This article is informational. It is not investment advice and is not written by a wallet provider. It summarizes and contextualizes a Trezor Blog article titled "What you need to know about selecting the best cold wallet for crypto security this year". The source says this is no longer the current version of the article and points readers to a newer blog titled "Choosing a new crypto hardware wallet in 2026: Avoid these common mistakes" at https://trezor.io/blog/insights/choosing-a-new-crypto-hardware-wallet-in-2026-avoid-these-common-mistakes.

What happened to the XRP cold wallet story?

In October 2025, a US man woke up to discover that 1.2M XRP, worth over $3.05M at the time, had been stolen from what he called his cold wallet. The post frames the loss as his entire retirement. He said, "I just had over $3,000,000 of XRP stolen off of my cold wallet".

The source then explains that the wallet was not, in fact, a cold wallet. It was a hot wallet connected to the internet.

Why the story mattered beyond one theft

The man's experience and the response to his viral video are presented as a warning about confusion in the crypto security industry. One quoted response in the source says:

"One lesson our industry needs to do better with is not causing confusion with products when you offer both custodial and non-custodial products."

The source says he thought he was doing everything right. It argues that this and other similar stories show the need for a change in crypto security going forward.

It also points out that comments on social posts often show that many users are still stuck trusting companies, just as they were trusting exchanges before the first hardware wallet, Trezor Model One, was created.

Two comments quoted in the source illustrate the confusion:

"I've always wondered this. Most of these wallets are made in smaller countries with less laws. Say they went bankrupt and decided to pull everything from everyone."

"it's a theory going around with companies that don't show their full code. It's possible to have a back door built into the coding. Hypothetically whoever owns a wallet company could pull millions or billions in funds and disappear. Without crypto regulation, no country is going to go after them internationally."

The source says less transparency causes more speculation, even if untrue. It argues that, going forward, anyone who wants to keep crypto safe needs to be distrustful, suspicious, and meticulous in their research. Following the advice of one influencer is not enough. Trusting a few reviews will not cut it.

The trend described in the source is that 2026 will be the year users demand trustless security. It says this will be considered non-negotiable for anyone serious about protecting digital savings.

What should users look for in 2026?

The source asks: but what should you be looking for? If you are new, how are you supposed to know what is good or bad? It offers a starting point called "5 Signs your hardware wallet isn't as secure as you think".

1. It is not open-source

The source begins with the reasoning behind Satoshi Nakamoto's decision to make Bitcoin open-source:

"Being open source means anyone can independently review the code. If it was closed source, nobody could verify the security. I think it's essential for a program of this nature to be open source." - Satoshi Nakamoto

It says there should be no proprietary parts hidden "for your safety". No mysteries or surprises.

The source argues that banks, exchanges, and even some hardware wallets keep users guessing about what happens behind the scenes. In the world of crypto security, it says, this is unacceptable. It also says it is not trying to recreate an existing system.

The source warns that if someone decides to trust a hardware wallet that is not fully open-source, they may always have fear in the back of their mind about what could happen one day.

Trezor says it takes the same approach as Satoshi. It quotes a Reddit user:

"You can literally build the entire Trezor device yourself. The files for the 3d printable case is on Trezor's github, along with the schematics for the circuit boards and all of the little electrical parts needed to make your own."

The source says Trezor made the design open-source for one reason: so users never have to trust it blindly, and so they have full control over their assets.

2. It does not have a screen

The source says self-custody security is a difficult balance between usability, security, and privacy.

It argues that a hardware wallet without a screen leans heavily toward usability at the cost of security.

One risk it highlights is that a user cannot see exactly what they are signing. If the actual address cannot be verified on the hardware device, the user is trusting the screen on a phone or computer. If the phone was infected with malware, the risk increases.

Another risk is that wallet backup generation, often called a seed phrase, cannot be considered totally secure and offline if the generated words appear on a phone screen. The source says that technically means the user has a hot wallet exposed to the internet. It says the reason a hardware wallet with a screen displays the words offline is that these words should never touch an online digital environment.

The source says these are just a couple of risks a user may unknowingly be exposed to when choosing a hardware wallet without a screen.

3. It is not a true cold wallet

The source says this might seem obvious because the main point of investing in a hardware device is to secure keys offline in a cold wallet that is not attached to the internet.

However, it points back to the XRP story and the no-screen warning, arguing that many people are unknowingly securing crypto with hot wallets.

It asks two key questions:

  • Are the keys generated offline?
  • Does the hardware wallet show these words on devices connected to the internet?

The source says both are red flags and that a buyer should spend time confirming these points before investing in a hardware wallet.

