The 3 Best Crypto Cold Wallets

A short list of the hardware wallets I actually use and recommend, and what each one does well.


01 / 01 Sections Sections

2026-07-31 · Hardware

A short list of the hardware wallets I actually use and recommend, and what each one does well.

Affiliate disclosure. The D’CENT and ELLIPAL links on this page are affiliate links. If you buy through them, I earn a commission at no extra cost to you. The Trezor links are not. This page is a shortlist of devices I recommend and what each one gets right. It is not a comparative review of the whole market, and it does not attempt to catalogue every limitation of every device. Do your own diligence before moving a meaningful position onto any of them.

A cold wallet is a device that keeps your private keys off any internet-connected machine and signs transactions on its own hardware. That is the whole job. Everything else on a spec sheet is a variation on how the keys get stored, how the signing gets approved, and how the signed transaction gets back out to the network.

The differences between the good ones come down to four things: what chip holds the key, how data moves in and out of the device, whether anyone outside the company can read the code, and how the company behaves when something goes wrong.

Positions one and two are my preference and I say why. Prices and firmware versions were checked on 31 July 2026. Check the date before you act on any of it.


The comparison table

1. D’CENT Biometric 2. ELLIPAL Titan 2.0 3. Trezor
Price (USD) $119, list $159 $149, list $169, plus $29.90 adapter Safe 3 $59, Safe 5 $129, Safe 7 $249
Secure element Yes, chip not named publicly Yes, chip not named publicly Infineon OPTIGA Trust M (V3). TROPIC01 as a second element on Safe 7
Certification Stated “EAL5+” Stated “CC EAL5+” Certified EAL6+ across the Safe line
Connectivity USB-C, Bluetooth LE 4.1 QR code only. No USB data, Bluetooth, WiFi or NFC USB-C on all. Bluetooth 5.0+ on Safe 7
Air-gapped No Yes, fully No
Firmware open source No No Yes, and certified open hardware
Assets supported 4,959 coins and tokens, 100 networks 10,000+ assets, 45+ chains Thousands, varies by model
Backup Recovery phrase Generates 24 words, imports 12 to 24 12, 20 or 24 words, plus SLIP-39 multi-share
Passphrase Yes Yes Yes
Independent audit Coinspect firmware review, remediation confirmed April 2019 Adversarial research on the predecessor device, 2019 Yes, published on Trezor’s own site
Company, base IoTrust, South Korea ELLIPAL Limited, Hong Kong SatoshiLabs, Czech Republic

1. D’CENT Biometric Wallet

What it is. A hardware wallet from IoTrust, a South Korean company founded in January 2017 and based in Gangnam, Seoul, built around a fingerprint sensor and a certified secure chip. You approve transactions with your fingerprint on the device itself, and it pairs with a phone over Bluetooth LE or plugs in over USB-C. It weighs 36 grams and is about the size of a car key fob. IoTrust’s founding team came out of HansolSecure, and the company has taken roughly 9 billion won in cumulative investment from backers including Korea Investment Partners and KB Investment.

Why I keep coming back to it. Two reasons, and neither is the chip.

The first is the fingerprint. Most hardware wallets make you punch a PIN into a tiny screen every time you want to do anything, so people pick short PINs and stop checking the address on the display because the whole ritual is tedious. Touching a sensor takes under a second, and the practical effect is that I actually verify the destination address on the screen instead of rushing through it. Security you skip is not security. The device holds up to two registered fingerprints and the sensor gates transaction approval on the hardware, with a 4 to 8 digit PIN underneath as the fallback.

The second is chain coverage, and this is the part worth buying it for. D’CENT’s own supported-assets page lists 100 blockchain networks and 4,959 coins and tokens. What matters is which chains get native signing support rather than token support bolted onto an Ethereum app. Their developer documentation carries dedicated signing sections for the XRP Ledger, Hedera including HTS tokens, Klaytn, Tron, Stellar, Tezos, VeChain, NEAR, Havah, Polkadot and Polkadot parachains, and Cosmos. Native Hedera and XRPL support at this price is genuinely unusual, and if you hold assets on the smaller networks you have probably had the experience of buying a wallet and then discovering your chain needs a third-party app nobody has updated in eighteen months.

