Skip to main content
Independent guide: not affiliated with or endorsed by SatoshiLabs or the Trezor brand. This site never asks for your recovery seed — no legitimate site or support agent ever will. Always confirm you are on the real trezor.io domain before you type anything.
Trézor.io/StartSetup guide Start setup
Menu
Protection

Hardware wallet security: the seed, the PIN and the phishing page

Coins are not stolen from hardware wallets by breaking the chip. They are stolen from photographs, cloud notes, copied addresses and friendly strangers who offer to help. This page is the version of the safety advice that accounts for how people actually lose money.

One sentence covers most of this page

Anyone who learns your recovery seed can take your coins, from anywhere, without your device, at any time, and nothing you do afterwards will stop them. Treat those words as the money itself.

What the recovery seed is

When a wallet is created, the device generates a random sequence and turns it into a list of ordinary words — usually twelve, sometimes twenty or twenty-four depending on the model and the backup format you choose. Those words are a mathematical stand-in for every private key in the wallet. Enter them into any compatible device and you are back in control of the funds; that is the entire point, and also the entire risk.

The device is therefore not the thing you are protecting. The device is a convenient, tamper-resistant way to use keys that live on paper. Lose the device and you restore from the seed and carry on. Lose the seed and the device becomes a paperweight the moment it fails, wipes itself or gets lost.

A red padlock resting on a black computer keyboard
The seed is the master key: everything the wallet protects is downstream of one list of words.

Four facts worth knowing before you store it

  • The order matters. Words out of sequence restore a different, empty wallet — or nothing at all. Copy them in order, numbered.
  • Spelling and language matter. Word lists exist per language, and a mistyped word is a wrong word.
  • It is not tied to the brand. The words follow an open standard, so a compatible device from another maker can restore the same wallet. Your backup is not locked to one company staying in business.
  • It cannot be changed. There is no “reset the seed” button that keeps the funds: a new seed means a new wallet and moving coins deliberately.

Storing it safely, in practice

Do

  • Write it by hand on the card from the box, in order, legibly, and read it back once.
  • Keep two copies in two places if your risk includes fire, flood or moving house.
  • Consider stamped metal for the copy you want to survive a house fire, especially above a balance you would grieve.
  • Store it where nobody casually encounters it — not on a desk, not in a labelled envelope.
  • Tell exactly one person only if you have a real need for inheritance, and explain the method rather than the words.

Never

  • Photograph it. Cameras sync, back up and classify images automatically.
  • Type it into any app or website — notes, password managers, email drafts, spreadsheets, “seed checkers”.
  • Store it in the cloud, encrypted or not. You are one password reset away from losing everything, and one breach away from someone else finding it.
  • Split cleverly and forget the rule. Invented schemes (“every third word is fake”) fail years later, when memory is the only record.
  • Let anyone else write it down or read the screen while it is displayed.

PIN, passphrase and what each one really protects

The PIN protects the device

  • Four to nine digits, entered on the device itself — never in the computer's keyboard.
  • It stops someone who has the physical device from using it. It does not encrypt your funds, and it is useless to a thief who also has your seed.
  • Repeated wrong entries cause the device to wipe itself. That protects you against guessing, and it is exactly why the seed backup comes first in the setup order.
  • Forgetting the PIN is a minor event: restore the seed on the same or a replacement device and set a new one.

The passphrase protects the seed

  • An optional extra word or phrase that gets mixed into the seed to derive a separate wallet. Same device, same seed, different wallet — often called a hidden wallet.
  • Its real value: someone who finds your written seed still cannot reach the passphrase-protected wallet without the passphrase.
  • Its real cost: the passphrase is not stored on the device and is not recoverable. Forget it, or type it with one character off, and that wallet is gone forever. Nobody — including support, including a forensic lab — can restore it.
  • Every character counts, including case, spacing and punctuation. Type it the same way every time, and back it up as carefully as the seed itself, on a different medium if you can.
  • Practical advice: do not enable one the day you set up your first wallet. Get comfortable with the basics first, then add it deliberately, with a written record you can follow at 2 a.m.
A passphrase is not a password you can reset

Password managers reset passwords. Passphrases derive wallets. There is no “forgot passphrase” route, no support ticket that fixes it, and no way to brute-force a long one. If that sentence makes you uneasy, the answer is not to avoid passphrases forever — it is to write yours down as carefully as the seed and store it separately.

