Security & privacy

What the app protects, and what only you can protect

A hardware wallet moves one specific risk — a stolen computer — from "your life savings are gone" to "an annoyance". It does not move the others. This page separates the two: the parts of Trezor Suite that genuinely defend you, the settings worth getting right once, and the habits no software can perform on your behalf.

Last reviewed: September 2026

Closed laptop on a table, representing a computer that never holds the wallet's keys

The security model in one paragraph

Your private keys are created inside the hardware wallet and never leave it in usable form. The app on your computer is a coordinator and a display: it reads public blockchain data, builds transactions, and asks the device to sign them. Signing requires a physical confirmation on the device screen, so a compromised computer can annoy you, mislead you or lie about balances — but it cannot move funds by itself.

Everything below follows from that single property. It is also the reason the device screen, not the app window, is the place you check addresses and amounts.

What each layer protects
Layer Protects against Does not protect against
Hardware wallet Key theft from an infected or stolen computer You approving a transaction you did not read
PIN Someone using a stolen device Someone who also has your recovery backup
Passphrase Theft of device plus recovery backup Losing the passphrase yourself
Network privacy settings Link between your IP address and watched addresses Public on-chain analysis of the addresses themselves

PIN and device access

The PIN is entered on the device itself, or through a scrambled keypad the app draws whose layout is randomised — which defeats both shoulder-surfing and screen-logging malware. It exists to stop a thief who has the physical device.

Two behaviours are worth knowing before you pick four digits:

  • Wrong attempts get slower, then destructive. The device deliberately increases the delay between attempts, and past a threshold it can wipe itself. That is a feature: it turns a stolen device into a brick rather than an offline guessing game. The exact retry behaviour is documented by the manufacturer and has changed between model generations — check your model rather than assuming.
  • Wiping is not a backup. A self-erased device is recoverable only from your written backup. If your backup is incomplete, the anti-theft feature is also a data-loss feature.

Avoid PINs that are a phone's last four digits, a birthday, or the same code you use for the door. Four digits is a small space; make it an unguessable one.

Passphrases: the opt-in second secret

A passphrase is a word or phrase you supply, which is combined with your device's backup to derive a different wallet entirely. Enter a different passphrase and you get a different set of addresses and balances. This has three practical effects:

  • A second secret to steal. A thief with your device and your written recovery words still sees only the wallet with no passphrase. That is the strongest argument for using one.
  • Hidden wallets. Keep long-term holdings in a passphrase-protected wallet and spending money in the default one, so daily use never touches savings addresses.
  • An unrecoverable secret. The passphrase is not part of your backup and cannot be reset. No support channel, no manufacturer and no piece of software can recover it.

If you use a passphrase, write it down and store it separately from the recovery backup, in a place someone else can reach if you are not around. Test the exact spelling and capitalisation by restoring a small test amount. A passphrase that exists only in your memory is a plan for losing the money.

Be aware of the trade-off in the other direction: with a hidden wallet, an attacker who finds only openable wallets may assume that is all there is. That is plausible deniability — and it is worth exactly as much as your ability to keep your cool under pressure.

Backups that survive real life

The recovery backup is the wallet, expressed as words. It is the highest-value object most people will ever write by hand. Treat storage as a design problem, not an afterthought.

Format

  • Paper is cheap and fine for a while, but it burns, mildews, tears and fades. It is also legible to anyone who finds it.
  • Stamped metal survives fire, flood and time, and is the usual choice for money someone intends to hold for decades.
  • Multiple stakes — a multi-share backup — split the secret so that a set number of shares is needed. It protects against a single point of loss and introduces the risk of losing the wrong shares. Available on supported models.

Storage

  • Two copies, in two physically separate locations, neither of them with the device.
  • No photographs, no cloud scans, no password-manager entries. If a copy exists digitally, treat the wallet as compromised and move funds to a new one.
  • Tell one trusted person that a backup exists and how to reach it — without telling them what it is worth or what it says.

Verify, do not assume

A backup you have never restored from is a belief, not a backup. Once setup is finished, restore the same words onto the device or a spare and confirm the addresses match. Do it before there is anything meaningful on the wallet.

Firmware and updates

Device firmware is the code that actually protects the keys. Updates fix bugs and add support for new networks, which means keeping it current is part of staying secure — and that updating is also a moment when you should be paying attention.