Pros

  • Fingerprint approval on the device, which makes careful verification the easy path rather than the annoying one
  • Certified secure chip, stated as CC EAL5+ on the Biometric Wallet
  • 4,959 coins and tokens across 100 networks, with native signing for chains most competitors skip
  • Small and light at 36 grams, genuinely pocketable, made in Korea
  • USB-C and Bluetooth LE, so it works with a phone without an adapter
  • Wipes itself to factory settings after repeated unauthorised login attempts
  • No CVE has ever been assigned to D’CENT or IoTrust. I checked the NIST National Vulnerability Database directly and both queries return zero results
  • $119 at time of writing, below the Titan 2.0 and below most mid-range competitors

Price. $119, listed down from $159, direct from the D’CENT store. Note that the Biometric Wallet page showed as sold out when I checked on 31 July 2026.

Verdict. The wallet I reach for when I want a dedicated signing device without the friction that makes people cut corners, and the one I recommend to anyone holding assets on Hedera, XRPL or Cosmos who is tired of chains being an afterthought. Buy it for the biometric approval and the native chain coverage.

Check the current D’CENT price (affiliate link)


2. ELLIPAL Titan 2.0

What it is. A fully air-gapped wallet in a sealed metal body. There is no USB data port, no Bluetooth, no WiFi and no NFC on the Titan line. Every transaction moves as a QR code: the phone app shows a QR, the Titan’s camera reads it, you approve on the 4-inch touchscreen, and the Titan displays a second QR containing the signed transaction that the phone scans back. Nothing else crosses the gap, ever.

Why I keep coming back to it. The air gap on the Titan is the real thing, not a marketing adjective. A lot of wallets described as “cold” still carry a USB data path or a Bluetooth radio, and the manufacturer’s argument is that the secure element covers it anyway. ELLIPAL removed the connection instead of defending it. They swapped the chipset specifically to eliminate network capability and replaced the USB charging port with a contact port, so charging happens through a separate adapter that ELLIPAL describes as blocking direct data-cable connection.

The body backs it up. One solid piece of metal, screen sealed with an IP65-rated dust and liquid seal, and an anti-tamper mechanism ELLIPAL says wipes the device automatically if a breach is detected, leaving visible damage if someone forces it open. For a device that sits in a drawer or a safe holding a long-term position, that combination is the right set of tradeoffs.

There is also something worth crediting in their history. In 2019 a competitor’s research team took apart ELLIPAL’s earlier EC01 device and published real findings. ELLIPAL shipped a fix, started a bounty programme, paid a bounty, and then built the Titan around removing the class of problem entirely. Getting caught is common. Responding by redesigning the product is not.

Pros

  • Genuine air gap with QR-only signing. No USB data, no Bluetooth, no WiFi, no NFC on the Titan line
  • Sealed one-piece metal body, IP65 seal, anti-tamper auto-wipe
  • Large 4-inch touchscreen, which makes address verification easy to do properly
  • 10,000+ assets across 45+ chains
  • Generates 24-word backups, imports 12 to 24 words, supports a passphrase, and takes private key and keystore imports
  • Zero CVEs have ever been assigned to any ELLIPAL product

One thing to get right, because the headlines got it wrong. In October 2025 a US-based holder lost $3.05 million in XRP, and a lot of coverage ran it as “ELLIPAL hacked”. ZachXBT traced the theft and concluded the victim believed they were using a cold-storage product when in reality it functioned as a hot wallet. The Block reported no device zero-day and attributed the cause to user error. ELLIPAL discontinued all hot wallet services on 31 October 2025.

Price. $149 at time of writing, list $169, plus $29.90 for the Security Adapter you need to charge and update it.

Verdict. The one I trust for the position I do not intend to touch for a year. The air gap is real, the body is serious, and the bulk is the price of removing every radio from the device.

Check the current ELLIPAL price (affiliate link)


3. Trezor

What it is. The company that made the first hardware wallet, SatoshiLabs of Prague, founded in 2011, with the original Trezor One launching on 29 July 2014. The current line is the Safe 3 at $59, the Safe 5 at $129 and the Safe 7 at $249. All three carry an Infineon OPTIGA Trust M (V3) secure element rated EAL6+ and connect over USB-C. The Safe 7 adds Bluetooth 5.0+ and a second secure element, the TROPIC01 from Tropic Square.

