SatoshiLabs · Safe 7

Trezor Safe 7

TROPIC01 is a RISC-V with published RTL, hence programmable. OPTIGA and the STM32U5 are there so that this layer alone does not pay the seed. Auditable is not “the die equals the Verilog”.

Open MCU, opaque siliconMulti-coinMulti-SE

TROPIC01 is not a frozen authenticator and is not an ST33. It is a RISC-V CPU whose RTL, application firmware and ECC coprocessor are published. You can patch a curve. A lab that faults signature verification can run unsigned code on it — that is exactly what Donjon showed in 2026. Openness and programmability are the same object.

OPTIGA EAL6+ and the hardened STM32U5 remain in the path. Trezor published that funds hold if a single layer falls. That is the scenario the architecture exists for. It is also the admission: a “transparent” SE is not an unattackable SE, and RTL on GitHub is not the wafer in your living room.

The touchscreen targets clear signing. Device updates are thought post-quantum on the MCU bootloader. For a physical attacker the cost goes up. For an attacker who reads the C, application firmware remains readable. Neither verifies the die.

Fits if

Physical theft / seizure, defense in depth, users who want the “new school” Trezor.

Keep in mind

Donjon 2026: laser fault, unsigned TROPIC01 firmware possible in lab. No impact on funds according to Trezor, thanks to the other layers. Price, youth, and the die is not the RTL.

Related incidents