Independent resourceNot affiliated with SatoshiLabs. Download Trezor Suite only from the official site.trezor.io
SuiteGuideTrezor Suite, explained

Security · 5 min read

The Trezor Suite security checklist: 10 things to verify

Run through this before you send anything meaningful. It takes about ten minutes, and every item on it corresponds to a way people actually lose funds.

A single gold-coloured Bitcoin coin on a dark background

Hardware wallets are hard to break into remotely, which is exactly why attackers have moved to the human in front of them: a fake download, a phishing page, a support conversation that ends with the words "just type your seed here". This checklist is aimed at that reality. It is not about the cryptography; it is about the ten moments where a small habit saves a large amount of money.

  1. 1

    The address bar, not the search result

    You are on the manufacturer's own domain, typed by you or opened from a bookmark you created. Sponsored search results and lookalike domains are the top delivery mechanism for malicious wallet builds.

  2. 2

    The app version is current

    Open the about panel and confirm you are on a recent release. Security fixes ship in updates, and an outdated build is the easiest thing for malware to target.

  3. 3

    The device is the one you own

    Same serial, same physical device, same cable from the box. A device that arrived pre-configured, or with a seed included on a card, is compromised by design.

  4. 4

    Your recovery seed is not typed anywhere

    You have not entered it into the app, a website, a browser extension or a support form. The device itself is the only place those words are ever entered.

  5. 5

    The seed is offline and findable

    Written by hand on paper or metal, stored deliberately, with a second copy somewhere physically separate. Not photographed, not in a cloud note, not in an email draft.

  6. 6

    The backup has been verified

    You have run the device's own check, and ideally restored onto a spare device once. A backup you have never tested is an assumption, not a backup.

  7. 7

    The device screen is the last word

    Before confirming any transaction, read the destination address and the amount on the device display. If it disagrees with your computer, stop — the device is the truth.

  8. 8

    New addresses, not reused ones

    Request a fresh receiving address for each payment. It costs nothing and prevents anyone from stitching your income together from the public ledger.

  9. 9

    Privacy switches are deliberate

    You know whether Tor is on, whether the app points at your own node, and whether analytics was left enabled. Defaults are usable; they are not private.

  10. 10

    Somebody else knows what to do

    Written instructions for a trusted person: which hardware wallet you use, where the backup physically is, how to get the app from the official page — and never the seed itself in that document.

The five-minute version

If you only remember three things

  • Install the app from the official page and reach it through your own bookmark.
  • Never type your recovery seed into anything other than the hardware device itself.
  • Read the address and amount on the device screen before you confirm every transaction.

Keep the list somewhere you will see it

The habits decay. Re-reading this once before a large transfer — and once a year otherwise — is enough to keep them sharp. The security page has the longer version, and the backup guide covers item five and six in detail.

Ready to get the real app?

Trezor Suite is free to use and is published by the hardware wallet's manufacturer. Download it from the official site — never from an ad, a search result lookalike or a file someone sent you.