Four days ago, Trezor told nearly 14,000 customers that their names, phone numbers and home addresses had been stolen. Not from Trezor, but from ShipMonk, the logistics company that puts its devices in boxes.
That sentence contains the whole argument of this review. Trezor's hardware has never been remotely compromised to steal funds in thirteen years of operation. Its customers, however, have been exposed four separate times through third parties, and the most recent exposure included the one category of data that turns a crypto owner into a physical target.
If you are choosing a hardware wallet in Greece in 2026, the chip specifications matter less than you have been led to believe. This article covers both anyway, because the chip story, as it happens, is genuinely interesting.
The company
SatoshiLabs is based in Prague. Pavol "Stick" Rusnák and Marek "Slush" Palatinus met at the brmlab hackerspace in Prague in 2011; the company was incorporated in 2013 and shipped the Trezor Model One, the world's first cryptocurrency hardware wallet, on 29 July 2014, funded through preorders, with a first batch of roughly 1,000 devices. [1][2][3]
Palatinus has a second claim on crypto history: he created Slush Pool, the first publicly available Bitcoin mining pool, which continues today as Braiins. It was the security demands of running that pool that pushed him toward hardware custody in the first place. [1][3]
Leadership is split across the group, and sources muddle it. Matěj Žák has been CEO of Trezor since January 2023, having joined in 2019 as a product manager; Palatinus handed over the role and remained with the company on the strategic and technical side. Palatinus is CEO of SatoshiLabs, the parent group. Rusnák is co-founder and CTO of SatoshiLabs. Tomáš Sušánka is Trezor's CTO. [2][4][5]
Tropic Square, the company that designed the Safe 7's headline chip, is a sister company inside the same SatoshiLabs group, not an independent supplier. That matters when reading claims about the chip, and we return to it below. [6]
Headcount is not reliably public: Tracxn lists 208 for Trezor and 56 for SatoshiLabs, other databases give a 50-200 band. The company has never disclosed revenue or taken a publicly reported venture round, and is described as bootstrapped, though that is not independently confirmed. [4][7][8]
The devices
| Model | Launched | Price | Security chips | Notes |
|---|---|---|---|---|
| Model One | 2014 | Legacy | General-purpose MCU only | No secure element |
| Model T | 2018 | Legacy | General-purpose MCU only | First touchscreen |
| Safe 3 | Oct 2023 | ~$79 | EAL6+ secure element + TRZ32F429 MCU | Entry model |
| Safe 5 | Jun 2024 | ~$129 (launch $169) | EAL6+ secure element + STM32U5 MCU | Touchscreen, haptics |
| Safe 7 | Nov 2025 | $249 / €249 | TROPIC01 + Optiga EAL6+ + STM32U5 | Bluetooth, Qi2, IP67 |
[9][10][11][12][13]
The Safe 7 began shipping on 23 November 2025 but availability has been geographically staggered, so it is worth checking the official store for your region rather than assuming stock. A Bitcoin-only edition is available. [9][10]
Security architecture: what actually protects the seed
The core model is the same across every device: the private key is generated on the device, never leaves it, and every transaction must be physically confirmed on the device's own screen. A compromised computer or phone cannot silently redirect funds, because the destination address is displayed on hardware the malware does not control. [9]
Where the models differ is what happens if someone steals the device.
