We use technologies like cookies to store and/or access device information. We do this to improve browsing experience and to show (non-) personalized ads. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Техническое хранение или доступ необходимы для законной цели хранения предпочтений, которые не запрошены подписчиком или пользователем.
The technical storage or access that is used exclusively for statistical purposes.
Техническое хранилище или доступ, который используется исключительно для анонимных статистических целей. Без повестки в суд, добровольного согласия со стороны вашего интернет-провайдера или дополнительных записей от третьей стороны информация, хранящаяся или полученная только для этой цели, обычно не может быть использована для вашей идентификации.
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
What is a hardware wallet and how does it work?
A hardware wallet can look like a USB flash drive, which makes it easy to mistake it for a device that holds your cryptocurrency. The device stores private keys that let you spend your coins, and signs transactions without passing those keys to your computer or phone. A backup lets you recover access to your funds even if the device breaks or goes missing; protecting the keys will not help, however, if you disclose your seed phrase or approve a malicious operation.
Where your cryptocurrency is stored
Cryptocurrency exists as records on a blockchain — a database maintained by network nodes, which keep copies of it. Those records make it possible to determine how many coins belong to each address. Your bitcoin or USDT remains on the blockchain, even when your wallet is switched off and sitting in a drawer.
To spend coins from an address, you need to create a digital signature using the corresponding private key. In Bitcoin and Ethereum, a private key is a secret 256-bit number. Network nodes verify the signature to confirm that the transfer is authorised; anyone with the private key can create a valid signature and spend the coins.
A hardware wallet generates keys inside the device and keeps them isolated from your computer or phone. The signature is also created on the wallet itself when you confirm an operation with a button press or a tap on the screen. Different addresses use separate keys, which the wallet derives from a shared cryptographic seed.
A wallet backup lets you restore those keys and regain access to your coins. It is usually a seed phrase of 12 or 24 English words based on the BIP39 standard, which the wallet displays during initial setup; newer Trezor devices also commonly use 20-word backups based on a different standard, SLIP39. Anyone who learns your phrase can access the funds without the device, unless the wallet is also protected by a passphrase. If you lose both the backup and access to the device, with no other copies available, you will not be able to recover the wallet. We explain the role of the backup in more detail in our guide to seed phrases.
If you have lost your written seed phrase but the device still works and you can confirm transactions, create another wallet with a new backup and transfer your funds to it. If the device itself breaks or goes missing, a saved phrase will let you restore the wallet on a compatible model. The manufacturer, retailer and support team do not have your keys and cannot restore access for you.
Why a hardware wallet is called a cold wallet
Wallets are described as hot or cold depending on whether their private keys are kept isolated from internet-connected devices. Software wallets such as MetaMask or Trust Wallet usually store keys on your smartphone or computer, unless you have connected a hardware wallet to them. Although the keys are encrypted, they are on the same device as your browser, messaging apps and downloaded software. A malicious app or extension could gain access to the keys or seed phrase.
In a hardware wallet, keys are generated and stored inside the device. When you connect it to a phone or laptop by cable, Bluetooth or NFC, it receives the transaction data and returns the signed result. The keys themselves are not transmitted during this exchange, so the computer does not receive them even if it is infected with malware.
Some models, such as the Keystone 3 Pro, exchange transaction data through QR codes displayed on screens, without using USB or a wireless connection for that exchange. These are known as air-gapped wallets. Avoiding those connections removes the associated attack paths, while transactions are still signed inside the device without exposing the keys, just as they are in other hardware wallets.
If you keep funds on Binance or WhiteBIT, the exchange controls the keys to its addresses and records your balance in its internal database. If the exchange is hacked, blocks your account or shuts down, you cannot independently access those funds: access depends on the exchange. We explore this difference in our comparison of hardware wallets and exchanges.
How a hardware wallet signs a cryptocurrency transaction
For a regular transfer, you open the app and enter the recipient’s address and the amount. The app and device then carry out the following steps:
The third step requires careful checking because an infected computer or phone can display false information. For example, malware can monitor the clipboard and silently replace a copied wallet address with an attacker’s address, often one with similar first and last characters. The substitution may go unnoticed in the app, while the hardware wallet’s screen, controlled by the device itself, shows the address in the transaction it received. Check the entire address on that screen.
