Our selection standard

How we decide what’s worth trusting

Most comparison sites pretend every device is fine and let affiliate links do the talking. We don’t. This is a Bitcoin-only guide with an opinion — but a careful one. We judge every device on two separate things, and keeping them separate is the whole point.

A hard security floor

Non-negotiables about whether the security model is sound. Miss one and the device is disqualified — not a matter of taste.

Savings-grade criteria

What we want on a device guarding a decade of cold savings. A secure device that misses one isn’t unsafe — it’s just built for spending, not for a vault.

That gives three tiers. Every device is covered in full no matter where it lands.

Built for cold storage

9

What we’d trust with long-term savings.

Clears the security floor and every savings-grade criterion: minimal, verifiable, self-sovereign, Bitcoin-only. A dumb, offline, checkable lump of metal whose only job is to guard your keys for years.

  • Coldcard Q
  • Coldcard Mk5
  • Trezor Safe 3
  • Trezor Safe 5
  • Trezor Safe 7
  • BitBox02 (BTC-only)
  • Blockstream Jade
  • Blockstream Jade Core
  • Blockstream Jade Plus

Built for spending

2

Secure — but suited to active or smaller balances, not a savings vault.

These clear the security floor: the maker cannot take your coins and no firmware feature can ship your keys off the device, so they are honest self-custody. They miss a savings-grade criterion — a general-purpose OS, or a dependence on a living company’s servers — that adds surface or a lifeline you would not want on money you are locking away for a decade. For everyday use or smaller amounts, they are genuinely good.

  • Foundation Passport Prime
  • Bitkey

Doesn’t clear our bar

1

Fails a security non-negotiable.

These miss the hard security floor — not a matter of fit or taste. We still cover them in full, because pretending they don’t exist wouldn’t help you, but we would not put your keys on one.

  • Ledger Nano family

How we judge

The security floor — miss one and it’s disqualified

  1. Your keys can never leave over the internet

    No feature — vendor or firmware — can copy, shard, or ship your secret off the device to a server.

    Why: The whole reason to own cold storage is that the secret never touches an online system. A device whose firmware is capable of exporting your seed — even encrypted, even opt-in — has put back exactly the risk you paid to remove. Capability is the fail, not just use.

  2. Verifiable — not a closed black box

    The code that touches your keys is open enough to inspect, so you are not simply trusting one company’s secret firmware.

    Why: Verify, don’t trust — the idea every rule in this guide is an instance of. If the security-critical firmware is closed and unauditable, your safety reduces to a company’s word — and words have been broken before. Source you can read (ideally rebuild and match) clears this; a sealed operating system does not.

Savings-grade — miss one and it’s “built for spending,” not disqualified

  1. Bitcoin-only firmware

    A firmware that runs only Bitcoin is available for the device.

    Why: A signer juggling dozens of other coins carries code you will never use, and every line is attack surface. For money you are locking away, less code doing one job is the safer bet. We only ask that a Bitcoin-only build exists, not that the device can never do anything else.

  2. A minimal, single-purpose signer

    Lean firmware built to hold keys and sign — not a general-purpose gadget that installs apps, stores files, or stays wirelessly connected.

    Why: Every extra app, file store, and radio is another door and another thing that can break. A device you cannot turn into a little internet computer is a smaller target — exactly what you want standing guard for years. Great for a daily gadget; more than a vault needs.

  3. Self-sovereign, portable recovery

    A backup you hold — a standard seed you can restore in independent software — with no dependence on a company’s servers or app to get your coins back.

    Why: Self-custody means no permission slips and no expiry date. If your recovery leans on a company staying alive, online, and willing, then your ten-year plan is really their business plan. A seed you can stamp on steel and restore anywhere is the opposite of lock-in.

Why “more” is a problem for savings

It sounds backwards: how can a device that does more — more apps, a helpful phone app, a company that can help you recover — be a worse choice? Because long-term savings and daily spending want opposite things.

Spending money should be easy: reachable, forgiving, quick to recover if you fumble. A little complexity buys real convenience. But savings you’re locking away for a decade should be boring: a dumb, offline, verifiable lump of metal with almost nothing that can go wrong and no lifeline you don’t control. Every extra feature is another line of code that can carry a bug; every radio is another way in; every dependence on a company is a bet that they’ll still be alive, online, and willing in ten years. None of that makes a device insecure today — it makes it the wrong tool for the one job where simplicity is the security. That’s rule 05 in practice: the simplest setup that covers you wins, and complexity you don’t fully control is itself a threat.

