Orca Crypto
Safety

Hardware wallets

The single most effective upgrade to your security, and it costs less than a phone case.

Updated 2026-08-308 min readEssential
The short answer

A hardware wallet stores private keys in a dedicated device and signs transactions internally, so the key never reaches your computer. It is worth buying once you hold more than you would be comfortable losing, typically a few thousand dollars. Buy directly from the manufacturer, never secondhand.

How it protects you

With a software wallet, the private key exists on your computer or phone. It is encrypted, but it is there, and malware with sufficient access can potentially reach it.

A hardware wallet generates and stores the key inside a chip that has no mechanism for exporting it. When you transact, the unsigned transaction goes to the device, the device signs it internally, and only the signature comes back. The key never leaves.

The second screen matters as much as the chip
It also gives you a second screen. Malware can change what your computer displays, and it cannot change what the device shows. Always verify the destination address on the device screen, not the browser.

When to buy one

HoldingsRecommendation
Under a few hundred dollarsA software wallet with a well stored seed phrase is proportionate
A few hundred to a few thousandWorth considering. The device costs less than a bad week
Above a few thousandYes. This is the clearest cost to benefit decision in crypto
Substantial holdingsYes, plus a multisig and a documented recovery plan

Ledger or Trezor

Ledger

The most widely supported

  • Supports the widest range of assets and chains
  • Secure element chip, certified against physical attack
  • Works smoothly with MetaMask, Phantom and most wallets
  • Compact, and the mobile experience is good
  • Firmware is closed source, which some people will not accept
  • A 2020 customer data breach exposed buyer contact details, and phishing followed

Trezor

Fully open source

  • Firmware is open source and auditable end to end
  • Excellent Bitcoin support and tooling
  • Shamir backup on some models, which is a genuinely better recovery scheme
  • Long track record and a strong reputation for transparency
  • Fewer supported chains than Ledger
  • Older models lack a secure element, so physical access is a bigger concern

Both are legitimate. Choose Ledger for breadth of asset support, Trezor if open source firmware matters to you. Either is a large improvement over software alone.

Buying safely

This is not paranoia
Buy directly from the manufacturer website. Never from a marketplace, never secondhand, never from a third party seller offering a discount. A tampered device can arrive preloaded with an attacker recovery phrase, and everything you send to it goes straight to them. This attack has happened to real people.
  1. Order from the official site

    Manufacturer direct, always.

  2. Check the packaging

    Look for tamper evidence. Modern devices also verify their own firmware authenticity on first boot.

  3. Generate a new seed on the device

    The device creates the phrase. If a device arrives with a phrase already written on a card, it is compromised. Destroy it and contact the manufacturer.

  4. Write the phrase by hand

    On the supplied card or, better, on steel. Two copies, two locations.

  5. Update firmware before funding

    Do this through the official app, then verify the device is genuine.

  6. Send a small test amount

    Confirm it arrives and confirm you can send it back out. Then move the rest.

What it does not protect against

  • Signing a malicious transaction. If you approve a drainer contract, the hardware wallet signs it faithfully. Read the device screen.
  • Losing the recovery phrase. The device is a key holder, not the key. Lose the phrase and lose the device, and the funds are gone.
  • Phishing. If you type your recovery phrase into a fake support page, the hardware is irrelevant.
  • Physical coercion. A passphrase protected hidden wallet is the usual mitigation, with its own risks.

Common questions

Which hardware wallet should a beginner buy?

Either Ledger or Trezor. Ledger if you hold assets across many chains, Trezor if open source firmware matters to you. Both are far better than software alone.

What happens if the device breaks?

Nothing, provided you have the recovery phrase. Buy a replacement, restore, and everything comes back. The phrase also works in a different manufacturer device, because the standard is shared.

Can I use a hardware wallet with MetaMask?

Yes. You get the MetaMask interface while the key stays in the device and every transaction is confirmed on its screen. This is the recommended setup for anyone using DeFi with real money.

Is a hardware wallet overkill for a small amount?

Below a few hundred dollars, probably. The cost is fixed while the protection scales, so it becomes obviously worthwhile fairly quickly.

Where to go next

Get a second pair of eyes on your setup

A security session reviews what you hold, where it sits, what approvals are open and what would happen if your laptop were compromised tomorrow. Most people find at least one thing worth fixing.