SatoshiLabs · Safe 3, Safe 5

Trezor Safe 3 / 5

Open MCU firmware, reproducible builds, OPTIGA Trust M as a companion SE — not as the wallet CPU. Heir to the Trezors without helper silicon.

Open MCU, opaque siliconMulti-coinApproachable

After glitching of the One and Model T, SatoshiLabs glued an OPTIGA Trust M EAL6+ next to an STM32 that still runs open firmware. The OPTIGA wraps, attests, hardens the PIN. Keys do not live “in” the OPTIGA the way they live in an ST33. Filing Safe 3 next to Ledger under “has an SE” is the catalogue shortcut.

Application firmware is published, auditable, aimed at reproducibility: that is the MCU you can, given time, bring close to a hash. The OPTIGA, no. Passphrase and SLIP39 are first-class. Safe 5 gains a screen; Safe 3 remains the entry.

You read what composes the transaction. You still trust Infineon for a ROM you will not dump. This is neither Coldcard (two authenticators) nor Ledger (vendor OS in the chip that signs).

Fits if

Balance of auditability / UX, passphrase and Shamir, mixed use.

Keep in mind

USB: PC malware remains an issue, mitigated by the screen. The OPTIGA is not auditable like the MCU firmware. This is not an ST33.

Related incidents