Trézor.io/Start® — Starting Up Your Device
Everything that happens between unboxing a hardware wallet and seeing your first confirmed balance: the official app, the firmware install, the recovery seed you write down by hand, and the handful of checks that keep the whole thing yours.
- Roughly 10–20 minutes end to end
- No account, no email, no password
- Your seed words never touch a website
What “Trezor.io/Start” actually is
The address printed on the card inside the box is not a product you buy or an account you create. It is the on-ramp to the official app and the guided first-run flow — and knowing exactly what belongs on that journey is most of your protection.
A hardware wallet arrives empty on purpose. There is no wallet inside the box, no seed phrase printed on a card, no PIN you were given. On first run the device generates its own keys and shows them to you once, as a list of words, for you to copy onto paper. From that moment the device holds the keys and the paper holds the backup — and nobody, including the manufacturer, has ever seen either.
The official start page is simply where that process begins: it points at the app for your operating system (desktop, web or mobile) and hands you to a guided flow that installs firmware, has you choose between creating and recovering a wallet, and walks you through the backup.
This site is an independent explanation of that same journey, written so you can read it before you plug anything in and know what each screen is about to ask you. It is not the official website and it has no connection to the company that makes the device.
Type the address yourself, or use a bookmark you created before you bought the device. Read the domain character by character, and remember that a search result marked “sponsored”, a link in a chat message and a page that appears after an ad are all places where the wrong site waits. A padlock in the address bar means the connection is encrypted — it says nothing at all about who owns the page.
What happens on that first run, in one paragraph
App installed → device connected by cable → firmware installed and verified on the device screen → choice between “create new wallet” and “recover wallet” → a PIN of four to nine digits typed on the device → twelve or more words revealed one at a time, written down and re-checked → an optional passphrase → a first account → a receiving address you verify on the device display. That is the whole ceremony. Everything below goes through it properly.
Before you begin: set yourself up to do it once
Almost every botched setup comes down to a missing cable, a hurried seed backup or a download from the wrong address. Five minutes of preparation removes all three.
Have these ready
- The device and its original cable. Spare cables are often charge-only and will never appear in the app.
- A computer you trust with a free USB port, or a phone if you plan to work from the mobile app.
- The recovery card from the box and a pen. Pencil fades, screenshots leak.
- A quiet ten minutes where nobody is looking over your shoulder or filming a screen.
Do these checks first
- The box seal is intact and the packaging has not been re-taped or re-glued.
- Nothing in the box contains seed words. A card with a prefilled phrase means the seller, not the device, knows your keys.
- You reached the official website yourself and saved it as a bookmark you will reuse.
- You bought from the official store or a listed reseller — marketplace resale is where tampered devices turn up.
The setup journey, stage by stage
Seven stages, in the order the guided flow presents them. Each one links into the detailed walkthrough with the checks, the warnings and the things that go wrong most often.
1 · Check the box and the device
Tamper-evident packaging, cable in the box, and a close look at the device before it is ever powered on.
Stage 1 →2 · Get the official app
Desktop, web or mobile — and the three ways a download page can be a fake without looking like one.
Stage 2 →3 · Connect and install firmware
Direct USB, the current release, and why the device screen is the only confirmation that counts.
Stage 3 →4 · Create a new wallet
Why “create” rather than “recover” on a new device, and what happens if the device already has a wallet.
Stage 4 →5 · Write down the recovery seed
The one step worth slowing down: handwriting, order, no photographs, no cloud notes, no typing.
Stage 5 →6 · PIN, name, first account
A four-to-nine digit PIN on the device, an optional passphrase, and an account that holds the coins you add.
Stage 6 →7 · Receive, verify, test
Verify every address on the device display and send a small test amount before the real one.
Stage 7 →If something sticks
Device not recognised, bootloader mode, a stalled firmware install, a forgotten PIN — the checklist covers it.
Troubleshooting →What the app looks like once you are through setup
Menu names change between app versions, but the structure is stable: one place for balances, one for accounts, one for the device itself.
Accounts and balances
Each coin lives in its own account inside the app: a Bitcoin account, an Ethereum account, and so on. The app shows balances by reading the public blockchain — it never needs your keys to display them.
Group them how you like, and expect small differences in options per account type.
Receive and send
“Receive” produces an address and asks you to confirm it on the device screen before you share it. “Send” builds a transaction on the computer and asks the device to authorise it — that hand-off is the whole point of a hardware wallet.
Fees can be chosen by speed or set manually if you prefer to control them.
Device settings
Firmware version and update checks, the device label, PIN changes, the passphrase setting and the option to wipe and start again. Most of these are confirmed on the device, not in the app.
Privacy and extras
Third-party services for buying, selling and exchanging are optional and separate from the wallet. Advanced options such as coin control and network privacy settings exist for people who want them — none of it is required to hold coins safely.
Five rules that actually protect the coins
Hardware wallets do not fail because the chip is weak. They fail because a seed ended up in a photograph, an address was copied from a clipboard, or a helpful stranger offered to “validate” a wallet.
1. The seed never leaves paper
No photographs, no cloud notes, no password manager, no email draft, no typing it into any website. Offline handwriting, or stamped metal if you want it to survive a house fire.
2. Verify on the device screen
Every address you receive to, and every transaction you send, is confirmed on the device's own display. Malware on the computer can alter what you see on screen but not what the device shows.
3. Test small, then move the rest
Send a small first transaction to a new address or account, confirm it arrives, then send the remainder. It costs a fee and saves a fortune.
4. Keep firmware current
Update when the app offers a signed release, and check the version on the device during the update. Skip downloads from anywhere other than the official address.
5. Distrust anyone who contacts you
Support never messages first. No legitimate service needs your seed words, your screen, or a remote-control session. Anyone who asks for those is attacking you, however friendly the tone.
Longer versions of each rule, plus what to do if a seed has already leaked, are on the security page.
Read the security guideThe five questions that come up first
Short versions here; the full list — cables, passphrases, phones, forgotten PINs — is on the FAQ page.
What is Trezor.io/Start?
It is the official starting point for a new device: the address that leads to the app download and the guided first-run flow. This site is an independent guide that explains the same process, stage by stage, with the safety checks spelled out.
Do I need to create an account first?
No. There is no signup, no email address and no password involved in setting up a hardware wallet. The wallet exists on the device, and the recovery seed is the only backup — which is why the seed deserves more care than any password you have ever created.
Do I ever type my recovery seed into a website?
Never. Seed words are entered on the device itself, or on a replacement device when restoring. A page, chat window or support agent asking you to type them is harvesting your funds — close it.
How long does the whole thing take?
Ten to twenty minutes for most people, including the firmware install. The part worth not rushing is the seed backup: writing twelve or more words by hand and re-reading them takes minutes and prevents the only unrecoverable mistake in the process.
Which models does this guide cover?
Model One, Model T, Safe 3 and Safe 5, plus the desktop, web and mobile apps. Only the on-device controls differ between models — navigating with two buttons versus a touchscreen — so the sequence is the same, and this guide follows it once. The device comparison covers the differences.
Ready to start the walkthrough?
Seven stages with the checks, the warnings and the common failures — from opening the box to confirming your first test transaction.