Some hardware wallets aim to create air-gapped devices that can be assembled by hand by end users, or tailored to industry professionals in a free and open-source ethos. Others close the source and aspire to become the Apple or Macintosh of hardware wallets, leading through their design of user guardrails. Trezor seems to have found a middle ground with the Safe 7.
The device feels like what you might expect from a modern iPhone, metal exterior, a wide screen that reaches the border of the device, and tactile feedback clearly designed to deliver satisfaction to the user. The Safe 7 manages to give you the impression, the experience, that Bitcoin is a real thing, a physical thing, in a way most other wallets do not.


Trezor also navigates the divide between Bitcoin and crypto users quite well. It pulls it off by delivering two different firmware stacks and designs; the standard multi-coin version, which comes in black and green, and the Bitcoin-only orange. Users can switch back and forth at will, regardless of which one they order, but Bitcoiners who already know what they want can get the orange version and won’t have to do any off-path firmware upgrades. Both types of users can switch to the other firmware type if they are so inclined, regardless of device color.
The choice does, however, have some consequences; many updates to firmware revolve around coins other than Bitcoin. As a result, Bitcoin-only firmware is leaner; Trezor’s support articles put it plainly: “Added advantages of running Bitcoin-only firmware include fewer regular updates (compared to the Universal firmware) and reduced risk of bugs or security issues.”

The Magic Words
The first thing you’ll notice if you have some experience with Bitcoin but have never used Trezor is the size of their word list. The Safe 7 offers 20 words for the wallet’s backup, rather than 12 or 24 as most others. This is a security design choice that Trezor has been building on for many years.
The 20-word standard called SLIP-39 was first introduced by Trezor in 2019 with their announcement of the Shamir backup feature. Shamir lets users split up the wallet’s backup seed words into shards, a threshold of which can be used to recreate the Bitcoin wallet, but any one of which alone is insufficient.
Take, for example, a two-of-three Shamir setup; users write down three lists of 20 words, and store them in separate physical locations: the bank, the home, the office. Any one of those found by a thief or destroyed by a fire or flood is not a catastrophic loss. The single shard can not give anyone access to the wallet, and the other two shards let the owner regain control and move the coins to a new wallet setup. This quality is often called ‘redundancy’, and it is also achieved by multi-signature wallets, though with different trade-offs, such as onchain transaction costs. Shamir backups come from an old, well-known cryptographic scheme called Shamir Secret Sharing, which Trezor built its own implementation of.

The extra words, compared to the more popular 12-word standard, do not give users more entropy; Trezor is clear that users can expect the same 128 bits of entropy as with 12-word seeds. However, the word list used in SLIP-39 is, according to Trezor, carefully curated to avoid confusing or similar words.
SLIP-39 also unlocks something that BIP-39 does not; extendability into Shamir. Users who initially create a single seed 20-word backup with a Trezor device can later on create a redundant set of Shamir shares, like a three-of-five. These shares recreate the same wallet, which means users do not need to do onchain transactions to transfer funds. They should, however, consider destroying their original 20-word single seed, since it alone will also be able to restore the wallets involved.
There is a full FAQ from Trezor that interested users can read up on. SLIP-39 is supported by other wallets like Sparrow and Electrum, though it has far less adoption than its predecessor.

Top of the Line User Experience
The Safe 7 demonstrates a deep investment in design and user experience with a series of subtle but memorable features. The most iconic of all, in my experience testing the device, was how it responds to an important approval decision, such as signing a transaction or changing the security PIN code. The user is asked to press and hold a digital button at the bottom of the screen. The device starts to slowly vibrate with an internal gyro, as two green lights start to flow from the button around the edges of the screen. As the lights reach the top of the screen to meet, the gyro accelerates, producing an escalating mechanical sound and sensation in your hand. The experience culminates in the full illumination of the screen frame, with a small green LED lighting up at the top, confirming the completion of the action. The whole sequence happens in a second or two, but it makes this otherwise rather digital and abstract experience of moving bitcoin feel quite real.
Compared to other Trezors I have tested, like the Model T and the classic Trezor One, the thought gone into making it comfortable to use cryptographic money is evident. The buttons on the screen, for example, are much bigger than the Model T, resolving common mistyping occurrences that can potentially have significant consequences, such as when inputting the security PIN. If a user inputs such a PIN incorrectly in most hardware wallets, it can escalate negative consequences up to wiping the device memory. The bigger finger-sized digital buttons relieve that unnecessary stress. The metal casing without a doubt gives the Safe 7 a sense of maturity, leaving behind the plastic shell of older models.



One curious feature within the interface is that of a “Wipe PIN”, a special PIN code that, when entered on device login, deletes the user data. This feature is not well explained in Trezor’s public documentation; its function is written about, but not its purpose: What risk or threat is it trying to address? What use case? The more paranoid bitcoiners have asked for features of this sort as a solution to low-likelihood but high-impact scenarios like the infamous “wrench attack”, where a thief forces the user to open their wallet to steal the funds.
The problem with Trezor’s Wipe PIN is that it makes it quite obvious that you just deleted the wallet’s contents, something a wrench attacker is not likely to be happy about in that scenario. At least one other hardware wallet has implemented a more sophisticated version of this feature, which would delete the main user’s wallet, but open up a second ‘decoy’ wallet, and not give up the trick via the UI. For those of us paranoid enough to think about this, a more advanced wipe PIN would be welcome.
The Safe 7 also has Bluetooth connectivity as well as an internal battery that can be charged via Qi2 wireless chargers. The device can be used via USB-C connection with Bluetooth disabled via settings. This alternative operation mode frees the user from cables, another subtle but powerful design choice that relieves added stress during the signing of a transaction. Bitcoin’s immutable, irreversible spending nature makes every signing decision high stakes enough as it is. For more paranoid users, a hardware off switch for the Bluetooth antenna would be nice.


