Overview
Hardware wallets store private keys offline. A careful setup prevents key exposure, mitigates supply-chain tampering, and guards against common user errors. Treat the setup as the single most important security moment for your crypto holdings.
Step-by-step setup
- Inspect packaging: Ensure the seal is intact and there is no evidence of prior tampering. If the device looks pre-initialized or the seal is broken, return it.
- Power on & initialize: Only initialize a new wallet on the device itself. Follow on-screen prompts to generate a new seed. Never enter a recovery phrase supplied by someone else.
- Create a strong PIN: Choose a 6–8 digit PIN that you do not use anywhere else. Avoid birthdays or obvious sequences. The PIN protects the device if it’s lost or stolen.
- Record your recovery phrase by hand: Write the 24 (or 12) words on the included sheet or a metal backup. Store copies in physically separate, secure locations. Do not photograph or store digitally (no cloud, no phone notes).
- Verify device attestation: Use the official companion app to check the device certificate. Attestation confirms your device is authentic and its firmware hasn't been tampered with.
- Optional passphrase: Consider adding a passphrase (a 25th word) for an extra layer of security. Understand the recovery implications: losing the passphrase can permanently lock funds.
- Update firmware: If prompted, update firmware using the official app. Firmware updates often contain security fixes — verify authenticity before applying updates.
- Perform a test transaction: Send a small amount to confirm the full receive-and-spend flow is correct before transferring larger sums.
Why each step matters: on-device generation keeps private keys offline; handwritten recovery prevents remote theft; attestation ensures device integrity; and test transactions reduce the chance of irreversible loss.