How it works
The device can authorize a transaction without exposing the private key directly to the connected computer. Users still need to verify what they are signing and protect recovery information.
What to check
Check firmware provenance, supported networks, recovery procedures and whether transaction details are shown on the device itself.
- Verify transaction details on-device
- Keep recovery material separate
- Use official firmware and software
Limits and risks
A hardware wallet is not a guarantee against phishing or malicious approvals. An attacker may still trick a user into signing a harmful transaction.
Primary sources
Bitcoin Developer Reference↗Ethereum developer documentation↗FATF: Virtual Assets↗General information only. Investment products can lose value, and terms, fees and regulation can change.