A hardware wallet keeps your private key on a small dedicated device that never hands it to your computer. Transactions are signed inside the device and only the signature comes out, so malware on your laptop can ask for a signature but cannot steal the key.

That is the theory. In practice, almost every hardware wallet failure happens during setup or purchase rather than during use — which is good news, because those are the two parts you fully control.

Before you buy: the part most guides skip

Buy directly from the manufacturer, or from a reseller the manufacturer lists on its own site. Not a marketplace listing, not an auction site, not second-hand, not a gift from someone you met online.

The attack is simple. A device is pre-initialised with a seed the attacker already knows, resealed, and sold cheaply. You fund it and they empty it whenever they choose — possibly months later. A variant ships a card in the box with a “recovery phrase” already printed on it, sometimes with instructions to use those words to “activate” the device.

The rule that defeats all of it: a genuine hardware wallet never arrives with a seed phrase. Not on a card, not in a leaflet, not in an email. The device generates the phrase itself, in front of you, the first time you set it up. Any phrase that reaches you any other way belongs to somebody else.

Tamper-evident seals are worth checking but not worth trusting on their own — holograms and shrink wrap are cheap to reproduce. The reliable check is the initialisation step below.

The setup, in order

  1. Get the companion app from the manufacturer’s own domain, typed into the address bar rather than clicked from a search result. Paid ads above real search results are a standing distribution channel for fake wallet software.
  2. Let the app check the device is genuine and update the firmware before anything else. This is the step that catches a tampered or counterfeit unit.
  3. Choose “create new wallet”, never “restore”. Restore is for a phrase you generated yourself in the past.
  4. Write down the words the device screen shows you, in order, on the supplied card or on metal. Not on your phone, not in a password manager, not photographed. The screen on the device is the only display in the process that malware cannot rewrite.
  5. Set a PIN you will remember. The PIN protects against someone physically holding the device; it has nothing to do with the phrase.
  6. Complete the on-device confirmation where it asks you to re-enter selected words. This catches transcription errors while they are still fixable.

Verify the backup before you fund it

An unverified backup is not a backup. The phrase is the only thing standing between you and total loss if the device is destroyed, and people routinely discover a mis-copied word at the exact moment it cannot be corrected.

Two ways to prove it, in increasing order of confidence: use the vendor’s built-in recovery-check feature if the device has one, or wipe the freshly-created device and restore it from the phrase alone. The second is the real test, and it costs nothing before there are funds on it.

Then move a small amount first. Confirm it arrives, confirm you can send a little of it back out, and only then transfer the rest. Our guide to storing a seed phrase covers where the written copy should live afterwards.

What the device does not protect you from

A hardware wallet secures the key. It does not secure your judgement, and the distinction matters:

  • Anything you approve. If you sign a malicious token approval, the device signs it faithfully. This is how most well-secured wallets are still emptied.
  • Address substitution. Malware can swap the destination address in your browser. Always read the recipient on the device screen, not the one on your monitor.
  • Losing the phrase. The device is replaceable. The phrase is not.
  • Being talked into it. No support agent, migration tool, airdrop checker or “wallet validator” ever needs your phrase — see our guide to spotting a crypto scam.

Habits that keep it working

Update firmware through the official app rather than a link. Verify addresses on the device screen every time, including the first and last characters and a few in the middle. Keep a wallet that only ever holds long-term funds and never connects to applications, separate from whatever you use day to day. And re-read the recipient before you press confirm — that button is the last reversible moment in the whole process.

Nothing here is financial advice. Self-custody losses are permanent — see our risk disclaimer.