Benefits and key features of hardware wallets
Hardware crypto wallet is a physical device for “cold” storage of private keys, kept offline and used to sign transactions securely.
Unlike hot wallets, hardware devices minimize the attack surface: private keys never leave the device, and every transaction is confirmed with physical buttons.
How a hardware wallet works
- Keys are generated and stored only on the device.
- Transactions are signed inside the device and confirmed with buttons.
- Only a signed hash is sent to the network — never the keys themselves.
Principle: Not your keys — not your crypto.
Key advantages
- Suitable for long‑term storage of larger sums — risk is lower than with hot wallets.
- Protection against malware and phishing — keys are inaccessible to the OS and browser.
- Compatible with DeFi and staking — connect via vendor apps and WalletConnect.
Key criteria for choosing a hardware wallet
- Security — the top priority. The device should provide robust protections: PIN and/or passphrase, 2‑factor support, encryption, plus a Secure Element (SE) chip with a high certification level. Some models use CC EAL5+ and above, ensuring resistance to sophisticated hardware attacks. Open‑source firmware is an extra plus that allows community audits.
- Ease of use — a clear, simple UX matters both at setup and in daily use. Intuitive navigation via buttons or a touchscreen makes confirming transactions easier. For beginners, prefer models with a screen that shows all transaction details and a straightforward setup flow via the vendor app.
- Asset support — different models support different sets of coins. Some focus on Bitcoin only; others support hundreds or thousands across multiple networks. Before buying, check that your assets are supported. For example, Ledger devices can store 5,500+ coins and tokens.
- Compatibility & connectivity — verify which OSes and devices the model supports. Most wallets connect to PCs (Windows, macOS, Linux) and smartphones (via Bluetooth or OTG cable for Android). Some devices are USB‑only, while fully air‑gapped options use QR codes — increasing security but requiring a phone camera.
- Price & availability — prices range from ~$50 to $300+. Premium models add advanced features (touchscreen, wireless charging, biometrics, etc.), which may be overkill for newcomers. Don’t skimp on security — choose reputable manufacturers and buy only from official resellers.
What else to consider
Tip: the table below lists key parameters of popular 2024–2025 models.
Comparison table of the best hardware wallets
| Model | Price | # Coins | Compatibility | Highlights | Pros | Cons |
|---|---|---|---|---|---|---|
| Trezor One | ~$65 (59 €) | >1000 | PC Android (OTG) | OLED; 2 buttons no SE; open‑source | Low price simple interface open code | No BT/mobile app fewer new coins slightly weaker without SE |
| Trezor Model T | ~$219 | >1800 | PC Android (OTG) | Touch 1.54″ (color) microSD (Shamir) open‑source | Convenient touch UX Shamir Backup; CoinJoin includes Monero | High price no BT/iOS plastic body |
| Ledger Nano X | $149 | >5500 | PC Android/iOS (BT) | OLED; 2 buttons BT+battery SE CC EAL5+ | Very broad support Ledger Live is convenient certified SE | Closed firmware trust concerns (Recover/leaks) costlier than peers |
| Ledger Stax | $279 | >5500 | PC Android/iOS (BT) | E‑Ink 3.7″ (touch) Qi charging SE EAL6+ | Premium UX large screen high security | Very expensive non‑removable battery closed firmware |
| Coldcard Mk4 | $150 | BTC‑only | PC PSBT: microSD/USB | OLED + keypad 2× SE; no BT NFC (opt.) | Max security for BTC open‑source multisig/PSBT | Bitcoin only harder for beginners pricier than budget models |
| Keystone 3 Pro | $149 | >5500 | Standalone (QR) Android / iOS | 4″ screen; 3× SE fingerprint; no USB/BT self‑destruct | Full air‑gap multisig open‑source | QR‑only data flow bulky mid‑range price |
| BitBox02 | $120 | ~1500 | PC Android (USB‑C) | Compact USB‑C touch sides microSD backup | Swiss quality SE + open‑source handy backup; BTC‑only option | No iOS fewer coins costlier than budget models |
| NGRAVE ZERO | $398 (398 €) | >1000 | Standalone (QR) Android / iOS | 4″ touch; camera SE EAL7; biometrics fully offline | Max protection (EAL7) comfortable UX Graphene backup; DeFi via QR | Very expensive less battle‑tested closed firmware; needs smartphone |
| SafePal S1 | $50 | >30,000 | Standalone (QR) Android / iOS; USB | Screen + camera battery Binance Labs‑backed | Most affordable; simple physical buttons broad coverage | Dated UI infrequent updates small screen/battery |
Note: Prices are indicative and change over time. Warranty is usually 1–2 years. Asset support may be native (in the vendor app) or via third‑party wallets (MetaMask, Electrum, etc.).
