Hardware wallet
What is a hardware wallet?
A hardware wallet is a physical device, often the size of a usb stick, that stores your keys offline. Transactions are confirmed on the device itself, so the key never leaves it. This is also known as cold storage and is considered one of the safer ways to keep crypto.
Is a hardware wallet safer than a wallet on my phone?
A hardware wallet keeps the keys offline, which makes it harder for malicious software on your phone or computer to reach them. It remains important to keep the matching recovery words safe and secret, because anyone who has them can still restore the wallet.
Is a hardware wallet necessary for small amounts?
That is a trade off between convenience and risk. Many users keep a small amount in a wallet on their phone and put larger holdings on a separate device. There is no fixed amount above which it is always needed.
What happens if the device breaks?
Access lies in the recovery words, not in the device. With those words the wallet can be set up again on a new device. Without them there is no way back.
Does a hardware wallet protect against fraud?
Not against deception. If you approve a transaction yourself because someone talks you into it, the device carries out that instruction. Protection against fraud lies in assessing the request, not in the hardware.
Can a second hand hardware wallet be safe?
Only if you reset the device yourself and generate new recovery words yourself. Words that came supplied with the device should never be used.
What a device does and does not protect against
Keeping key material offline removes one category of risk almost entirely: software on a computer or a phone that reads what it should not. It does nothing about the categories that cause most losses in practice. If you are persuaded to approve a transfer, the device will approve it faithfully. If you type a recovery phrase into a page that looks like a support site, the balance can be emptied without the device being touched at all. And if the phrase is lost, the offline storage is exactly as final as it was designed to be.
For a file that has two consequences worth stating plainly. First, the presence of such a device is not evidence that a transfer was unauthorised, because a confirmed transaction looks the same either way. What matters is the sequence of contact that preceded it. Second, a claim that funds were stolen despite offline storage usually points to the recovery phrase rather than the hardware, and that changes what has to be reconstructed: the messages, the moment and the destination, in that order.
One practical habit is worth more than any of this: keep the recovery phrase somewhere that no screen ever sees, and treat every request for it as hostile by default. It costs nothing and it removes the failure mode that hardware cannot cover.
See also
Your own situation
If you are reading this, you probably have a question about your own situation. That is exactly what Paucitas does.
The first step is contact by phone. We prefer to schedule that call through WhatsApp, so you do not have to wait. In the call we look together at what can factually be established in your case and what Paucitas can examine for you.