Wallets · 14 / 86 · 3 min
Hardware wallets and cold storage
A hardware wallet keeps the private key off the computer you browse with. Offline reduces some risks. It does not stop you approving a bad transaction.
The device keeps the key off the computer. It will sign a bad transaction if you confirm it.
A worked case
A hardware wallet owner connects to a fake site. The device screen shows an approval for the whole token balance. They confirm because they trust the device. The key never touched the browser. The signature did.
What offline protects
Malware on the laptop has a harder time copying the key. You confirm payments on the device itself. That confirmation is the point. Read the address and the amount on the device, not only on the computer screen.
What it does not protect
If you type the seed into a website, the hardware was pointless. If you buy the device from a stranger who set it up, the seed may already be theirs.
Buy from the maker or a shop you can check. Set it up yourself. Write the seed where a camera and a cloud backup cannot see it.
The device will sign what you confirm
A hardware wallet keeps the private key off the computer you browse with. Ledger and Trezor are the usual names. In 2020 Ledger's customer database was leaked: names, email addresses, phone numbers. The keys were not in that leak. What followed was years of convincing phishing, including fake devices and letters, because the attackers knew who owned a wallet. The company wrote its own account of the breach. The lesson is not that hardware is useless. It is that the key's safety and the owner's safety are different problems.
The device also does not know your intent. It shows a destination and an amount, or a hash you cannot read, and it signs if you press the buttons. People have confirmed drainers on a hardware wallet because they trusted the object in their hand more than the words on its screen. Offline stops a class of malware. It does not stop a person who approves a bad transaction.
Buy the device from the maker, not from a search ad. Read the screen. The leak is the record of what happens when a list of owners escapes, even if the keys do not.
Read it yourself
These links are the record. They are not a recommendation, and they are not instructions. A news story or a court paper can still be wrong about a detail. The check does not change because a famous name is in the story.
Apply the check
Open a question. The line is about this topic. It is not a verdict that anything is safe.
The attacker, after you confirm.
You, at the moment of confirmation. The device does not know your intent.
The signature you approved.
Check yourself
Does a hardware wallet stop a bad approval?
No. It shows you the approval. You can still accept it.
After this you can confirm the address on the device, and never type the seed into a page.
