Security alert · 30 Jul 2026: a seed-generation flaw in Coldcard devices was disclosed. What to do →

Infineon OPTIGA Trust M in the Trezor Safe 5 and BitBox02 Nova

TL;DR

The OPTIGA Trust M V3 is a secure element from Infineon, certified CC EAL6+. Trezor and BitBox use it as a guard: it checks your PIN and releases a secret that unlocks the keys, while the bitcoin code stays on an open-source microcontroller.

Why this chip

Most secure elements come with non-disclosure agreements that stop wallet makers from publishing how they use them. Trezor says it picked the OPTIGA Trust M because its documentation is available without an NDA, which fits open-source firmware. BitBox uses the same chip in the BitBox02 Nova, for the same reason.

What it does in a Trezor Safe 5

  • Checks your PIN, without storing the PIN itself.
  • Holds a secret that, together with your PIN, decrypts the keys stored on the main chip. It only releases that secret after a correct PIN.
  • Adds its own randomness when a new seed is created.
  • Holds a certificate that proves the device is genuine, used by Trezor Suite’s authenticity check.

What it doesn’t do

Sign transactions. That happens on the main microcontroller, running Trezor’s open-source firmware. The secure element provides physical protection, and all the code that handles your bitcoin can be checked by anyone. See what is a secure element.

Certification

Common Criteria EAL6+, with protection against fault injection and side-channel attacks. What that level means is explained in CC EAL6+ explained.

Reviews: Trezor Safe 5 · BitBox02 vs BitBox02 Nova