# Trezor

> Source: https://timechain.wiki/wiki/trezor · TimechainWiki, the Bitcoin encyclopedia. (note · self-custody)

> Trezor, made by Satoshi Labs (Prague, Czech Republic), is the original hardware wallet — first shipped in 2014 by the team that authored BIP-39 and SLIP-39. The current flagship (Oct 2025) is the **Trezor Safe 7** ($249) — a 2.5″ touchscreen, Bluetooth-capable device whose landmark feature is a **dual secure element including the auditable, open-design TROPIC01 chip** (a first for hardware wallets); below it sit the **Safe 5** ($129, touchscreen) and **Safe 3** ($79, buttons), with the Model T (discontinued) and Trezor One remaining firmware-supported. Distinguishing features are **native SLIP-39 support** (essentially unmatched by other major hardware wallets), fully open-source firmware and hardware schematics, and a mainstream UX that has made Trezor a typical first-hardware-wallet recommendation. Trade-offs: broad altcoin support that some treat as attack-surface expansion, multisig signing performance that lags Coldcard and BitBox02 per Lopp's 2024 report, and past hardware vulnerabilities (notably the 2018 STM32 attack on the original Trezor One) addressed through later hardware revisions. The strongest fit is mainstream holders, SLIP-39 users, and the open-source-aligned.

---

## What this is

**Vendor**: Satoshi Labs (Prague, Czech Republic). Founded by Marek "slush" Palatinus and Pavol Rusnak (2013). The team is also responsible for authoring BIP-39 (mnemonic seeds), SLIP-39 (Shamir's secret sharing for seeds), and operating Slush Pool (the first Bitcoin mining pool). Their pedigree in Bitcoin infrastructure runs deep.

**Product line as of 2026-07-17**:

- **Trezor Safe 7** ($249) — **the current flagship** (launched Oct 2025). 2.5″ colour touchscreen, **wireless (encrypted Bluetooth, incl. iPhone) + USB-C**, aluminium body with Qi2 charging and a LiFePO₄ battery, and a **"quantum-ready" boot chain**. Its landmark feature is a **dual secure element** pairing a certified EAL SE with **TROPIC01** — the first *auditable* (open-design) secure element in a hardware wallet, addressing the long-standing "the SE is a closed black box" critique. Native SLIP-39.
- **Trezor Safe 5** ($129) — the middle model; 1.54″ colour touchscreen; single EAL 6+ secure element; native SLIP-39; USB-C only. The touchscreen sweet spot below the flagship.
- **Trezor Safe 3** ($79) — entry-level; button-based UX + small mono screen; single EAL 6+ secure element; native SLIP-39; USB-C only. Budget hold-and-forget pick.
- **Trezor Model T** (legacy, ~$215 historical) — predecessor flagship; touchscreen but older architecture; now discontinued (production ended), though still firmware-supported
- **Trezor One** (legacy, ~$59; verify current) — the original 2014 device; still firmware-supported but architectural limitations apply

_The three Safe models share firmware, Trezor Suite, native SLIP-39, passphrase support, and on-device approval; they differ in screen/input, wireless, secure-element design, and price. All remain multi-coin._

**Firmware**: Fully open-source under GPL. Hardware schematics are also published. This is the strongest open-source posture in the hardware-wallet field; independent researchers can audit both firmware and hardware design.

**Secure element**: Trezor Safe 5 and Safe 3 use the Optiga Trust M (Infineon, EAL 6+ certified). This is a meaningful upgrade from the Trezor One/Model T, which used general-purpose microcontrollers without dedicated secure elements (a known concern in the original architecture).

