Hardware wallets (cold wallets)
Last reviewed: August 2026
In one line
It's a device the size of a USB stick or a card that holds your key and signs transactions inside itself, so the key never passes through your computer. They're also called cold wallets because the key never touches a device that's connected to the internet. It's the best security purchase in crypto, and even so, if you're just starting out, you probably don't need one yet.
First things first: what a wallet holds
Your coins live on the blockchain, not inside the app. What your wallet holds is the private key that authorizes moving them, and that key comes from your seed phrase: the 12 or 24 words the app showed you the day you created it.
So the useful question isn't where is my crypto — it's always in the same place — it's who can touch my key. This whole page is about that and nothing else. The long version, with addresses and examples, is in Wallets.
The key sits on your computer or phone, which are connected. Malware that reaches them can read it.
The key sits inside the device's chip. Your computer only receives the already-signed transaction.
So, do I need one?
A hardware wallet solves one very specific problem: your computer or your phone being compromised. In a normal app, the key sits on a machine that browses, downloads things and receives messages. In a hardware wallet, the key lives on a separate chip that does nothing else.
- Losing what you hold in crypto would genuinely hurt
- You're going to leave it sitting for months or years
- You sign on sites you hadn't used before (it won't stop you signing something bad, but it shows it to you on a screen malware doesn't control)
- Someone else uses the computer where your wallet is
- You hold about the price of a dinner and you're learning
- It's all on an exchange — there the device changes nothing, because the key isn't yours and there's nothing for it to protect: Binance vs Uniswap
- You only buy and never interact with dApps (applications that run on a blockchain: a decentralized exchange, a game, a loan)
- Your only use is receiving a payment now and then
The short rule, if you'd rather have a number
How much you hold is the best shortcut for deciding: there's a table by amount in Wallets. If you're in the lowest band of that table, a well-backed-up software wallet is a perfectly reasonable decision, not an embarrassing shortcut.
And something almost nobody says: buying it is the easy part. What decides whether it helps you is writing the seed phrase down properly and keeping it somewhere else. If you're only going to do one of the two, do that one: Backing up your seed phrase.
How it works
The private key never leaves the device. When you sign something:
- The unsigned transaction goes into the device
- The device signs it inside, with the key it never exposes
- Only the signature comes out, and it's useless for stealing anything else
That's why, even if your computer is infected, the attacker can't copy your key: it isn't there.
The device's screen is half the invention
A compromised computer can show you one address on the monitor and send a different one. The device's little screen isn't controlled by malware: what you read there is exactly what you're about to sign. That's why you always verify on the device, not on the monitor.
(Ledger sells a separate service that can extract a backup of the key; it ships switched off, you have to subscribe, and it's explained further down.)
Which models exist today
The two most used brands are Ledger and Trezor. All of their current models have a secure element — a separate chip built to resist someone opening it up and reading the key out. What changes between them is the screen, the connectivity and the price.
| Model | Price tier | What sets it apart |
|---|---|---|
| Trezor Safe 3 | Trezor's cheapest | Two buttons, monochrome screen, cable only |
| Trezor Safe 5 | mid | Color touchscreen that vibrates when you tap it |
| Trezor Safe 7 | Trezor's top | Bluetooth, wireless charging, and an extra secure element (TROPIC01) on top of the one it already had |
| Ledger Nano S Plus | cheapest of all | Buttons, small screen, cable only |
| Ledger Nano X | mid | Buttons, with Bluetooth |
| Ledger Nano Gen5 | mid | E Ink touchscreen, Bluetooth and NFC |
| Ledger Flex | mid-high | Like the Gen5, with a higher-contrast screen and better finish |
| Ledger Stax | Ledger's top | Curved touchscreen, wireless charging |
Two notes on this table
The Nano S Plus and the Nano X are still on sale, but Ledger now presents them as a backup device rather than your main one. If you're buying only one, keep that in mind.
And watch out for the name Safe: here it's a Trezor model. In multisig you'll meet Safe on its own, which is something else entirely — a contract for multi-signature wallets.
Models rotate; old guides don't
The Ledger Nano Gen5 and the Trezor Safe 7 were announced in late 2025, so they don't appear in most of the comparisons you'll run into. And the other way around: the Trezor Model One and Model T, still recommended across half the internet, are discontinued. Prices change even faster: check them on the official site.
There are other serious brands — BitBox, Coldcard (Bitcoin only), Keystone (signs by scanning QR codes, no cable or Bluetooth). We don't cover them here, but if they catch your eye, the buying rules below apply just the same.
Ledger or Trezor
| Aspect | Ledger | Trezor |
|---|---|---|
| Firmware | Closed | Open: anyone can review it |
| Secure element | Closed | Closed, except the Safe 7's TROPIC01 |
| Bluetooth | Nano X, Nano Gen5, Flex, Stax | Safe 7 |
| Touchscreen | Nano Gen5, Flex, Stax | Safe 5 and Safe 7 |
| Backup split into several shares | No | Yes, across the Safe line |
| Backup held by custodians | Ledger Recover, optional and paid | Offers nothing like it |
Three things people usually ask about Ledger, without the drama:
They've had at least two customer-data leaks — in 2020, and in January 2026 through Global-e, the provider that processes their store's shipping. Neither involved private keys or PINs: what leaked were names, emails, phone numbers and shipping addresses. The practical consequence for you is that you may get very well-targeted phishing, by email, by phone and even by physical mail. Their having your number is also the door to a SIM swap. Neither company will ever ask you for your words — see Spotting scams.
