Skip to content
ISO Coins

Guide 5

Guide 5 - Set up a hardware wallet safely

Buy from the official store, check the box and the device, update firmware through the official app, create the seed phrase on the device, back it up, and test recovery before funding.

11 min readLast updated: October 11, 2026

Goal

By the end of this guide you will own a that you bought from the manufacturer, inspected, set up yourself, backed up and tested, with an empty balance and a recovery plan you have proved works. Only then is it ready to receive coins (guides 6 and 7).

A hardware wallet is a type of : a small device that keeps your away from your internet-connected computer and signs transactions inside the device. It reduces some risks and creates others, mainly the risk of losing the backup. Nothing here recommends a brand or an amount.

Time needed

  • Ordering and delivery: days, depending on shipping.
  • Unboxing and inspection: 10 minutes.
  • Setup, PIN and firmware: 20-30 minutes.
  • Writing and storing the backup: 20 minutes.
  • Test recovery: 30-45 minutes.

Before you start

  • Guide 1 done, especially the plan for where the will and will not live.
  • A computer you trust and an official companion app downloaded only from the manufacturer's site.
  • A pen, the blank backup card or sheet from the box, and a safe, dry place.
  • Check that the wallet you choose supports your coins: the wallet table below and the manufacturer's coin pages decide this, not marketing.

Steps

Step 1 - Buy only from the official store

Counterfeit and tampered devices are sold through marketplace listings and discount sites. Ledger recommends buying directly from Ledger or from authorised resellers, because the Genuine Check confirms the secure element, not where a box has been on the way to you (this is our reading of Ledger's guidance; the exact wording was not verifiable by script). [1][2] Trezor says to never buy from an unauthorised third party. [5]

Go to the manufacturer's official store from the table below, typing the address yourself or using this site's verified link. The table shows which of the eight coins each wallet supports, based on the manufacturers' own pages, and the notes there flag partial support and third-party apps.

Buy only from the official store - never second-hand

WalletPriceOpen sourceXRPXLMXDCALGOHBARIOTAQNTADA

Ledger

Ledger's own coin pages cover all eight coins; XDC needs an unnamed third-party wallet and IOTA is shown via MetaMask.

from 69 USDPartial✓Ledger Wallet✓Ledger Wallet✓✓Ledger Wallet✓Ledger Wallet✓MetaMask✓Ledger Wallet✓Ledger WalletLedgerBuy on the official site

Trezor

Trezor's coin pages state that Algorand and Hedera are not supported, and IOTA works only through a third-party wallet app. An official Trezor XDC page could not be found, so XDC is not listed.

59-249 USDFull✓Trezor Suite✓Trezor Suite---✓✓Trezor Suite✓Trezor SuiteTrezorBuy on the official site

Keystone

Keystone's firmware changelog names companion apps for XRP, Cardano, IOTA and Stellar, while Algorand, Hedera, Quant and XDC appear only on its generic asset list.

from 149 USDFull✓Keystone Nexus✓xBull Wallet---✓Nightly Wallet-✓Keystone NexusKeystoneBuy on the official site

Tangem

Tangem's help center lists six of the eight coins, with Hedera available only for Tangem hardware wallets, and no IOTA or Quant support was found.

from 59.9 USDPartial✓Tangem app✓Tangem app✓Tangem app✓Tangem app✓Tangem app--✓Tangem appTangemBuy on the official site

The wallets verified here are Ledger, Trezor, Keystone and Tangem. Coin support differs: for example, Trezor's pages state Algorand and Hedera are not supported, and Tangem's help center lists six of the eight coins. Check your exact coin before ordering.

Step 2 - Inspect the package and the device

Do this before you connect anything.