---

## Who this is for

Trezor is a strong fit for:

- **First-time hardware-wallet users** — Trezor's UX is the most mainstream of the major hardware wallets; the touchscreen-based flow on the Safe 5 is approachable
- **SLIP-39 / Shamir users** — the canonical SLIP-39 implementation; no other major hardware wallet matches Trezor's native support
- **Open-source purists** — Trezor's GPL firmware and open hardware schematics are the strongest open-source position in the field
- **Mainstream multisig holders** — Trezor pairs well in multi-vendor multisig (typically with Coldcard or BitBox); coordinator support is universal
- **Holders who value vendor longevity** — Satoshi Labs has shipped hardware wallets continuously since 2014; the longest track record in the industry

Trezor is **less appropriate** for:

- **Bitcoin-only purists who care about attack surface** — Trezor supports many altcoins, which some treat as undesirable; the firmware paths for those coins are real code that could in principle harbour vulnerabilities affecting Bitcoin keys
- **High-volume multisig signers** — Trezor's 100-input PSBT signing was slower than Coldcard or BitBox02 in Lopp's 2024 report; for routine large-transaction signing, others perform better
- **Strict air-gap holders** — Trezor is USB-only; no QR-code or MicroSD signing paths
- **The deeply privacy-conscious** — Trezor's Suite (the official companion app) makes network requests on launch that some holders treat as undesirable telemetry; alternatives exist (Sparrow, Electrum) but the default workflow is Trezor-Suite-oriented

---

## Features and capabilities

### Trezor Safe 5 specifics (2026 flagship)

- **Colour touchscreen** — 1.54-inch display; legible for long addresses; touch-input for passphrase entry
- **EAL 6+ secure element** (Infineon Optiga Trust M) — physical-attack resistance comparable to Ledger, Foundation Passport, Coldcard
- **USB-C** — modern connector
- **NFC** — for contactless interaction with mobile coordinators
- **Native SLIP-39** — the canonical implementation; supports both single-group and multi-level configurations

### Common to current Trezor line (Safe 5, Safe 3)

- **Fully open-source firmware** (GPL)
- **Open hardware schematics** — published; independently reviewable
- **BIP-39 standard** — Trezor authored the spec
- **SLIP-39 native** — Trezor authored this spec too
- **PSBT v2 support** — modern PSBT handling
- **BIP-380 output descriptors** — for multisig
- **BIP-39 passphrase support** — entered on the device (touchscreen on Safe 5, button-cycle on Safe 3)
- **Bitcoin + many altcoins** — the multi-coin support is a trade

### Trezor-specific quirks

- **SLIP-39 native support** — the differentiating feature. A holder who wants SLIP-39 backup essentially must use Trezor (or one of the very few other supporting devices).
- **Trezor Suite** — the official companion app; works well for single-sig but multisig holders typically use Sparrow, Specter, or Nunchuk
- **Recovery seed verification flow** — Trezor's "check backup" feature lets the holder verify the recorded seed against the device without exposing the seed to the host computer
- **Multi-coin firmware** — Bitcoin support is the core; altcoin support is in the same firmware. Some holders see this as attack-surface expansion.

---

## Tradeoffs vs alternatives

| Dimension | Trezor Safe 5 | Coldcard Q | BitBox02 BTC-only | Foundation Passport |
|---|---|---|---|---|
| Price | $129 | $249 | $137 | $199 |
| Bitcoin-only | No (multi-coin) | Yes | Yes (BTC-only variant) | Yes |
| Open-source | Yes (GPL, hardware too) | Source-available | Yes (OSI) | Yes (OSI) |
| Secure element | Yes (EAL 6+) | Yes | Yes | Yes |
| Air-gap signing | No (USB only) | QR + MicroSD | No (USB only) | QR only |
| Native SLIP-39 | Yes | No | No | No |
| BIP-85 | Good | Excellent | Good | Limited |
| Touchscreen | Yes (colour) | Yes (colour, on Q) | No (touch buttons) | Yes (colour) |
| Passphrase entry | Excellent (touchscreen) | Best (QWERTY on Q) | Good | Good (touchscreen) |
| Lopp 100-input signing | Moderate | Fast | Fast | Fast |

Compared to Coldcard: Trezor's open-source posture is stronger; Coldcard's BIP-85 and air-gap features are stronger; the SLIP-39 native support is unique to Trezor among Coldcard's competitors.