Model One and Model T have no secure element. They rely on general-purpose STM32 microcontrollers, which were never designed to resist physical attack. This is the source of every serious Trezor vulnerability in the historical record. [14][15]
Safe 3 and Safe 5 added an EAL6+ certified secure element alongside the microcontroller. The secure element handles PIN verification and key storage, making seed extraction through conventional physical attack substantially harder. [14][16]
The Safe 7 uses three independent chips from three different vendors: Tropic Square's TROPIC01, an Infineon Optiga secure element certified to EAL6+, and an STM32U5 microcontroller. Trezor's design principle is that no single chip holds enough to compromise the wallet. It is also the first hardware wallet to use post-quantum cryptography for firmware updates, device authentication and the boot process. [9][17]
The Safe 7's other differences are conveniences rather than security: Bluetooth Low Energy, Qi2 wireless charging, a LiFePO₄ battery rated for four times the charge cycles of standard lithium, a 2.5-inch Gorilla Glass touchscreen, IP67 rating and an anodised aluminium body. Both USB-C and Bluetooth connections are encrypted using the Trezor Host Protocol. [9][17][18]
Open source, and the TROPIC01 argument
Trezor's firmware and the Trezor Suite application have always been open source. That is common enough among serious wallet vendors. [19][20]
What is not common is the secure element. Every certified EAL6+ chip on the market (in Ledger devices, in OneKey devices, in Trezor's own Safe 3 and Safe 5) has a closed internal architecture protected by non-disclosure agreements. You trust the vendor's claims because you cannot check them. [11][12]
TROPIC01 is the first secure element whose complete hardware design, firmware and specification are published for public review. The pitch is that backdoors cannot be silently introduced and supply-chain modifications to the chip design would be detectable. [11][12][17]
This is a genuine advance in transparency, and it should be reported as such. It is also, immediately, a story about what transparency costs.
The laser attack: a competitor broke Trezor's chip, and Trezor thanked them
What happened. Tropic Square supplied TROPIC01 samples to Ledger Donjon (the security research unit of Trezor's main commercial rival) for an independent audit. In late January 2026 Donjon reported a successful laser fault injection attack. Coordinated public disclosure followed on 3 June 2026. [21][22][23]
The technical detail. Researchers decapsulated the chip and used a precisely calibrated 1064 nm laser to inject faults into the Ed25519 signature verification performed during firmware updates and boot. This gave them arbitrary firmware execution on the chip. They demonstrated success by modifying the chip to return "HACK" in its device identification response. Building on that, Tropic Square's own engineers identified a second path targeting MAC-and-Destroy, the hardware mechanism underpinning PIN verification. [21][23][24]
What it does not do. The attack requires physical possession of the device, desoldering, decapsulation and specialised laboratory equipment. It is not remote. It defeats one of three independent security layers. Private keys, wallet backups and PINs are not stored on TROPIC01. Ledger Donjon reported that the MAC-and-Destroy secret storage resisted their extraction attempts entirely during the initial testing window. [21][22][23]
What is still open. The vulnerability affects all TROPIC01 chips currently in the field and cannot be fixed by ordinary firmware update, because it is a hardware-level issue. A firmware mitigation exists: disabling the chip's MAINTENANCE mode closes the primary entry point. A hardened silicon revision is scheduled for late 2026, with full technical details expected in spring 2027. No CVE identifier has been assigned and Donjon's complete technical writeup has not been published. [23][24]
The industry story underneath. Ledger Donjon has now disclosed lab-grade physical attacks against two rival cold-storage products inside a year. In late 2025 it demonstrated a "tearing attack" against Tangem cards; Tangem disputed the severity and declined a bounty, and the exchange turned adversarial. Trezor instead published the disclosure itself, credited the competitor that broke its chip, and framed the episode as evidence that its open model works. Donjon, for its part, described Tropic Square's handling of the disclosure as "exemplary." [24][25]
Whatever you conclude about the chip, that exchange is the strongest single argument for Trezor's approach, and it only happened because the chip was open enough to audit.
