What it actually does

A hardware wallet is a small dedicated device that stores your private keys and signs transactions internally. The keys never leave it. Your laptop can be riddled with malware and still never see the secret that controls your coins, because it only ever receives a finished signature.

The second protection is the screen. You confirm the amount and destination on the device itself, so malware that swaps an address in your browser gets caught by you reading the device rather than the screen it compromised.

What it does not do

This is the part that gets people hurt, because a device labelled secure encourages the assumption that the thinking is over.

  • It cannot stop you approving a bad transaction. If you are tricked into confirming a payment to an attacker, the device does exactly what it was designed to do.
  • It cannot protect a leaked recovery phrase. Anyone with those words has your coins, device or no device.
  • It is not a backup. Losing it is survivable only because of the phrase you wrote down. The device is replaceable; the phrase is not.
  • It does not hide that you own Bitcoin. As below, buying one can do the opposite.

Buying one without creating a problem

Counterfeit and tampered hardware wallets are a documented category of attack. The pattern repeats: devices bought from marketplaces or third-party sellers that arrive pre-configured, sometimes with a printed card of recovery words already filled in, sometimes with modified internals. The attacker knows the phrase before you do, waits until you fund it, and empties it.

A sealed hardware wallet box as delivered
Sealed, direct from the manufacturerPhotographed for this guide

The rules are short and they are not negotiable:

  • Buy directly from the manufacturer's own website. Not a marketplace listing, not an auction site, not a reseller offering a discount, and never second hand at any price.
  • A device that arrives with a recovery phrase already written down is an attack. There is no exception. Genuine devices generate the phrase in front of you, on first setup.
  • Check the packaging and run the manufacturer's authenticity check in their official app before setting anything up. Every serious manufacturer publishes a current guide for this. Follow theirs, not a summary.
  • Only ever update firmware through the official application, and never in response to an email, letter, or pop-up telling you to.
Buying direct protects the device, not your privacy. Ordering a hardware wallet creates a record connecting your name and home address to the fact that you hold Bitcoin. That record has leaked repeatedly. Consider a delivery address that is not your home, and expect targeted approaches regardless.

Why that warning is there

In January 2026 Ledger notified customers that order data had been accessed at Global-e, a third-party e-commerce provider handling international orders. Names, postal addresses, email addresses, phone numbers and order details were exposed. Ledger's own systems, devices and recovery phrases were not compromised, and no funds were taken directly.

The damage was downstream. Reports of impersonation emails referencing real orders began almost immediately, and postal addresses enabled physical letters impersonating official communications, complete with QR codes leading to fake verification steps. Ledger had a comparable exposure in 2020 affecting a much larger group, and that one produced years of phishing.

Two lessons, and neither is that hardware wallets are bad. First, the secure element did its job both times; the failure was commercial infrastructure around it. Second, any company that ships you a physical object necessarily knows where you live, which is a permanent, unavoidable cost of buying one, and worth planning around rather than discovering later.

Choosing between them

For a Level 1 holder, almost any current device from an established manufacturer with an open track record is sufficient, and the differences between them matter far less than doing the setup properly. Well regarded options include Trezor, Ledger, Coldcard, BitBox and Blockstream Jade. Nothing on this site earns anything from naming them.

What actually matters when choosing:

  • A screen you can genuinely read and verify addresses on
  • Firmware and a company history you can investigate
  • Standard recovery phrase support, so you are not locked to one brand
  • A setup process you personally can complete without guessing

After it arrives

Setting it up is its own job: verification, phrase backup, a test restore before funding, and a test transaction before moving anything meaningful. That sequence has a dedicated guide.

Sources