🛡️ Multisig: the next level of protection
A hardware wallet solves only part of the problem.
For large holdings, use a 2‑of‑3 setup with devices from different vendors.
For large holdings, use a 2‑of‑3 setup with devices from different vendors.
Trezor One — the legendary “veteran” starter
| 🔌 Connectivity | USB (micro‑USB) no BT/battery | 💰 Coins | >1,000 BTC, ETH, LTC, ERC‑20, etc. |
|---|---|---|---|
| 📟 Screen/controls | Monochrome OLED 2 physical buttons | 🧩 Compatibility | PC: Windows / macOS / Linux Android (OTG) iOS — no |
| 📱 App | Trezor Suite Desktop + Web + Trezor Bridge | 🛡️ Security | Open‑source; no SE PIN, passphrase, offline signing |
In short: Trezor One — the first commercial hardware wallet (2014) by SatoshiLabs. A simple wired device without battery or Bluetooth, with a small OLED and two buttons. Supports 1,000+ assets, works via Trezor Suite on PC/Android. Firmware is open‑source; to protect against physical access, enabling a passphrase is crucial.
Description
Asset support
| Networks | Notes |
|---|---|
| BTC, ETH (+ERC‑20), LTC, etc. | Covers major assets. |
Compatibility
Security 🔐
In practice
- Install Trezor Suite and Trezor Bridge on PC; connect via micro‑USB (Android via OTG).
- Initialize: set your PIN; write down the 24‑word seed; optionally enable a passphrase for a hidden wallet.
- Confirm operations on the device: verify the first/last characters of the address on the OLED before “Confirm.”
Tip: store the paper seed separately from the device; if using a passphrase, record and store it separately from the seed.
Pros
Cons
✅ Bottom line: an excellent first hardware wallet — inexpensive, straightforward, time‑tested. With passphrase enabled and basic hygiene, Trezor One remains a reliable choice for small to mid‑sized portfolios. If you want an SE chip/touchscreen, consider Trezor Safe 3 (budget) or Model T (flagship).
Trezor Model T — SatoshiLabs’ flagship
| 🔌 Connectivity | USB‑C microSD for Shamir no BT/battery | 💰 Coins | ≈1,800+ BTC, ETH, ERC‑20, XRP, ADA; SOL via external wallets |
|---|---|---|---|
| 📟 Screen/controls | 1.54″ color touchscreen touch PIN/Passphrase | 🧩 Compatibility | PC; Android (OTG) iOS — no |
| 📱 App | Trezor Suite Desktop + Web | 🛡️ Security | Open‑source; no SE Shamir Backup, CoinJoin, FIDO2, Passphrase |
In short: Model T is Trezor’s premium version with a color touchscreen: enter PIN/Passphrase directly on the device, Shamir Backup (seed splitting), CoinJoin support and FIDO2. Philosophy — maximum openness (no Secure Element).
Description
Asset support
| # Coins | Highlights |
|---|---|
| ≈1,800+ | BTC, ETH + thousands of ERC‑20; XRP, ADA; Monero (XMR) — Model T only. |
Security 🔐
Tip: enable a passphrase (hidden account) and store Shamir shares in different places.
Pros
Cons
✅ Bottom line: Trezor Model T strikes a great balance between comfort and strong security without closed components. If you want a touchscreen, Shamir backup and open code — this is Trezor’s full‑featured flagship.
Ledger Nano X — the Bluetooth bestseller
| 🔌 Connectivity | USB‑C / Bluetooth battery (standalone use) | 💰 Coins | ≈5,500+ BTC, ETH, ERC‑20, BEP‑20, NFT… |
|---|---|---|---|
| 📟 Screen/controls | OLED 128×64 2 buttons | 🧩 Compatibility | PC; Android / iOS* *iOS — some BT limitations |
| 📱 App | Ledger Live buy/swap/stake/NFT | 🛡️ Security | SE CC EAL5+ BOLOS OS, PIN, Passphrase, U2F opt. Ledger Recover (off) |
In short: Ledger Nano X — a compact “USB stick” with Bluetooth and a battery; support for ≈5,500+ assets, the Ledger Live ecosystem, and a CC EAL5+ Secure Element. A strong all‑rounder for everyday use.
Description
Security 🔐
Tip: enable a passphrase for a hidden account and buy only from official sellers. On iPhone, use wired mode if you need full control.