  • Ledger: the recovery sheet in the box must be blank. A device that comes with a phrase or PIN already set must not be used; Ledger says it never provides either. [2]
  • Trezor: check that the package is complete and untampered. Trezor devices ship without firmware, so a device that already has firmware installed should not be used. Trezor's guide lists a tamper-evident holographic seal over the USB-C port on the Safe 7 and Model T and over the connector on the Safe 5 and Safe 3, while the Model One has two holographic stickers on the box, so read the guide for your model. [5][6]
  • Keystone: inspect the box for signs of opening, and plan to complete its device verification (labelled skippable, but described as crucial for detecting contamination in transit) when you receive it. We did not find a statement about tamper-evident seals on the cited page. [10]
  • Tangem: the Tangem app checks authenticity when you scan a card, and warns if it detects a counterfeit. [13]

Take photos of the box seals if you want to keep evidence for a dispute. If anything looks wrong, stop and contact the manufacturer from its official site, and do not follow instructions from a card or note in the box that tells you to visit a different address.

Step 3 - Install the official app and update the firmware

Download the companion app only from the manufacturer's official website, then follow the on-screen setup.

  • Ledger: use Ledger Wallet, connect and unlock the device, open My Ledger, and approve any OS update on the device. Ledger notes a very small chance that an OS update resets the device, so confirm your recovery phrase works before updating. [4]
  • Trezor: Trezor Suite installs and verifies firmware; it checks the device's firmware version and RevisionID against a database stored in Trezor Suite and on a remote server, and blocks access with a warning if they do not match. [7]
  • Keystone: firmware is signed, and for file-based updates you can compare the SHA256 value with the official website. [11][12] Some Keystone support pages are older, so check the current page before following menu paths.
  • Tangem: firmware and features are handled through the Tangem app.

Never install firmware from a link in an email, a message or a search ad.

Step 4 - Create the wallet and write the seed phrase

The device must generate the seed phrase and show it to you on its own screen. Ledger tells users to accept only the phrase displayed on the device's secure screen. [2] If a website, an app or a person gives you a phrase, it is a scam.

  1. Choose a PIN on the device. Use something that is not a birthday or sequence, and do not reuse your phone PIN.
  2. Write each word by hand, in order, on the blank card or sheet. Check each word twice against the screen.
  3. Do not photograph it, type it, or say it aloud near a microphone.
  4. Store it as planned in guide 1.

Tangem differs. Tangem's cards come without a private key, which is generated on the card's chip when you create the wallet, and the box contains 2 or 3 cards. A seed phrase is offered as an option ("if you want one"), and Tangem's FAQ says the derived private keys are then uploaded to the cards. We could not confirm from the cited pages that the backup cards give identical access or that seedless is the default, so read Tangem's current documentation before choosing. [13][14]

Step 5 - Paper versus metal backup

Paper is cheap and easy to destroy: Trezor notes that paper backups are vulnerable to fire and flood, and that anyone with a 12- or 24-word backup benefits from a metal copy to offset disaster risk. [9] Metal resists fire and water but can be lost or stolen like paper, and it has the same secrecy requirement.

A balanced approach: write on the card first, then, if you choose, copy the words onto metal stamped or engraved by you, and store the two in different places. Never store the only copy where a single flood, fire or burglary reaches it. No photographs, and no pre-made "recovery" services that require the words to be typed in.

Step 6 - Optional passphrase, and its risks

A is an extra word you add on top of the seed phrase to open a separate, hidden wallet. It protects you if someone finds the words, and it creates a serious risk if you forget it. Trezor states that a forgotten passphrase cannot be recovered by anyone, including Trezor Support; that a mistyped passphrase opens a different, usually empty wallet; and that a passphrase cannot be changed, only moved from. [8] Use it only if you understand these risks.

If you use one, store it separately from the seed phrase and test it with a tiny amount first. If you are a beginner, skipping it for now and learning it later is a reasonable choice. The decision is yours.

Step 7 - Test recovery before putting funds in

A backup you have not tested is a hope. With the wallet still empty:

  1. Note the first receiving address, or the account identifier, that the app shows.
  2. Reset the device, or use a second device of the same model, and restore from your written words.
  3. Confirm that the same address appears. If it differs, the backup or the process has a problem, and you have lost nothing yet.

Ledger provides a Recovery Check that confirms your phrase without wiping the device. [3] For other devices, read the manufacturer's current recovery instructions before wiping. Do the first test with no money in the wallet.

