Skip to main content
Independent guide: not affiliated with or endorsed by SatoshiLabs or the Trezor brand. This site never asks for your recovery seed — no legitimate site or support agent ever will. Always confirm you are on the real trezor.io domain before you type anything.
Trézor.io/StartSetup guide Start setup
Menu
First-run setup · Model One · Model T · Safe 3 · Safe 5

Trézor.io/Start® — Starting Up Your Device

Everything that happens between unboxing a hardware wallet and seeing your first confirmed balance: the official app, the firmware install, the recovery seed you write down by hand, and the handful of checks that keep the whole thing yours.

  • Roughly 10–20 minutes end to end
  • No account, no email, no password
  • Your seed words never touch a website
4 modelsModel One, Model T, Safe 3 and Safe 5 — same sequence, different buttons
12–24 wordsThe recovery seed the device generates for you to write down
0 formsNothing here ever asks for a seed, private key or password
1 test sendThe habit that catches a wrong address while the amount is small
Orientation

What “Trezor.io/Start” actually is

The address printed on the card inside the box is not a product you buy or an account you create. It is the on-ramp to the official app and the guided first-run flow — and knowing exactly what belongs on that journey is most of your protection.

A hardware wallet arrives empty on purpose. There is no wallet inside the box, no seed phrase printed on a card, no PIN you were given. On first run the device generates its own keys and shows them to you once, as a list of words, for you to copy onto paper. From that moment the device holds the keys and the paper holds the backup — and nobody, including the manufacturer, has ever seen either.

The official start page is simply where that process begins: it points at the app for your operating system (desktop, web or mobile) and hands you to a guided flow that installs firmware, has you choose between creating and recovering a wallet, and walks you through the backup.

This site is an independent explanation of that same journey, written so you can read it before you plug anything in and know what each screen is about to ask you. It is not the official website and it has no connection to the company that makes the device.

Reaching the real page is the skill worth practising

Type the address yourself, or use a bookmark you created before you bought the device. Read the domain character by character, and remember that a search result marked “sponsored”, a link in a chat message and a page that appears after an ad are all places where the wrong site waits. A padlock in the address bar means the connection is encrypted — it says nothing at all about who owns the page.

What happens on that first run, in one paragraph

App installed → device connected by cable → firmware installed and verified on the device screen → choice between “create new wallet” and “recover wallet” → a PIN of four to nine digits typed on the device → twelve or more words revealed one at a time, written down and re-checked → an optional passphrase → a first account → a receiving address you verify on the device display. That is the whole ceremony. Everything below goes through it properly.

Preparation

Before you begin: set yourself up to do it once

Almost every botched setup comes down to a missing cable, a hurried seed backup or a download from the wrong address. Five minutes of preparation removes all three.

Have these ready

  • The device and its original cable. Spare cables are often charge-only and will never appear in the app.
  • A computer you trust with a free USB port, or a phone if you plan to work from the mobile app.
  • The recovery card from the box and a pen. Pencil fades, screenshots leak.
  • A quiet ten minutes where nobody is looking over your shoulder or filming a screen.

Do these checks first

  • The box seal is intact and the packaging has not been re-taped or re-glued.
  • Nothing in the box contains seed words. A card with a prefilled phrase means the seller, not the device, knows your keys.
  • You reached the official website yourself and saved it as a bookmark you will reuse.
  • You bought from the official store or a listed reseller — marketplace resale is where tampered devices turn up.
A hardware wallet resting beside its plain white packaging on a wooden desk
A genuine box is deliberately plain: a device, a cable, a leaflet and a blank recovery card. Anything pre-filled, pre-sealed or hand-addressed should make you stop.
Orientation

What the app looks like once you are through setup

Menu names change between app versions, but the structure is stable: one place for balances, one for accounts, one for the device itself.

Accounts and balances

Each coin lives in its own account inside the app: a Bitcoin account, an Ethereum account, and so on. The app shows balances by reading the public blockchain — it never needs your keys to display them.

Group them how you like, and expect small differences in options per account type.

Receive and send

“Receive” produces an address and asks you to confirm it on the device screen before you share it. “Send” builds a transaction on the computer and asks the device to authorise it — that hand-off is the whole point of a hardware wallet.

Fees can be chosen by speed or set manually if you prefer to control them.

Device settings

Firmware version and update checks, the device label, PIN changes, the passphrase setting and the option to wipe and start again. Most of these are confirmed on the device, not in the app.

Privacy and extras

Third-party services for buying, selling and exchanging are optional and separate from the wallet. Advanced options such as coin control and network privacy settings exist for people who want them — none of it is required to hold coins safely.

A tablet propped beside a white keyboard on a desk, standing in for the wallet app screen
The desktop app is the most complete way to manage a wallet; the web app runs in a browser and the mobile app is built for viewing balances and light use on the move.
Protection

Five rules that actually protect the coins

Hardware wallets do not fail because the chip is weak. They fail because a seed ended up in a photograph, an address was copied from a clipboard, or a helpful stranger offered to “validate” a wallet.

1. The seed never leaves paper

No photographs, no cloud notes, no password manager, no email draft, no typing it into any website. Offline handwriting, or stamped metal if you want it to survive a house fire.

2. Verify on the device screen

Every address you receive to, and every transaction you send, is confirmed on the device's own display. Malware on the computer can alter what you see on screen but not what the device shows.

3. Test small, then move the rest

Send a small first transaction to a new address or account, confirm it arrives, then send the remainder. It costs a fee and saves a fortune.

4. Keep firmware current

Update when the app offers a signed release, and check the version on the device during the update. Skip downloads from anywhere other than the official address.

5. Distrust anyone who contacts you

Support never messages first. No legitimate service needs your seed words, your screen, or a remote-control session. Anyone who asks for those is attacking you, however friendly the tone.

Longer versions of each rule, plus what to do if a seed has already leaked, are on the security page.

Read the security guide
Quick answers

The five questions that come up first

Short versions here; the full list — cables, passphrases, phones, forgotten PINs — is on the FAQ page.

What is Trezor.io/Start?

It is the official starting point for a new device: the address that leads to the app download and the guided first-run flow. This site is an independent guide that explains the same process, stage by stage, with the safety checks spelled out.

Do I need to create an account first?

No. There is no signup, no email address and no password involved in setting up a hardware wallet. The wallet exists on the device, and the recovery seed is the only backup — which is why the seed deserves more care than any password you have ever created.

Do I ever type my recovery seed into a website?

Never. Seed words are entered on the device itself, or on a replacement device when restoring. A page, chat window or support agent asking you to type them is harvesting your funds — close it.

How long does the whole thing take?

Ten to twenty minutes for most people, including the firmware install. The part worth not rushing is the seed backup: writing twelve or more words by hand and re-reading them takes minutes and prevents the only unrecoverable mistake in the process.

Which models does this guide cover?

Model One, Model T, Safe 3 and Safe 5, plus the desktop, web and mobile apps. Only the on-device controls differ between models — navigating with two buttons versus a touchscreen — so the sequence is the same, and this guide follows it once. The device comparison covers the differences.

Ready to start the walkthrough?

Seven stages with the checks, the warnings and the common failures — from opening the box to confirming your first test transaction.

Open the setup walkthrough