Pros
Cons
✅ Bottom line: Ledger Nano X is a “golden mean” of convenience and security. If you want a universal multi‑asset wallet with mobile access and can accept closed firmware, the Nano X is an excellent choice.
Ledger Stax — premium E‑Ink with magnets
| 🔌 Connectivity | USB‑C / Bluetooth Qi wireless charging; battery | 💰 Coins | ≈5,500+ BTC, ETH, ERC‑20, NFT… |
|---|---|---|---|
| 📟 Screen/controls | 3.7″ curved E‑Ink, touch always‑on, custom lockscreen/NFT | 🧩 Compatibility | PC; Android / iOS |
| 📱 App | Ledger Live buy/swap/stake/NFT | 🛡️ Security | SE CC EAL6+ Ledger OS, PIN, Passphrase, BLE 5.2, opt. Ledger Recover (off) |
In short: Ledger Stax — a “mini‑reader” with a large curved E‑Ink display, magnetic stacking body, Qi charging, and an EAL6+ SE. Feature‑wise it’s close to the Nano X, but the UX is elevated: full addresses on screen, touch PIN, personalization.
Description
Security 🔐
Pros
Cons
✅ Bottom line: Ledger Stax — for enthusiasts and pros who want top‑tier usability without compromising security. Comparable security to the Nano line, with much better UX. If budget allows and you want a “luxury” experience, it’s one of the best picks for 2025.
Coinkite Coldcard — maximum paranoia for Bitcoin
| 🔌 Connectivity | USB (power/data) microSD (PSBT, air‑gap) NFC (opt.); no BT/battery/Wi‑Fi | 💰 Coins | BTC‑only experimental LTC/testnets |
|---|---|---|---|
| 🎛️ Screen/controls | monochrome OLED numeric keypad (12 keys) | 🧩 Compatibility | PC offline via microSD/NFC |
| 📱 App | — Electrum, Sparrow, Specter, etc. | 🛡️ Security | 2× Secure Element duress PIN, Brick Me, PIN protections passphrase (BIP‑39), TRNG, tamper sensors |
In short: Coldcard Mk4 — a BTC‑centric wallet with full offline flow via PSBT on microSD (no need for USB/BT). Transparent case, monochrome display, numeric keypad. Inside: 2× Secure Elements, duress PIN, Brick Me, and advanced multisig. Ideal for Bitcoin security maximalists and long‑term storage.
Description
Security 🔐
Asset support
In practice
- PSBT flow (offline): build a transaction in Electrum/Sparrow/Specter → export PSBT to microSD → insert card into Coldcard and sign → return the file to PC/phone and broadcast.
- Multisig: use Coldcard as one key in a 2‑of‑3, etc.; the device shows which signatures are attached.
- Watch‑only: export xpub and monitor on PC without exposing private keys.
- NFC (optional): enable only if needed; keep off for maximum isolation.
Pros
Cons
✅ Bottom line: Coldcard Mk4 is the benchmark for “paranoid‑grade” BTC storage and multisig setups. Ideal when convenience is secondary to your threat model.
Note: The Coldcard Q1 (~$200) has been announced — larger screen, keyboard, camera for QR; aimed at secure QR transaction scanning. Wider availability expected through 2024–2025.
Keystone 3 Pro — fully air‑gapped with QR codes
| 🔌 Connectivity | Air‑gap (QR) no BT/USB data removable battery / 4×AAA | 💰 Coins | ≈5,500+ BTC, ETH, ERC‑20, NFT… |
|---|---|---|---|
| 📟 Screen/controls | 4″ touchscreen camera for QR | 🧩 Compatibility | Android / iOS PC: QR from screen |
| 📱 App | Keystone Companion MetaMask Mobile, WalletConnect | 🛡️ Security | 3× Secure Elements open‑source firmware Self‑Destruct, fingerprint Passphrase, PSBT (BTC) |
In short: Keystone 3 Pro is a fully air‑gapped wallet with a QR scanner and 4″ touchscreen: no Bluetooth or USB data — QR only. Inside are three Secure Elements, plus fingerprint unlock and a tamper self‑destruct. Multi‑asset support on par with Ledger (≈5,500+), direct integration with MetaMask Mobile and WalletConnect, and PSBT + multisig for BTC.
Description
Asset support
Security 🔐
In practice
- Install Keystone Companion (Android/iOS) and create a wallet on the device.
- Sending: the app prepares a transaction → shows a QR → Keystone scans and signs offline → displays a response QR → the app scans and broadcasts.
- Alternative: for large payloads, export via microSD instead of QR.
