Bitcoin Magazine frames Safe 7 as a middle path in hardware wallets
Bitcoin Magazine has published a long-form review of the Trezor Safe 7, arguing that the device lands between two familiar ends of the hardware wallet market: products built around a free and open-source ethos for advanced users, and products that lean on closed design and polished guardrails for a broader consumer base.

In the review, the Safe 7 is described as feeling closer to a modern smartphone than a traditional hardware wallet, with a metal exterior, a wide screen stretching to the edge of the device, and tactile feedback built into key actions. The author says that design choice makes bitcoin feel more concrete during use in a way many other wallets do not.
The device also tries to separate the needs of bitcoin-only users from those of broader crypto users. Trezor offers two firmware stacks and two design versions: a standard multi-coin edition in black and green, and a Bitcoin-only orange edition. Users can switch between the two firmware types regardless of which model they buy, but users who already know they only want bitcoin can choose the orange version and avoid an extra firmware change after purchase.
That choice has practical consequences. The review notes that many firmware updates focus on assets other than bitcoin, making the Bitcoin-only firmware leaner. Trezor’s support material states that the added benefits of running Bitcoin-only firmware include fewer regular updates than the Universal firmware and lower exposure to bugs or security issues.
20-word backups and SLIP-39 are central to the device’s security model
One of the first things users may notice, according to the review, is the backup format. Safe 7 uses 20 words for wallet backup instead of the more common 12 or 24 words.
The review ties that choice to Trezor’s long-running security design. It says the 20-word SLIP-39 standard was first introduced by Trezor in 2019 when the company announced its Shamir backup feature. Shamir allows a wallet backup seed to be split into multiple shards, with only a threshold number needed to reconstruct the wallet. Any single shard on its own is not enough to restore access.

The article gives a two-of-three example. A user writes down three separate 20-word lists and stores them in different locations, such as a bank, a home and an office. If one copy is stolen or destroyed by fire or flood, that is not a catastrophic loss. A single shard cannot unlock the wallet, while the other two shards still let the owner recover control and move funds to a new setup.
The review describes this as a form of redundancy and notes that multisignature wallets can achieve a comparable result, though with different trade-offs, including on-chain transaction costs. Shamir backups are based on Shamir Secret Sharing, a long-established cryptographic scheme that Trezor implemented for its own system.
It also stresses that the extra words in SLIP-39 do not mean more entropy than a standard 12-word seed. Trezor says users should still expect 128 bits of entropy. The distinction, according to the company, is that the SLIP-39 word list was curated to avoid confusing or similar terms.
SLIP-39 also opens a path that BIP-39 does not. Users who start with a single 20-word seed on a Trezor device can later create a redundant Shamir setup, such as a three-of-five arrangement, without sending funds through on-chain transactions. Those shares rebuild the same wallet.
The review says users should consider destroying the original 20-word single seed after doing so, because that seed alone would still be enough to restore the wallet. It also notes that Trezor has published a full FAQ on the topic, and that other wallets including Sparrow and Electrum support SLIP-39, even though adoption remains much lower than for its predecessor. The article includes an example in which a single-seed SLIP-39 Safe 7 wallet is recovered into Electrum.
User experience is one of the strongest points in the review
The review spends considerable time on the Safe 7’s physical interaction design. The feature that stood out most to the author was how the device handles high-stakes approvals, such as signing a transaction or changing the security PIN.

In that flow, the user presses and holds a digital button at the bottom of the screen. The device begins a slow vibration through its internal gyro while two green lights move up from the button around the screen edges. As those lights meet at the top, the gyro accelerates and creates a stronger mechanical sound and sensation in the hand. The action ends with the full screen frame illuminated and a small green LED at the top confirming completion.
The sequence lasts only one or two seconds, but the author argues that it makes an otherwise abstract digital action feel more real.
Compared with other Trezor models the reviewer has tested, including the Model T and the classic Trezor One, the Safe 7 is presented as a more comfortable device for handling cryptographic money. One example is the size of the on-screen buttons, which are larger than those on the Model T. That reduces mistyped inputs, especially when entering a security PIN. The review notes that repeated PIN errors on many hardware wallets can escalate into severe consequences, including wiping device memory, so larger finger-sized buttons reduce unnecessary stress.
The metal casing is also singled out as a sign of maturity compared with the plastic shells of older models.
Another feature discussed in the interface is the so-called Wipe PIN, a special PIN that deletes user data when entered during login. The review says Trezor’s public documentation explains what the feature does, but not clearly why it exists or which threat model it is meant to address.
The article links that question to requests from more security-focused bitcoin users for defenses against rare but severe coercion scenarios, including the so-called wrench attack, where a thief forces a user to unlock a wallet. The reviewer argues that Trezor’s implementation has a drawback: it makes it obvious that wallet contents were deleted, which may not help in such a scenario. The piece says at least one other hardware wallet has implemented a more advanced version that deletes the main wallet while opening a second decoy wallet without revealing the trick through the user interface. The author says a more advanced wipe PIN would be welcome for users who think in those terms.

Bluetooth, internal battery and the limits of the air-gap principle
The Safe 7 supports Bluetooth and includes an internal battery that can be charged with Qi2 wireless chargers. It can also be used over USB-C with Bluetooth disabled in settings. The review sees cable-free operation as a subtle but meaningful design decision, one that removes friction during transaction signing at a moment when bitcoin’s irreversible spending model already raises the stakes.
At the same time, the article says more cautious users may prefer a physical off switch for the Bluetooth antenna.
The review devotes a full section to the air-gap principle. No earlier Trezor model had both an internal battery and Bluetooth. Adding them is described as a major product choice that matches what a broader consumer market expects from current hardware, but it also creates new risk surfaces.
One concern is battery failure over time. The article points out that many devices, from phones to hardware wallets, have experienced battery swelling and damage as they age. Trezor addresses that by saying it chose LiFePO₄ cells, whose chemistry is more stable and safer than standard lithium-ion batteries. In the company’s documentation, swelling is described as extremely unlikely.
Bluetooth raises a separate concern. The review says wireless connectivity brings in a largely closed-source software and hardware stack and enables interaction with the device at range, which cuts against the air-gapped principles commonly associated with bitcoin cold storage.

To limit that risk, Trezor says it isolates the Bluetooth antenna and uses it only to send end-to-end encrypted messages. The company built the Trezor Host Protocol for that purpose. According to the review, the same technology is also used over USB-C. Trezor’s position is that neither the cable nor the Bluetooth stack should be trusted with unencrypted data.
Even so, the reviewer argues that wireless capability places the Safe 7 outside the stricter air-gapped or cold-storage category and closer to a high-security warm wallet. The article contrasts that with a hot wallet, defined there as a general computer or server connected to the internet and holding private key material.
Entropy design uses four sources, but no direct user-generated entropy at setup
The hardware section of the review treats entropy as a critical issue. It says that if the Coldcard hack demonstrated anything, it is that cold storage means little without strong entropy. In this context, entropy refers to the random and unpredictable input used to generate cryptographic secrets, such as repeated dice rolls that are then processed into private keys, public keys and seed words.
Trezor has published a separate technical article on how it generates and uses entropy for wallet key creation. The review says the Safe 7 combines four sources:
- entropy from the host computer or phone;
- a hardware TRNG in the STM32 microcontroller, one of the chips in the device;
- the Optiga secure element, a second chip in the hardware;
- and TROPIC01, Trezor’s latest independently auditable secure-element chip.
Those four sources are supposed to be combined when a wallet is created, and the firmware handling that logic is open source under GPL 3.
The company does not currently let users inject their own entropy directly during wallet creation. The review says there are no dice rolls in the setup process, though users can add a passphrase, often called a 25th word, to accounts derived from already-created keypairs, which serves a somewhat similar purpose.

Trezor CTO Tomas Susanka, in a conversation with Efrat Fenigson cited by the review, said user-generated entropy matters only if the code actually uses it. He argued that the Coldcard bug was not a failure of hardware-generated entropy itself, but a failure in firmware implementation that did not properly use that entropy because of the bug.
Trezor CCO Danny Sanders told Bitcoin Magazine that user-added entropy has been discussed extensively, but that it is not a hard no. He said Trezor’s broader customer base is “multiples” of Coldcard’s and “cannot be asked to throw dice.” Sanders added that many users are already mentally overloaded just by writing down a 20-word backup.
The review concludes that the security gain from user-supplied entropy is marginal when other machine-generated entropy sources are properly used.
Shipping exposure, phishing risk and Trezor’s anonymous delivery plan
The article also turns to the operational risks of buying a hardware wallet online and having it shipped home. According to the review, that purchase path is becoming increasingly hard to accept for Trezor and for the hardware wallet sector more broadly.
The immediate reason is a recent breach affecting Trezor through its shipping partner ShipMonk, placing the company alongside Ledger in having user shipping-related records exposed. Earlier this month, 67,000 U.S. customer records were compromised from ShipMonk databases. The review says Trezor stated that most of those records were supposed to have already been deleted by the shipping provider.
The article argues that the breach raises the risk of targeted harassment. It notes that in countries such as France, crypto users are already high on the target list for organized crime. From an operational security perspective, the review says using a P.O. Box is now close to a requirement for crypto-related purchases. It also states that neither large corporations nor governments should be assumed capable of securely protecting personal data, given the broader history of internet leaks.

Another option mentioned is buying hardware wallets in person at major conferences with cash or bitcoin to avoid shipping exposure entirely.
Trezor is also working on a response. The review says the company has teased an Anonymous delivery service after the breach. Sanders told Bitcoin Magazine that the service would be available in the European Union within weeks and would expand to the United States soon after. Public data cited in the piece indicates that Trezor still uses ShipMonk at present.
The reviewer’s bottom line
In its conclusion, the review describes the Safe 7 as a serious product evolution compared with older models such as the Model T and Trezor One, and as a strong addition to a self-custody setup.
The author says the device looks especially well suited as one part of a multi-vendor multisig arrangement or as a daily-use warm wallet. The review also says Trezor’s Shamir backup feature deserves a place among more advanced self-custody approaches.
The review was first published by Bitcoin Magazine and written by Juan Galt.