One boundary on that, because it is easy to carry this argument too far. Everything above is about one device — how much code, how many radios, how many companies are inside the thing guarding your keys. It is not an argument that your whole arrangement should rest on a single one of them. A lean, boring signer is exactly what we want, and it should still not be the only thing standing between you and losing everything. What we believe sets out how those two fit together: fewer moving parts inside each component, and never one component whose failure is total.

Built for cold storage — and the caveats worth knowing

All 9 devices in this tier clear the floor and every savings-grade criterion. The cleanest pick — BitBox02 (BTC-only) — clears the bar with no caveat at all. The other 8 earn their place too, but honesty cuts both ways: each makes a trade-off worth understanding before you buy.

Built for spending — secure, but not a vault

These clear the floor: honest self-custody, where the maker can’t take your coins and no firmware feature can ship your keys off the device. They miss a savings-grade criterion, so we’d reach for the tier above for money you’re locking away — while happily using these for day-to-day or smaller balances.

Foundation Passport Prime

Foundation Devices
Foundation Passport Prime

Misses (savings-grade):

  • A minimal, single-purpose signer

The Passport Prime is well-engineered — open-source, air-gap-capable, with a secure element and a Bitcoin-only first-party wallet — so this is not a security knock. It sits here because it is no longer a minimal signer: it is a general-purpose secure platform that also stores 2FA codes, passkeys and files, adds Bluetooth and NFC, and can run third-party apps. That is more code and more surface than you want on a device whose entire job should be guarding keys for a decade. As a do-more device or an active-use signer it is genuinely capable; for a set-and-forget cold vault we would reach for something simpler from the tier above. If Foundation ships a stripped Bitcoin-only signer again — as the older $199 Passport was — it moves up.

Bitkey

Block, Inc.
Bitkey

Misses (savings-grade):

  • Self-sovereign, portable recovery

Bitkey is the most interesting device here, and it clears the security floor cleanly: there is no single master seed to steal, it is a 2-of-3 across three independent keys, and the one key Block holds on its servers cannot move your coins on its own. Architecturally that is stronger against seed theft than a single-seed device. What keeps it out of the cold-storage tier is dependence, not danger. Everyday recovery and setup run through Block’s app and servers; the firmware is source-available but not independently reproducible; there is no 24-word seed you can stamp on steel and walk away with; and while you can export a watch-only descriptor, a clean exit still leans on Block’s own tooling. For an active, phone-first holder or a smaller balance, that trade is often worth it — the experience is excellent and it is real self-custody. For a decade-long vault we would rather not have a company’s servers anywhere in the recovery path. That is exactly the line between it and Ledger: Bitkey splits trust and stays open enough to read; Ledger concentrates a single secret behind firmware you can’t.

Doesn’t clear our bar — and exactly why

Fails the hard floor above. Still covered everywhere else on the site, because pretending it doesn’t exist wouldn’t help you — but we wouldn’t put your keys on one.

Ledger Nano family

Ledger
Ledger Nano family

Fails:

  • Your keys can never leave over the internet
  • Verifiable — not a closed black box

By default a Ledger keeps its seed on the device and cannot spend your coins — that part is genuine self-custody, and worth stating plainly. What disqualifies it is what the 2023 “Ledger Recover” service revealed: the closed firmware is capable of extracting your 24-word seed, encrypting it, splitting it, and sending the pieces to third-party custodians over the internet — a capability Ledger had previously told customers was impossible. Recover is opt-in and paid, so this is not a default backdoor or a proven theft. But because the secure-element firmware is closed and unauditable, you cannot verify which code your device is running, so your security collapses to trusting one company not to export your single master secret — now, under a future update, or under a subpoena. A lone seed guarded by an unverifiable black box is exactly the model the security floor exists to reject. (The 2020 leak — around a million customer email addresses, with names, home addresses and phone numbers for roughly 270,000 of them — fuelled phishing and physical-threat campaigns, and doesn’t help its case.)

The one rule behind all of it

Verify, don’t trust. A device earns the top tier by being something you can actually check and actually hold — Bitcoin-only, unable to leak your seed, open to inspect, doing one job, with a backup no company controls. See how each device measures up in the full comparison.

Last verified: July 31, 2026