The Trezor Model T was the touchscreen wallet that moved a lot of people from thinking about self-custody to owning hardware, and plenty of those devices are still in drawers, still holding coins, still working fine. It is no longer on sale. What has changed since most of them were bought is the threat model, because the one weakness the Model T has always had is the one that gets worse every time a customer address list leaks.
Where the Trezor Model T stands in 2026
Trezor's own product page is direct about the status: the Model T is no longer sold, and the Safe 5 is the device that took its place. Support has not been withdrawn, though. The company commits to software updates until at least 2031 and critical security fixes until at least 2036, which is a longer runway than most consumer electronics get and worth crediting.
The hardware itself holds up. A 1.54-inch colour touchscreen at 240 by 240 pixels, a microSD slot, a wired connection to the computer, and a backup story that was ahead of everyone else at the time: the Model T was the first hardware wallet to ship multi-share backup using the SLIP-39 standard, alongside ordinary BIP-39 seeds of twelve, twenty or twenty-four words. Trezor got to splitting a recovery secret before the rest of the industry did, and that deserves saying plainly.
The chip that isn't there
Here is the trade-off that came with it. The Model T stores its secret inside a general-purpose STM32 microcontroller rather than a dedicated secure element, which is a chip built specifically to resist someone attacking it with tools in hand. That choice was deliberate and it came from an open-source position: secure elements ship under vendor agreements that make full public auditing difficult, and Trezor preferred a part it could document end to end.
The cost of the choice is documented too. The read protection downgrade attack against STM32 parts, which Trezor responded to publicly, uses voltage glitching to knock the chip's protection down a level and read out the contents of flash memory. In 2023, the security firm Unciphered demonstrated the extraction of a seed phrase from a Trezor T it had been handed, describing the underlying flaw as unpatchable in the silicon. The Safe series that followed added an EAL6+ certified secure element, which is a quiet admission of what the earlier design left open.
What the attack requires, and why that changed
None of this is a remote risk. Nobody drains a Model T over the internet using this technique; an attacker needs the device in their hands, specialist equipment, and the knowledge to use it. For years that made the whole discussion academic for a normal holder, since the scenario required a thief who both stole your specific wallet and knew what to do with it afterwards.
That calculation has shifted. Hardware wallet customer databases keep leaking through third parties: Trezor's shipping provider exposed records for 80,689 customers during 2026, including United States orders going back to 2019, and Ledger has been through two similar leaks of its own. Those files pair a name and a home address with the brand of wallet at that address. An attack that needs someone to physically hold your device stops being theoretical once a list exists telling people where the device lives.
The passphrase is the mitigation, and it has a catch
Trezor's answer to this class of attack is the passphrase, an extra word or sentence you supply that produces a different wallet from the same seed. Get it right and an extracted seed opens an empty account. It works, and any Model T owner still holding meaningful value should have one set.
The catch is that a passphrase is one more secret with no recovery path. Forget it and the coins are gone, with no support line and no reset, which is why plenty of people set one, write it next to the seed card, and quietly undo the protection they just bought. A defence that most users implement wrong is a defence with a design problem underneath it.
What Model T owners should do about backup
Start with the parts that cost nothing. Set a passphrase if you have not, keep it somewhere separate from the recovery card rather than in the same envelope, and treat the device as something to keep out of sight rather than on a desk. If your address appeared in a vendor leak, assume the calls and emails that follow will sound convincing, and never read a recovery secret aloud to anyone.
Then look at the structure. On a Model T, the whole wallet still comes down to a set of words on a card in a place, and the passphrase is a second item in a second place; both are objects a person can find, and both are things you can be talked or pressured into surrendering. SLIP-39 multi-share was Trezor's attempt at fixing this, and it remains an option most owners never turned on because splitting shares by hand is work.
TapSafe Recovery does the splitting for you as part of setup. Recovery on Ryder One divides through a custom implementation of Shamir's Secret Sharing: half sits on the Recovery Tag, half sits in an encrypted share in your iCloud or Google Drive, and no single piece opens the wallet on its own. Recovery Contacts can hold a quarter each and never see anything about your holdings. The seed phrase stays readable on the device under the BIP-39 standard as a last resort, so nothing about this locks you to our hardware.
If you are thinking of buying one secondhand
Don't. A discontinued wallet on a marketplace is a device you cannot verify, from a seller you cannot check, running firmware that could have been tampered with before it was boxed up again. The saving is forty or fifty dollars against a risk that has no upper bound. Anyone shopping at that price point is better served by a new device from the manufacturer, whichever brand they choose.
For owners staying put, the Model T remains a working hardware wallet with years of support ahead of it, and there is no reason to panic. For anyone upgrading, the question worth asking of the next device is what happens to your recovery when the box is opened, since that is the part the last generation left to you.
Ryder One is 149 USD for the Starter Combo and 179 USD for the Super Safe Combo, with an EAL6+ Infineon secure element, NFC-only communication and firmware audited by Halborn. Have a look at the device.
Meta description: The Trezor Model T is discontinued but supported to 2036. What the missing secure element means, why address leaks change the risk, and what owners should do.




Share: