TL;DR
A secure element is a tamper-resistant chip, the same kind used in bank cards and passports. In a hardware wallet it protects secrets against someone who has the device in their hands. It doesn’t protect you from a fake computer or a leaked seed backup.
What it protects against
Physical attacks. Someone who steals a hardware wallet can open it, probe the chips, glitch the power supply or measure tiny changes in power use to extract secrets. Secure elements are designed to resist exactly that: they detect tampering, hide their internals and lock or wipe themselves after too many wrong PINs.
What it doesn’t protect against
- A copy of your seed words. Whoever has the words doesn’t need the device.
- A compromised computer that shows you a wrong address. That’s what checking addresses on a device screen with your multisig registered is for (step 8).
- Weak seeds from a firmware bug, like the Coldcard flaw disclosed in 2026 that affected seeds created on those devices since 2021.
Three ways makers use it
| What runs on the secure element | Chip | |
|---|---|---|
| Ledger | Everything: keys, signing, what the screen shows | ST33K1M5 (Nano S Plus) |
| Trezor Safe 5 | PIN check and a secret that unlocks the keys | OPTIGA Trust M V3 |
| BitBox02 | A secret that unlocks the keys, attempt counter | ATECC608B |
| Blockstream Jade | No secure element; a remote “blind oracle” instead | None |
Ledger’s approach gives the strongest physical protection to the keys themselves, but the code on the chip isn’t public. Trezor and BitBox keep the bitcoin code on an open microcontroller and use the secure element only as a guard. See open vs closed source hardware wallets.
Certification
Secure elements are usually certified under Common Criteria, for example EAL6+. That tells you how thoroughly the chip was evaluated, not that the whole wallet is secure.
In a multisig
Less critical than with a single wallet. A thief who defeats one device’s secure element only gets one of the two keys they need.