Security
Choosing and using a hardware wallet
A hardware wallet is a physical device that stores private keys offline and signs transactions locally, so the keys never touch a connected computer or phone. For anyone holding crypto over a longer period, this is generally the most practical way to reduce the risk of hacks, malware and platform failures. At the same time, a hardware wallet is not a cure-all: careless handling, an insecure backup of the seed phrase, or a tampered device can undo the protection it offers. Below we cover what to look for when buying one, how to set it up safely, and the mistakes that occur most often in practice. It does not recommend any specific brand or model.
What a hardware wallet does and does not solve
The core principle is separation: the private key is generated and stored in an isolated chip that is not directly connected to the internet. When you send a transaction, companion software on a computer or phone passes the details to the device, which signs the transaction internally and returns only the signed, encrypted result. The key itself is never exposed to malware on your computer.
What a hardware wallet does not solve is human error. If you enter the wrong address yourself, approve a fraudulent transaction without checking its details, or share your seed phrase with someone posing as support, the device offers no protection. Treat a hardware wallet as one layer within a broader set of precautions, not a guarantee on its own.
Criteria worth checking before you buy
Always buy a hardware wallet directly from the manufacturer or an authorised, official reseller. Second-hand devices or marketplace offers carry the risk that the device has already been tampered with, for example preloaded with a seed phrase known to the seller. On arrival, check that the packaging shows no signs of tampering and that any security seals are intact.
Also consider support for the coins you actually use, open-source firmware (so the code can be publicly audited), regular firmware updates, and how the manufacturer has handled previously reported vulnerabilities. A device that has not received updates in years is a less logical choice than an actively maintained model.
- Bought directly from the manufacturer or an official store
- Packaging and seals intact on arrival
- Support for the relevant coins and networks
- Actively maintained firmware with a transparent update history
Setting up the device for the first time
During setup, the device itself generates a new seed phrase, typically 12 or 24 words. It is important that these words only ever appear on the device's own screen and are never typed into a computer, phone or cloud note. Write them down by hand on the included card or a similar physical medium.
Next, set a PIN for the device itself; this protects against unauthorised physical use but does not replace the seed phrase as a backup. Some devices offer an optional passphrase (an extra 'twenty-fifth word') that creates a hidden wallet; this is an advanced feature that adds protection but also increases the risk of losing access yourself if you forget the passphrase.
After installation, test the recovery procedure with a small amount: send a small quantity of crypto to the device, restore the wallet using the written-down seed phrase on a second (freshly configured) device or in simulation mode, and confirm the balance matches. This confirms the backup works before you move larger amounts.
Verifying transactions on the device's own screen
A common attack technique involves malware that replaces the receiving address on your computer with an attacker's address while the rest of the screen looks normal. The defence against this lies in the hardware wallet's own small screen: check the full address and amount on that screen for every transaction, not just on your computer or phone.
Take the time to compare the address letter by letter, or at least the first and last characters, against the source you obtained it from. If in doubt, it is better to cancel the transaction and re-verify the source than to force an approval.
Multiple devices and multisig
For larger amounts, some users consider a multisig setup, where multiple hardware wallets are required to approve a transaction. This prevents the loss or compromise of a single device from granting access to all funds, but requires more technical knowledge and careful backup planning.
A simpler alternative is a second hardware wallet kept as a backup, with its own separately stored seed phrase copy at a different physical location. This protects against loss from fire, theft or a defective device without the complexity of multisig.
Frequently asked questions
Do I need a hardware wallet for small amounts?
For small amounts used actively, storage on a regulated platform is often practical enough. As the amount grows or the holding period lengthens, the benefit of a hardware wallet increases.
Can a hardware wallet be hacked remotely?
Because the private key never leaves the device and is not directly connected to the internet, a remote attack on the key itself is very difficult. Risks mainly involve prior physical tampering, compromised firmware, or human error when verifying transactions.
What if I lose my hardware wallet or it breaks?
As long as you have safely stored the seed phrase, you can restore the wallet on a new device. The device itself is replaceable; the seed phrase is the actual key to your funds.
Do I need different hardware wallets for different coins?
Usually not, since most modern hardware wallets support multiple networks and coins through a single device and seed phrase. Check in advance whether your specific coins are supported.
Is it safe to buy a second-hand hardware wallet?
This is not recommended. A second-hand device may have been tampered with, for example preloaded with a known seed phrase, making a new device from an official seller the safer choice.
Read next
Holding your own crypto
How to set up a self-custody wallet, store a seed phrase safely and decide when a hardware wallet is worth it. Practical guide, not advice.
Storing your seed phrase safely
How to store and back up a seed phrase without exposing it to hacks, loss or theft. Practical methods and common mistakes explained.
Recognising phishing and wallet drainers
How to recognise phishing sites, fake messages and wallet drainers targeting crypto users. Practical warning signs and protective steps.
Spot crypto scams before you pay
From guaranteed returns to fake platforms: the recurring patterns behind crypto fraud and the checks you can run in two minutes.