Exchange glossary

Trezor

Trezor is a hardware wallet: the key is created inside the device and stays there, and every transfer is confirmed by hand on its screen. Against an infected computer that protects you; against a recovery phrase talked out of you, or a signature you put there yourself, it does not. The line that “Trezor does not support TRC20” is wrong: that limit belongs to a third-party app, not the device.

A hardware wallet is a separate device that keeps the key and signs transfers inside itself. All that goes out is the finished signature, and the maker puts it in so many words: the private key never leaves the device.

What it rules out and what it does not

It rules out the infected computer: the key cannot be reached even on a compromised machine, and the recipient's address is to be checked against the screen of the device itself — the vendor writes outright that the address on the computer screen cannot be trusted. It rules out a stolen computer too: without the device nobody can move the money.

Three things it does not rule out. A recovery phrase talked out of you: with it access is gained without the device at all. Physical access — the maker itself says that with hardware attacks the question is “not if, but when”. And a harmful transaction a person signed themselves: against permissions granted to a website the hardware gives no extra protection.

TRC20 is supported

The claim that “Trezor does not support TRC20” came from a third-party wallet and describes not the network but the pairing. That wallet does support TRON and TRC-20 tokens — just not when the signing is asked of a Trezor connected to it: the limitation sits on exactly that pair. The device itself supports the network: in the vendor's own app TRON and all TRC-20 tokens work, USDT among them — on Safe 7, Safe 5, Safe 3 and Model T. The one model where this is unavailable is Model One, and old-style TRC-10 tokens are supported nowhere.

Open source and EAL6+ — with caveats

The firmware and even the board schematics are published openly, but two caveats are compulsory. The Common Criteria EAL6+ certification covers one separate secure-element chip in Safe 5 and Safe 3, not the device as a whole. For the second chip of the top model the description and the firmware are open while the bootloader is closed — the repository names the licences of the silicon suppliers as the reason.

The leaks happened at contractors

From 2022 to 2026 the confirmed leaks happened not at the vendor but at outside companies: an email sender, the support portal, logistics and again an email sender — the last one on 09.09.2026. The number of contacts taken out has been revised by the vendor twice in eight days: as of 19.09.2026 it is 347,149. Keys and funds were not touched a single time. What every leak did do was raise the risk of targeted phishing, and twice that is confirmed: in September 2026 a letter went out in the vendor's name with a link to a page that asked for the recovery phrase, and in January 2024 a fraudster wrote to the victims directly and fished for that same phrase. This is precisely the threat that hardware does not save you from.

More on this: What a hardware wallet protects you from, and what it does not

Go to exchange

All terms