Compared to BitBox02: both are fully open-source; Trezor has SLIP-39 and a touchscreen, BitBox is cheaper and Bitcoin-only. Both pair well in multi-vendor multisig.

Compared to Foundation Passport: Passport is strict air-gap (no USB signing); Trezor is USB-connected. Both have touchscreens and secure elements; Passport is Bitcoin-only.

---

## Setup and operation

The setup flow (high-level):

1. **Verify packaging** — Trezor ships with tamper-evident seals; verify intact on arrival.
2. **Connect via USB** — Trezor Suite walks through firmware install (the device ships without firmware, which is a security feature — the holder installs verified firmware as the first step).
3. **Choose seed format** — standard BIP-39 (12 or 24 words) or SLIP-39 (multiple shares with threshold).
4. **Record the seed (or shares)** — Trezor displays the words on the device screen; the holder writes them down.
5. **Verify the seed** — Trezor's check-backup flow asks the holder to enter specific words.
6. **Optionally set up a passphrase** — Trezor supports BIP-39 passphrases entered on the device.
7. **Pair with a coordinator** — Trezor Suite for single-sig; Sparrow, Specter, Nunchuk for multisig.

The operational flow for signing:

- Coordinator builds the PSBT
- Transfer to Trezor via USB
- Trezor displays the transaction details on its touchscreen; the holder verifies addresses
- Holder confirms; Trezor signs internally
- Signed PSBT returns to coordinator via USB
- Coordinator finalizes and broadcasts

For multisig, the same flow with multiple devices; each device signs in turn.

For SLIP-39 wallets, the recovery flow involves entering the threshold number of shares; the device reconstructs the master seed internally. The exposure window during reconstruction is the structural caveat discussed in [SLIP-39 and Shamir Secret Sharing](https://timechain.wiki/wiki/slip-39-and-shamir-secret-sharing.md).

---

## Recovery — restoring the wallet on a fresh device

_As of 2026-09-12, checked against Trezor's own guides and support pages (linked inline)._ Two Trezor facts shape a recovery: **Trezor Suite is required to start it**, on every model including the battery-powered Safe 7; and the model decides the backup format — a 20-word list is SLIP-39, and 12, 18 or 24 words are BIP-39. Trezor now calls the seed the **wallet backup** and notes the older term, *recovery seed*, is what will be printed on a holder's card.

### What may be in hand

**Safe 3** (small, monochrome, two buttons, USB-C), **Safe 5** (colour touchscreen, USB-C), **Safe 7** (touchscreen, aluminium, a built-in battery, Bluetooth and USB-C, two secure elements), and the older **Model T** (touchscreen) and **Model One** (two buttons, micro-USB), both [off sale since January 2026 but supported until at least 2036](https://trezor.io/other/product-updates/how-long-will-trezor-model-one-and-model-t-be-supported). Default backup by model, per the maker's [table](https://trezor.io/learn/security-privacy/personal-security-standards/understanding-trezor-wallet-backups-12-20-or-24-words): Model One 24-word BIP-39; Model T 12-word BIP-39; Safe 3 before June 2024 12-word BIP-39, from June 2024 20-word SLIP-39; Safe 5 and Safe 7 20-word SLIP-39. Only the Model One cannot restore SLIP-39. Power: every model but the Safe 7 draws from the USB cable; the Safe 7's non-replaceable battery lasts about a day and the device [works normally on USB-C when it is dead](https://trezor.io/guides/trezor-devices/trezor-safe-7/trezor-safe-7-battery). Devices ship without firmware, Suite installs it, and a wiped device shows Suite's "firmware is already installed" screen, which is expected for an inherited unit. On a device that still holds the seed, [a firmware update may wipe it](https://trezor.io/support/troubleshooting/device-issues/using-trezor-after-a-long-time) — always on firmware 1.6.1, and when switching between Bitcoin-only and universal firmware — so the maker says not to update without the backup in hand. A Model One on firmware 1.7.0 or older is invisible to current Suite and needs Suite 25.1.2 first. Standalone Trezor Bridge is deprecated and should be uninstalled.

