PickACrypto

How to Set Up a Hardware Wallet

By the PickACrypto Team · Updated Jul 19, 2026

A hardware wallet is a small dedicated device that keeps your keys off the internet permanently. Transactions get signed inside the device, so the keys never touch your computer, and even a thoroughly compromised laptop can't steal what it never sees. It's the standard answer for holdings you'd mind losing, it's the standard we push throughout this site's custody writing, and the setup is a calm evening's work. The security it buys comes from a handful of specific practices rather than from the gadget itself. A hardware wallet used carelessly is expensive theatre. Here's the careful version.

Step 1: Buy the device new, from the maker

Two rules, both absolute. Buy direct from the manufacturer (Ledger, Trezor, and a few other long-established names) or a listed authorised reseller, and never second-hand or from marketplace sellers, where pre-tampered devices with pre-known seed phrases are a documented scam. When it arrives, be suspicious of anything pre-configured. A real device never ships with a seed phrase already set, and any included card with words printed on it means the funds you load will be someone else's the moment they arrive. A tampered-looking box, or a "replacement device" arriving unrequested after a data breach: same verdict. Don't use it; contact the maker.

Step 2: Initialise on the device, and let it generate the phrase

Install the official companion app (sourced with the same paranoia as any software wallet download: official site, typed URL), connect the device, and choose "set up as new". Set the PIN on the device itself, and let the device generate a fresh seed phrase, shown only on its own screen. Never import an existing hot-wallet phrase into a hardware device "to upgrade it". A phrase that has ever lived on an internet-connected machine stays hot forever, whatever hardware it later touches. Write the words by hand as the device shows them. That tiny screen is the whole point: the phrase exists nowhere a computer can read.

Step 3: Back up the phrase to the standard the money deserves

Everything in our seed phrase guide applies at full strength, with one addition: if the holdings justified buying hardware, they justify a steel backup and a recovery test. Wipe the device (or use its check feature) and restore from your written words before serious funds arrive. You want proof the backup works while proving it costs nothing. Remember the device is replaceable; the phrase is not. A lost or dead device plus an intact phrase equals a mild errand. The reverse equals a total loss.

Step 4: Do the first transfer as a drill

Receive a small test amount first: generate the address in the companion app, verify it on the device's screen (malware on the computer can swap displayed addresses; the device screen is the truth), send, confirm arrival. Then send a small amount out, to an exchange or your hot wallet, so you've exercised the full loop: transaction built on the computer, details verified and approved on the device. Only then move the real holdings across, and for large sums there's no shame in two tranches. Every mechanic you'll ever need was just rehearsed at stakes that don't matter.

Step 5: Run it with cold-storage habits

The device can now mostly live in a drawer. It's needed only to move funds out; deposits arrive whether it's connected or not, and you can watch balances anytime via the app or on-chain like any address. The habits that preserve the security you just built: verify addresses on-device for every meaningful send; keep using a hot wallet for daily DeFi traffic so the cold keys sign rarely (connecting hardware through a hot interface for occasional dapp use is fine, since the point is the keys stay in the device, but sign nothing you haven't read); apply firmware updates from the official app when prompted; and file the phrase-request rule under permanent. Device makers get breached and their customer lists leak, which is why hardware owners are prime phishing targets. The device defends your keys; the habits defend the device. Both together are what "cold storage" actually means.

Frequently asked questions

Do I really need a hardware wallet?

Once losing your holdings would hurt, yes. The device removes your computer's entire malware and phishing surface from the equation for a modest one-off cost. Below that threshold, a well-run software wallet is fine, and the seed-phrase discipline matters more than the hardware either way.

What happens if my hardware wallet breaks or is lost?

Nothing happens to your funds: they live on the blockchain, not in the device. Buy a replacement (or restore into a compatible wallet), enter your seed phrase, and everything reappears. This is exactly why the phrase backup, not the device, is the thing to guard.

Can a hardware wallet be hacked?

Remote compromise of the keys is what the design prevents, and it has held up well across the major vendors. Real-world losses come from elsewhere: phishing the owner's seed phrase, tampered second-hand devices, and signing malicious transactions on-device without reading them.