Own your keys on hardware you can read

Every device below is open enough to audit: firmware you can build, designs you can study, and a maker who sells to you directly. Everything closed is in the excluded list at the bottom — with its reason named, because a silent skip teaches nothing. Same bzDiD at every rung; this is a climb, not a restart.
Three rules before you spend a dollar.
1 · Order direct from the manufacturer. Never marketplaces, never resellers — supply-chain tampering is the one attack you can decline by habit.
2 · Your written 24 words are the floor at every rung. The device is a lock; the phrase is the door that survives every device.
3 · Verify what you receive: check the seal ritual the maker documents, and confirm firmware signatures on first boot. If a step feels skippable, that's the step.

The ladder at a glance

$RungDeviceAir-gap
$0Spare phone, opticalyour own onboarding surfacescreen ⇄ camera
~$50Build-it-yourselfSeedSigner · KruxQR only, stateless
$59–79First open commercialTrezor Safe 3USB (not air-gapped)
$79–169Open budget / multi-chainJade Plus · Keystone 3 ProQR camera
$249The anchorTrezor Safe 7 (bSAFE)USB · BLE(Noise) · beam-capable
$349Premium open air-gapPassport PrimeQR camera · microSD
$249the anchor · T5

Trezor Safe 7

firmware openschematics publicauditable SE (TROPIC01)FIDO2not QR-air-gapped stock

Three hardware layers — TROPIC01 (the first secure element outside researchers can audit), an EAL6+ SE, and an open MCU — plus a committed post-quantum path. The BNR fork (bSAFE 7) adds what the mission needs, including the optical beam. Trezor has shipped open firmware since the first generation; that track record is the product.

~$50 in partsthe build-party rung

SeedSigner

fully openstateless — no secrets at restcommodity partsBitcoin-only

A signer you assemble yourself from a Pi Zero, camera, and screen. It holds nothing when powered off — the seed enters per session by QR or dice. No customs form flags it, no company can stop making it, and building one teaches more than reading ten reviews. The rung that turns users into producers.

~$35–65diy, second flavor

Krux

fully openruns on cheap K210 boardsBitcoin-only

Same philosophy as SeedSigner on different silicon — flash open firmware onto an off-the-shelf device with a camera and screen. A second independent implementation of the same idea is health, not redundancy.

$59–79first commercial rung

Trezor Safe 3

firmware opensecure elementFIDO2USB only

The cheapest fully-open-firmware commercial signer — and because it speaks FIDO2, the same $59 object can be your passkey. The natural first step off the spare-phone rung.

$79–169open budget air-gap

Blockstream Jade / Jade Plus

fully open, board includedQR camera air-gapno SE — blind-oracle model (disclosed)BTC/Liquid only

Open to the last line, cheap, camera-based QR signing. Its twist: instead of a secure element, the key is sealed to a rate-limited oracle — run Blockstream's or your own. That dependency is honest and disclosed, and self-hosting the oracle fits a sovereign stack unusually well.

$119–149multi-chain air-gap

Keystone 3 Pro

app + SE firmware openQR/UR nativehardware partially openno FIDO2

The pragmatic pick if you arrive holding many chains: broad support, BC-UR animated-QR signing with every major software wallet, and — rare anywhere — the secure-element firmware is published. Know its limits and it serves well.

$349premium open air-gap

Foundation Passport Prime

CERN-OHL-S open hardwareKeyOS: Rust microkernel, apps get child seedsQR + microSDFIDO2

The most architecturally interesting open device shipping: a Rust microkernel OS where each sandboxed app receives a hardened child seed and can never touch the root. Open hardware under a real open-hardware license, not just published schematics. Priced for the committed.

~$149honorable mentions

BitBox02 · OneKey · Cypherock X1

open firmware

BitBox02: clean open firmware, USB-only — solid, adds no modality. OneKey: open multi-chain alternative. Cypherock X1: no seed phrase at all — the key is Shamir-split across NFC cards, a genuinely different recovery geometry worth studying.

excluded — reason named, never a silent skip

Ledger — closed secure element, and the Recover service proved firmware can extract seed material to third-party custodians. Fails the sovereignty test at the architecture level, not the feature level.
Coldcard — battle-tested hardware, but the firmware license left OSI open source after the Passport fork dispute. Source-visible is not open; excluded on license, respected on engineering.
NGRAVE, Tangem, and card-style wallets — closed firmware and/or no display to verify what you sign. If you cannot read it and cannot see it, it is not yours.

For the largest holdings: no single device — however open — should hold a life-changing balance alone. Use a 2-of-3 multisig across different makers and firmware lineages (e.g. Safe 7 + Passport Prime + SeedSigner). All three speak QR, so the quorum works fully air-gapped, and no single supply chain is a single point of failure.

the manufacturer shelves

Every card opens the manufacturer's own product page in a new window. We show, we never middleman.

TREZOR — trezor.io
Trezor Safe 7
Trezor Safe 7
Advanced future-proof crypto security with wireless freedom
the new flagship ↗
Trezor Safe 5
Trezor Safe 5
Touchscreen ease for everyday crypto management
the bSAFE target rung ↗
Trezor Safe 3
Trezor Safe 3
Simple, reliable crypto security with a two-button pad
the workhorse ↗
Safe 7 · BTC-only
Safe 7 · BTC-only
Bitcoin-only firmware variant
the purist ↗
Safe 5 · BTC-only
Safe 5 · BTC-only
Bitcoin-only firmware variant
the purist ↗
Safe 3 · BTC-only
Safe 3 · BTC-only
Bitcoin-only firmware variant
the purist ↗
FOUNDATION — foundation.xyz (was foundationdevices.com)
foundation.xyz — reachable from your browser
Passport Prime
The newest Foundation hardware wallet — air-gapped signing lineage. Site image withheld: foundation.xyz refuses our reader (ECONNRESET ×3); link is founder-verified.
manufacturer ↗
github.com/Foundation-Devices
Foundation on GitHub
Open-source firmware and tools — the repos behind every Passport. For the hardware lab's open-review doctrine.
manufacturer ↗