  • Signatures are verified by the device. An altered or unofficial firmware image is rejected because the wallet checks it against the manufacturer's signing key before installing. That check is the reason a hacked download page is not automatically fatal.
  • Update through the app, with the device connected by cable. Do not update from a link in a message, and do not rush an update with a low battery.
  • Your backup must exist first. An interrupted firmware write can leave a device needing a restore. Most updates finish harmlessly; you want the boring case covered anyway.
  • Read what changed on the manufacturer's release notes, then verify the version the app reports afterwards.

Phishing and support scams: the most common way funds are lost

The economics of attacking hardware wallets are unhelpful for attackers: the device works. So the attacks move to you. What you will actually encounter:

  • Fake apps and installers. Paid search adverts, lookalike domains and cloned download pages. Reach software only from the manufacturer's own published channel, and verify what you downloaded before installing it.
  • "Support" that contacts you first. Real support does not open a chat, send a form or ask you to share your screen for a seed-related problem.
  • Phishing pages that ask for your recovery words on the pretence of "verifying", "migrating" or "unlocking" your wallet. No legitimate process on earth requires this.
  • Fake device warnings. Emails claiming your firmware is compromised, with a "fix" that is malware.
  • Compromised extensions and wallets that alter the address you pasted. This is exactly what on-device verification defeats: confirm the recipient on the device screen.
The one rule that defeats nearly all of it: recovery words, PIN and passphrase are entered only on the hardware device itself, never in a browser, app field, chat or phone call. There is no exception for anyone, ever — including people claiming to be from the wallet maker, an exchange, the police or this site.

Network privacy: who learns which addresses you watch

A wallet app must ask someone about your addresses. By default that someone is a server belonging to the app's maker, which can correlate your IP address with the addresses you are watching — a serious privacy problem even though it does not threaten the funds. Suite gives you two ways to change that:

  • Tor. Routes the app's traffic through the Tor network so queries are not tied to your IP address. Slower, occasionally fussy, and the simple switch for most people who care.
  • A custom backend. Point the app at your own node or a compatible Electrum-style server you trust, so address queries never reach a third party at all. More control, more maintenance, and it makes you responsible for that server's uptime and correctness.

Neither option hides what is already public. Once funds move, the blockchain records the amounts, the addresses and the timing forever. Privacy practice — avoiding address reuse, not merging unrelated coins, using coin control — matters as much as the transport does.

Physical security, which people underestimate

  • Device theft is survivable, if your PIN is good and your backup is not with it. Assume a stolen device means starting again with a restored wallet.
  • Consider the "wrench attack". Someone who knows you hold crypto can pressure you in person. Obvious packaging, public talk about your holdings and a visible hardware wallet on a desk all reduce your options. A passphrase-protected wallet with a modest second wallet on the device is a defensible arrangement.
  • Travel deliberately. Devices and cables through airport security are fine; a written backup in a carry-on bag is not. Keep the backup and the device apart when you move between places.
  • Factory-reset before selling or gifting a device and confirm the reset finished on the device screen, not just in the app.

What the app cannot protect you from

  • Approving the wrong transaction. If you confirm a payment to an attacker's address on the device, it is a valid payment. The device shows the truth; it cannot read your intent.
  • Giving your recovery words away. There is no technical countermeasure. Only the rule above.
  • A tampered device bought from an untrusted seller. Setup warnings and physical inspection reduce the risk; buying from the manufacturer removes it.
  • Third-party services you connect. Buy, sell, swap and staking flows run through outside providers with their own terms, identity checks and risks. Their failures are not the wallet's failures.
  • Market losses, exchange collapses and counterparty risk generally. Self-custody removes the middleman's custody risk, not the asset's volatility.
  • Losing your own backup, passphrase or PIN through carelessness. The most common way self-custody goes wrong, and the one with no recovery path.

A five-minute self-audit

Answer these honestly once a year. Any "no" is this week's task.

  • Does a fire, a flood or a burglar have to destroy only one place to end my backup?
  • Have I ever restored from my backup to prove it works, and did the addresses match?
  • Is any photograph, scan, note or backup of my recovery words stored digitally?
  • Is my passphrase, if I use one, stored separately from my recovery words and findable by someone else?
  • Is my device firmware on a current, verified version?
  • Can I describe, without checking, exactly what the device screen shows before I approve a payment?
  • If someone messaged me right now claiming to be support, would I know what to refuse?

Reminder: this site is an independent guide. It never asks for your recovery words, PIN or passphrase, and no page here will ever request remote access to your computer.

Next steps

Where to go next: work through the setup walkthrough if the wallet is new, review the supported assets before adding accounts, and use the FAQ for the everyday questions.

Related pages