Trezor Safe device authentication check

Trezor Safe 3 and Safe 5 each include a Secure Element chip that helps protect your wallet and verify your device's authenticity.

Trezor Safe 7 builds on this design with three hardware layers of security: TROPIC01 and OPTIGA Trust M (the two secure elements), and the STM32U5, a hardened security microcontroller unit (MCU).

Trezor Safe 7
Trezor Safe 7
Sécurité avancée et pérenne avec liberté sans fil
Trezor Safe 5
Trezor Safe 5
Confort exceptionnel grâce à un écran tactile couleur vif et un retour haptique pour chaque confirmation. Découvrez une sécurité avancée pour les cryptos.

How does device authentication work?

During the manufacturing process of the Trezor Safe hardware wallets, a unique certificate is issued to each new device before it leaves the production line.

The device certificate is securely stored inside the Secure Element on Trezor Safe 3 and Trezor Safe 5. On Trezor Safe 7, both secure elements (TROPIC01 and OPTIGA Trust M) participate in the authentication process, with the MCU coordinating verification.

As part of the May 2026 updates, the device authenticity check gained post-quantum support using the ML-DSA algorithm. This means the device verification process now also checks a signature from the MCU using ML-DSA-44, a lattice-based post-quantum signature algorithm.

This builds on Safe 7's existing challenge-response authenticity model: when you connect the device, Trezor Suite sends a random challenge, and the device's Secure Elements (TROPIC01 and OPTIGA Trust M) sign it and return that signature along with the factory-issued device certificate; Suite then checks these signatures against Trezor' public keys to confirm the device is genuine.

Previously this attestation relied on the two secure elements, with the MCU coordinating verification between them. This update promotes the MCU from a coordinator to a third, independently auditable signature layer. Thus, even if a quantum computer could eventually break classical signature schemes, an attacker still couldn't forge a valid device certificate or spoof a genuine Trezor.

This process helps verify the authenticity of your new Trezor Safe hardware wallet and makes it significantly harder to tamper with. It ensures you are always using a genuine Trezor device, safeguarding your coins and tokens.

Is device authentication mandatory?

If you only use Trezor Suite with official Trezor devices, do not turn off this check. This feature is a security measure designed to protect you from using a fake or compromised device.

Users may opt out of the device authentication process, but we strongly advise against it.

The authenticity check should only be disabled if you need to connect unofficial devices to Trezor Suite, such as DIY builds.

If you’re absolutely sure you want to turn off the Device Check feature, you can do so in the Settings menu in Trezor Suite.

Are there any privacy concerns associated with device authentication?

No. The device certificate is neither tracked nor stored anywhere. It is checked only by Trezor Suite and then immediately discarded. It is not sent anywhere, meaning your privacy is always preserved.

Cet article vous a-t-il été utile ?