How to set up a hardware wallet without locking yourself out
A hardware wallet solves one problem well: it keeps your private keys off an internet-connected computer, so malware that empties a browser extension wallet cannot touch it. That is a real improvement and it is why the devices exist.
It also hands you a second problem that the marketing rarely leads with. Once you hold your own keys, there is no support line, no password reset, and no institution that can reverse a mistake. The realistic way to lose money with a hardware wallet is not an attacker. It is a drawer, a house move, and a recovery sheet nobody ever checked.
This guide is about that second problem, because the first one is largely solved by buying the device and following the screen.
The device is not the asset
The single idea worth internalising before you buy anything: the recovery phrase is the wallet. The device is a convenience wrapped around it.
Twelve or twenty-four words are generated when you set the device up. Anyone who has those words has your funds, on any device, forever, without your hardware. Equally, if the device dies in a fire and you have the words, you have lost nothing — buy another one, type them in, and your balance is there.
Everything that follows is a consequence of that one fact. The device is replaceable. The words are not.
Buy it from the manufacturer
Buy directly from the maker’s own site, not a marketplace, not a reseller, not secondhand, and not a “deal”.
The attack is straightforward: someone buys a device, initialises it themselves, writes the pre-generated recovery words onto the card in the box, reseals it, and resells it. The buyer follows the card, funds the wallet, and the seller empties it whenever they like. It has happened often enough that every manufacturer now warns about it.
A genuine device asks you to generate a new recovery phrase during setup. If a device arrives with a recovery phrase already filled in on a card, it is compromised. There is no legitimate reason for that to happen — no exceptions, no matter how official the packaging looks.
Write the words down on something that survives
Write the recovery phrase by hand, on the card in the box or on metal, in the order shown.
Do not photograph it. Do not type it into a password manager, a note app, a document, or an email to yourself. Do not put it in cloud storage. The moment those words exist as a file on an internet-connected device, you have undone the entire reason for buying the hardware — you now have a hot wallet with extra steps.
Paper is adequate for most people and fails in exactly the ways you would expect: fire, flood, and fading. Stamped or engraved metal plates solve those and cost about as much as a cheap device. If the amount you are protecting is more than the cost of a metal backup, buy the metal backup.
Two details that catch people out:
- Word order matters. Number them.
- Handwriting matters. Several words in the standard list look alike in a hurry. Print in capitals. You are writing for a stranger — possibly yourself in ten years, possibly your executor.
Test the recovery before you fund it
This is the step almost everybody skips, and skipping it is the single most common way self-custody actually fails.
You have a recovery phrase. You believe it is correct. You have never checked. If you transcribed a word wrong, or reversed two, you will not discover it at setup — you will discover it on the day the device is already broken or lost, which is precisely the day it cannot be fixed.
So check it while checking is free:
- Set the device up and write the phrase down.
- Send a small, genuinely trivial amount to the wallet.
- Wipe the device — factory reset it. Yes, deliberately.
- Restore it from your written words alone.
- Confirm the small amount is there.
If step 5 works, your backup is real and you can fund the wallet properly. If it does not, you have discovered it at a cost of nothing, which is the entire point.
Doing this once, honestly, is worth more than any amount of reading about custody.
Where a hardware wallet is and is not the right answer
| Option | Best for | Who holds the keys |
|---|---|---|
| Exchange accountnot yours | Buying, selling, and amounts you would shrug off | The exchange |
| Mobile / browser wallet | Spending, small balances, day-to-day use | You, on an online device |
| Hardware wallet | Long-term holdings you do not touch often | You, offline |
| Multi-signature | Large amounts, shared control, inheritance | You plus co-signers |
There is no single correct row. A hardware wallet holding an amount you would not miss is mostly ceremony, and an exchange holding your retirement is a counterparty bet you may not know you are making. Most people end up using two or three of these at once, for different jobs.
The passphrase question
Most devices support an optional extra word — sometimes called a 25th word or a passphrase — which produces an entirely different wallet from the same recovery phrase.
It is genuinely useful, and it is where confident people lose money. The passphrase is not stored on the device or in your recovery phrase. There is no recovery for it. Forget it and the funds are gone as completely as if you had never written the seed down at all.
If you use one, it needs the same treatment as the seed: written down, stored separately, and tested by wiping and restoring. If that sounds like more discipline than you want to maintain for the next decade, skip it. A well-stored 24-word phrase with no passphrase protects you from every threat most people actually face.
Plan for the boring failure
Long holding periods do not fail dramatically. They fail because someone moved house, or because the one person who knew where the metal plate lived was not available when it mattered.
Two questions worth answering now, in writing:
- If your home were gone tomorrow, could you still recover? That means a second copy, somewhere geographically separate.
- If you were not available, could the people who should inherit this actually reach it? Not “would they find the device” — would they know what a recovery phrase is, and where yours is, and what to do with it?
Neither question is technical. Both decide the outcome more often than anything on the device’s screen.
The short version
Buy from the manufacturer. Write the words on something durable, by hand, never digitally. Wipe the device and restore it from your written words before you fund it. Keep a second copy somewhere else. Decide about the passphrase deliberately rather than because it sounded advanced.
Do those, and you have removed nearly every realistic way this goes wrong.