Encyclopedia Bitcoin basics · Entry 186
Hardware wallets: what the device protects and what it cannot check
In this article
At a glance
Key facts
Keep the host and signer distinct
An online application can discover outputs, estimate a fee and propose a transaction. The signer needs enough information to check the inputs, outputs and authorization policy before approving. The signed result can then return to the host for broadcast.
Keeping keys away from the host reduces one exposure path. It does not make every file, firmware update or signing request safe, and it does not prevent the user from approving the wrong destination.
The screen should match the intended payment
Imagine a 75,000-satoshi request. Malware changes the destination before it reaches the device. The device may faithfully display that changed destination: its value is that you can compare the actual proposed spend with a trusted request. Approving without comparison defeats that protection.
For receiving, a supported device can display its own generated address. Compare that with the address the host asks you to share. Trezor’s documentation explicitly distinguishes these checks from knowing who controls an outside address.
Protect the backup as well as the device
A lost device is not necessarily lost funds if the required recovery material and wallet configuration survive. Conversely, someone with enough recovery secrets can bypass the need to steal the physical device. A device PIN and a mnemonic passphrase have different purposes.
Record the supported recovery procedure and any additional policy information. Do not assume every hardware wallet uses the same mnemonic format or that a single participant’s seed reconstructs a multisignature wallet.
Direct answers
Questions people ask
Are the bitcoins physically inside the hardware wallet?
No. Outputs are recorded on the chain. The device holds or derives keys used to satisfy spending conditions; the host can display the same public record without possessing those keys.
Can a hardware wallet stop me from paying a scammer?
It can help verify the transaction it signs, but a valid destination can belong to a scammer. You must establish the intended recipient independently and check that the displayed payment matches that intent.
Inspect the evidence
The answer and key facts have stable claim links. These records retain the scope and qualification when reused.
A hardware wallet keeps signing keys in a dedicated device and authorizes transactions through its supported interface. A host application can prepare and broadcast payments without holding those keys. The device display helps you check what will be signed, but it cannot determine whether an outside recipient is honest. Backup exposure, unsupported transaction details and the device’s own security remain important.
Educational explanation. Product-specific behavior is scoped to the cited documentation, checked 2026-10-02.
Scope: Bitcoin · data through 2026-10-02. Verification: verified · 2026-10-02T19:29:20.637Z.
Link to this claimDevice role: Protect keys and authorize supported spends
Scope: Bitcoin · data through 2026-10-02. Verification: verified · 2026-10-02T19:29:20.637Z.
Link to this claimHost role: Prepare requests and relay signed transactions
Scope: Bitcoin · data through 2026-10-02. Verification: verified · 2026-10-02T19:29:20.637Z.
Link to this claimDisplay limit: It confirms transaction data, not a merchant’s honesty
Scope: Bitcoin · data through 2026-10-02. Verification: verified · 2026-10-02T19:29:20.637Z.
Link to this claimRevision history
- — First publication after primary-source research and separate automated verification.
Source register
Sources and references
Retrieval dates and locators are recorded individually.- Securing your walletBitcoin.org
Backup scope, online exposure, offline signing, custody and software update practices.
Locator: Be careful with online services; Backup your wallet; Encrypt your wallet; Offline wallet for savings; Hardware wallets; Keep your software up to date · Retrieved: 2026-10-02T18:53:53.659ZOpen source - Trezor’s Trusted DisplayTrezor
Manufacturer explanation of device display checks and the limits of a host-computer screen.
Locator: Trusted display article: on-device verification steps and limits of what the device verifies · Retrieved: 2026-10-02T18:53:56.900ZOpen source - Partially Signed Bitcoin Transaction FormatBitcoin Improvement Proposals
Offline signing workflow, UTXO information and separate signing/finalization/broadcast steps.
Locator: Roles; Creator; Signer; Transaction Extractor · Version / scope: Pinned BIPs revision · Retrieved: 2026-10-02T18:53:54.151ZOpen source - Hierarchical Deterministic WalletsBitcoin Improvement Proposals
Deterministic key derivation, backup scope and public/private child derivation.
Locator: Motivation; Extended keys; Security · Version / scope: Pinned BIPs revision · Retrieved: 2026-10-02T18:53:54.013ZOpen source - Mnemonic code for generating deterministic keysBitcoin Improvement Proposals
Entropy and checksum table, intended computer-generated randomness and NFKD seed derivation.
Locator: Generating the mnemonic; From mnemonic to seed · Version / scope: Pinned BIPs revision · Retrieved: 2026-10-02T18:53:54.120ZOpen source - TransactionsBitcoin developer documentation
Inputs, outputs, authorization, change, coinbase exceptions and fee accounting.
Locator: Introduction; Spending An Output; P2PKH Script Validation; Multisig; Transaction Fees And Change; Avoiding Key Reuse · Version / scope: Developer guide; historical implementation details require qualification · Retrieved: 2026-10-02T18:53:53.759ZOpen source
Research and drafting use AI assistance. A separate automated review checks claims against primary sources; no external expert or named human review is implied. Publication, substantive editing, source retrieval and verification are recorded separately. This version was independently checked by an automated reviewer on 2 October 2026.
Editorial method and correctionsDegrees of Satoshi editorial project. “Hardware wallets: what the device protects and what it cannot check.” Published 2026-10-02; updated 2026-10-02. https://degreesofsatoshi.com/encyclopedia/hardware-wallets-explained/