Why it is on the list. Trezor is the most open company in this category by a wide margin, and it is not close. The firmware is open source, and the hardware designs carry an OSHWA open-hardware certification (UID CZ000005) on top of that. Two of the three wallets on this page pay me a commission and neither of them lets you read a line of firmware. Trezor does. If verifiability is your top criterion, buy a Trezor and stop reading this article.

The backup system is the best available. Trezor authored SLIP-39 and supports multi-share backup on the Safe 3, Safe 5 and Safe 7, splitting recovery across up to 16 shares with a threshold, so losing one share loses you nothing. Nothing else here matches it.

Their disclosure culture is the strongest evidence of good faith in the category. They publish a standing vulnerability section on their own site, including a competitor’s findings against their own products, and when that competitor’s research team broke their newest chip they co-published the disclosure the same day. They also committed to basic maintenance until at least 2031 and critical security updates until at least 2036 on two products they no longer sell.

Pros

  • Open-source firmware and OSHWA-certified open hardware, the only genuinely auditable option here
  • Certified Infineon OPTIGA Trust M (V3) secure element, EAL6+, across the whole Safe line
  • SLIP-39 multi-share backup, up to 16 shares with a threshold, which no competitor matches
  • Multisig well supported through Electrum, Sparrow and Casa
  • Published vulnerability disclosures, including findings against their own products
  • Long support commitments, including on discontinued models
  • The Safe 3 at $59 is the best cheap entry point in the category, with a genuinely certified secure element at a price where competitors cut corners

Price. Safe 3 $59, Safe 5 $129, Safe 7 $249 at list.

Verdict. The right answer for anyone who would rather verify than trust, and the wallet I would tell a security-minded friend to buy without hesitating. Open firmware, certified open hardware, the best backup design available, and a $59 entry point. This is the only wallet on the page you can actually audit.

Buy direct from trezor.io rather than a marketplace reseller.


How to choose

Ignore the feature lists and answer these in order.

How much are you protecting, and from whom? A few hundred dollars of trading capital and a life-changing long-term position are different problems. Small amounts and frequent access favour convenience: D’CENT or a Safe 3. Large amounts you rarely touch favour an air gap and a metal body, which means the Titan 2.0.

Does the device have a radio? This is the sharpest dividing line in the category and most buyers never think about it. Bluetooth and NFC are attack surface that an air-gapped device simply does not have. Everyone selling a Bluetooth wallet will tell you the secure element covers it, and they are probably right. The Titan 2.0 side-steps the argument by not having the radio.

Can anyone outside the company read the code? Two of the three wallets here are closed source, and they are both wallets I earn a commission on. I would rather say that plainly than let you find out later. WalletScrutiny’s framing is the honest one: with closed firmware you cannot verify the product, so if the provider puts your funds at risk on purpose or by accident, you probably will not know before people start losing money. Trezor is the only genuinely open option on this page. If verifiability is your top criterion, the ranking above is not the ranking for you.

What does the certification actually cover? An EAL rating belongs to a chip evaluated against a specific security target, not to the wallet as a product. A narrowly-scoped EAL6+ evaluation is not automatically better in practice than a broader EAL5+ one, and a certified core designed into a product does not make the product certified. When a company states an EAL level without naming the chip or publishing a certificate reference, as both D’CENT and ELLIPAL do, treat it as a claim rather than a verified fact.

How does the seed get made and backed up? Trezor’s multi-share backup is the best recovery design available. A passphrase is supported by everything on this page and is the mitigation of last resort for a stolen device.

Do you need multisig? If you are protecting a serious position, multisig removes single-device failure from the picture, and that includes single-device firmware bugs. Trezor is the well-supported option here.

Keep your firmware current. Every wallet on this page ships firmware updates, and some of them fix real security issues. Check for an update before you move a meaningful position onto any device, and check again periodically after that. Manufacturers publish security advisories on their own sites and they are worth reading.

One last thing. A hardware wallet moves the risk from an exchange’s balance sheet to your ability to protect a backup phrase. It does not remove risk. Most people who lose crypto from a hardware wallet lose it by typing their recovery phrase into a phishing site, not by having their secure element defeated in a laboratory.


Sources

Corrections

None yet.

Last updated: 2026-07-31

More from the journal

Continue reading.