The vulnerability record
| Date | Researcher | Attack | Models | Physical access? | Status |
|---|---|---|---|---|---|
| 2018 (35C3) | Wallet.Fail | Glitching attacks | One, T | Yes | Mitigated |
| Jan 2020 | Kraken Security Labs | Voltage glitching / RDP downgrade; encrypted seed extracted in ~15 min, PIN then brute-forced | One, Model T | Yes | Unfixable in hardware; defeated by passphrase [15][26] |
| 2023 | Unciphered | Seed and PIN extraction from a Model T supplied by CoinDesk | Model T | Yes | Trezor identified it as an RDP downgrade variant; not fixable without recall [27] |
| Mar 2025 | Ledger Donjon | Voltage glitching of the TRZ32F429 MCU to extract the shared secret between secure element and microcontroller, enabling malicious firmware that still appears genuine | Safe 3 (and noted for Safe 5) | Yes (supply chain) | Firmware mitigation issued; Safe 5's STM32U5 resistant [14][16][28] |
| Jun 2026 | Ledger Donjon / Tropic Square | Laser fault injection on TROPIC01 | Safe 7 | Yes (lab conditions) | Firmware mitigation; hardened silicon due late 2026 [21][23] |
Two patterns are worth drawing out for readers.
First, every one of these attacks requires the attacker to have your device in their hands. None is remote. The 2020 Kraken attack is the most practically alarming of the set (Kraken estimated a consumer-friendly glitching rig could be mass-produced for around $75), and its own recommended defence was simply to enable a BIP39 passphrase, because the passphrase is never stored on the device. [26]
Second, the March 2025 Safe 3 finding is the one that changes buying behaviour, because it is a supply-chain attack. It only meaningfully threatens someone who bought a device second- or third-hand, or from an unverified marketplace seller. Both Trezor and Ledger drew the same conclusion: buy directly. [16][28]
The breaches that actually cost people money
This is the section most wallet reviews skip, and it should not be skipped.
| Date | Vector | Scope |
|---|---|---|
| April 2022 | MailChimp compromise; phishing emails sent through Trezor's mailing list to lookalike download domains built to harvest seed phrases | 106,856 customers' data involved [29][30] |
| February 2023 | Mass impersonation campaign by email and SMS urging users to "secure their device" on a phishing page | Widespread [29] |
| January 2024 | Unauthorised access to a third-party support ticketing portal | ~66,000 users who had contacted support since December 2021: names, usernames, email addresses. Attackers used the data to phish for 24-word recovery seeds; at least 41 users received such emails within days [29][31][32] |
| August 2026 | ShipMonk fulfilment breach via a critical SQL injection zero-day in Metabase, a third-party analytics platform | 13,689 customers [33][34][35] |
The ShipMonk breach in detail
Metabase notified ShipMonk on 6 August 2026 that an unauthorised party had exploited a flaw in its software. ShipMonk informed Trezor on 10 August; Trezor disclosed publicly on 13 August. [33][35][36]
11,742 customers had full exposure: name, email address, phone number and shipping address. 1,947 had partial exposure: name, city and email address. Affected customers received orders between 10 May and 8 August 2026 in the United States, United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal. Orders fulfilled through Amazon were handled by a different partner and were not affected. [33][34][36]
Greece is not on that list. Greek customers who ordered in that window appear to be outside the affected set, but anyone who received a notification email was affected, and anyone who did not was not, which is the only reliable test. [34]
Trezor's 90-day data retention policy limited the scope, though some older orders appear in the partial-exposure group. The company said this was the first breach in its thirteen-year history to expose customer phone numbers and shipping addresses. The extortion group ShinyHunters claimed responsibility for the Metabase campaign, which also caught laptop maker Framework and form builder Tally. [33][34][35]
Why this is the serious one. Email addresses enable phishing. Home addresses enable something worse. Chainalysis documented 46 violent crypto-related incidents worldwide through late June 2026, against 40 in the same period of 2025, with kidnappings accounting for 52% of them, and more than $30 million taken in violent attacks in the first half of 2026 against $58 million for all of 2025. A leaked list of confirmed hardware-wallet owners with home addresses is precisely the input that market wants. [37][38]
Trezor's response is a product change: an "Anonymous Delivery" option using a dedicated checkout, neutral unbranded packaging, locker collection and automatic deletion of address data after delivery, targeted for launch in the EU in September 2026 and in the US by year end. [37][38]
Context, not excuse. Ledger's 2020 breach exposed the records of roughly 270,000-300,000 customers alongside over a million email addresses, and victims were later mailed counterfeit Ledger devices; scammers were still sending Ledger owners fake "Quantum Resistance Security Update" letters with malicious QR codes as recently as May 2026. Ledger disclosed a further leak through its payment processor Global-e in January 2026. This is an industry-wide failure of third-party data handling, not a Trezor-specific one. [30][37][39]
Seed, recovery and portability
Trezor uses the BIP39 standard: 12 or 24 words generated on the device. Newer models support multi-share (Shamir) backup, splitting the recovery across several shares of which a threshold is required. Passphrase support creates hidden wallets that are invisible without the passphrase, and the passphrase is never stored on the device, which is what makes it the defence against every physical extraction attack in the table above. [19][40][41]
Portability is the underrated feature. Because the seed follows an open standard, it can be restored on a competitor's device or in open-source software. Your funds do not depend on SatoshiLabs continuing to exist. For a thirteen-year-old private company with undisclosed financials, that is a more meaningful guarantee than any corporate assurance. [19]
Software and supported assets
Trezor Suite runs on desktop, web and Android, with a browser extension, and covers portfolio tracking, send and receive, buy, sell, swap and staking in one dashboard. Setup takes roughly 15-20 minutes with no account registration. Reviewers consistently report the desktop app is the most polished, with the browser extension and mobile app less so. [42][43]
Notable features: Tor support, coin control (choosing which UTXOs to spend), MEV protection, dust and address-poisoning protection, firmware and device authenticity checks, and Suite Sync, which stores labels locally with encrypted backups rather than on Google Drive or Dropbox. [42][44]
Assets: native support in Suite for Bitcoin, Ethereum and all ERC-20 tokens, Solana, Tron, Cardano, Litecoin, Ethereum Classic, XRP and Dogecoin, among others; reviews cite 1,000+ coins and tokens across models. Some assets, Monero and Tezos among them, are supported by the firmware but require a third-party wallet application, which does not compromise security because keys never leave the device. Staking for Ethereum, Cardano and Solana is available directly in Suite. [43][45][46]
What it costs
The device price is the honest part: roughly $79 for the Safe 3, $129 for the Safe 5, $249 / €249 for the Safe 7. There are no recurring fees, no subscription and no custody charge. [11][12][13]
The buy, sell and swap features inside Trezor Suite are a different matter. They are powered by Invity, an aggregator that compares offers from multiple providers, with payment via card, SEPA, PayPal, iDEAL, Bancontact, SOFORT, EPS and others, plus an OTC route for larger amounts. The convenience is real; the cost is not competitive. One 2026 review puts the realistic all-in cost at around 5% and up depending on asset and provider, and notes the same is true of Ledger and MetaMask. [43][47]
Practical advice worth stating plainly: buy on a MiCA-licensed exchange, then withdraw to the Trezor. Use Invity only when the convenience genuinely outweighs several percent.
Privacy
Two things Greek readers should understand before setup.