Pros
Cons
✅ Bottom line: Keystone 3 Pro suits those who want maximum air‑gap without giving up multi‑asset support and mobile DeFi. Great as a cold vault paired with MetaMask Mobile and as a node in multisig setups. Compared to Ledger — stronger threat model (no cable/BT), but less “one‑click” simplicity.
BitBox02 — Swiss quality and minimalism
| 🔌 Connectivity | USB‑C microSD (backup) no BT/battery | 💰 Coins | ≈1,500+ ERC‑20 |
|---|---|---|---|
| 🎛️ Screen/controls | OLED touch‑sensitive sides | 🧩 Compatibility | PC Android (USB‑C) |
| 📱 App | BitBoxApp | 🛡️ Security | SE ATECC608A open‑source; Anti‑Klepto; U2F |
In short: BitBox02 — a compact “USB key” with OLED and touch sides. Two variants: Multi Edition (multi‑asset) and Bitcoin‑only Edition (minimal attack surface). One‑file backup on microSD; open‑source firmware; separate Secure Element.
Description
Asset support
| Edition | # Coins | Networks / Notes |
|---|---|---|
| Multi | ~1,500+ (ERC‑20) | BTC, ETH, LTC, ADA, etc.; all ERC‑20 (USDT/USDC, etc.). |
| BTC‑only | BTC | Bitcoin only; Lightning via third‑party apps; reduced attack surface. |
Compatibility
Security 🔐
In practice
- Install BitBoxApp (Windows/macOS/Linux/Android) and connect via USB‑C.
- Initialize: the device generates a seed; the app offers an automatic backup to microSD (included) — remove and store separately.
- On‑device confirmations: touch sides — left/right tap = “←/→”, simultaneous touch = “OK/confirm.”
- Verify addresses: the screen is small but crisp; check the first/last characters and scroll to view the full address as needed.
💡 Tip: before your first send, practice the side‑touch gestures so you can hit “OK” confidently.
Pros
Cons
✅ Bottom line: an elegant, secure choice focused on BTC/ETH and ERC‑20 with a convenient microSD backup. If you need Bluetooth/iOS or the broadest asset list, consider Ledger Nano X/S Plus or the new BitBox Nova (BT + iOS, EAL6+ SE).
NGRAVE ZERO — ultimate offline protection
| 🔌 Connectivity | Air‑gap (QR) USB‑C: charging/firmware | 💰 Coins | ~1,000+ |
|---|---|---|---|
| 📟 Screen/controls | 4″ touchscreen 480×800; QR camera | 🧩 Compatibility | Android / iOS mobile app |
| 📱 App | Liquid WalletConnect; MetaMask/Rabby via QR | 🛡️ Security | SE EAL7 NGRAVE OS; tamper sensors; Perfect Key (biometrics + sensors) |
In short: NGRAVE ZERO is a fully offline “smartphone‑like” wallet with a 4″ screen and camera. No Wi‑Fi/Bluetooth/USB data; QR only. Certified EAL7 Secure Element, custom NGRAVE OS, tamper sensors. Backup via the Graphene steel set (two plates). Supports ~1,000+ assets; managed through the Liquid app (Android/iOS) with DeFi integrations.
Description
Security 🔐
Asset support
In practice
- Install NGRAVE Liquid (Android/iOS) and create the wallet on the device.
- Perfect Key: follow prompts — ZERO mixes RNG with your fingerprint and sensor data to form the seed.
- Sending: build the tx in Liquid → show a QR → ZERO scans and signs → ZERO displays a response QR → scan it in Liquid to broadcast.
- Backup: use Graphene (two steel plates) or a classic paper/metal solution; store parts separately.
- Charging/updates: via USB‑C; no data over cable.
Pros
Cons
✅ Bottom line: a solution for “hodling” large holdings with maximum security. The ZERO + Graphene combo provides both digital and physical resilience; for day‑to‑day multi‑asset use/budget, Ledger/Trezor/Keystone are more practical.
Other noteworthy hardware wallets
SafePal S1 — budget air‑gap with QR
| 🔌 Connectivity | Air‑gap (QR); opt. USB | 💰 Coins | >30,000 |
|---|---|---|---|
| 📟 Screen/controls | Screen + camera; buttons | 🧩 Compatibility | Android / iOS |
| 📱 App | SafePal App | 🛡️ Security | SE chip; closed firmware |
Pros
Cons
In short: a great “first” cold wallet when saving money and needing many networks.
