Independent resourceNot affiliated with SatoshiLabs. Download Trezor Suite only from the official site.trezor.io
SuiteGuideTrezor Suite, explained

Security & privacy

Trezor Suite security, without the marketing

A hardware wallet removes the biggest attack surface in crypto — keys living on an internet-connected computer. It does not remove the human one. This page is honest about which is which.

Never type your recovery seed into a website or app

Your recovery seed is the master key to your funds. No genuine wallet app, website or support agent will ever ask you to enter it — if a page asks for it, leave immediately.

The one rule that matters most

Your recovery seed is the wallet. Anyone who has it has your funds, forever, without needing your device, your PIN or your computer. Treat those words as cash in an envelope — never typed, never photographed, never stored online.

01

The split between the app and the device

Everything about this security model follows from one design decision: the keys never leave the hardware.

When you create a wallet, the private keys are generated on the device itself and are designed never to be exportable. The app on your computer — Suite, in any of its forms — never holds them. It reads public information from the blockchain, builds transactions for you to inspect, and hands them to the device to be signed.

That means a compromised laptop, a malicious browser extension or a stolen password still does not let anyone spend your coins. They would need you to confirm the transaction on the device, which is why the habit of reading the device screen is the most valuable thing you can learn on this site.

It also means the app can be installed, reinstalled and moved between computers freely. You can plug the same device into a different machine, add the accounts again from the device, and carry on. Nothing critical lives on the computer.

02

What a hardware wallet plus Suite protects against

Real, meaningful protection — provided you use it correctly.

  • Malware that scans your computer for private keys or wallet files: there is nothing on the machine to find.
  • A hacked website or a stolen password: those cannot sign a transaction on your behalf.
  • A tampered destination address on screen: the device shows the real one and waits for your approval.
  • Remote theft of an entire computer: the funds are not on it.
  • Someone photographing the app: discreet mode hides every balance.
  • Old, buggy software: open-source code and frequent signed updates mean fixes are visible and checkable.

03

What it does not protect against

Every one of the losses in the wild falls into this list.

Self-custody moves the responsibility to you. The device protects the keys; it cannot protect you from a decision you make with your own hands.

Confirming without reading

If you approve a transaction you did not verify on the device screen, you have authorised whatever it actually says — including a different address.

Typing your seed somewhere

Restoring a wallet through a website, a browser extension or remote help hands over everything. No legitimate service needs it.

Fake software and fake support

Malicious installers and chat "support" are how attackers get around hardware security entirely — by making you help them.

Losing your only backup

A fire, a flood, a house move or a forgotten hiding place can end access just as completely as a thief. Backups are part of security.

Sharing your PIN and passphrase

Someone with the device and the PIN can move funds. The passphrase is a real, additional secret — keep it separate from the seed.

Trading on a wrong assumption

Nothing here prevents you sending to the wrong network or the wrong person. Crypto transfers are final.

04

PIN, passphrase and backups

Three separate mechanisms that people routinely confuse.

Difference between the device PIN, the passphrase and the recovery seed
MechanismWhat it isWho needs itIf you lose it
Device PINA code you enter on the device itself to unlock itYou, every time you use the deviceRestore the wallet from your recovery seed onto a device (or wipe and set up again)
PassphraseAn extra word or phrase that creates an entirely separate hidden walletOnly you, optionallyWithout it, the passphrase-protected wallet is unreachable — the standard seed does not open it
Recovery seedThe 12, 20 or 24 words that encode your private keysYou, if the device is lost, stolen or brokenFunds remain on the blockchain but become permanently inaccessible to you

The passphrase deserves particular care: a typo, or a lost capital letter, creates a different empty wallet, and your funds sit in a wallet you can no longer open. Write it down with the same discipline as the seed, and keep the two in different places so that a single find or a single fire does not take both.

For backups, the classic single seed is the simplest and still perfectly respectable option. On models that support it, a Shamir backup splits the secret into several shares with a threshold — say, any three of five — so no single location can be robbed for the whole wallet. Either way, test the backup before you rely on it: use the device's own check, and recover onto a spare device if you want certainty.

Metal beats paper, in more than one place

Paper survives a lot except water and fire. A stamped metal plate costs little and survives both. Whatever you use, keep copies in geographically separate, non-obvious places you can actually reach in an emergency.

05

Phishing and seed safety

Since the technology is hard to break, attackers aim at the person holding it.

Wallet phishing has a few well-worn shapes: a fake "wallet validation" page that asks for your recovery words; a support agent who needs to "verify your ownership"; an email pretending to be a security alert with a link; an extension in a browser store that looks like a companion app. All of them want the same thing, and it is always the same 12–24 words.

  • No legitimate wallet, app, exchange or support team asks for your recovery seed or passphrase. Ever.
  • Reach the app through a bookmark you created on the official page — not through search ads or links in messages.
  • Read every transaction on the device screen, address and amount, before you confirm it.
  • Send a small test amount to a new address, especially for large transfers.
  • Be sceptical of anyone who contacts you first about your wallet, whoever they claim to be.
  • Ignore any software, video call or remote-access tool a 'helper' asks you to install.

06

Privacy: what the app can reveal, and how to reduce it

A wallet is pseudonymous, not anonymous. Suite gives you the switches that matter.

To show your balances, Suite has to ask servers about your addresses. By default those are public backend services, which means whoever runs them can, in principle, group your addresses together and pair them with your IP address. Switching on Tor hides the IP; running your own node hides the queries. Neither makes your transactions private on the blockchain itself — that depends on how you use addresses, which is what coin control and fresh receiving addresses are for.

Two smaller points worth knowing. Buying crypto through an in-app partner normally involves identity verification, so the purchase is linked to you, even though the coins end up in your own account. And app analytics can be left off in settings — a one-line privacy win.

07

The practical checklist

Print it, or keep the tab open while you set up.

Do

  • Download only from the official manufacturer page; bookmark it.
  • Write the recovery seed by hand, on paper or metal, at setup time.
  • Verify addresses and amounts on the device screen.
  • Test your backup, and test recovery if you can.
  • Keep the app and firmware updated.
  • Send a small test transaction before a large one.

Never

  • Type your seed into a website, app, chat or support form.
  • Photograph, email or cloud-sync your seed or passphrase.
  • Install a wallet build from a search ad, mirror or file attachment.
  • Approve a transaction without reading the device screen.
  • Share your PIN, or keep the passphrase next to the seed.
  • Trust anyone who contacts you about your wallet first.

08

If something goes wrong

Calm, in order, without making it worse.

If you typed your seed into a website: assume the wallet is compromised. Create a new wallet on a trusted device, write down its new seed, and move your funds to it as quickly as network conditions allow. Do not reuse the old seed, and do not keep sending to the old addresses.

If your computer looks infected: do not sign transactions on it. Set up the new account from a different, clean machine, verify the destination on the device screen, and move the funds across.

If you lost your device but have your seed: buy a replacement, restore from the seed, and check that your accounts and balances return. Then wipe the old device from your list of worries.

If you lost the seed: there is no recovery path. Not through the manufacturer's support team, not through us, and not through any paid "recovery service" that offers to brute-force your words — those offers are aimed at people in exactly this position.

Keep going

Put the theory into practice

The setup and backup guides walk through the same material as a sequence of clicks, in the order that keeps you safe.

Golden padlock resting on a computer keyboard, symbolising wallet security

Ready to get the real app?

Trezor Suite is free to use and is published by the hardware wallet's manufacturer. Download it from the official site — never from an ad, a search result lookalike or a file someone sent you.