Step 8 - Run the genuine check

On Ledger, open Ledger Wallet, go to My Ledger and select the device: it should show that the device is genuine. [1] Trezor Suite checks the firmware version and RevisionID, and Keystone and Tangem have their own verification steps above. [7][10][13]

Be clear about the limits. A genuine check confirms the device's firmware and secure element are authentic. It does not replace buying from the official store, and it cannot tell you where the box has been. Trezor describes its check as an extra safeguard against counterfeit devices, not as a replacement for buying from authorised sources. [5][7]

Common mistakes

  • Buying second-hand or from a marketplace at a discount. [2][5]
  • Using a pre-filled recovery sheet or a phrase someone gave you. [2]
  • Typing the phrase into a computer, phone or website.
  • Skipping the recovery test and discovering a typo years later.
  • Storing both backups in the same place.
  • Using a passphrase without a plan, then forgetting it. [8]
  • Installing the companion app from a search ad or a link in a message.
  • Ignoring support limits. Some coins need a third-party wallet app, so confirm before you fund.

If something goes wrong

The genuine check or firmware check fails. Stop. Do not enter a seed phrase. Contact the manufacturer through its official site. Trezor Suite shows a warning and restricts access until you contact Trezor Support. [7]

The firmware update stalls. Keep the device connected, retry, and use the desktop app. Ledger recommends the desktop app if a mobile update stalls. [4]

The restored wallet shows a different address. Re-check each word and its order, and any optional passphrase. Do not fund until the test passes.

You lost the device. With the backup you can restore on a new device of a compatible type. Without it, the funds cannot be recovered.

You suspect the box was opened. Do not use the device. Contact the manufacturer. See also guide 10.

Official help articles

  • Ledger - Check that your Ledger device is genuine [1]
  • Ledger - Recovery Check [3]
  • Ledger - Update Ledger OS [4]
  • Trezor - Is my device safe to use? [5]
  • Trezor - Authenticate Trezor Model T [6]
  • Trezor - Firmware authenticity check [7]
  • Trezor - Passphrase issues [8]
  • Trezor - Keeping your wallet backup safe [9]
  • Keystone - Get started and device verification [10]
  • Tangem - How to tell if your Tangem wallet is authentic [13]

Sources

  1. Check that your Ledger device has a genuine secure element with Ledger Wallet - Ledger Support - https://support.ledger.com/article/4404389367057-zd
  2. Scams Targeting Crypto Holders (blank recovery sheet, buying from official sources) - Ledger Support - https://support.ledger.com/article/scams-targeting-crypto-holders
  3. Recovery Check - Ledger Support - https://support.ledger.com/article/360007223753-zd
  4. How to perform a complete update of your Ledger setup - Ledger Support - https://support.ledger.com/article/8458939792669-zd
  5. Is my device safe to use? - Trezor Support - https://trezor.io/support/a/is-my-device-safe-to-use
  6. Check the authenticity of Trezor Model T packaging and contents - Trezor - https://trezor.io/guides/trezor-devices/trezor-model-t/authenticate-model-t
  7. Trezor firmware authenticity check - Trezor Learn - https://trezor.io/learn/security-privacy/how-trezor-keeps-you-safe/trezor-firmware-authenticity-check
  8. Fix passphrase wallet problems in Trezor Suite - Trezor Support - https://trezor.io/support/troubleshooting/trezor-suite-issues/passphrase-hidden-wallets-issues
  9. Keeping your wallet backup safe - Trezor - https://trezor.io/guides/backups-recovery/general-standards/keeping-your-wallet-backup-safe
  10. Get started (device verification) - Keystone - https://keyst.one/get-started
  11. Verify the SHA256 checksum of the firmware update file - Keystone Support - https://support.keyst.one/getting-started/firmware-upgrading/check-the-sha256sum-of-the-firmware-update-file
  12. Firmware checksum verification - Keystone Guide - https://guide.keyst.one/docs/firmware-checksum
  13. How to tell if your Tangem wallet is authentic - Tangem Blog - https://tangem.com/en/blog/post/verify-tangem-wallet-authenticity/
  14. Everything about seed phrases in Tangem Wallet - Tangem Blog - https://tangem.com/en/blog/post/seed-phrase-faq/