A hardware wallet keeps your private keys on a device that never connects them to the internet, so a compromised computer can't drain your holdings. Ledger and Trezor are the two established options, and for most people either is sufficient — the real choice is between Ledger's broader ecosystem and Trezor's open-source firmware. What matters far more than the brand is where you store the recovery phrase.
Crypto assets are volatile and largely unprotected by deposit guarantees. Never invest money you can't afford to lose. In Sweden, crypto disposals are taxable events — see our K4 guide.
What a hardware wallet actually does
Owning crypto means holding a private key. Whoever holds the key holds the asset — there is no bank behind it and no fraud department to call.
Leave the key on an exchange and you're trusting the exchange. Leave it on your laptop and you're trusting that your laptop has never run anything malicious.
A hardware wallet moves the key onto a dedicated device that signs transactions internally and never exposes the key to your computer. Your laptop can be fully compromised and the attacker still can't sign a transaction — they'd need the physical device and its PIN.
That's the entire value proposition. It's narrow, and it's genuinely effective against the attack that actually empties people's holdings: remote theft.
A hardware wallet does not protect you from approving a malicious transaction yourself. If you connect it to a fraudulent site and sign what it asks for, the device does exactly what you told it to. It protects the key, not the judgement.
The thing that matters more than the device
When you set up either wallet, it generates a recovery phrase — typically 24 words. That phrase is your money. Anyone who reads it can recreate your wallet on any device, anywhere, with no PIN required.
Which means the security question isn't Ledger versus Trezor. It's: where does that phrase live, and who else can reach it?
Never digitise it. Not a photo, not a password manager, not a note in your email, not a cloud backup. The moment the phrase exists as a file, the whole device becomes decoration.
Write it on paper or metal, and store it somewhere a flood or a landlord can't reach. Steel backup plates exist for exactly this and are worth the small cost if you're holding anything meaningful.
Consider a passphrase. Both brands support an optional extra word on top of the 24 — sometimes called a 25th word — which creates an entirely separate wallet. It protects against someone finding your written phrase. It also means forgetting it loses everything, permanently, with no recovery.
Test recovery before you fund the wallet properly. Send a small amount, wipe the device, restore it from the phrase alone, and confirm the funds appear. Ten minutes now, versus discovering a transcription error at the worst possible moment.
Ledger: the ecosystem case
Ledger devices are built around a Secure Element — the same class of tamper-resistant chip used in payment cards and passports. It's a genuine engineering advantage against someone who has physical possession of your device.
One detail the marketing doesn't lead with: the certification isn't uniform across the range. The Stax, Flex, Nano Gen5, and Nano S Plus all carry a Secure Element certified to Common Criteria EAL6+. The Nano X sits at EAL5+ — one grade below, and it's the cheapest Ledger with wireless.
The larger counterweight is that Ledger's firmware is closed-source. You cannot independently verify what the device does; you're trusting the company's word and its audits.
Two events are worth knowing before you buy, because they're the substance of most criticism you'll encounter.
The 2020 customer data breach. Ledger's e-commerce database was exposed, publishing the names, addresses, and phone numbers of a large number of customers. No funds were taken — the breach never touched the devices — but it produced years of targeted phishing, and in some cases physical threats, against people known to hold crypto at a known address.
The Ledger Recover controversy. Ledger announced an optional, subscription-based seed recovery service that encrypts and splits the recovery phrase across custodians. The technical objection was immediate: it demonstrated that firmware could be made to extract the seed, which many users had believed architecturally impossible. Ledger's position is that it's opt-in and always was possible in principle. Both statements are true, and the argument is really about trust rather than facts.
If you value one company controlling a polished, broad ecosystem — very wide coin support, a mature desktop and mobile app — Ledger is the stronger product. If closed-source firmware is a dealbreaker for you, none of that compensates.
Trezor: the open-source case
Trezor's argument is verifiability. Firmware and hardware designs are open — anyone can audit them, and researchers regularly do. When a vulnerability is found, it's found in public.
The historic weakness was that older models lacked a Secure Element, making physical extraction possible for a well-equipped attacker with the device in hand. That gap is closed on the current range: the Safe 3, Safe 5, and Safe 7 all carry an OPTIGA Trust M (V3) Secure Element certified to EAL6+.
The Safe 7 goes further, adding a second Secure Element called TROPIC01 alongside the first. Trezor describes it as the only independently auditable secure element available — worth knowing that the chip comes from Tropic Square, a company in the same group, so that description is the manufacturer's own.
The passphrase feature was always Trezor's answer to physical attacks, and it remains the strongest mitigation on either brand: a device seized without the passphrase yields an empty-looking wallet.
The trade-offs are real. Coin support is narrower than Ledger's, particularly at the long tail. Only the Safe 7 offers wireless connection — the Safe 3 and Safe 5 are USB-C only. The software is capable but less consumer-polished.