Phishing, fake pages and “helpful” strangers

This is where almost all real losses begin, and it rarely looks like a scam at the time. The pattern is always the same: something asks for your seed words, or the site you are on is not the site you think you are on.

  • Seed-entry forms. No legitimate wallet, app, exchange or support tool ever asks for your recovery words. A page with a neat twelve-word box is a harvesting form.
  • “Validate”, “synchronise”, “migrate” or “unlock” your wallet. Invented processes designed to sound like technical necessities. Real wallets do not need any of them.
  • Support that contacts you first. Real support never opens a conversation, never asks you to share your screen, never installs remote-control software, and never needs your seed. Treat every inbound message about your wallet as hostile.
  • Prize, airdrop and giveaway pages. Connect-your-wallet pages that drain funds, or claim forms that ask for seed words to “verify ownership”.
  • Lookalike addresses in ads and search results. A paid placement above the real site, or a domain differing by one character. The design can be identical; the domain is the only evidence.
  • Fake mobile apps and fake updaters. Store search results include paid placements too. Check the developer name, review count and listing history before installing.
  • Clipboard and address-swapping malware. Less about seeds, more about destinations: it silently replaces an address you copy. This is why every receive address and every send destination is confirmed on the device screen.
  • Physical “help”. Someone offering to set the device up for you, or to “check” your written words, is asking to own your money.
Test your own scepticism in one question

Is anything asking me for words that would let someone else restore my wallet? If yes, it is theft, regardless of who is asking, how official the page looks, or how urgent the reason is.

Physical security and the supply chain

  • Buy from the official store or a listed reseller. Marketplace resale is where devices with a pre-existing wallet appear. The discount is never worth it.
  • Inspect the packaging before you trust the device. A resealed box, a damaged seal or a device that looks used is a reason to exchange it, not to test it.
  • A device with a wallet already on it is not yours. No PIN of your own, a pre-written seed card, or a wallet that already has history means someone else holds the keys.
  • Keep the device somewhere sensible. It is worthless to a thief without the PIN, but losing it is still a wipe-and-restore event you would rather avoid at an airport.
  • Beware “second-hand device with funds included”. This is a scam in both directions: the seller keeps the seed, or the seed is long compromised.
  • Do not store the seed with the device. Keeping the backup in the same bag as the hardware removes the entire benefit of having a backup.

If your seed has leaked

Perhaps you photographed it once and deleted the photo. Perhaps you typed it into a page that felt official. Perhaps you are not sure at all. The response is the same, and it is urgent but not complicated.

  1. Assume the wallet is compromised. Do not argue with yourself about whether anyone actually saw it. Deleted files, synced photos and uploaded words are all recoverable by someone else.
  2. Create a brand-new wallet on your device — a fresh seed, with the device generating new keys. Never “reset” the old one and keep using the same words.
  3. Write the new seed down properly, offline, by hand, and check it once. That single step is the whole recovery plan.
  4. Move the funds, smallest first. Send a small test amount to the new wallet, confirm it arrives, then move the rest. If a drainer is already watching, speed matters more than fee optimisation.
  5. Stop using the old seed and the old accounts. Bookmark nothing. If you used a passphrase-held wallet derived from the same seed, migrate that too.
  6. Check what else shared that seed. A wallet restored to a second device, an old mobile app, a screenshot in a shared folder — all of it needs retiring.
Do not “watch and wait”

Seed compromise rarely announces itself. The first sign is often an empty wallet, and by then nothing can be reversed. Migrating voluntarily costs a transaction fee; hesitating costs everything in the wallet.

The checklist worth keeping

  • Seed written by hand, in order, stored offline, with a second copy or a metal backup.
  • No photograph, no cloud note, no password manager entry, no email draft containing it.
  • A PIN you use nowhere else, entered on the device, with the seed as the recovery route.
  • Every receive address and every send verified on the device screen before it is used.
  • The official site bookmarked, and no wallet bookmark that arrived from a link.
  • Firmware updated when a signed release is offered, from inside the official app.
  • A test send done before any large transfer, every time you change devices or addresses.
  • Nobody else has ever seen the words, and nobody who contacts you first will.

Set it up once, set it up safely

The walkthrough puts this advice in order, at the moment in the setup flow where each decision actually happens.

Open the setup walkthrough