What a hardware wallet does, precisely
Your coins are not "in" a wallet; they are on the blockchain, controlled by whoever holds the private key. A hardware wallet is a small computer whose only job is to hold that key and sign transactions with it. The key never leaves the device. Your phone or laptop prepares a transaction, sends it to the device, the device shows you what it is about to sign, you press a button, and the signed transaction goes back out. Malware on the computer can see everything except the key, and cannot sign without your press.
That is the entire security model. It defends against: malware, phishing sites that ask you to sign without showing the details, remote attackers of any kind. It does not defend against: you approving a bad transaction because you did not read the screen, losing the seed phrase, a fake device bought from a reseller, or someone who physically coerces you.
The devices, compared
| Ledger (Nano S Plus / X / Stax / Flex) | Trezor (Safe 3 / Safe 5) | Coldcard (Mk4 / Q) | BitBox02 | Keystone 3 Pro | |
|---|---|---|---|---|---|
| Secure element | Yes | Yes (Safe series) | Yes | Yes | Yes (three) |
| Firmware open source | No (apps are; core OS is not) | Yes | Yes | Yes | Yes |
| Air-gapped option | No (USB / Bluetooth) | No (USB) | Yes (microSD, QR on Q) | No (USB) | Yes (QR only) |
| Bitcoin | Yes | Yes | Yes โ Bitcoin-only device | Yes | Yes |
| Ethereum / ERC-20 / stablecoins | Yes | Yes | No | Yes | Yes |
| TRON / TRC-20 USDT | Yes | No native support | No | No | Yes |
| Monero | Yes, via the official Monero GUI/CLI | Yes, via the official Monero GUI/CLI | No | No | No |
| Zcash | Transparent only | Transparent only | No | No | Shielded (Orchard) via Zashi โ recent |
| Solana | Yes | Yes | No | No | Yes |
| Notable | Largest coin support; 2023 "Recover" opt-in seed-backup service caused controversy | Fully open; Safe 3 is the best-value open device | Bitcoin maximalist tool; strongest air-gap workflow | Simple, Swiss, open | Broadest air-gapped multi-chain support |
Two takeaways. If you hold Monero on hardware, it is Ledger or Trezor with the official Monero software โ nothing else. If you hold USDT on TRON, Ledger or Keystone. If you hold only Bitcoin and want the strictest model, Coldcard.
Setup: where the protection is actually won or lost
- Buy from the manufacturer. Reseller and marketplace units have been tampered with. If the device arrives "pre-set-up" with a seed card already filled in, it is a scam โ a real device generates the seed on first use, in front of you.
- Write the seed on the card, by hand, once. Never photograph it, never type it into anything, never store it in a cloud note. The seed is the wallet; the device is just a signer. Anyone with the seed has everything.
- Store the seed separately from the device โ a metal backup for fire and water, in a second location.
- Set a PIN; consider a passphrase. A BIP-39 passphrase creates a hidden wallet from the same seed; it protects against seed theft and gives plausible deniability under coercion. It also means a forgotten passphrase is permanent loss โ write it down separately.
- Verify addresses on the device screen, every time, for both receiving and sending. This is the one habit that defeats clipboard malware and address poisoning.
- Update firmware from the official app only, and only when the device asks.
Using a hardware wallet with an account-free swap
A swap does not care what kind of wallet you use; it sees addresses. The flow with hardware on both ends:
- Open the pair page โ say BTC โ XMR. Enter the amount; note the limits.
- Receiving address: in your Monero GUI connected to the hardware device, generate a new subaddress; verify it on the device screen; paste it into the form.
- Refund address: a fresh Bitcoin address from your hardware wallet.
- Click Swap now; save the status link.
- In your Bitcoin wallet app, send the exact amount to the deposit address shown. Verify the deposit address on the device screen against the status page before confirming. Choose a fee that confirms in one or two blocks.
- After 2 Bitcoin confirmations the XMR is sent; your Monero GUI shows it after a block or two.
The reverse, XMR โ BTC, works the same way: receiving address from the Bitcoin hardware wallet, verified on screen; deposit sent from the Monero GUI with the device confirming. Stablecoin swaps โ USDT (TRC-20) โ BTC, BTC โ ETH โ follow the same pattern with the corresponding apps.
Privacy note: the companion app
The device holds the key; the companion app (Ledger Live, Trezor Suite, the Monero GUI) talks to the network. Most companion apps use the vendor's servers to fetch balances, which means the vendor learns your addresses. For Bitcoin, connect Sparrow or Electrum to your own node instead; for Monero, point the GUI at your own node or a trusted one over Tor. The network privacy guide covers the options.
Convenience trade-offs, honestly
- Bluetooth and touchscreens (Ledger X/Stax/Flex, Trezor Safe 5, Keystone) are convenient and slightly larger attack surfaces. Not a reason to avoid them; a reason to keep firmware current.
- Air-gapped devices are the most secure and the slowest to use; every transaction is a QR or microSD round-trip.
- Multi-coin support means more firmware, more apps and more updates; a Bitcoin-only device has less to go wrong.
- Mobile use works on all modern devices; the phone becomes the companion, with the same privacy caveat.
Frequently asked questions
Is a hardware wallet necessary for small amounts? Below a few hundred dollars, a well-maintained mobile wallet with a backed-up seed is reasonable. Above what you could not afford to lose, hardware is the standard.
What if the manufacturer disappears? Your seed is standard (BIP-39 for most coins; Monero has its own 25-word format). Any compatible wallet restores it. The device is replaceable; the seed is not.
Can I use one device for Bitcoin, Monero and USDT? Ledger covers all three; Trezor covers Bitcoin and Monero but not TRON. Check the table.
Is a "seed backup service" safe? It sends encrypted shares of your seed to third parties. It is a convenience that reintroduces custodial risk; most security-conscious users decline it.
Does the swap know I used a hardware wallet? No. It sees a deposit from an address and a receiving address; how they are controlled is invisible to it.
BTC โ XMR
USDT (TRC-20) โ BTC
XMR โ BTC