Short version

We earn a small commission when you buy a hardware wallet (or another privacy tool) through one of our links. The recommendations themselves are made first, the affiliate program is a way to get paid for them after. The open-source hardware wallet guide was written before any of the wallet-vendor programs were active, and the criticism in that guide (Ledger, supply-chain risk, fingerprint sensors, etc.) is unaffected by which wallet company is willing to pay us a referral fee.

What "affiliate" means here

An affiliate program is a deal where a vendor pays us a small percentage of the sale when someone clicks one of our links and buys something. The cookie that tracks the referral usually lasts 30 to 90 days, so if you click a Trezor link today and buy a Safe 5 two weeks from now, Trezor still knows the referral came from us and still pays us.

Commission rates for the wallet vendors we work with are in the 10–15% range. On the $129 Trezor Safe 5 (the current MSRP at trezor.io, as of 2026-06-08) that's roughly $13–19 per sale. On a higher-end device, a bit more. Not life-changing money for a site this size, but it covers hosting, the build pipeline, and the time the editor-in-chief spends on audits and revisions. Without the affiliate income the site runs on donations and the editor's day job.

We do not run display ads. We do not sell your data. We do not take sponsored posts. Affiliate is the only revenue model that comes from the tool recommendations themselves.

Current wallet-vendor affiliate relationships

Scope note: this page covers hardware wallet and security-key vendors, the category where readers most need per-vendor clarity. The site also runs affiliate programs in other categories (VPNs, data removal, backup, antivirus, crypto tax tools); every monetized review carries its own disclosure box at the top, and the site-wide transparency notice lives on the resources page.

This is the list of wallet vendors we have an active affiliate relationship with. It is also the complete list: if a wallet appears in our guides and is not on this page, we are not earning from that recommendation. The full tracking sheet (commission rates, signup dates, first-revenue dates) lives in a version-controlled inventory file in the site's repository and is updated every time a status changes; this page is regenerated from the same facts. Payment details never appear in it or here.

Vendor Status Program
Trezor (SatoshiLabs) Affiliate Active since 2026-07-06 In-house program (affil.trezor.io), up to 15% commission, 30-day cookie
Foundation Devices (Passport Prime) Affiliate Pending enrollment Ambassador / referral program, reward-based, self-serve application
Coldcard (Coinkite) No public program (vendor outreach only) No affiliate program exists. We are not paid for any Coldcard recommendation.
Keystone (Cobo) No public program (vendor outreach only) No affiliate program exists. We are not paid for any Keystone recommendation.

Trezor's enrollment went live on July 6, 2026, so Trezor links across the site now carry referral tracking. Foundation's enrollment is still pending: those links point at the vendor's normal site with no referral tracking, and we earn nothing from those clicks. Whenever an enrollment goes through, the links get a referral parameter and the inventory brief above flips from "pending" to "active". If a vendor is not on this page, the site is not earning from recommending them, including Ledger, which is mentioned in the open-source guide as a foil but has no program on this site.

What we will never trade for the money

Our criticism is not for sale

Our disclosure policy in one line: "Affiliations will not stop us calling out problems." We mean it. The current and historical criticism in our wallet guides (closed-source firmware, supply-chain risk, fingerprint-sensor UX concerns, the Ledger Recover scandal, BitBox's centralized update channel, Jade's beta status, the MetaMask-Keystone QR pairing history) is unaffected by which vendor has an affiliate program open this quarter.

Specifically:

  • No sponsored placements. A wallet does not get moved up or down the recommendation list because they are paying us. The order is the order.
  • No review embargoes. If a wallet ships a firmware update that bricks devices, we will say so the same week, not 60 days later because the affiliate contract has a "no negative coverage" clause (we would not sign a contract that has one).
  • No removal of criticism to keep the link live. If Trezor or Foundation ever asks us to soften a paragraph in exchange for keeping the affiliate program, the right answer is to drop the program, not the paragraph.
  • No special-access journalism. We will not take "reviewer units" with a side agreement, "early access" briefings with non-disclosure terms, or "embargoed" security disclosures. The wallet guides are written from publicly shipped firmware and from the wallets we or the editor personally own.

What does change when we enroll

Two things, both small, both visible:

  1. Outbound wallet links become tracking links (for Trezor, a short affil.trezor.io link that redirects straight to trezor.io; other networks use a referral parameter). The destination is the same vendor site. One redirect at most, no different page, no popup.
  2. The disclosure is visible where the link is. Every monetized review opens with an affiliate-disclosure box before the first tracked button, and guide or article body copy that carries an affiliate link points here (an inline "affiliate link, see our disclosure" note). If you find a monetized link without either, that is a bug: report it and we will fix it.

That is the entire change. The wording of the recommendation does not move, the order does not move, and the editorial voice stays where it was.

Privacy of the click

When you click an affiliate link, the vendor's network (Trezor's in-house affiliate platform, financeAds, Foundation's ambassador program, or whatever network that vendor uses) sees your click and may set a cookie. That is a third-party cookie set by the vendor's network, not by us. We do not see who clicked, we do not get a name or email, and we do not get to retarget you.

The wallet guides themselves do not require cookies to read. We use privacy-respecting analytics (see our privacy approach), and we do not load any vendor pixel on this site.

How to verify

Two checks anyone can run. First, this page: if a wallet is recommended anywhere on the site and is not listed above, the site is not earning from it. Second, the links themselves: hover any vendor button and look at the destination. A tracking link (like affil.trezor.io) means we earn from it and the page you are on must say so; a plain vendor URL means we do not. If those two ever disagree, that is a bug: please tell us and we will fix it.

Questions or concerns

Got a question about how a specific link is monetized? Spotted a wallet that should be on this page and isn't? The fastest path is the support page; we read every note. Editorial decisions stay with the editor-in-chief.

Related reading

Editorial policies and how we make decisions: