Skip to content
ESEN

Hardware wallets (cold wallets)

Last reviewed: August 2026

In one line

It's a device the size of a USB stick or a card that holds your key and signs transactions inside itself, so the key never passes through your computer. They're also called cold wallets because the key never touches a device that's connected to the internet. It's the best security purchase in crypto, and even so, if you're just starting out, you probably don't need one yet.

First things first: what a wallet holds

Your coins live on the blockchain, not inside the app. What your wallet holds is the private key that authorizes moving them, and that key comes from your seed phrase: the 12 or 24 words the app showed you the day you created it.

So the useful question isn't where is my crypto — it's always in the same place — it's who can touch my key. This whole page is about that and nothing else. The long version, with addresses and examples, is in Wallets.

The key touches the internetThe key never leaves
Software wallet

The key sits on your computer or phone, which are connected. Malware that reaches them can read it.

Hardware wallet

The key sits inside the device's chip. Your computer only receives the already-signed transaction.

So, do I need one?

A hardware wallet solves one very specific problem: your computer or your phone being compromised. In a normal app, the key sits on a machine that browses, downloads things and receives messages. In a hardware wallet, the key lives on a separate chip that does nothing else.

You want one if…
  • Losing what you hold in crypto would genuinely hurt
  • You're going to leave it sitting for months or years
  • You sign on sites you hadn't used before (it won't stop you signing something bad, but it shows it to you on a screen malware doesn't control)
  • Someone else uses the computer where your wallet is
Not yet, if…
  • You hold about the price of a dinner and you're learning
  • It's all on an exchange — there the device changes nothing, because the key isn't yours and there's nothing for it to protect: Binance vs Uniswap
  • You only buy and never interact with dApps (applications that run on a blockchain: a decentralized exchange, a game, a loan)
  • Your only use is receiving a payment now and then

The short rule, if you'd rather have a number

How much you hold is the best shortcut for deciding: there's a table by amount in Wallets. If you're in the lowest band of that table, a well-backed-up software wallet is a perfectly reasonable decision, not an embarrassing shortcut.

And something almost nobody says: buying it is the easy part. What decides whether it helps you is writing the seed phrase down properly and keeping it somewhere else. If you're only going to do one of the two, do that one: Backing up your seed phrase.

How it works

The private key never leaves the device. When you sign something:

  1. The unsigned transaction goes into the device
  2. The device signs it inside, with the key it never exposes
  3. Only the signature comes out, and it's useless for stealing anything else

That's why, even if your computer is infected, the attacker can't copy your key: it isn't there.

The device's screen is half the invention

A compromised computer can show you one address on the monitor and send a different one. The device's little screen isn't controlled by malware: what you read there is exactly what you're about to sign. That's why you always verify on the device, not on the monitor.

(Ledger sells a separate service that can extract a backup of the key; it ships switched off, you have to subscribe, and it's explained further down.)

Which models exist today

The two most used brands are Ledger and Trezor. All of their current models have a secure element — a separate chip built to resist someone opening it up and reading the key out. What changes between them is the screen, the connectivity and the price.

ModelPrice tierWhat sets it apart
Trezor Safe 3Trezor's cheapestTwo buttons, monochrome screen, cable only
Trezor Safe 5midColor touchscreen that vibrates when you tap it
Trezor Safe 7Trezor's topBluetooth, wireless charging, and an extra secure element (TROPIC01) on top of the one it already had
Ledger Nano S Pluscheapest of allButtons, small screen, cable only
Ledger Nano XmidButtons, with Bluetooth
Ledger Nano Gen5midE Ink touchscreen, Bluetooth and NFC
Ledger Flexmid-highLike the Gen5, with a higher-contrast screen and better finish
Ledger StaxLedger's topCurved touchscreen, wireless charging

Two notes on this table

The Nano S Plus and the Nano X are still on sale, but Ledger now presents them as a backup device rather than your main one. If you're buying only one, keep that in mind.

And watch out for the name Safe: here it's a Trezor model. In multisig you'll meet Safe on its own, which is something else entirely — a contract for multi-signature wallets.

Models rotate; old guides don't

The Ledger Nano Gen5 and the Trezor Safe 7 were announced in late 2025, so they don't appear in most of the comparisons you'll run into. And the other way around: the Trezor Model One and Model T, still recommended across half the internet, are discontinued. Prices change even faster: check them on the official site.

There are other serious brands — BitBox, Coldcard (Bitcoin only), Keystone (signs by scanning QR codes, no cable or Bluetooth). We don't cover them here, but if they catch your eye, the buying rules below apply just the same.

Ledger or Trezor

AspectLedgerTrezor
FirmwareClosedOpen: anyone can review it
Secure elementClosedClosed, except the Safe 7's TROPIC01
BluetoothNano X, Nano Gen5, Flex, StaxSafe 7
TouchscreenNano Gen5, Flex, StaxSafe 5 and Safe 7
Backup split into several sharesNoYes, across the Safe line
Backup held by custodiansLedger Recover, optional and paidOffers nothing like it

Three things people usually ask about Ledger, without the drama:

They've had at least two customer-data leaks — in 2020, and in January 2026 through Global-e, the provider that processes their store's shipping. Neither involved private keys or PINs: what leaked were names, emails, phone numbers and shipping addresses. The practical consequence for you is that you may get very well-targeted phishing, by email, by phone and even by physical mail. Their having your number is also the door to a SIM swap. Neither company will ever ask you for your words — see Spotting scams.

Ledger Recover is an optional paid service that stores an encrypted backup of your seed phrase split across three custodians (one of them is Ledger) and returns it to you after verifying your identity. It's useful for someone terrified of losing the paper, and it's the exact opposite of what someone wants if they bought the device so the key would never leave it. It's opt-in: if you don't want that, you don't subscribe.

The Ledger Recovery Key is a different thing, and it's worth not confusing them: it's a PIN-protected chip card where you store your 24 words instead of on paper. It isn't "the seed gone digital" in the sense that worries you: it isn't a file, it doesn't sync, and it doesn't live on a device that also browses. It's one more physical backup, with the same two questions as always — what if you lose it, what if it breaks. If it gives you confidence, use it in addition to paper or metal, never instead of.

Recommendation

Both brands are serious, and either one is an enormous step up from keeping everything in an app. If open source or a backup split into several shares matters to you, Trezor. If support for a huge number of networks and the mobile app matter, Ledger.

Buying one without getting a tampered device

Buy it from the manufacturer's official site

ledger.com · trezor.io

Don't buy it on Amazon, eBay, MercadoLibre or secondhand. Tampered devices have shown up preloaded with a seed phrase the seller already chose: you use it normally for weeks and one day you're drained. The price difference never makes up for that.

When it arrives, there are two signals, and the second matters more than the first.

A new device never comes with words already written inside. If the box includes "your 24 words" pre-printed, or a card telling you to use them, it's a scam: the device generates those words in front of you, the first time you turn it on.

But the attack that actually worked didn't include any: they're counterfeit units that arrive by mail dressed up as a replacement. So the useful rule is shorter than it looks: your words only ever go into a device you bought yourself. What that scam looks like, and why it finds you: The hardware wallet you didn't order.

Setting it up

  1. Install the official app and let it verify the device
    Ledger Live or Trezor Suite check the device is genuine before anything else
  2. Turn it on and choose a PIN
    this is what protects the device if it's physically stolen — on a Ledger, three wrong PINs wipe it, so the paper matters from day one
  3. The device generates your seed phrase and shows it to you
    on its screen, not on the computer
  4. Write it down by hand, on paper or metal
    never a photo, never a file. Metal is what survives a fire
  5. The device asks you to confirm some of the words
    this checks that you copied it correctly
  6. Store the backup away from the device
    if they're in the same drawer, a single theft takes both
  7. Send a small amount first
    receive it, move it, and only then send the rest

That last step is the one almost everyone skips and the one that buys the most peace of mind.

Start on paper — it's free and you can do it today. If what you're holding is going to sit there for years, move it later to a metal plate: paper in a drawer doesn't survive a fire, and that's how most people lose the backup.

And reach the program by typing the address by hand: there are counterfeit builds of Ledger Live and Trezor Suite buying ads to rank above the real site.

Day to day

  1. You connect the device
  2. You open the app
    Ledger Live, Trezor Suite, or your usual wallet
  3. You build the transaction on the computer
  4. The device shows the details on its screen
    Send 0.5 ETH · To: 0x71C7…976F
  5. You compare and confirm on the device
    this is the step that makes everything before it matter
  6. The device signs and the transaction goes out

What a hardware wallet doesn't do

Worth knowing before you buy one, so you don't get overconfident:

It doesn't protect you from…What does protect you
Signing a malicious transaction yourselfReading what you're signing: Before you sign
Typing your words into a fake websiteNever typing them anywhere: Scams
Sending to the wrong address or networkChecking, and doing a small test first: Common mistakes
Losing the paper with your seed phraseTwo copies in two places: Seed phrase

The device protects the key. The decisions are still yours.

If you lose it or it breaks

This is the part that scares people for no reason, so plainly: the device is not your money. It's a lock. Your seed phrase is the key, and with it you restore the same wallet on any device that supports the BIP39 standard, which is nearly all of them — even a different brand.

What happenedWhat you do
You lost it, but you have the seed phraseBuy another and restore. You lost nothing.
It broke or got wetSame: restore on a new one.
It was stolenThey have to guess your PIN, and after several failed attempts the device wipes itself. Even so, restore your wallet on another device and move the funds to a new wallet.
You forgot the PINReset it and restore with the seed phrase.
You lost the device and the seed phraseThis one is irreversible. It's the only case worth preventing.

Two details when switching brands

A backup split into several shares (Trezor's Multi-share Backup, formerly called Shamir) only restores on a Trezor: Ledger doesn't support that format.

And if you restore on another brand and the balance shows zero, it's almost always that the app is looking at a different address path, not that the money is gone. It's explained, with what to do, in What happens if….

Read that table backwards and you get the one rule you have to follow: the backup on paper or metal is what makes everything else recoverable.

Using it with MetaMask or Rabby

You don't have to change interfaces. You can keep using your usual wallet and let the device handle only the signing:

Rabby or MetaMask the interface you already use
Your hardware wallet this is where signing happens
They combine: you browse and build everything as always, but the key never leaves the device.

In the wallet, look for "connect hardware wallet", pick the brand and follow the instructions. From then on, every signature gets asked for on the device.

When a single device isn't enough anymore

A hardware wallet still has one single point of failure: its seed phrase. If the amount justifies it, the next step is a multisig — several keys on separate devices, of which more than one is needed to move the money. Your hardware wallets are still the ones that sign.

Summary

  • It keeps your key on a separate chip and signs inside: your computer never sees it
  • Always verify on the device's screen, not on the monitor
  • Current models: Trezor Safe 3/5/7 and Ledger Nano S Plus, Nano X, Nano Gen5, Flex and Stax
  • Official site only — and a device you didn't order is an attack, even if it's sealed
  • Losing the device isn't losing the money; losing the device and the backup is
  • If you're starting out with little, it isn't mandatory: backing up your seed phrase is

If you came looking for something else:Someone is going to send me crypto · I want to cash out to local currency · Start from the beginning