### Unlocking a device that still holds the seed

The [PIN](https://trezor.io/guides/trezor-devices/trezor-fundamentals/pin-protection-on-trezor-devices) is 4 to 50 digits, entered on a matrix that shuffles after every attempt: on the touchscreen models directly, on the Safe 3 by scrolling with the buttons and pressing both to select, and on the Model One through a blind matrix of dots on the computer screen keyed to positions shown on the device. A correct PIN opens Suite's dashboard on the **Standard wallet**; a passphrase wallet is never shown automatically. From there, Settings › Device › Wallet backup › **Check backup** tests a written phrase against the device without wiping it, the account's Details tab shows the xpub, and Sparrow can connect by USB. **The device erases itself after the maximum wrong attempts** — 10 on the Safe 7, 16 on the others — and is then restored from the backup, not bricked. A holder may also have set a [**wipe code**](https://trezor.io/learn/security-privacy/personal-security-standards/create-wipe-code-to-erase-device), a second number that erases the device the moment it is entered in the PIN dialog; a second number in a holder's notes deserves that suspicion. No duress wallet, fingerprint or anti-phishing words exist; the Safe 7 shows a Bluetooth pairing code that USB avoids.

### Wiping the device

With the PIN: Suite › Settings › Device › Danger Area › [**Wipe device**](https://trezor.io/guides/backups-recovery/general-standards/how-to-wipe-your-trezor-safe-3), confirmed on the device (hold the right button on a Safe 3, hold to confirm on the touchscreens); the Safe 7 can also wipe itself under Settings › Device on its own screen. This removes keys, PIN, name and passphrase settings and keeps the firmware. Without the PIN, a [**factory reset from the bootloader**](https://trezor.io/support/troubleshooting/device-issues/how-to-reset-your-trezor-pin-using-factory-reset) erases everything including firmware: connect the Safe 3 or Model One while holding the left button, the Safe 5 or Model T while swiping the touchscreen, or hold the Safe 7's power button until the bootloader appears, then choose Factory reset. The maker recommends Check backup before any wipe or update.

### Restoring from the backup

Every restore starts in Suite (desktop for Windows, macOS or Linux, the web app in a Chromium browser, or the Android app; an iPhone works only with the Safe 7 over Bluetooth): **Setup my Trezor** or, on a wiped device, Yes, Set up my Trezor › [**Recover wallet**](https://trezor.io/guides/backups-recovery/general-standards/recover-wallet-on-trezor-safe-3) › Start recovery › confirm on the device › accept the terms › choose the word count › enter the words. Entry is on the device for every model but one: the Safe 3 scrolls letters with its buttons and offers suggestions; the Safe 5, Safe 7 and Model T use a T9 keyboard where each letter tile is tapped once per letter and the device proposes valid words. The **Model One types the words on the computer**, either in a shuffled order the device dictates ("Standard recovery") or letter by letter on a blind matrix ("Advanced recovery"), which the maker notes is slower. The device ends on "Wallet recovery completed" and Suite continues to a PIN — set one immediately — and coin activation.

**SLIP-39 shares** (firmware 2.7.2 or later, not the Model One) are entered [entirely on the device](https://trezor.io/guides/backups-recovery/advanced-wallets/recover-a-wallet-with-multi-share-backup), in any order; after the first share the device announces how many more it needs, and it remembers its place if unplugged between shares so a holder's shares can be collected from several places. A 20-word list whose third and fourth words are *academic academic* is a single-share backup; shares of one wallet share their first two words. The three-word SLIP-39 checksum stops an incorrectly copied share, where BIP-39's final word catches only fifteen mistakes in sixteen. There is no SeedQR and no encrypted backup file. After a restore the seed lives on the device behind the PIN.