The risks of blind signing
For a regular transfer, the wallet displays the recipient’s address and the amount, but requests involving smart contracts can be more complex. Examples include swapping tokens on a DEX (decentralised exchange), allowing an app to spend your tokens, or approving an operation in a multisignature wallet, where several people must confirm it. If the device cannot display what the request does, you may see only undecoded data or a hash and a warning. Approving an operation without being able to verify its meaning on the device’s screen is called blind signing. You are then relying on information from the computer, even though your keys remain protected inside the wallet.
This risk was demonstrated in the Bybit attack on February 21, 2025, when the exchange lost approximately $1.5 billion in crypto assets. According to Sygnia’s investigation, the attackers compromised the computer of a developer at Safe{Wallet}, a platform for managing multisignature wallets, and altered the code of its web interface. Bybit’s signers saw what appeared to be an ordinary transfer between their own wallets in the browser, but approved an operation that changed the smart contract’s logic and gave the attackers control of the funds. The devices did not display that change in a readable form, so the signers could not verify it on their wallet screens. The FBI attributed the theft to North Korean hackers.
Manufacturers are introducing clear signing to help users understand smart contract requests. It displays the operation in a readable form, such as “swap 100 USDT for ETH” or “allow this app to spend your USDC”. Support depends on the contract, device model and software. If the wallet warns you about blind signing and you do not understand what you are signing, reject the operation. We explain the difference between clear signing and blind signing in a separate guide.
What to do if your wallet is lost, broken or stolen
A PIN protects access to the device, and limiting the number of attempts makes it harder to guess. When the limit for incorrect PIN entries is reached, the wallet wipes its data: Ledger after three consecutive attempts, Trezor Safe 7 after ten, and Trezor Safe 3 and Safe 5 after sixteen. Recovery after a wipe requires your backup and the passphrase, if you used one.
Attacks involving physical access to the device are a separate risk. A secure element makes extracting keys harder, while older models without one are more vulnerable. In 2020, Kraken Security Labs researchers demonstrated how to extract the seed from a Trezor Model One or Model T with approximately 15 minutes of physical access. They recommended additional protection for these models through a long, strong passphrase, which is not stored on the device.
If the device is lost, broken or wiped after incorrect PIN attempts, your funds remain on the blockchain. You can use the backup on another wallet, including one from a different brand, as long as it supports the backup format, the networks you use and the way your addresses are derived. Most hardware wallets support 12- and 24-word BIP39 phrases.
Compatibility with 20-word SLIP39 backups is more limited. According to Trezor’s documentation, this format has been the default for Safe 3 since June 2024, and is also the default for Safe 5 and Safe 7. The Model T supports it too, but still creates a 12-word BIP39 backup by default. Ledger uses BIP39. Before switching brands, check the documentation for support for the specific format and version of your backup. If your SLIP39 backup consists of several shares, recovery requires the number of shares you specified during setup.
If the device was stolen or may have fallen into someone else’s hands, restore access on a genuine, compatible wallet and transfer the funds to a new wallet with a new backup. Restoring from the old phrase recreates the same keys and does not disable the missing device. Trezor recommends this approach; setting a new PIN on another device does not change the old keys either.
A passphrase adds protection through a secret phrase you choose yourself. Used together with your seed phrase, it gives access to a separate, hidden wallet. Someone who finds your seed phrase cannot open that wallet without the correct passphrase, although a short, predictable passphrase can be guessed. Choose a long, unique passphrase and store it separately from your seed phrase. If you forget it, the seed phrase alone will not be enough to recover the hidden wallet. Our separate guides cover passphrase setup and risks, as well as seed phrase storage.
What a hardware wallet cannot protect you from
You can still lose funds while using a hardware wallet if you approve a malicious operation, buy a counterfeit device or disclose your seed phrase to scammers. In these cases, the attackers do not need to overcome the private-key protection in a genuine wallet.
Approving an operation without checking it
For the device’s screen to help protect your funds, you need to read the operation details before confirming. Scammers rely on the habit of pressing “Confirm” without checking: under the guise of an airdrop (a supposed free token distribution), a reward claim or a DEX swap, they ask you to sign a token spending approval that they can later use to steal your tokens. If the wallet’s screen shows an unfamiliar address, an unlimited spending approval or a blind signing warning, reject the operation and find out what the app is requesting.
Buying from a private seller or an unverified retailer
Modified and counterfeit wallets can be difficult to distinguish from genuine ones by appearance. In 2026, hardware security researcher Joe Grand presented his analysis of a Ledger Nano X with an unauthorised circuit board inside its case. That board contained a cellular module with an eSIM, which could not be spotted without opening the case.