Ledger Recover is an optional paid service that stores an encrypted backup of your seed phrase split across three custodians (one of them is Ledger) and returns it to you after verifying your identity. It's useful for someone terrified of losing the paper, and it's the exact opposite of what someone wants if they bought the device so the key would never leave it. It's opt-in: if you don't want that, you don't subscribe.
The Ledger Recovery Key is a different thing, and it's worth not confusing them: it's a PIN-protected chip card where you store your 24 words instead of on paper. It isn't "the seed gone digital" in the sense that worries you: it isn't a file, it doesn't sync, and it doesn't live on a device that also browses. It's one more physical backup, with the same two questions as always — what if you lose it, what if it breaks. If it gives you confidence, use it in addition to paper or metal, never instead of.
Recommendation
Both brands are serious, and either one is an enormous step up from keeping everything in an app. If open source or a backup split into several shares matters to you, Trezor. If support for a huge number of networks and the mobile app matter, Ledger.
Buying one without getting a tampered device
Buy it from the manufacturer's official site
Don't buy it on Amazon, eBay, MercadoLibre or secondhand. Tampered devices have shown up preloaded with a seed phrase the seller already chose: you use it normally for weeks and one day you're drained. The price difference never makes up for that.
When it arrives, there are two signals, and the second matters more than the first.
A new device never comes with words already written inside. If the box includes "your 24 words" pre-printed, or a card telling you to use them, it's a scam: the device generates those words in front of you, the first time you turn it on.
But the attack that actually worked didn't include any: they're counterfeit units that arrive by mail dressed up as a replacement. So the useful rule is shorter than it looks: your words only ever go into a device you bought yourself. What that scam looks like, and why it finds you: The hardware wallet you didn't order.
Setting it up
- Install the official app and let it verify the deviceLedger Live or Trezor Suite check the device is genuine before anything else
- Turn it on and choose a PINthis is what protects the device if it's physically stolen — on a Ledger, three wrong PINs wipe it, so the paper matters from day one
- The device generates your seed phrase and shows it to youon its screen, not on the computer
- Write it down by hand, on paper or metalnever a photo, never a file. Metal is what survives a fire
- The device asks you to confirm some of the wordsthis checks that you copied it correctly
- Store the backup away from the deviceif they're in the same drawer, a single theft takes both
- Send a small amount firstreceive it, move it, and only then send the rest
That last step is the one almost everyone skips and the one that buys the most peace of mind.
Start on paper — it's free and you can do it today. If what you're holding is going to sit there for years, move it later to a metal plate: paper in a drawer doesn't survive a fire, and that's how most people lose the backup.
And reach the program by typing the address by hand: there are counterfeit builds of Ledger Live and Trezor Suite buying ads to rank above the real site.
Day to day
- You connect the device
- You open the appLedger Live, Trezor Suite, or your usual wallet
- You build the transaction on the computer
- The device shows the details on its screenSend 0.5 ETH · To: 0x71C7…976F
- You compare and confirm on the devicethis is the step that makes everything before it matter
- The device signs and the transaction goes out
What a hardware wallet doesn't do
Worth knowing before you buy one, so you don't get overconfident:
| It doesn't protect you from… | What does protect you |
|---|---|
| Signing a malicious transaction yourself | Reading what you're signing: Before you sign |
| Typing your words into a fake website | Never typing them anywhere: Scams |
| Sending to the wrong address or network | Checking, and doing a small test first: Common mistakes |
| Losing the paper with your seed phrase | Two copies in two places: Seed phrase |
The device protects the key. The decisions are still yours.
If you lose it or it breaks
This is the part that scares people for no reason, so plainly: the device is not your money. It's a lock. Your seed phrase is the key, and with it you restore the same wallet on any device that supports the BIP39 standard, which is nearly all of them — even a different brand.
| What happened | What you do |
|---|---|
| You lost it, but you have the seed phrase | Buy another and restore. You lost nothing. |
| It broke or got wet | Same: restore on a new one. |
| It was stolen | They have to guess your PIN, and after several failed attempts the device wipes itself. Even so, restore your wallet on another device and move the funds to a new wallet. |
| You forgot the PIN | Reset it and restore with the seed phrase. |
| You lost the device and the seed phrase | This one is irreversible. It's the only case worth preventing. |
Two details when switching brands
A backup split into several shares (Trezor's Multi-share Backup, formerly called Shamir) only restores on a Trezor: Ledger doesn't support that format.
And if you restore on another brand and the balance shows zero, it's almost always that the app is looking at a different address path, not that the money is gone. It's explained, with what to do, in What happens if….
Read that table backwards and you get the one rule you have to follow: the backup on paper or metal is what makes everything else recoverable.
Using it with MetaMask or Rabby
You don't have to change interfaces. You can keep using your usual wallet and let the device handle only the signing:
In the wallet, look for "connect hardware wallet", pick the brand and follow the instructions. From then on, every signature gets asked for on the device.
When a single device isn't enough anymore
A hardware wallet still has one single point of failure: its seed phrase. If the amount justifies it, the next step is a multisig — several keys on separate devices, of which more than one is needed to move the money. Your hardware wallets are still the ones that sign.
Summary
- It keeps your key on a separate chip and signs inside: your computer never sees it
- Always verify on the device's screen, not on the monitor
- Current models: Trezor Safe 3/5/7 and Ledger Nano S Plus, Nano X, Nano Gen5, Flex and Stax
- Official site only — and a device you didn't order is an attack, even if it's sealed
- Losing the device isn't losing the money; losing the device and the backup is
- If you're starting out with little, it isn't mandatory: backing up your seed phrase is
If you came looking for something else:Someone is going to send me crypto · I want to cash out to local currency · Start from the beginning