### The passphrase

Trezor's [**Passphrase wallet**](https://trezor.io/guides/backups-recovery/advanced-wallets/what-is-a-passphrase) (older docs say hidden wallet) sits beside the Standard wallet and is **off by default after any restore**: Suite › Settings › Device › Passphrase › Use Passphrase wallets, then the wallet switcher's **+ Passphrase wallet** › Open previously used. The passphrase is typed in Suite or, on every model but the Model One, [on the device](https://trezor.io/guides/trezor-suite/using-a-passphrase-wallet-in-trezor-suite) via Enter passphrase on Trezor; the device then shows it for a character-by-character check. Up to 50 ASCII characters, case-sensitive, spaces count, keyboard layout matters. It is never stored, and Suite asks for it again for every signature and address verification. A mistyped passphrase opens a different, empty wallet with no error, so the maker's check is not a fingerprint (Suite shows none) but the **last eight characters of the first receive address**, recorded beside the passphrase when the wallet was set up. Sparrow shows the master fingerprint after import, and its FAQ names a sudden change of every address as the classic sign of a wrong passphrase.

### Connecting to Sparrow and confirming the first address

Trezor is a USB device in Sparrow's terms — [**Connected Hardware Wallet**](https://sparrowwallet.com/docs/connected-wallet.html), which Sparrow's own guide walks through with a Trezor. Close Suite first, since one application at a time can hold the device. File › New Wallet › name › Connected Hardware Wallet › **Scan…** › PIN (and passphrase, if enabled) on the device › **Import Keystore** › **Apply**. Linux may need Tools › Install Udev Rules; Windows may need a WinUSB driver installed with Zadig; a charge-only cable is a common cause of a missing device. Nothing is exported from the device itself; for a watch-only wallet Suite's account Details › Show public key displays the xpub as text and QR. Old Trezor web-wallet users are [usually on nested segwit](https://sparrowwallet.com/docs/faq.html) (`3…` addresses), so an empty native-segwit import means trying that script type, or File › Import Wallet › Scan for Connected Devices to let Sparrow find it. Sparrow over Bluetooth to a Safe 7 is undocumented; use the cable.

Address check: Sparrow's Receive tab › **Display Address** shows the address on the device; Suite's own flow is Receive › [**Verify**](https://trezor.io/guides/sending-receiving-staking-funds/trading-crypto-in-trezor-suite/receive-crypto-in-trezor-suite). Suite's default account is SegWit (`bc1q`, `m/84'/0'/0'`), with Taproot, Legacy SegWit and Legacy as separate account types each holding its own addresses; the account's Details tab shows the path. A passphrase must be applied before verification, or Suite reports "Passphrase is incorrect".

### Multisig

[Trezor Suite does not manage multisig](https://trezor.io/learn/supported-assets/bitcoin/multisig-wallets-how-multi-key-security-protects-your-bitcoin); the device is one key in a wallet coordinated by Sparrow, Electrum or a service such as Casa or Unchained, and it stores no configuration. Sparrow imports the Trezor's cosigner xpub over USB like any keystore and sends it PSBTs to sign. The maker's warning is the standard one: keep the xpub of every key, not only the signing quorum, or a lost key loses the funds. See [Multisig setups](https://timechain.wiki/wiki/multisig-setups.md).

---

## Security considerations

### Strengths

- **Fully open-source firmware and hardware** — strongest auditability in the field
- **EAL 6+ secure element** (Safe 5, Safe 3) — physical-attack resistance
- **Long vendor track record** — Satoshi Labs has shipped hardware wallets since 2014; transparent about past issues
- **Native SLIP-39** — the only mainstream hardware wallet with this capability
- **Authored the underlying specifications** (BIP-39, SLIP-39) — deep alignment between firmware and protocol

### Known concerns

- **Multi-coin firmware** — the same firmware that signs Bitcoin transactions also handles many altcoins. Some holders treat this as attack-surface expansion; others see it as fine.
- **The 2018 STM32 vulnerability (Trezor One)** — a physical-attack vulnerability that allowed seed extraction with specialized equipment. Affected the original Trezor One; the Safe 3 and Safe 5 use a secure element that addresses this class of attack.
- **Trezor Suite network requests** — the default companion app makes some network requests at launch that some holders treat as undesirable. Alternative coordinators (Sparrow, etc.) avoid this.
- **The "Recovery" feature controversy** — Trezor has at times offered seed-recovery services that critics treat similarly to Ledger's 2023 Recover, though at smaller scale. Trezor has been clearer about user opt-in and the scope of these services.

### Supply-chain integrity

Buy directly from trezor.io or authorized resellers (typically vetted Bitcoin-focused stores). Avoid generic marketplaces. The tamper-evident packaging is the canonical check.

The Trezor Safe 5 ships without firmware installed — the holder installs verified firmware as the first setup step. This is a structural defence against supply-chain attacks: a tampered device must include malicious firmware, which the holder-installed verified firmware would overwrite.

---

## Pricing and acquisition

_As of 2026-07-17 (Safe 7 added; prices reverified against trezor.io/compare; prior review 2026-07-15)_:

- **Trezor Safe 7**: $249 USD MSRP (flagship; dual SE incl. auditable TROPIC01; Bluetooth)
- **Trezor Safe 5**: $129 USD MSRP
- **Trezor Safe 3**: $79 USD MSRP
- **Trezor Model T**: ~$215 (legacy; now discontinued — historical price; verify current)
- **Trezor One**: ~$59 (legacy budget device; verify current)

**Authorized channels**: trezor.io directly; authorized resellers listed on their site (Coinkite, Bitcoin-focused stores). Trezor ships globally.

**Bulk and business pricing**: volume discounts for multisig configurations; institutional pricing available.

---

## Common pitfalls

**Trezor One in 2026 setups.** The original Trezor One lacks a secure element; the 2018 physical-attack vulnerability is unaddressed in hardware. Acceptable for Tier 0 or very small balances; not appropriate for Tier 1+. Upgrade to Safe 3 or Safe 5.

**Confusing SLIP-39 with multisig.** Trezor's SLIP-39 support is a backup-distribution scheme, not multisig. See [SLIP-39 and Shamir Secret Sharing](https://timechain.wiki/wiki/slip-39-and-shamir-secret-sharing.md) for the structural difference.

**Using Trezor Suite for substantial multisig.** Trezor Suite handles single-sig well but multisig workflows are better served by Sparrow, Specter, or Nunchuk. Mixing coordinators is fine; using Suite for everything is suboptimal.

**Treating altcoin support as a feature.** For Bitcoin-only holders, the altcoin support is irrelevant; for the strict Bitcoin-only crowd, it is a structural concern. Either way, the altcoin features should not influence the device choice.

**Skipping the firmware-installation step.** Trezor ships without firmware specifically so the holder verifies the install. Skipping verification (e.g., installing whatever firmware Suite suggests without checking signatures) undermines the structural defence.

**Three identical Trezors in multisig.** Defeats vendor diversity. Pair Trezor with Coldcard, BitBox02, or other distinct vendors.

**Defaulting to BIP-39 when SLIP-39 is the better fit.** If the holder genuinely wants Shamir-distributed backup, Trezor's native SLIP-39 makes the workflow tractable; choosing BIP-39 by default misses the device's distinguishing feature.

---

## Tooling and resources

**Trezor documentation** _(as of 2026-05-14)_:

- trezor.io — official site
- The Trezor support discussion — comprehensive
- The Satoshi Labs blog — release notes, security advisories
- The "slush" and "stick" accounts (Marek Palatinus, Pavol Rusnak) — running commentary

**Coordinator software supporting Trezor**:

- Trezor Suite — official, single-sig optimal
- Sparrow Wallet — multisig-friendly
- Specter Desktop — multisig-focused
- Nunchuk — desktop and mobile
- Bitcoin Core (with PSBT)

**The synthesis document**: *Bitcoin Self-Custody & Security* (LegacyCipher, April 2026) — Trezor treated as the mainstream-UX choice with the SLIP-39 niche.