4. It does not use an NDA-free or auditable Secure Element chip

The source says that in 2019, Trezor tested a commonly used Secure Element chip and discovered three things:

  • The 3rd party certifications have little value in terms of how secure they are.
  • They were often overly complex, which the source says is the enemy of security, making them easy to exploit. It says Trezor exploited them quite fast in testing.
  • The team was not allowed to share discovered vulnerabilities publicly, which it says was against its ethos.

The source adds that competitors using the same chip publicly criticized Trezor. It says the chip was essentially a placebo because users were unaware of vulnerabilities and Trezor could not legally inform anyone about them.

Trezor says it decided that using an NDA-free Secure Element chip was not up for debate. It later implemented the auditable TROPIC01 chip into the Trezor Safe 7.

The source explains that tamper-resistant chips protect a device against physical attacks by shielding the device's secrets, including the PIN.

It says that if the only thing a user is told about a Secure Element chip is that it offers "the highest level of security", without proof beyond certifications that the source already argues have little value, that is a red flag. It says this returns users to "trust me bro" security.

5. The company does not have enough proof of work

The source says being trustless is a necessity, but that does not discount reputation and history.

It asks:

  • Who is behind the company making the hardware wallet?
  • How long have they been around?
  • What are their goals and mission?
  • What is their history?
  • Who decides on their direction?
  • Are they 100% independently owned like Trezor, or are they a collection of VC, or venture capital, interests?

The source says this is a long-term investment, and a buyer does not want to purchase a hardware wallet from a company that becomes increasingly opposed to its original mission just a few years later.

For Trezor, the source says it has had the same mission since building the world's first-ever hardware wallet:

"Empower individuals to self-custody their bitcoin and crypto with tools that seamlessly balance security, privacy, and usability."

It says Trezor is still innovating 12+ years later.

The source says part of its 2026 goals is to make it easier for users to switch over to a trustless hardware wallet.

What does the source say about switching to Trezor?

The source acknowledges that switching to a new hardware device can seem daunting, especially for a long-term HODLer. It lists a few steps it says users should take to switch securely.

It says to choose the right device that meets the user's needs, noting that all models are available in Universal crypto or Bitcoin-only.

It provides a simple overview of the Trezor Safe Family:

  • Trezor Safe 7: Future-proof security with wireless freedom
  • Trezor Safe 5: Touchscreen ease for everyday use
  • Trezor Safe 3: Simple security with all the essentials

It says to create a new wallet because moving over a potentially insecure wallet defeats the intended purpose.

It says to always practice deleting and recovering the wallet before transferring any funds. Once tested, it recommends starting with a small amount.

It says to move crypto to a new wallet and to consider UTXO implications.

For users who want the migration to be as easy and secure as possible, the source suggests booking an Onboarding Session with one of Trezor's Trezor Experts, described as a 1:1 live session for step-by-step help.

A quoted verified reviewer says:

"This was my first time setting up a hardware wallet. Shawn was a pleasure to work with in setting up the trezor wallet. He was incredibly helpful by making sure I understood the fundamentals of protecting assets on the platform including protection from scams. I would highly recommend anyone who is looking to take ownership of their digital assets to get a Trezor wallet and do the expert onboarding session."

The source also promotes a Valentine's Day message, saying that if a current wallet is giving red flags, it is time for a clean break. It invites readers to switch to a partner that is fully open-source, transparent, and ready to commit, and says users can save up to 20% on bundles and fresh starts for a limited time.

What common FAQs does the source address?

The source includes a section titled "Switching to Trezor, common FAQs".

It asks what makes Trezor different from other hardware wallets and gives four points:

  • Trezor built the first-ever hardware wallet over 12+ years ago
  • It is fully open-source and independently owned since day one
  • Trezor says it built the first-ever quantum-ready wallet with an auditable Secure Element chip
  • Bitcoin-only models are available alongside the Universal model, with no difference in security

It asks whether it is safe to migrate the same crypto wallet to an existing hardware wallet. The source says that while a user can safely migrate the same wallet, it highly recommends creating a new wallet, testing recovery, and then transferring funds to the new address gradually. It says reusing an old or potentially compromised wallet backup defeats the purpose of upgrading security.

It asks why open-source matters so much for crypto security. The source says open-source software allows anyone to independently verify how a device works and is built, including how keys are generated, stored, and protected.

It asks what a cold hardware wallet is. The source defines it as a wallet that generates and stores private keys entirely offline, without ever exposing them to an internet-connected device.

Who wrote and published the original material?

The source article is attributed to Henry Windle, Senior Content Marketer, Trezor.

It says "Choosing a new crypto hardware wallet in 2026: Avoid these common mistakes" was originally published in Trezor Blog on Medium, where people are continuing the conversation by highlighting and responding to the story.