Security alert · 30 Jul 2026: a seed-generation flaw in Coldcard devices was disclosed. What to do →

Open vs closed source hardware wallets

TL;DR

Open-source firmware lets anyone check what a wallet does; closed code asks you to trust the maker. Secure elements are almost always closed. Trezor and BitBox keep the bitcoin code open and use the secure element as a guard; Ledger runs everything inside it. In a multisig with three brands, you can use both approaches.

What “open source” means here

The firmware’s source code is public. Security researchers can read it, and anyone can look for bugs or hidden behaviour. With reproducible builds, people can also check that the firmware on the device was built from that exact code.

Why secure elements are closed

Chip makers share the internals of their secure elements only under non-disclosure agreements. Code running on such a chip can’t be published. So a wallet maker has to choose: put everything on the secure element and keep some code closed, or keep the important code on an open chip and use the secure element for less.

MakerBitcoin codeSecure element
TrezorOpen, on the main chipOPTIGA Trust M as PIN guard
BitBoxOpen, on the main chipATECC608B or OPTIGA as guard
LedgerBitcoin app open; OS closedST33K1M5 runs everything
Blockstream JadeOpenNone; blind oracle

Does open source make it safer?

It means anyone can check it. Bugs still happen in open code, but they’re more likely to be found by someone other than an attacker, and hidden backdoors are much harder to slip in. Closed designs rely on the maker’s own reviews and certifications.

The multisig answer

Use makers with different approaches. A 2-of-3 with Trezor, BitBox and Ledger combines two open designs with one closed design. A flaw in any single approach only gets an attacker one of the two keys they need.