_As of 2026-07-17_: the Trezor Safe line spans three current models — **Safe 3** ($79, buttons), **Safe 5** ($129, touchscreen), and the **Safe 7** ($249, launched Oct 2025 — the flagship, with a dual secure element including the auditable TROPIC01 chip and encrypted Bluetooth). Firmware (Trezor Suite) is shared and actively updated across all three.

---

## Open questions for further development

- The multi-coin firmware question is contested. Is the attack-surface expansion a real concern, or is the engineering discipline sufficient that the altcoin paths don't affect Bitcoin keys? The synthesis treats this as a contested point worth flagging.
- SLIP-39 adoption beyond Trezor has been limited. If Trezor were to stop developing SLIP-39 support, what is the realistic migration path for existing SLIP-39 wallets? The open-source reference implementations provide a path but the UX would degrade.
- Trezor's open-source posture is the strongest in the field. Does this translate into measurable security improvements, or is the security parity with closed-source competitors? The empirical record is mixed.

---

## Related notes

**The framing context**:

- [Hardware wallets overview](https://timechain.wiki/wiki/hardware-wallets-overview.md) — the framework
- [Self-custody configuration ladder](https://timechain.wiki/wiki/self-custody-configuration-ladder.md) — Trezor fits well across Configurations 1, 2, 3, 4, 5
- [SLIP-39 and Shamir Secret Sharing](https://timechain.wiki/wiki/slip-39-and-shamir-secret-sharing.md) — Trezor is the canonical SLIP-39 implementation

**Per-device alternatives**:

- [Coldcard](https://timechain.wiki/wiki/coldcard.md) — the power-user alternative
- [BitBox](https://timechain.wiki/wiki/bitbox.md) — the fully-open-source Bitcoin-only alternative
- [Foundation Passport](https://timechain.wiki/wiki/foundation-passport.md) — the strict-air-gap alternative
- [Blockstream Jade](https://timechain.wiki/wiki/blockstream-jade.md) — the budget alternative
- [Bitkey](https://timechain.wiki/wiki/bitkey.md) — the non-technical alternative
- [Ledger considerations and tradeoffs](https://timechain.wiki/wiki/ledger-considerations-and-tradeoffs.md)

**Relevant capabilities**:

- [BIP-85 child seeds](https://timechain.wiki/wiki/bip-85-child-seeds.md)
- [PSBT and wallet descriptors](https://timechain.wiki/wiki/psbt-and-wallet-descriptors.md)
- [Passphrases and the 25th word](https://timechain.wiki/wiki/passphrases-and-the-25th-word.md)
- [Seed phrases and BIP-39](https://timechain.wiki/wiki/seed-phrases-and-bip-39.md)

**Custody configurations**:

- [Multisig setups](https://timechain.wiki/wiki/multisig-setups.md)
- [Collaborative custody services](https://timechain.wiki/wiki/collaborative-custody-services.md)

**Operational practice**:

- [Backup strategies for seeds](https://timechain.wiki/wiki/backup-strategies-for-seeds.md)
- [Recovery rehearsal practice](https://timechain.wiki/wiki/recovery-rehearsal-practice.md)
- [Common attack vectors](https://timechain.wiki/wiki/common-attack-vectors.md)

**The principal practitioners**:

- [Jameson Lopp](https://timechain.wiki/wiki/jameson-lopp.md)
- [Pieter Wuille](https://timechain.wiki/wiki/pieter-wuille.md) — Bitcoin Core developer; involved in PSBT and descriptor specs

**The sub-MOC home**:

- [Practical self-custody and sovereignty](https://timechain.wiki/wiki/practical-self-custody-and-sovereignty.md)
