A hardware wallet has two jobs it cannot hand to anyone else: produce a number nobody can guess, and keep it somewhere nobody can reach. Screens, coin lists and charging standards are packaging around those two sentences, and this summer went badly for the first one.

They are not the same product. Trezor’s Safe 7 is a multi-asset flagship with a touchscreen, Bluetooth and wireless charging; Coldcard’s Q signs Bitcoin only, through a keyboard, a QR camera and AAA batteries. The choice is between philosophies about who must be trusted, not between spec sheets.

The file on each

Trezor’s bet: make the silicon inspectable

Every secure-element wallet asks you to trust a chip you cannot read. Trezor’s answer on the Safe 7 is TROPIC01, which the company bills as the first auditable secure element, beside a certified EAL6+ Optiga and a general-purpose STM32U5 — three layers from three chip makers, on Trezor’s published specifications. If one vendor’s black box proves flawed, it is not the only thing between an attacker and your keys.

That claim has now been tested, which is the point of making it. Ledger’s Donjon team audited the part and published on 3 June 2026: per Tropic Square’s advisory, a laser fault-injection attack bypassed bootloader signature verification and, with a second step, reached the chip’s MAC-and-Destroy boundary. The preconditions are heavy — the device in hand, the chip ground open from the back, and lab equipment the advisory prices above 30,000 euro — and Trezor’s response the same day says the flaw cannot reach a Safe 7 PIN, funds or backup, that chip being one of three independent layers. Hardened silicon is due late in 2026, the chipmaker says. Call it the process working rather than the product failing; call it a finding all the same, one not yet closed in the silicon on sale today.

Coldcard’s bet: fewer things, further away

Coinkite’s position is narrower by design. Bitcoin only; air-gapped signing over QR, microSD or NFC rather than a cable into a browser; extensive duress-PIN features; firmware published as open source and reproducible, so advanced users can check what runs — all per Coinkite. Fewer parts, fewer chains, fewer reasons to talk to anything.

And this summer the narrow design failed at its narrowest point: a flaw in the way the device generated seeds, present in firmware shipped from 2021 until July 2026, left those seeds reconstructable. Loss estimates have moved: The Crypto Times cites an early figure near $88m and a later, broader one around $112m, so treat any single total as provisional. The response was quick and concrete: the August firmware forces user-supplied entropy into every new seed — dice, coin flips or timed key presses, blended with the device’s own sources — and adds re-verification of a transaction just before signing, tighter USB handling and RNG error checks, per the same report.

Read the limit carefully. A firmware update cannot repair a seed already generated. Anyone whose wallet was created on affected firmware in that window has to generate a fresh seed on fixed firmware and move the coins, per Coinkite’s guidance as reported. Patching the factory does not recall the cars.

The claim to discount

The Safe 7’s post-quantum headline is real and narrower than it sounds. Per Trezor’s own page, the SLH-DSA-128 scheme covers firmware updates, device authentication and the boot process. That defends the supply chain: a tampered unit in the post is a live threat. It does not make the Bitcoin or Ethereum key on it quantum-resistant; those keys live under their own chains’ rules.

Verdict

Hold several assets and want something a household can operate, and the Safe 7 is the sensible pick, with Bluetooth off where the software permits. Hold Bitcoin and nothing else, and the Q’s air gap is sturdier — generate the seed with your own dice on current firmware, and migrate promptly if yours predates the fix.

The briefing does not change with the hardware. The recovery phrase belongs on paper or metal, offline: never typed into a keyboard, never photographed, never stored in a cloud, never given to support. Set either against what a Ledger does and does not protect first. Crypto assets carry high risk, and self-custody moves that risk onto your own desk — so read both vendors’ documentation and buy the device whose failure mode you could live with.