Side by side
| Ledger (current range) | Trezor (current range) | Exchange account | |
|---|---|---|---|
| Firmware | Closed-source | Open-source, publicly auditable | Not applicable |
| Secure Element | Yes — EAL6+, except the Nano X at EAL5+ | Yes — EAL6+ across Safe 3, Safe 5, and Safe 7 | Not applicable |
| Coin support | Broader | Narrower at the long tail | Varies by exchange |
| Wireless signing | Yes, on all but the Nano S Plus | Yes, on the Safe 7 only | Yes |
| Passphrase support | Yes | Yes | No |
| You hold the keys | Yes | Yes | No — the exchange does |
Specifications checked against each manufacturer's own comparison pages, August 2026. Both ranges change; confirm before buying.
Best for most readers: a current-generation Trezor, on one ground — you get an EAL6+ Secure Element without having to take a company's word for what the firmware does. Ledger is the better buy if you hold assets Trezor doesn't support.
If you're buying Ledger for wireless on a budget, note that the Nano X is the one device in the range certified at EAL5+ rather than EAL6+. The Nano Gen5 and Flex have Bluetooth and the higher certification.
What this costs
Two cost notes that don't change with pricing.
Buy the cheapest model that supports your assets. The security architecture is largely shared within a brand's current generation; the premium models mostly buy screens, connectivity, and materials rather than better key protection. The Nano X certification gap above is the one exception worth checking.
Budget for the backup. A steel recovery plate costs a fraction of the device and addresses the failure mode that actually loses people money — a paper phrase destroyed, faded, or thrown out during a move.
Who should NOT use a hardware wallet
- You hold a small amount you'd shrug off losing. A reputable exchange with strong two-factor authentication is a reasonable place for a holding worth less than the device plus the backup plate. The security upgrade isn't free, and the added complexity has its own failure modes.
- You trade actively. Signing every transaction on a physical device is friction by design. If you're moving positions weekly, you'll end up leaving funds on the exchange anyway, and a wallet you route around protects nothing.
- You have nowhere secure to store a recovery phrase. In a shared flat, a sublet, or a first-year housing situation that might change twice, the phrase is the weak point and a device doesn't fix it. Solve storage first.
- You know you'll lose it. This is not a character judgement. Self-custody has no reset link, no support line, and no recovery. If losing a phrase is a realistic outcome for you, an exchange's account recovery is a genuine feature, not a weakness.
- Someone else needs access if something happens to you. Self-custody with no succession plan means the holding dies with you. Solvable — but solve it deliberately, not by accident.
The Swedish part: tax, inheritance, and where to keep the backup
Moving crypto to your own wallet is not a taxable event. Transferring between wallets you control isn't a disposal. Selling, swapping one asset for another, or spending it generally is — and each of those is reported on the K4 form. The general rule is that disposals are taxable and transfers are not; check your own situation rather than relying on this line.
Where to keep the backup is a genuinely Swedish problem. Bank safe deposit boxes have become scarce here as branches have moved away from cash handling, so the default answer available elsewhere often isn't available to you.
Your hemförsäkring (home insurance) will not cover a stolen recovery phrase or the assets behind it. Don't assume the contents cover extends to it.
Inheritance. Swedish estate administration can't reach an asset it doesn't know exists and can't unlock a wallet without the phrase. If you're in a sambo (cohabiting) relationship or have children, a documented plan for how someone else reaches the holding matters more than the choice of device.
Buying safely
Buy from the manufacturer's own store, or an official reseller listed on their site. Never from a marketplace, never secondhand, never from a seller on a crypto forum.
The attack is simple and it works: a tampered device arrives pre-configured with a recovery phrase the seller already knows. You fund it, they empty it. A "sealed" box means nothing — seals are trivially replaced.
A genuine device generates your recovery phrase in front of you, on the device, during setup. If a wallet arrives with a phrase already written down, on a card, in the packaging, or anywhere at all — it's compromised. Don't use it. Don't move funds "just to test." Contact the manufacturer.
What I'd do in your situation
If you're holding crypto worth more than a few months' rent and it currently sits on an exchange, buy a current-generation Trezor, order a steel backup plate at the same time, and set both up on a quiet evening rather than in a hurry. Test the recovery before you move anything substantial.
Choose Ledger instead if you hold something Trezor doesn't support.
And if you're new here and still setting up a bank account, do that first. A hardware wallet is a good purchase; it is not urgent, and nothing about it improves the situation of someone still waiting on a personnummer.
Crypto assets are volatile and largely unprotected by deposit guarantees. Never invest money you can't afford to lose. In Sweden, crypto disposals are taxable events — see our K4 guide.
Last updated: August 2026. Swedish rules change — if you spot something outdated, tell us and we'll fix it.