What is a hardware wallet?
A hardware wallet is a small device that keeps crypto private keys offline and signs transactions without exposing them to a computer.
A hardware wallet is a small electronic device, often the size of a USB stick, built to do one job: keep the private keys that control cryptocurrency off the internet. It is the most common form of cold wallet. People sometimes search for it as a "crypto ledger device," after Ledger, one of the best-known brands.
How does a hardware wallet work?
The device generates its keys internally and never lets them leave. It holds no coins. Those stay on the blockchain.
To make a payment, the user prepares a transaction in a companion app on a phone or computer, which passes it to the device unsigned. The device displays the details on its own screen, and the user confirms with a physical button or touch. The device then signs the transaction internally and hands back only the signature.
The computer never sees the key, so the key stays out of reach even if the computer is infected with malicious software. A PIN protects the device if it is lost or stolen. The wallet can be rebuilt on a replacement using its seed phrase, the list of 12 or 24 words written down at setup.
Which companies make them?
Ledger, based in France, and Trezor, made by the Czech company SatoshiLabs, are the longest-established names. Many other manufacturers now compete with them. Designs differ on points such as whether the software is open to public inspection. Cryptoweek does not recommend products.
Ledger the company should not be confused with a ledger in the general sense, which is a blockchain's record of balances.
Where do people go wrong?
The device protects the key. It cannot protect the owner from being tricked. Losses tend to follow a few patterns:
- Tampered or fake devices. Units bought second-hand or from unofficial sellers have arrived already set up, sometimes with a seed phrase printed on a card in the box. A phrase someone else chose is a phrase someone else knows. Manufacturers say to buy directly from them or from an authorized seller, and that a genuine device generates a new phrase itself.
- Typing the seed phrase into a computer. Fake companion apps and phishing emails ask owners to enter their words to "restore" or "update" a wallet. Makers say the words should only ever be entered on the device.
- Approving without reading. A hardware wallet signs whatever its owner confirms. If the screen shows a transfer or permission the owner does not understand and they approve it anyway, the funds can be taken with a valid signature.
- Losing the backup. A device that breaks is replaceable. The words are not, as the guide to losing a seed phrase explains.
Skeptics add that owners must still trust the manufacturer's hardware and software updates, and that the extra steps and the purchase price put off casual users.
This guide explains how things work. It is not financial, legal or tax advice. Last updated .