What is a hardware wallet?
- Author
- CRYPTO PORT Editorial
- Published
- Updated
- Reading time
- 4 min
In short
A hardware wallet locks the private key inside a dedicated device and performs signing there. Even a compromised computer never sees the key. That advantage only holds, though, if you check the transaction on the device's own screen.
Key points
- The key never leaves the device
- Transaction details are confirmed on the device screen
- A compromised PC still cannot extract the key
- Buy only through official channels
Definition
Dedicated hardware that stores private keys internally and completes transaction signing on-device, with no path for extracting the key.
You connect the device to a computer or phone and compose the transaction in a wallet app. The data goes to the device, which displays the destination and amount on its own screen. Only after you press the physical button does it sign, and only the signature comes back out.
This matters precisely when the connected computer cannot be trusted. Malware that rewrites the destination address cannot rewrite what the device shows, so comparing the two catches it. Approving without reading the screen removes the protection entirely.
How you buy one matters too. Devices bought second-hand or from unofficial sellers have arrived with a seed phrase already set by the attacker. Buy from the manufacturer or an authorised seller, and go through initial setup generating the phrase yourself.
Watch out for
- · Approving without reading the device screen defeats the entire point
- · Second-hand or unofficial units may arrive pre-configured by an attacker
- · It only protects you if a seed backup exists for when the device fails