Your node choice determines who sees your transactions. If you do not connect Suite to your own node, you use Trezor's hosted node, and unless you take further steps, that node can associate your extended public key with your transactions. Enabling Tor in Suite obscures your IP address; running your own node is the complete answer. [48]
Coin control lets you avoid merging UTXOs whose histories you would rather keep separate. It is off the beaten path for beginners but it is the difference between a private wallet and a transparent one. [42]
The regulatory position, and why it is short
A non-custodial wallet manufacturer is not a crypto-asset service provider and does not need a MiCA licence. Trezor never holds your keys or your assets, so no regulated service is involved. Anyone telling you to check whether your hardware wallet is "MiCA-licensed" has misunderstood the regulation. [49][50]
This is explicit in EU law rather than a matter of interpretation. Article 79 of the Anti-Money Laundering Regulation (Regulation 2024/1624), applicable from July 2027, states that it does not apply to users, nor to manufacturers of hardware or software wallets, nor to providers of self-hosted wallets. The AMLR's prohibitions on anonymous accounts and privacy coins bind exchanges, not you. [51][52]
What does reach you sits at the boundary. Under the Transfer of Funds Regulation, a licensed exchange must verify ownership of a self-hosted wallet for transfers above €1,000. In practice this means that the first time you withdraw a meaningful sum from a Greek-accessible exchange to your Trezor, the receiving address becomes permanently linked to your verified identity in that exchange's records. Self-custody remains legal and unrestricted; the pseudonymity people once associated with it does not survive that link. [51][52]
The European Commission opened a targeted consultation on the MiCA review in May 2026, closing 31 August 2026, with a report that could carry a "MiCA II" proposal due by 30 June 2027. Nothing currently proposed bans self-custody. [52]
Buying one in Greece
Trezor ships to over 200 countries from its official store, and Greece appears explicitly on the shipping list, including for the Safe 7. Delivery from the Czech Republic is an intra-EU shipment, so no customs procedure applies; the customs warnings in Trezor's documentation concern shipments leaving the EU. Standard EU consumer warranty and return rights apply to purchases from the official store. [53][54][55]
The one rule that matters more than any other in this article: buy from the official Trezor shop, an authorised reseller, or Trezor's own Amazon storefronts. Trezor operates official Amazon stores in twelve countries with stock supplied and kept separate by the company. Warranty and RMA are handled directly only for purchases made through trezor.io; if you buy from a reseller, you negotiate with that reseller, and terms vary. [55][56]
Never buy a hardware wallet from a general marketplace listing, an auction site or a second-hand seller. The March 2025 Safe 3 supply-chain finding is exactly the attack this rule prevents, and counterfeit Trezor devices capable of stealing keys have circulated before. [16][31]
How it compares
| Wallet | Secure element | Firmware open source | SE auditable | Notable incident history |
|---|---|---|---|---|
| Trezor Safe 7 | TROPIC01 + EAL6+ Optiga + STM32U5 | Yes | Yes (TROPIC01) | TROPIC01 laser attack (lab), Jun 2026 |
| Trezor Safe 5 / Safe 3 | EAL6+ + MCU | Yes | No | Safe 3 supply-chain glitching, Mar 2025 |
| Trezor One / Model T | None | Yes | n/a | Seed extraction, 2020 and 2023 |
| Ledger | EAL-certified, closed | Partly | No | 2020 customer data breach (~270k-300k records); Global-e leak Jan 2026 |
| Coldcard | Dual secure element | Yes | No | Bitcoin-only |
| Tangem | Certified SE | Partly | No | Donjon "tearing attack", late 2025; response disputed |
| BitBox02 / Keystone / Jade / OneKey | Varies | Varies | No | None listed |
[9][11][12][14][24][30][39]
The pattern across the market: Trezor competes on transparency, Ledger on certified hardening, Coldcard on Bitcoin-only minimalism, Tangem on convenience. None of them has had a device remotely compromised to steal user funds. All of the large ones have leaked customer data.
Who this is for, and who it is not for
Buy a Trezor if you want open-source firmware you or someone else can actually audit, you value BIP39 portability, you are willing to set a passphrase, and you will buy from an official channel. The Safe 5 at roughly $129 is the sensible default for most people; the core security model is identical to the Safe 7.
Buy the Safe 7 if the portfolio you are protecting makes a $120 premium irrelevant, you want the auditable secure element and three-vendor architecture, or you want Bluetooth and IP67 for travel.
Look elsewhere if you want a Bitcoin-only device with maximal air-gapping (Coldcard, Foundation Passport), or if you would rather have certified closed hardening than auditable openness (Ledger). Both are defensible positions.
