How it keeps your keys safe
Several layers work together:
- Keys stay on the device. Private keys are generated on the hardware wallet and never leave it. The app only ever sees public data and signed transactions.
- On-device confirmation. Every transaction and every receive address is shown on the device's own screen for you to verify, so a compromised computer can't reroute funds without you noticing.
- PIN protection. The device is locked with a PIN. Repeated wrong guesses trigger increasing delays, making brute force impractical.
- Optional passphrase. An additional passphrase (sometimes called a "hidden wallet") creates wallets that don't exist anywhere until the exact passphrase is entered. It's powerful but unforgiving — forget it and the funds are gone.
- Recovery seed. When you set up the device it produces a recovery seed — a list of words that can restore your wallet if the device is lost or damaged. This seed is the single most sensitive thing you own.
Never type your recovery seed into a computer or website
Legitimate software will never ask you to enter your recovery seed on a keyboard or web form. The seed is written down on paper during setup and entered only on the device itself when recovering. Any site or app that asks you to type your seed is a scam. This single habit prevents the large majority of hardware-wallet thefts.
Continue with the official documentation
For current requirements and instructions about private keys and device security, consult the official Trezor documentation before proceeding.
Visit the official Trezor Suite page