Trezor Safe 3 — affordable Trezor with SE
| 🔌 Connectivity | USB; no BT | 💰 Coins | Hundreds/thousands |
|---|---|---|---|
| 📟 Screen/controls | OLED; 2 buttons | 🧩 Compatibility | PC; Android (OTG) |
| 📱 App | Trezor Suite | 🛡️ Security | Secure Element + open‑source stack |
Pros
Cons
In short: the “people’s” Trezor for 2025 — great for starting and long‑term use.
Blockstream Jade — open‑source, USB/BT/QR
| 🔌 Connectivity | USB / Bluetooth / QR | 💰 Coins | BTC + some altcoins |
|---|---|---|---|
| 📟 Screen/controls | Screen; buttons; camera | 🧩 Compatibility | PC; Android / iOS |
| 📱 App | Green / third‑party | 🛡️ Security | No classic SE; OSS hardware/software |
Pros
Cons
Foundation Passport (Batch 2) — BTC‑focused with friendly UX
| 🔌 Connectivity | Air‑gap (QR) | 💰 Coins | BTC‑only |
|---|---|---|---|
| 📟 Screen/controls | Color screen; keypad | 🧩 Compatibility | Works with BTC software |
| 📱 App | Sparrow/Specter, etc. | 🛡️ Security | SE + open‑source; strong tamper design |
Pros
Cons
Tangem Wallet — an NFC “smart card” instead of a key‑fob
| 🔌 Connectivity | NFC (card chip) | 💰 Coins | Multi‑asset |
|---|---|---|---|
| 📟 Screen/controls | No screen; via smartphone | 🧩 Compatibility | Android / iOS |
| 📱 App | Tangem App | 🛡️ Security | SE EAL6+; firmware immutable (closed) |
Pros
Cons
Recommendations: choosing a hardware wallet
For beginners & everyday use
For power users, DeFi/NFT
For maximum security of large holdings
Important:Always verify addresses on the device screen, keep your seed offline (ideally in metal), and never share PIN/seed under any circumstances.
Conclusion
One‑paragraph takeaway: Hardware wallets are “digital safes” for cold storage. They isolate private keys and protect assets from remote attacks and centralized‑platform risks. The market offers solutions for every scenario — from budget models for starters to premium devices for maximum paranoia.
Why it matters
Practical recommendations
- Buy only from official resellers.
- Initialize the device yourself, write the seed offline (preferably on metal), and store copies in different places.
- Enable PIN and Passphrase (25th word), especially for large amounts.
- Make a test transaction with a small amount before moving the full balance.
- Update firmware and apps only from official sources.
- Verify addresses on the device screen before every confirmation.
- Disable wireless interfaces if you don’t need them, or choose fully offline solutions (QR/PSBT).
- For large holdings consider multisig (2‑of‑3 with different devices/vendors).
Tip: the best hardware wallet is the one you know how to use correctly. Spend time with the documentation and the vendor’s learning materials.
| 🗝️ Do |
|
|---|---|
| 🚫 Avoid |
|
Bottom line: cold storage is basic financial hygiene in crypto. A properly configured hardware wallet will serve you for years and give peace of mind for long‑term investments.
❓ FAQ
How do I back up a seed phrase safely: Shamir, passphrase, metal — which to choose?
Bottom line: for regular sums — metal + a duplicate in another location; for large sums — metal + passphrase or Shamir 2‑of‑3/3‑of‑5. Always test recovery.
Minimum: write the seed offline (no photos/scans), make two sets, and store them separately. Metal backups withstand fire/water. USB, Bluetooth or QR (air‑gap): what’s actually safer and when to use which?
Bottom line: maximum isolation — QR/PSBT; USB is safe if you verify on‑device; BT is convenient, but keep it off when not needed.
What if my computer/phone is infected but my hardware wallet is “clean”?
Bottom line: keys on the device are safe, but the interface may have tampered details. Move operations to a “clean” host and, if necessary, migrate funds to a new seed.
How to use DeFi/NFT safely with MetaMask and a hardware wallet?
Bottom line: separate “storage” and “activity” addresses, sign EIP‑712 only, limit allowances, always use a hardware key.
What is critical to verify on the device screen before signing?
Bottom line: recipient address, asset/amount, network/chainId, fees, contract method/spender and special fields (Tag/Memo).
When does multisig make sense, and how to build cross‑vendor (Ledger + Trezor + Coldcard)?
Bottom line: for large sums — 2‑of‑3 with devices from different vendors and geographically separated keys/backups.
How to plan inheritance: instructions, lawyers, timelocks?
Bottom line: separate plan: legal will + technical instructions for heirs; do not put the seed directly into the text of the will.