issues."

The Magic Words

The first thing an experienced bitcoin user who has never handled a Trezor will likely notice is the size of the company's word list. The Safe 7 generates a 20-word wallet backup rather than 12 or 24 words used by most other wallets. This is a security design choice Trezor has been building on for years: the 20-word standard, known as SLIP-39, was first introduced by the company in 2019 alongside its announcement of the Shamir backup feature.

The naming reflects two standards tracks: BIP-39 is the Bitcoin Improvement Proposal that defines the 12- and 24-word seed phrases most wallets use, while SLIP-39 comes from the SatoshiLabs Improvement Proposal series published by Trezor's maker.

Shamir lets users split their wallet's backup seed words into shards, a threshold of which can recreate the Bitcoin wallet while any single shard alone is insufficient. In a two-of-three Shamir setup, for example, users write down three lists of 20 words and store them in separate physical locations — the bank, the home, the office. If a thief finds one shard, or a fire or flood destroys it, the loss is not catastrophic: a single shard grants no one access to the wallet, and the remaining two let the owner regain control and move the coins to a new wallet setup.

This quality, often called redundancy, can also be achieved with multi-signature wallets, though with different trade-offs such as onchain transaction costs. Shamir backups derive from an old, well-known cryptographic scheme called Shamir Secret Sharing, for which Trezor built its own implementation.

The extra words, compared to the more popular 12-word standard, do not give users more entropy; Trezor is clear that users can expect the same 128 bits of entropy as with 12-word seeds. According to the company, however, the word list used in SLIP-39 is carefully curated to avoid confusing or similar words.

SLIP-39 also unlocks something BIP-39 does not: extensibility into Shamir. Users who initially create a single 20-word seed backup with a Trezor device can later create a redundant set of Shamir shares, such as a three-of-five. Because these shares recreate the same wallet, no onchain transactions are needed to transfer funds. Users should, however, consider destroying their original 20-word single seed, since it alone will still be able to restore the wallets involved. Trezor maintains a full FAQ on the topic. SLIP-39 is also supported by other wallets such as Sparrow and Electrum, though it has far less adoption than its predecessor.

Top of the Line User Experience

The Safe 7 demonstrates a deep investment in design and user experience through a series of subtle but memorable features. The most striking, in testing the device, was its response to important approval decisions, such as signing a transaction or changing the security PIN code. The user is asked to press and hold a digital button at the bottom of the screen. The device begins to vibrate slowly via an internal gyro as two green lights flow from the button around the edges of the screen. As the lights reach the top of the screen to meet, the gyro accelerates, producing an escalating mechanical sound and sensation in the hand. The sequence culminates with the full illumination of the screen frame and a small green LED up at the top, confirming completion. The whole ritual lasts a second or two, but it makes the otherwise abstract experience of moving bitcoin feel quite real.

Compared with other Trezor models, such as the Model T and the classic Trezor One, the thought put into making cryptographic money comfortable to use is evident. The on-screen buttons are much bigger than the Model T's, resolving the common mistyping occurrences that can carry significant consequences — for instance, when inputting the security PIN. On most hardware wallets, entering a PIN incorrectly can escalate to wiping the device memory. The bigger, finger-sized digital buttons relieve that unnecessary stress. The metal casing also gives the Safe 7 a sense of maturity, leaving behind the plastic shell of older models.

One curious interface feature is the "Wipe PIN" — a special PIN code that, when entered at device login, deletes the user data. Trezor's public documentation describes its function but not its purpose: what risk or threat is it trying to address? What use case? Security-conscious bitcoiners have requested features of this sort as a response to low-likelihood but high-impact scenarios like the infamous "wrench attack", where a thief forces a user to open their wallet to steal the funds.

The problem with Trezor's Wipe PIN is that it makes it quite obvious the wallet's contents have just been deleted — something a wrench attacker is unlikely to accept in that scenario. At least one other hardware wallet has implemented a more sophisticated version of this feature, which deletes the main user's wallet but opens a second "decoy" wallet without revealing the trick via the user interface. For those paranoid enough to think about this, a more advanced wipe PIN would be welcome.

The Safe 7 also offers Bluetooth connectivity and an internal battery that can be charged via Qi2 wireless chargers. The device can alternatively be used via a USB-C connection with Bluetooth disabled in the settings. Wireless operation frees the from cables — another subtle but powerful design choice that relieves added stress when signing a transaction, given that bitcoin's immutable, irreversible spending nature already makes every signing decision high-stakes. For more cautious users, a hardware off switch for the Bluetooth antenna would be a welcome addition.

The Airgap Principle

By strict definition, an air-gapped wallet never touches a network at all, keeping the environment where private keys live physically separated from the online world. No Trezor model before the Safe 7 shipped with an internal battery or Bluetooth. Adding such technology is a significant decision, delivering real gains in what a broader consumer base might expect from modern hardware, but also introducing potential risks.

