How to Choose a Hardware Wallet (And Set It Up Properly)
Every hardware wallet keeps your keys offline β that part is solved. What differs is the security model, the coins supported, and how easy it is to make an expensive mistake. Here is how to choose and set one up.
Key takeaways
- Every hardware wallet already solves the core job β keys offline; the differences are security model, coin support and ease of mistakes.
- Look for a secure element, open-source firmware, support for the coins you hold, and clear recovery.
- Buy sealed, directly from the manufacturer β never used or from a third-party marketplace.
- Generate your own seed on first boot, back it up on metal, and test recovery before funding it.
A hardware wallet solves exactly one problem, and it solves it well: your private key is generated on a device that never connects to the internet, and it never leaves that device. Transactions are sent in, signed inside the chip, and sent back out signed. Malware on your laptop can see what you are doing but cannot extract the key. Everything else β screens, apps, coin lists, price charts β is packaging around that single guarantee.
What actually differs between devices
- β’Secure element vs open source. A certified secure element resists physical extraction if the device is stolen, but its firmware is usually closed. Fully open-source devices are auditable but often rely on a general-purpose chip. This is a genuine trade-off between two different threat models, not a question with one right answer.
- β’Coin support. Bitcoin-only devices exist and are deliberately simpler β less code, smaller attack surface. Multi-chain devices cover thousands of assets but pull in far more software. Check your specific coins before buying, not the headline number.
- β’Connectivity. USB-only is the most conservative. Bluetooth and NFC are convenient for mobile use and add a wireless surface; the signing still happens on-device, so the risk is smaller than it sounds but not zero. Fully air-gapped devices (QR or microSD) never physically connect at all.
- β’Screen quality. Underrated. The screen is where you verify the address and amount you are actually signing. A tiny display that forces you to scroll through an address is a display you will eventually stop reading β which is precisely how address-swapping malware wins.
- β’Passphrase and multisig support. A passphrase (sometimes called a 25th word) creates a separate hidden wallet from the same seed. Multisig requires several devices to approve a spend. Both are strong; both add ways to lock yourself out.
How much wallet do you need?
Scale the setup to the balance, because complexity has a failure rate of its own.
- β’Under a few thousand: any reputable device, single seed phrase, two metal backups. Do not over-engineer.
- β’Meaningful savings: same, plus a passphrase you can genuinely remember or store separately from the seed β and test recovery before funding.
- β’Life-changing sums: 2-of-3 multisig across devices from different manufacturers, keys in different locations. This removes single points of failure but demands a written recovery plan someone else could follow.
Complexity you do not fully understand is a loss waiting to happen. More people lose crypto to their own clever setup than to attackers. If you cannot explain your recovery process out loud, simplify it.
Buying without getting scammed
- β’Buy direct from the manufacturer's own site, or an official reseller listed there. Never a marketplace listing, never secondhand, never an eBay bargain.
- β’A new device must generate a fresh seed phrase in front of you. If it arrives with a printed phrase, a scratch card or a pre-filled card 'for your convenience', it is a scam device. Do not use it, whatever the packaging says.
- β’Firmware-check on first connect using the official app. Genuine devices verify against the manufacturer's key.
- β’Manufacturer databases have leaked customer names and addresses before, and buyers received convincing phishing letters and fake replacement devices by post. Physical mail about your wallet is not automatically legitimate.
First-time setup, step by step
- β’Set it up yourself, offline, with nobody watching and no camera in the room.
- β’Let the device generate the seed. Never accept one supplied by anything or anyone else.
- β’Write the words by hand, in order, on the supplied card β then transfer them to metal. Never photograph, never type into a phone, never store in a password manager or cloud note.
- β’Set a device PIN. This protects against physical theft, not against seed-phrase exposure.
- β’Wipe the device and restore from your written phrase before you fund it. This is the step everyone skips and the one that catches transcription errors while they are still free to fix.
- β’Send a small test transaction, confirm it arrives, then move the rest.
- β’Store two backups in separate physical locations. One backup in one house is one fire away from zero.
Using it safely afterwards
The device protects the key; it cannot protect your judgement. Verify the receiving address on the device's own screen, not the computer's β clipboard-swapping malware exists specifically to exploit the gap between the two. Read what you are signing: a request for an unlimited token allowance looks almost identical to a simple transfer in most interfaces. Revoke old approvals periodically. And keep the wallet you use for experimental DeFi separate from the one holding your long-term stack, so a bad signature cannot cost you everything.
Firmware updates matter β they patch real vulnerabilities β but do them from the official app, with your seed phrase backed up and verified first, and never in a hurry because a message told you to.
Is it worth it?
A hardware wallet costs a fixed amount, roughly the price of a nice dinner. The risk it removes scales with your balance. That maths tips over quickly: somewhere around a few thousand dollars, the device is unambiguously cheaper than the exposure. Below that, an honest hot-wallet setup with a properly stored seed phrase is defensible. Above it, the question is not whether to buy one but why you have not yet.
Where to store it safely
Keep your keys off the internet with a hardware wallet
Get a Ledger βPartner links β we may earn a commission at no extra cost to you. See our affiliate disclosure.
Frequently asked questions
- Ledger or Trezor β which is better?
- They optimise for different things. Ledger uses a certified secure element with closed firmware; Trezor is fully open source on a general-purpose chip. Choose secure element if physical theft is your main worry, open source if verifiability matters more to you. Both are far safer than leaving coins on an exchange.
- Can a hardware wallet be hacked remotely?
- Extracting the key remotely is what the design prevents β signing happens inside the device. The realistic remote attack is tricking you into approving a malicious transaction, which is why verifying on the device's own screen matters.
- What if the manufacturer goes out of business?
- Your funds are unaffected. Seed phrases follow open standards (BIP-39), so you can restore onto a device from any other manufacturer, or into a software wallet in an emergency.
- Do I need one hardware wallet per coin?
- No. One device holds keys for every chain it supports, all derived from a single seed phrase. Check that your specific coins are supported before buying.
- Should I use a passphrase?
- Only if you have a reliable way to store or remember it. A passphrase creates a hidden wallet and protects against seed-phrase discovery, but forgetting it loses the funds permanently β the phrase alone will not recover them.
- Is it safe to buy a used hardware wallet?
- No. A used or pre-seeded device may have a seed the seller already knows, letting them drain it the moment you fund it. Buy new, direct from the manufacturer.
Related tools
Self-custody means you are the bank β and the whole job is not losing or leaking your keys. A start-to-finish path through choosing a wallet, protecting the seed phrase, and avoiding the ways people actually lose crypto.