Hardware Wallets: What to Check Before You Buy One
Written with AI assistance and reviewed by the NorwegianSpark SA editorial team.
Affiliate disclosure: This article contains affiliate links. If you click a link and buy a subscription, we may earn a commission at no cost to you. Our editorial recommendations are never influenced by commissions — read the full disclosure.
A hardware wallet exists to solve one problem: keeping a private key on a device that never touches the internet, so that malware on your computer cannot read it. Everything else — the screen, the app, the card format — is packaging around that. This guide covers what to check before buying, and it is a buyer's guide rather than a review; no device was tested for it.
The one thing the device actually does
The key never leaves. That is the whole security model.
When you approve a transaction, the transaction is sent to the device, the device signs it internally, and only the signature comes back. The key itself is never transmitted, so a compromised computer sees a signature it cannot reuse for anything else.
This is why a hardware wallet defeats remote attackers in a way that no software wallet can. It is also why the on-device screen matters more than any other feature: if you verify the destination address only on your computer, malware can show you one address while the device signs another. The screen is what makes the guarantee real, and a device without one is asking you to trust the machine you bought it to distrust.
What it does not protect against
Three things, and all three are the owner rather than the device:
Approving a malicious transaction. If you sign it, it is valid. A wallet-draining approval is a transaction you authorised, and no hardware can distinguish that from one you meant.
Losing the recovery phrase. The device is replaceable. The phrase is not.
Revealing the recovery phrase. Anyone who has it has everything, from anywhere. No PIN on the device helps, because the phrase reconstructs the key without it.
The pattern is consistent: hardware wallets are excellent against remote technical attacks and useless against a person being persuaded. That is why every real-world loss story is social rather than cryptographic.
The backup question decides which device suits you
Most wallets generate a recovery phrase — a word list that reconstructs the key. It must survive fire, flood, moving house and decades, while being unreadable to anyone who finds it and findable by the right people if you die.
That last clause defeats most plans. Security nobody else can execute is a guarantee the holding dies with you.
Some devices take a different approach and use multiple cards or elements with no written phrase at all: you keep two or three physical items in separate places, and any one of them restores access. It removes the written-phrase risk, and it introduces a different one — the recovery is now bounded by physical objects you must not lose together.
Neither is universally better. The right question is which failure you are more likely to suffer: writing something down badly, or losing physical items. Answer that honestly and it selects the device. Our guide to cold storage versus exchange custody covers the prior decision of whether to self-custody at all.
Supply chain is the risk buyers underrate
A hardware wallet is the one product category where where you buy it is a security control, not a convenience.
A tampered device — pre-initialised with a key someone else knows, or physically modified — hands over everything the moment you fund it. This is not hypothetical; devices with pre-printed recovery phrases have been sold through marketplace listings.
So: buy from the manufacturer or an authorised reseller it names on its own site. Never from a marketplace listing, never second-hand, never opened.
And on first use: the device must generate the recovery phrase itself, in front of you. If it arrives with a phrase already written down, it is compromised. There is no legitimate reason for that ever to happen, and it is the single clearest warning sign in the category.
What to check before buying
- Is there an on-device screen for verifying addresses independently of your computer?
- Is the firmware open source or independently audited, and is the audit published?
- What is the recovery model, and can you realistically execute and test it?
- Which assets are supported, specifically the ones you hold — support varies more than the marketing suggests.
- How are firmware updates delivered and verified?
- Is the vendor's authorised-reseller list published?
- What happens if the company ceases trading? A wallet using a standard recovery phrase can be restored in other software. A proprietary scheme may tie you to one vendor's continued existence.
Before you move anything meaningful
- Send a small test transaction first and confirm it arrives.
- Verify the receiving address on the device's own screen, not the computer's.
- Test the recovery once, deliberately, before it matters. An untested backup is a belief, not a plan.
- Tell someone the backup exists and how to reach it.
Tangem is one of the card-based designs described above; judge it and any alternative on the checklist here rather than on form factor.
About the figures on this page
No price, supported-asset count or specification is quoted here. Asset support and pricing change with firmware releases and by region. Read the current figures on the manufacturer's own site — and buy from there.
Frequently Asked Questions
Is a hardware wallet worth it for a small holding?
It depends on whether the amount is one you could not afford to lose to someone else's failure. Many people keep a working balance on an exchange and long-term holdings in hardware, which matches the arrangement to the job rather than treating it as all-or-nothing.
What happens if I lose the device?
Nothing, if the backup is intact — the device is replaceable and the recovery restores the key. Losing the backup as well is what makes the loss permanent, which is why the backup is the real asset.
Can I buy one second-hand?
No. A tampered or pre-initialised device hands over everything the moment you fund it. Buy from the manufacturer or a reseller it names, and never accept a device that arrives with a recovery phrase already written down.
VPNTex is published by NorwegianSpark SA (Org no: 834 984 172). We may earn commissions on qualifying purchases via affiliate links. This does not affect our editorial independence. Full disclosure · Privacy policy