In April 2026, another researcher described a counterfeit Ledger Nano S Plus from a Chinese marketplace. Instead of a secure element, it contained an ESP32-S3 microcontroller that stored the PIN and seed phrase in plain text. A QR code in the box directed users to a copy of ledger.com offering a malicious app. The author later clarified that the counterfeit did not pass the real Ledger Genuine Check: the fake app simply displayed a successful verification message.
Buy directly from the manufacturer or an authorised reseller, and verify the seller against the partner list on the manufacturer’s website. Used devices sold on OLX or through Telegram channels, and suspiciously cheap marketplace listings, may be counterfeit or tampered with. Our guide to buying wallets on classified ad platforms explains the risks. A card with a seed phrase already printed on it means that someone else knows the phrase you have been given. When you create a new wallet, a genuine device generates the phrase itself and displays it on its own screen.
Entering your seed phrase on a third-party website or in an app
Scammers may also try to obtain your seed phrase by impersonating Ledger or Trezor support. They send emails about supposed data leaks, promote an “urgent firmware update” or ask you to install a fake app, then tell you to enter the seed phrase on a website, in a program or in a Telegram bot. The manufacturer, retailer and support team will not ask you to share your seed phrase with them: such a request is a scam, however official the message may look. We explain how to check these emails in our guide to crypto phishing.
When recovering a Ledger wallet or a newer Trezor model, enter the words on the device itself, following the official instructions. For the Trezor Model One, which uses a different entry process, use Advanced recovery: the wallet’s screen displays the letters, while you click the corresponding blank buttons in a grid on the computer without typing the words on the keyboard.
First steps after buying a hardware wallet
Set aside enough time to check the device and its backup carefully before transferring your main funds. If you are setting up a wallet for the first time, use our “First 30 minutes with a hardware wallet” guide. The main steps are:
Whether you need a hardware wallet depends on the amount you have saved and how you use cryptocurrency. If an exchange or mobile app holds an amount you cannot afford to lose, consider buying a device and plan how you will store its backup. For active trading, it may be more convenient to keep some funds on an exchange and move your long-term savings to your own cold wallet. You can compare models in our hardware wallet overview and catalogue.
For people in Ukraine, a backup can also be useful during relocation or evacuation: keeping the seed phrase, along with the passphrase if you use one, lets you restore access on another compatible device wherever you are.
Hardware wallets in the Lwallet catalogue
When choosing a model, consider support for your coins and networks, compatibility with your phone or computer, and how easy it is to check operations on the screen.
Ledger Flex
Trezor Safe 3
4,590.00 UAHOriginal price was: 4,590.00 UAH.3,590.00 UAHCurrent price is: 3,590.00 UAH.Keystone 3 Pro
OneKey Classic 1S
5,090.00 UAHOriginal price was: 5,090.00 UAH.4,590.00 UAHCurrent price is: 4,590.00 UAH.Conclusion
A hardware wallet lets you keep private keys isolated from your computer or phone and confirm operations on the device’s screen. To benefit from that protection, buy from a trusted seller, keep your seed phrase offline and check what every operation does before signing. A backup lets you recover access if the device breaks or goes missing; if you use a passphrase, you will need that for recovery too.
Related Posts
GrapheneOS and NitroPhone: a secure phone for crypto
GrapheneOS strengthens your smartphone’s security, while NitroPhone comes with the system already installed. A hardware wallet stores your private keys, but your phone still gives you access to other funds and services. It may hold exchange accounts, two-factor authentication (2FA) codes, the email account you use for recovery, Telegram, and hot wallets for everyday transactions. …
Ledger Flex setup: step-by-step guide from unboxing to your first transaction
Ledger Flex setup is best done step by step, from checking the box contents to completing your first test transaction. If you have just received a Ledger Flex, this guide will walk you through installing Ledger Wallet, running Genuine Check, creating a new wallet, writing down your Secret Recovery Phrase, and setting up your recovery …
Which hardware wallet should you buy as a gift?
A hardware wallet as a gift is a practical choice for someone who already owns crypto or is planning to move to self-custody. It keeps private keys protected and gives the owner more control over access to their assets, so its value goes well beyond the unboxing. But price and looks should not be the …
Crypto cards in Ukraine: availability, fees and limits
Crypto cards in Ukraine in 2026 let you pay for purchases without first withdrawing funds to a bank card. Whether you can get one depends on where you live and whether you pass identity checks; what you ultimately pay depends on conversion rates and fees. We compare providers that explicitly list Ukraine as a supported …