Setup walkthrough

Setting up Trezor Suite, in the order that keeps you safe

A hardware wallet is set up once and then used for years, so the half hour you spend here matters more than any later convenience. This walkthrough follows the same order every time: inspect the device, install or open the app, create the wallet, store the backup properly, then prove the setup works with small amounts before trusting it with more.

Last reviewed: September 2026

Laptop on a dark desk, the kind of computer a hardware wallet companion app is set up on

Before you begin

Have these to hand before you start, because two of them are useless if you fetch them later:

  • The hardware wallet itself, ordered from the manufacturer or an authorised reseller rather than a marketplace listing from an unknown seller.
  • A computer you trust — a machine that is up to date and not shared with strangers, running Windows, macOS or Linux, or a modern desktop browser for the web version.
  • Pen and paper for the recovery backup. A metal backup plate is a better long-term answer if you have one.
  • Thirty to forty-five minutes with no interruptions. Interrupted setup is how half-written backups happen.
  • A small amount to test with — enough to prove the flow works, small enough that a mistake is survivable.

Rule zero, before anything else: your recovery words are written down from the device screen and stored offline. Nothing else ever needs them — not a website, not an app field, not a support agent, not a form. Any request for them is an attempted theft, whatever the story attached to it.

1. Inspect the device before you plug it in

A hardware wallet is only as trustworthy as the chain of custody between the factory and your hands. Spend two minutes checking:

  • The packaging is intact. Seals, holographic strips and shrink wrap should be undamaged. A resealed box is a reason to stop, not a reason to be careful.
  • No recovery words are included. No legitimate manufacturer ships a device with a pre-written seed phrase. Paper with words on it in the box is the signature of a scam.
  • The device looks new. No scratches, no residue around the connector, no sign it has been opened or re-flashed.
  • It asks to be set up. A brand-new device has no PIN and no wallet. If it appears to already contain one, do not use it — contact the seller.

If anything looks off, return it. The cost of returning a device is trivial next to the alternative, and there is no way to undo a setup that was performed on a tampered wallet.

2. Install the desktop app, or open the web version

Trezor Suite comes in two forms, and both drive the same device in the same way. Choose by how you work rather than by which sounds safer — the keys never leave the hardware in either case.

The desktop application

  • Installs like any normal program on Windows, macOS or Linux.
  • Keeps its data — accounts, labels, preferences — in a local application folder.
  • Talks to the wallet over a direct USB connection, with no browser in the middle.
  • Updates itself once installed, so fewer manual download steps over time.

Download it from the manufacturer's own published channel. Type the address yourself or use a bookmark you created, rather than following a link from an email, an advert or a search result — those are the routes fake installers use.

The web application

  • Runs in a modern desktop browser with no installation.
  • Needs a browser that can speak to USB or WebHID devices; some browsers and locked-down systems will not allow it.
  • Depends entirely on you reaching the genuine address — bookmark it once, check it every time.

The desktop guide and the web app guide go through requirements and connection methods in detail.

First launch

On first run the app asks for a currency for display values and offers optional privacy and analytics choices. Nothing here is required for the wallet to work. Decline what you do not want; you can change all of it later in settings.

3. Create the wallet on the device

Connect the device with the cable it came with. The app will notice it and offer to set it up. Follow these rules as you go:

  • The device screen is the source of truth. Words, confirmations and warnings appear there. What the app window shows is a convenience.
  • Choose "create new wallet" for a fresh device. Use the recovery path only when you are deliberately restoring an existing wallet from its backup.
  • Read every prompt on the device, including the ones you think you have already understood.

The app never generates or stores your keys. It asks the device to do the work and then displays the result, which is why a compromised app window cannot hand your funds to anybody without a confirmation on the device itself.

4. Write down the recovery backup — this is the step that matters

During setup the device displays a set of recovery words, one at a time. Depending on the model and the backup scheme you choose, that is typically twelve, eighteen or twenty-four words, or a multi-share scheme from which a threshold of shares is needed. Whatever the format, the rules are the same:

  1. Write them by hand, in order, on paper or a metal plate. Spelling and word order both matter.
  2. Never photograph them and never type them into a computer, phone, password manager, note app, cloud document or chat, including one you think is private.
  3. Check the backup immediately. Most devices offer a verification step that asks you to confirm words in a random order. Do it, and fix mistakes now rather than in a crisis.
  4. Store it offline, separated from the device. A backup sitting next to the wallet protects against nothing.
  5. Consider two copies in two locations — for example a home safe and a bank box. One location can burn, flood or be burgled.
Your backup is the wallet. Anyone who has those words can restore it on their own device and spend everything, without ever touching your hardware. Treat it as cash — because functionally, that is what it is.

If you use a multi-share backup, decide deliberately who holds each share and how many are needed to restore. Splitting a backup across people is a protection against theft and a risk of loss at the same time; understand which you are buying.

5. Set a PIN, and decide about a passphrase

PIN

The PIN is entered on the device or through a scrambled on-screen keypad, and it protects the device itself: someone who steals the wallet cannot use it without it. Repeated wrong attempts are deliberately slowed down, and the device can erase itself after enough failures, so a short PIN is not the same weakness it would be on a website.

Passphrase

An optional passphrase, entered on the device or through its keypad, unlocks an additional hidden wallet derived from the same backup. Two facts follow, and both catch people out:

  • The passphrase is not in your backup. Your recovery words restore the wallets that had no passphrase, or that share the passphrase you also remember. Lose the passphrase and the hidden wallet is gone for good.
  • It needs its own storage plan, separate from the recovery backup, and ideally somewhere you can verify after months or years.

A passphrase is genuinely useful for separating long-term holdings from spending money, and for adding a second secret to a stolen device. It is a bad idea if you are the kind of person who will not write it down. The security guide covers the trade-offs.

6. Add an account and receive a small test amount

With the wallet created, the app offers to add an account. An account is a view of addresses for one coin or network; you can have several per coin when you want to keep purposes separate.

  1. Add the account for the coin you intend to use first.
  2. Open Receive and let the app generate a fresh address — a QR code appears alongside it for phone wallets to scan.
  3. Verify it on the device if the option is offered. The device screen should show the same address the app does; a mismatch means stop immediately.
  4. Send a small amount from wherever your coins currently are, then wait for it to appear in the app with confirmations.

Coins sit on the blockchain, not in the app. The balance you see is the app reading public chain data for addresses your device controls, which is why a fresh installation and the same wallet show the same numbers.

7. Send a first test payment

Receiving proves the addresses work. Sending proves the approval flow works, so test it while the amounts are still small:

  • Compose the transaction in the app: destination address, amount, and a fee level. Economy, normal and high priority are estimates of how quickly a miner includes it; a custom option exists for people who follow network conditions.
  • Check the amount twice. Most apps, including this one, work in whole units and in smaller denominations — a decimal point in the wrong place is a full-loss mistake, not a rounding error.
  • Approve on the device. The device shows the destination and the amount. Compare them against what you intended, character by character for large amounts.
  • Watch it confirm. Once it is in a block, send the rest.

If a transaction sits unconfirmed, the app can often reissue it at a higher fee where the network supports replacement. See the fee and coin control section for the mechanics.

8. A few minutes of housekeeping that pays off later

  • Label the account and the device. Two wallets, two connectors and a year of hindsight is a confusing combination.
  • Split purposes into separate accounts. Regular income in one, savings in another, so spending never exposes savings addresses.
  • Set the display currency to the one you think in, so the dashboard is meaningful at a glance.
  • Turn on the privacy options you want — routing through Tor or a custom backend server are both available in settings.
  • Write down where the backup is. Not the words themselves: a note that says which safe, which relative or which location, so a household member can find it in an emergency.

Mistakes that cost people money

  • Typing recovery words anywhere digital. The single most common route to total loss.
  • Photographing the backup "temporarily". Photos sync, back up and upload. There is no temporary.
  • Skipping the test transaction. Testing is not paranoia; it is how you learn the interface before it matters.
  • Buying a used or resold device without a full factory reset, or trusting a seller's word that it is wiped.
  • Keeping the only backup beside the device, in the same bag or the same house.
  • Believing a support message. Real support never needs your words, your PIN, your passphrase or remote access to your computer.
  • Approving a transaction without reading the device screen. The screen is the last line of defence and it only works if you look at it.

Where to go next

Next steps: read the security and privacy guide to finish the settings you skipped, check the supported assets page before adding more accounts, and keep the FAQ handy for the questions that come up in the first week.

Related pages