The Airgap Principle
No Trezor model before the Safe 7 came with an internal battery or Bluetooth. Adding such technology to the device is a big decision with significant gains in what a broader consumer base might expect from modern hardware, but also introduces some potential risks.
Internal batteries have been known to fail over time in many such devices, from hardware wallets to mobile phones, swelling and breaking out of their case. This can be a hazard and can destroy device memory or accessibility. Trezor addresses this concern, explaining that they chose the LiFePO₄ battery type, whose “chemistry is more stable and safer than common lithium-ion batteries.” In their documentation, they claim that “swelling is extremely unlikely.”
Meanwhile, integrating Bluetooth means adding a broadly closed-source software and hardware stack that unlocks interaction at range with the device, undermining the air-gapped principles of bitcoin cold storage. To solve this issue, hardware manufacturers like Trezor try to isolate the Bluetooth antenna and use it only to send messages that are encrypted end to end. To achieve this, Trezor built the Trezor Host Protocol, a technology that encrypts data in transit to the user’s computer, and which is also used via the USB-C cable connection. Trezor does not trust the USB cables nor the Bluetooth stack with unencrypted data.
Nevertheless, this wireless connection arguably moves the Safe 7 out of the air-gapped or cold storage category of Bitcoin wallets, closer to a high-security warm wallet, where a hot wallet would be a general computer or server connected to the internet, holding private key material.
Hardware Overview and Entropy
If the Coldcard hack taught us anything, however, it is that cold storage is meaningless without good entropy. Entropy is supposed to be the random and unpredictable input that is used to create a secret in cryptography, such as rolling dice 100 times and writing down the results. The dice outputs are the entropy that’s run through cryptographic algorithms to generate private and public key pairs, aka the seed words.
Trezor has a full and in-depth article about how they generate and use entropy to create wallet key pairs. With the Safe 7, they use four sources of entropy:
- The host computer or phone entropy.
- A hardware TRNG in the STM32 microcontroller – one of Trezor’s computer chips.
- The Optiga secure element, the second computer chip in the Trezor hardware.
- The TROPIC01, their latest “independently auditable” secure element chip.
The four independent sources are supposed to combine when generating your wallet. The firmware that handles this logic is GPL 3 open source.
Trezor does not currently enable user-generated entropy input into the creation of a wallet. There are no dice rolls, though the user can add a ‘passphrase’ or ‘25th word’ to accounts to keypairs already created, which serves a similar function.
Trezor CTO Tomas Susanka explained in a conversation with Efrat Fenigson that user-generated entropy only matters if the code actually uses it. He pointed out that the Coldcard bug was not a failure of hardware-generated entropy, but rather that the firmware failed to use that high-quality entropy in its software implementation, due to the bug.
Danny Sanders, CCO of Trezor, echoed this sentiment, though he told Bitcoin Magazine that the topic of user-added entropy had been “discussed a lot,” adding that “it’s not a hard no.” Rather, the broader user base of Trezor, which, according to Sanders, is “multiples” that of Coldcard, “cannot be asked to throw dice.” He added that “they already have a mental overload with just writing down words” refering to the 20-word seed backup. While the security benefits of user-added entropy are marginal, when other sources of machine entropy are actually used properly.
Shipping, Phishing and Wipe Codes
In terms of getting a Trezor hardware wallet, or any hardware wallet for that matter, buying it online and shipping it home is increasingly unpalatable. Trezor recently joined Ledger among large crypto hardware providers whose user databases have been hacked, specifically their shipping partner ShipMonk. 67,000 U.S. customer records were compromised from ShipMonk databases earlier this month; most of these records were supposed to have been deleted by the shipping company, according to Trezor. The result is an increased risk of targeted harassment of those users, who in countries like France are already high on the list for organized crime.
From an operational security perspective, it is now basically a requirement to have a P.O. Box for crypto-related purchases. No large corporation or government can be trusted to keep user personal data secure; the history of the internet demonstrates that conclusively. Users can also attend large conferences and buy their hardware wallet of choice with cash or bitcoin and avoid the shipping risk altogether.
However, on the topic, Trezor teased out an “Anonymous delivery” service they are building out in response to this breach. Sanders told Bitcoin Magazine the service will be available in the E.U. in a matter of weeks and will expand to the U.S. soon after. The company currently still uses ShipMonk according to public data.
Concluding Thoughts
Having used Trezor for many years, albeit older models like the Model T and the Trezor One, the Safe 7 strikes me as a serious evolution of the product and a strong addition to a self-custody setup. In particular, as part of a multi-vendor multisig, or as a daily-use warm wallet. Its Shamir backup feature also deserves a place among more advanced self-custody solutions.