1. How the recovery seed actually works
During start-up, your device generates a random sequence of words — the recovery seed. Those words are a human-readable form of the master key behind every account the device holds. Anyone who knows the words can rebuild the wallet on any compatible device, without your Trezor, your PIN or your computer. That is why the seed is the only thing worth protecting absolutely.
A few consequences follow directly from that, and they are worth reading twice:
- The seed is the wallet, the device is just a signer. If the device is lost, stolen or destroyed, the coins are not: you restore from the seed.
- A PIN protects the device, not the seed. Someone who finds your paper does not need the device at all.
- No institution can undo a seed leak. There is no chargeback, no support escalation, no reversal. Confirmations are final and instant.
- The words only ever belong in two places: generated on the device or screen you trust, and written on offline physical backup.
Depending on the model and the backup type you selected in step 5 of set-up, you will have 12, 20 or 24 words. All of them are equally restorable; longer seeds are not "safer" in any practical sense, they simply encode more entropy.
2. Storing the seed so it survives real life
The threat you are designing against is not a Hollywood hacker. It is fire, flood, a house move, a forgetful decade, and a burglar with five minutes in your study.
Good storage
- Hand-written on paper, in your handwriting, in ink
- Two copies, kept in two separate places
- A stamped metal backup for fire and water resistance
- A sealed envelope you would notice if it were opened
- Stored separately from the PIN and the device itself
Storage that will fail you
- Photos of the seed card, including "deleted" ones
- Cloud notes, email drafts, chat messages to yourself
- Password managers and browser form autofill
- Typing it into any website for "verification" or "validation"
- Both copies in one drawer, one safe or one house
If you ever digitised the seed, treat the wallet as compromised
A photo that went to a cloud backup, a note synced to a phone, a screenshot in a message thread — any of those means the words may already be in someone else's hands. The fix is not to delete the file; it is to generate a fresh wallet and move the funds.
3. The PIN: strong against the person holding your device
The PIN is entered on the device, usually on a scrambled keypad layout the device generates, so a keylogger on the computer learns nothing useful about it. Its job is narrow but important: an attacker with your device in their hands cannot spend from it.
- After a set number of incorrect attempts the device wipes itself. That defensive wipe is what makes a short PIN acceptable — but it also means a forgotten PIN equals a restore.
- Never store the PIN next to the seed, and never label the two in a way that connects them.
- A PIN is not a substitute for the passphrase feature, and neither one protects the written seed.
4. The passphrase: powerful, and easy to lose
A passphrase is a word or short sentence you type after the seed, which derives an additional hidden wallet. Two properties make it attractive:
- It is not stored on the device. Your seed backup alone, in someone else's hands, does not reveal the wallet.
- It is deniable. The seed without the passphrase opens a different, valid wallet — useful if someone compels you to unlock.
And the same properties are the risk:
- Forget it, or mistype it, and the funds in that wallet are gone permanently — no recovery path exists.
- Every character matters, including spaces, capitalisation and the character set.
- Back it up with at least the seriousness of the seed, and store it in a different place.
Our advice for a first wallet: set the PIN, skip the passphrase, and revisit it once you are comfortable restoring from your seed.
5. Supply chain and firmware
A hardware wallet can only be trusted if it came from a trustworthy origin and runs software you know the provenance of.
- Buy from the official shop or a listed authorised reseller — not a marketplace, not a second-hand listing.
- Check the packaging seal and holographic elements before opening, and keep the order confirmation.
- A new device should offer to create a wallet. If it already holds one, return it.
- Install firmware through Trezor Suite, which verifies the signature of each release before writing it.
- Download Trezor Suite only from the official site, and check the address bar each time you do.
No legitimate process needs your seed words
Not a firmware update, not a data migration, not a "security check", not a new device. Every request for those words is a theft attempt in progress. There is no exception to this rule.
6. Scams aimed at wallet owners
Attacks against self-custody are overwhelmingly social. They arrive as a search advert, a direct message, a "support" reply, or a site that looks exactly like the real one.
| What it looks like | How it works | Your move |
|---|---|---|
| A search advert for "trezor start" | A near-identical domain collects seed words or serves a tampered app | Ignore ads; type the address or use a bookmark |
| "Wallet validation" or "sync your wallet" | A page asks you to enter your seed "to reconnect" | Close it. No wallet ever needs this |
| Support that messages you first | Fake accounts offer help, then ask for the seed or a "remote session" | Real support never initiates contact and never asks for the seed |
| Fake giveaways and airdrops | You are told to "confirm" the wallet by entering the phrase | There is no such thing as a claim that needs your seed |
| A "new Trezor" with a filled-in seed card | The device was initialised by someone else before shipping | Return it; the seed is known to the seller |
| Clipboard and address-swapping malware | The pasted destination address is silently replaced | Always verify the address on the device screen before approving |
| Lookalike domains and homoglyphs | One letter differs, or a Unicode character mimics one | Bookmark the real site and read the address character by character |
7. Physical security and travel
- Keep the seed backup somewhere you would notice an intrusion, and somewhere that survives a fire.
- Do not discuss your holdings publicly — a wallet is not worth stealing, but a seed is.
- In transit, carry the device separately from the seed backup. Your funds need the seed, never the device.
- If you cross borders or face any risk of coercion, a passphrase on top of the seed gives you a plausible wallet to open.
- A safe-deposit box is a reasonable home for one copy of the seed — never the only copy.
8. If you think something went wrong
- Do not enter the seed anywhere to "check". There is nothing to check, and entering it is the attack.
- If the seed may have been exposed — a photo, a typed field, a shared screen — set up a fresh wallet on the device.
- Write down the new seed properly, verify it, then move all funds to the new wallet in a small test transaction first.
- Only after the funds are confirmed on the new wallet should you treat the old seed as retired. Never reuse it.
- If you typed the seed into a website, assume the wallet is being emptied automatically and move fast.
9. The short checklist
- Seed written by hand, twice, stored in two offline locations
- No digital copy exists anywhere — no photo, note, cloud sync or password manager entry
- PIN set and stored separately from the seed
- Backup verified through Suite before any deposit
- App and firmware installed only from the official source
- Every address and amount confirmed on the device screen
- Recovery practised once, from the paper backup, on a device you can wipe safely
- Nobody — online or offline — has ever seen or been told the words
Setting up for the first time?
The walkthrough puts these habits in the order you will actually meet them.