Internal batteries are known to fail over time in many devices, from hardware wallets to mobile phones, swelling and breaking out of their casing. This can be a hazard and can destroy device memory or accessibility. Trezor addresses the concern by choosing the LiFePO₄ battery type, whose "chemistry is more stable and safer than common lithium-ion batteries." In its documentation, the company claims that "swelling is extremely unlikely."

Integrating Bluetooth, meanwhile, means adding a broadly closed-source software and hardware stack that enables interaction with the device at range — undermining the air-gapped principles of bitcoin cold storage. To mitigate this, hardware manufacturers like Trezor isolate the Bluetooth antenna and use it only to send messages that are encrypted end to end. For this purpose, Trezor built the Trezor Host Protocol, a technology that encrypts data in transit to the user's computer and is also used over the USB-C cable connection. Trezor does not trust USB cables or the Bluetooth stack with unencrypted data.

Nevertheless, the wireless connection arguably moves the Safe 7 out of the air-gapped or cold storage category of Bitcoin wallets and closer to a high-security warm wallet — a hot wallet being a general computer or server connected to the internet that holds private key material.

Hardware Overview and Entropy

If the Coldcard hack demonstrated anything, it is that cold storage is meaningless without good entropy. Entropy is the random, unpredictable input used to create a secret in cryptography — such as rolling dice 100 times and writing down the results. Those outputs are run through cryptographic algorithms to generate private and public key pairs, known as the seed words. Trezor publishes a full, in-depth article on how it generates and uses entropy to create wallet key pairs.

With the Safe 7, Trezor draws on four sources of entropy:

  • The host computer or phone's entropy.
  • A hardware TRNG in the STM32 microcontroller, one of Trezor's computer chips.
  • The Optiga secure element, the second computer chip in the Trezor hardware.
  • The TROPIC01, the company's latest "independently auditable" secure element chip.

Secure elements are hardened chips designed to guard secrets against physical tampering, independent of a device's main processor. The four independent sources are combined when generating a wallet, and the firmware handling this logic is GPL 3 open source. As a copyleft free-software license, GPL 3 allows anyone to read, modify, and redistribute the code under the same terms — the kind of transparency that lets independent researchers verify, rather than trust, what the firmware actually does with those entropy sources. Trezor does not currently enable user-generated entropy input at wallet creation — there are no dice rolls — though users can add a "pass" or "25th word" to already-created keypairs, which serves a similar function.

Trezor CTO Tomas Susanka explained in a conversation with Efrat Fenigson that user-generated entropy only matters if the code actually uses it. He pointed out that the Coldcard bug was not a failure of hardware-generated entropy, but rather that the firmware failed to use that high-quality entropy in its software implementation due to the bug.

Danny Sanders, CCO of Trezor, echoed this sentiment, though he told Bitcoin Magazine the topic of user-added entropy had been "discussed a lot," adding that "it's not a hard no." The broader Trezor user base, which according to Sanders is "multiples" that of Coldcard, "cannot be asked to throw dice," he said, adding that "they already have a mental overload with just writing down words," referring to the 20-word seed backup. When machine entropy sources are actually used properly, the security benefits of user-added entropy are marginal.

Shipping, Phishing and Wipe Codes

Buying any hardware wallet online and shipping it home is increasingly unpalatable. Trezor recently joined Ledger among large crypto hardware providers whose user databases have been hacked — in Trezor's case through its shipping partner ShipMonk, whose databases exposed 67,000 U.S. customer records earlier this month. According to Trezor, most of those records were supposed to have been deleted by the shipping company. The result is an increased risk of targeted harassment of those users, who in countries like France are already high on the list for organized crime.

From an operational security perspective, having a P.O. Box is now basically a requirement for crypto-related purchases. No large corporation or government can be trusted to keep user personal data secure; the history of the internet demonstrates that conclusively. Users can also attend large conferences and buy their hardware wallet of choice with cash or bitcoin, avoiding shipping risk altogether.

On this topic, Trezor has teased an "Anonymous delivery" service it is building in response to the breach. Sanders told Bitcoin Magazine the service will be available in the E.U. within weeks and will expand to the U.S. soon after. According to public data, the company currently still uses ShipMonk.

Concluding Thoughts

Having used Trezor products for many years — albeit older models like the Model T and the Trezor One — the Safe 7 stands out as a serious evolution of the product line and a strong addition to a self-custody setup, in particular as part of a multi-vendor multisig arrangement or as a daily-use warm wallet. Its Shamir backup feature also deserves a place among more advanced self-custody solutions.

This article, Trezor Safe 7 Review: The FOSS Self-Custody Hardware Wallet, first appeared on Bitcoin Magazine and is written by Juan Galt.