Hardware

Cold storage devices that keep your Bitcoin offline and secure from online threats.

Why We Recommend

Bitcoin-only design since 2012. Dual secure elements (Microchip ATECC608 and Maxim DS28C36B). Fully air-gapped operation via MicroSD or NFC. 100% open-source firmware. Made in Canada with secure supply chain (tamper-evident packaging).

Services & Features

  • Coldcard Mk4 (USB-C, NFC, dual secure elements)
  • Coldcard Q (QWERTY keyboard, QR scanner, large screen)
  • SEEDPLATE metal backup
  • Trick PINs and Duress wallet
  • Spending policies and multisig support
  • USB Virtual Disk Mode for easy PSBT transfers

Why We Recommend

Built by Block (formerly Square). Named TIME's Best Inventions of 2024 (Privacy & Security). 2-of-3 multisig: you hold 2 keys (mobile app + hardware device), Block holds 1 recovery key (cannot act alone). Fully open-source under MIT license. Available in 95+ countries.

Services & Features

  • No seed phrase required (seedless security)
  • Fingerprint authentication
  • Mobile Pay mode (transfer without hardware option)
  • Inheritance feature for beneficiaries
  • 2-of-3 multisig with trusted contacts recovery
  • Integrated with Cash App, Coinbase, Robinhood, and MoonPay

Why We Recommend

Built by Blockstream. 100% open-source firmware and hardware. Unique 'Blind Oracle' PIN security model (no secrets stored on device when locked). Camera for air-gapped QR signing. Genuine Check hardware verification. Anti-Exfil protection against Dark Skippy attacks.

Services & Features

  • Air-gapped QR code signing
  • Stateless operation (SeedQR support)
  • Blind Oracle PIN security (nothing to steal from locked device)
  • Bitcoin and Liquid Network support
  • Multiple connectivity: USB, Bluetooth, QR codes
  • Jade Plus model with 66% larger screen and metal options

Why We Recommend

100% open-source (MIT license). No pre-built hardware to trust—build it yourself from generic components. Community-driven project since December 2020. Stateless design (no secrets stored on device). Reproducible builds for verification.

Services & Features

  • Air-gapped QR code signing
  • Stateless operation (all memory wiped on power off)
  • Dice roll entropy for trustless seed generation
  • SeedQR format support
  • Multisig support with Sparrow, Specter, BlueWallet, Nunchuk
  • BIP85 child seed generation

+1 more services

Why We Recommend

Swiss-designed and manufactured. Fully open-source firmware and hardware. Dual secure chip design. SOC 1 & SOC 2 audited. Highest-rated hardware wallet on Trustpilot.

Services & Features

  • BitBox02 (multi-coin)
  • BitBox02 Bitcoin-only edition
  • BitBoxApp
  • MicroSD instant backup
  • Secure multisig
  • Bitcoin insurance integration

Why We Recommend

Fully open-source hardware and software. Air-gapped by design. Made in USA. Backed by leading Bitcoin investors. Passport is widely praised for security and UX.

Services & Features

  • Passport Prime (personal security platform)
  • Passport Core (air-gapped signing)
  • Envoy mobile wallet
  • QR code air-gapped transactions
  • 2FA codes & security keys

Why We Recommend

World's first transparent, auditable secure element (TROPIC01). Open-source firmware. Post-quantum cryptography (SLH-DSA-128) protects firmware updates and authentication. Fully transparent and community-verifiable.

Services & Features

  • Bitcoin-only edition available
  • Dual secure elements (TROPIC01 + EAL6+)
  • Post-quantum cryptography
  • IP67 rated (dustproof, waterproof)
  • Qi2 wireless charging + USB-C
  • Encrypted Bluetooth for iOS, Android, desktop

+2 more services

Why We Recommend

TapSigner is manufactured by Coinkite, the company behind the well-regarded COLDCARD hardware wallet. The device generates and stores your private key (XPRV) entirely within a secure element chip - the key never leaves the card. Key generation uses verifiable entropy combining user-supplied chain code with the card's internal randomness, ensuring you can verify the key wasn't pre-generated.

Each card includes a factory certificate signed by Coinkite that can be cryptographically verified through their open-source Python tools (cktap) or by tapping the card to visit tapsigner.com/start. This certificate chain allows you to confirm your card is genuine and hasn't been tampered with. The NFC protocol is fully open, enabling any compatible wallet to integrate with TapSigner.

As a self-custody solution, there are no third-party servers involved in key storage or signing. Your Bitcoin security depends solely on the physical card and your PIN, with no centralized points of failure.

Services & Features

  • NFC tap-to-sign transactions
  • Secure element key storage
  • Multisig cosigning support
  • Lightning channel signing
  • PSBT and HWI compatible
  • Encrypted backup export

+2 more services

Why We Recommend

OpenDime operates as a fully self-custodial device where the private key is generated inside the hardware using 256KB of user-provided random data combined with the device's serial number and internal hardware random number generator. The key remains completely unknown and inaccessible until the device is physically unsealed by breaking a resistor, making it impossible for anyone, including the manufacturer Coinkite, to access funds on a sealed device.

The device includes a dedicated secure element for hardware-based key storage and features tamper-evident design with a transparent cover that makes any physical modification immediately visible. Coinkite, the manufacturer, also produces the well-regarded Coldcard hardware wallet and has established credibility in the Bitcoin hardware security space. The firmware is fully open-source on GitHub with reproducible builds, and a 75-line Python verification script allows users to audit the key generation process. No security incidents, exploits, or counterfeits have been reported, with the design claiming it would cost over $100 million to extract the factory key needed to create fakes.

Services & Features

  • Bitcoin-only bearer instrument
  • One-time-use USB stick design
  • Tamper-evident sealed private key
  • Off-chain physical transfers
  • Works with any USB device
  • Open-source firmware verification

+2 more services

Why We Recommend

Satscard is a non-custodial bearer device where the private key is generated and stored inside an EAL6+ certified secure element chip. The key never leaves the card or touches the internet, and users can add their own entropy (such as dice rolls) during setup to ensure keys cannot be pre-generated by the manufacturer.

The product is made by Coinkite, the same company behind the Coldcard hardware wallet and Opendime devices. Coinkite has been producing Bitcoin-focused hardware for years and is widely regarded as security-focused within the Bitcoin community. The SATSCARD protocol is fully open and auditable, allowing independent verification of how keys are generated and used.

There are no widely documented security breaches of Satscard. The device operates without any third-party servers or custody - whoever physically holds an unredeemed card controls the associated Bitcoin.

Services & Features

  • NFC tap-to-verify balance
  • Physical bearer Bitcoin transfers
  • 10 reusable slots per card
  • EAL6+ secure element chip
  • User-provided entropy support
  • Printed deposit QR code

+2 more services