Self-custody basics

How to set up a Trezor hardware wallet without giving away your keys

What a Trezor setup actually asks of you, and the moments in the process where people lose their funds. This is an independent guide: we are not Trezor, and nothing here will ever ask you for a recovery phrase.

  • By the Self-Custody Guide team
  • Updated 6 October 2026
  • About 8 minutes
Black electronic device with green bar display beside a blank notepad and pen on a dark slate board.

What a hardware wallet setup actually does

A Trezor is a small device that keeps your private keys somewhere your computer cannot reach them. Setting one up does four things: it confirms the device is genuine, writes the firmware, generates a brand new wallet, and shows you the recovery phrase that can restore it. Everything else in the process is detail around those four.

It helps to be precise about what the device is. A hardware wallet does not hold coins; it holds the keys that prove the coins on the public blockchain are yours. That distinction is why the recovery phrase matters more than the device, and why losing the device is an inconvenience while losing the phrase is final.

The one rule that protects everything

Your recovery phrase is the wallet. Whoever has it can move your funds without the device, without your PIN, and without asking you. Every legitimate setup flow generates that phrase on the device itself and asks you to write it down on paper. None of them ask you to type it into a website, a chat window, a support form, or a browser extension. If a page is asking for it, that page is the attack, and there is no version of this where it is not.

Where people actually lose money

Losses in self-custody almost never come from broken cryptography. They come from five ordinary moments:

  • Typing the recovery phrase into a site that imitates an official setup page.
  • Buying a device that arrived already initialised, or with a printed phrase card in the box.
  • Storing the phrase in a screenshot, a password manager, a cloud note, or an email to yourself.
  • Approving a transfer from the software without reading the address and amount on the device screen.
  • Downloading wallet software from a search result, an advertisement, or a link somebody sent you.

Getting the software from the right place

Type the address yourself. The official setup entry point is trezor.io/start, and the official companion software is Trezor Suite. Anything you reach through an advertisement, an email, a direct message, or a search result you did not verify is worth treating as hostile until proven otherwise. If you are not certain you are on the right page, close it and start again from the address in your own hands, and bookmark the real one so you never have to search for it.

After setup, the device is the point

A hardware wallet only helps if you use it as one. Before approving any transaction, compare the address and the amount shown in the software with what appears on the device screen. If the two disagree, stop: that screen is the entire reason the device exists. Update firmware only from inside the official software, with the device in your hand. Keep the device somewhere physically secure, but remember that the PIN guards against a casual find while the recovery phrase is what guards the funds. The phrase is what deserves the safe.

If you have already entered your phrase somewhere

Treat it as compromised, and act today rather than later. Generate a brand new wallet with a new phrase on a device you trust, then move your funds across. Do not reuse or re-enter the exposed phrase, and do not wait to see whether anything moves before you start. Anyone holding it can empty the wallet at any hour, without warning and without you.

The short version

Setting up a hardware wallet is not difficult. It is unfamiliar, which is a different thing, and that unfamiliarity is exactly what the pages imitating these setups depend on. Learn what normal looks like once, keep the phrase offline and out of every device you own, and read the small screen before you approve anything.

The process

What setup asks of you, step by step

Five steps, in the order the device walks you through them. Nothing legitimate deviates from this, which is what makes a deviation easy to recognise.

1

Prepare a private space

Unbox somewhere you will not be overlooked, use a computer you trust, and have somewhere offline to write. This is not a task for a shared, borrowed, or public machine.

2

Connect the device

Connect it and follow the instructions for your model. Read what appears on the device screen, not only what the computer is showing you.

3

Let the device generate the wallet

The keys and the recovery phrase are created on the device itself. Accept firmware only when the device asks for it, and never let a website offer to choose your phrase for you.

4

Write the phrase down, on paper

Record it by hand, in order, and store it where only you can reach it. Never photograph it, never type it into anything, and never keep it in the cloud.

5

Verify on the device, every time

Before approving any transaction, compare the address and the amount in the software with the ones on the device screen. They must match before you press anything.

Common questions

The things people ask before a first setup

If any of this disagrees with what your device or the official documentation is telling you, stop and check there first.

Only if you treat it as untrusted. Wipe it and let it generate a brand new wallet, so that you alone hold the recovery phrase. A device that arrives with a phrase already printed, or with a wallet already set up, should go back to the seller.

Assume it is compromised, because it is. Move everything to a new wallet with a new phrase, generated on a device you trust, as quickly as you can. Do not reuse the exposed phrase, and do not wait for a balance to move before you act.

You restore the wallet from your recovery phrase onto a replacement device. This is why the phrase is the thing to protect: the device is replaceable, the phrase is the wallet. Lose both and the funds are gone, and nobody can recover them for you.

No. Once the allowed attempts are used up the device wipes itself, and you restore from your recovery phrase onto it or onto another device. That reset is a feature rather than a failure: it is what stops somebody who finds the device from guessing their way in.

New guides

New guides, when they are worth your time

One email when a new guide goes up, plus the security notes we think matter. No wallet recommendations, no affiliate links, and never a request for your keys.