Explanation
A hardware wallet signs transactions without exposing the key to your computer. That removes most malware risk, but not the risk of losing both the device and the backup.
How a hardware wallet works
The device contains a chip the private key never leaves. Your computer assembles the transaction and sends it to the device; you read the amount and address on its small screen, press the button, and the device returns only the signature. Even on an infected computer, malware therefore cannot move funds without your physical confirmation.
That small screen is exactly why it matters: always check the first and last characters of the address on the device itself, not on your computer. Address-swapping malware is the most common attack.
When it is worth it
A practical rule of thumb: as soon as your crypto is worth more than three hardware wallets, it no longer belongs on an exchange or phone. A device costs roughly what you pay in spreads on a few trades, and shifts the risk from 'someone hacks my account' to 'I must be careful with my backup'.
The risks that remain
Cold storage solves theft over the internet, but not fire, loss of the backup, coercion, or blindly signing a malicious contract. Always buy the device directly from the manufacturer — never second-hand, never via a marketplace — and ignore any letter or email asking you to 're-activate' your device.
Key takeaways
- Always verify the address on the device screen.
- Only buy from the manufacturer, never second-hand.
- Store the seed backup separately from the device.
Frequently asked questions
+What if the manufacturer goes bankrupt?
Your seed phrase follows an open standard. You simply restore your wallet on another brand's device or in a software wallet.
+Should I insure the device?
The device itself costs little; the value sits in the backup. Invest in a second, well-hidden copy of your seed rather than in insurance.