Do not buy any hardware wallet if you are not prepared to write down a recovery phrase, store it offline, and never type it into anything. Every documented Trezor user loss traces back to that step, not to the device.
What we could not verify
The following are absent above because public sources did not support them: Trezor's revenue, profitability and ownership structure; a reliable employee count; the euro retail price including Greek VAT and shipping; whether Trezor Suite offers a Greek-language interface; whether Suite's transaction export is usable for Greek tax filing; whether the Anonymous Delivery option has actually launched in the EU as scheduled for September 2026; and whether a CVE has since been assigned to the TROPIC01 finding.
Frequently asked questions
Has Trezor ever been hacked? Not remotely, and not in a way that stole user funds. Researchers have extracted seeds from older models (One and Model T) with the physical device in hand and lab equipment. The company's customers, however, have had personal data exposed four times through third parties.
Was I affected by the August 2026 breach? Only if you received a notification email. The affected group was 13,689 customers who received orders between 10 May and 8 August 2026 in the US, UK, Sweden, Colombia, Brazil, Italy and Portugal. Greece was not on the list.
Is the Safe 7 unsafe after the laser attack? No. The attack requires physical possession, chip decapsulation and laboratory equipment, and it defeats one of three independent security layers. Keys, backups and PINs are not stored on the affected chip. A hardened chip revision is due in late 2026.
Do I need a MiCA licence check for a hardware wallet? No. A non-custodial wallet maker is not a CASP and does not need MiCA authorisation. EU law explicitly excludes hardware and software wallet manufacturers from the AMLR.
Where should I buy one in Greece? The official Trezor shop, an authorised reseller, or Trezor's official Amazon storefront. Never a general marketplace listing or a second-hand seller.
What is the single most important setup step? Enable a passphrase. It is not stored on the device, and it defeats every physical seed-extraction attack in the published record.
Sources
All accessed 17 August 2026. P = primary, S = secondary.
- P: SatoshiLabs, "Our Story", satoshilabs.com/our-story
- P: SatoshiLabs, Presskit, satoshilabs.com/presskit
- S: Trezor Australia, "About SatoshiLabs & Trezor"
- S: Tracxn, Trezor company profile, Jul 2026
- P: SatoshiLabs, "Trezor appoints Žák as new CEO", Jan 2023
- S: BitDegree, "Trezor Safe 7 Review", Mar 2026
- S: Tracxn, SatoshiLabs company profile, Jul 2026
- S: HyperSinc, Trezor (SatoshiLabs s.r.o.) profile
- P: Trezor, "Trezor Safe 7" product page, trezor.io/trezor-safe-7
- S: CryptoSlate, "Trezor Safe 7 Review 2026", Jul 2026
- S: CryoVault, "Trezor Safe 7 Review 2026", Apr 2026
- S: CryoVault, "Trezor Safe 5 vs Safe 7 2026", Apr 2026
- S: Thaibitcast, "In-depth Look at Trezor Safe 7", Jan 2026
- S: CryptoNews, "Ledger Claims Trezor Safe Devices Remain Vulnerable to Supply Chain Attacks", Mar 2025
- S: CryptoSlate, Trezor company profile, Mar 2026
- S: The Block, "Trezor discloses potential vulnerability in older Safe 3 crypto wallets", Mar 2025
- S: Bitcoin.com News, "New Trezor Safe 7 Boasts Quantum-Resistant Design and Dual Secure Elements", Oct 2025
- S: The Investors Centre, "Trezor Safe 7 Pre-Order Guide"
- S: Milkroad, "Trezor Hardware Wallet Review 2026", May 2026
- S: CryptoNews, "Trezor Wallet Review 2026", Jan 2026
- P: Ledger Donjon, "Laser Fault Injection on the TROPIC01 Open-Source Secure Element", 3 Jun 2026, donjon.ledger.com
- P: Trezor, "Trezor response: TROPIC01 chip disclosure (no impact to your funds)", 3 Jun 2026, trezor.io/blog
- S: The Block, "Ledger researchers find flaw in chip used by Trezor Safe 7", 4 Jun 2026
- S: Spoted Crypto, "Trezor Safe 7 TROPIC01 Chip Flaw: Ledger Laser Attack Explained", Jun 2026
- S: Cryptonomist, "Trezor and Tropic Square reveal a vulnerability in the TROPIC01 chip", 3 Jun 2026
- P: Kraken Security Labs, "Kraken Identifies Critical Flaw in Trezor Hardware Wallets"
- S: Crypto Daily, "Unciphered Highlights Vulnerability In Trezor T Hardware Wallet", May 2023
- S: TrueToCrypto, "Trezor Reveals Security Flaw In Older Safe 3 Wallets", Mar 2025
- S: BleepingComputer, "Trezor's support platform abused in crypto theft phishing attacks"
- S: BigGo Finance, "Trezor Says Shipping Partner Breach Exposed Data of Nearly 14,000 Customers", Aug 2026
- S: Blockonomi, "Trezor Breach Exposes 66,000 to Phishing", Jan 2024
- S: Hackread, "Trezor Data Breach Exposes Email and Names of 66,000 Users", Jan 2024
- S: BleepingComputer, "Trezor discloses data breach affecting nearly 14,000 customers", Aug 2026
- S: Rescana, "Trezor Data Breach Analysis: 14,000 Customers Exposed in ShipMonk Metabase SQL Injection Incident", Aug 2026
- S: SecurityWeek, "14,000 Trezor Customers Impacted by Data Breach at ShipMonk", Aug 2026
- S: CoinDesk, "Trezor warns 14,000 users after fulfilment partner suffers data breach", 13 Aug 2026
- S: Cryptopolitan, "14,000 Trezor users put on phishing alert after data breach", Aug 2026
- S: eSecurity Planet, "Trezor ShipMonk Breach Exposes Nearly 14,000 Customers", Aug 2026
- S: Bitcoin Magazine, "Trezor Warns Thousands of Users After Third-Party Data Breach", Aug 2026
- S: DailyCoin, "Trezor Warns of Phishing Risk After 14,000-Customer Data Leak", Aug 2026
- S: CryptoRecovers, "Trezor Hacked? Can Trezor Be Hacked, and How to Stay Safe", Aug 2026
- P: Trezor, "Trezor Suite Settings" knowledge base, trezor.io/learn
- S: Coincub, "Trezor Wallet Review 2026", Apr 2026
- P: Trezor, "Trezor Suite App", trezor.io/trezor-suite
- P: Trezor, "Trezor hardware wallet supported coins and tokens"
- S: Tracxn / SatoshiLabs news (Solana staking via Everstake, Mar 2025)
- P: SatoshiLabs, "Buy and exchange crypto with Invity using Trezor Suite"
- S: BuyBitcoinWorldwide, "TREZOR One Review: 5 Things to Know"
- S: Crypto Daily, "How Non-Custodial Wallets Protect Users After MiCA's July 2026 Enforcement", Jun 2026
- S: Tangem Learning Hub, "MiCA Regulation 2026: What It Means for Self-Custody and Hardware Wallets", Jun 2026
- S: Yannakas, "Self-Hosted Wallets Under EU Law", Jan 2026 (citing AMLR Regulation 2024/1624, Article 79)
- S: LeoDex, "MiCA Explained: CEX Rules, DEX Exemption, Self-Custody", Jul 2026
- P: Trezor, "Shipping estimates for Trezor Safe 7"
- P: Trezor, "Expected delivery time for orders from Trezor Shop"
- P: Trezor, "Where to buy a genuine Trezor hardware wallet"
- P: Trezor, FAQs, trezor.io/faqs