{
  "$schema": "https://degreesofsatoshi.com/encyclopedia/schemas/article-v1.json",
  "schemaVersion": "1.0.0",
  "id": "hardware-wallets-explained",
  "canonical": "https://degreesofsatoshi.com/encyclopedia/hardware-wallets-explained/",
  "collection": "bitcoin",
  "title": "Hardware wallets: what the device protects and what it cannot check",
  "description": "Understand hardware-wallet signing, device-screen checks and recovery without assuming the hardware can authenticate every request.",
  "aliases": [
    "how hardware wallets work",
    "how hardware wallets work explained"
  ],
  "dates": {
    "published": "2026-10-02",
    "modified": "2026-10-02",
    "verified": "2026-10-02T19:29:20.637Z",
    "dataAsOf": "2026-10-02"
  },
  "authorship": {
    "publisher": "Degrees of Satoshi editorial project",
    "process": "AI-assisted research and drafting with a separate automated source-verification pass; no external expert or named human review is implied."
  },
  "quickAnswer": {
    "text": "A hardware wallet keeps signing keys in a dedicated device and authorizes transactions through its supported interface. A host application can prepare and broadcast payments without holding those keys. The device display helps you check what will be signed, but it cannot determine whether an outside recipient is honest. Backup exposure, unsupported transaction details and the device’s own security remain important.",
    "claimId": "hardware-wallets-explained-quick-answer",
    "sourceIds": [
      "x425-btc-secure",
      "x425-btc-trezor-display",
      "x425-btc-bip174"
    ]
  },
  "keyFacts": [
    {
      "label": "Device role",
      "value": "Protect keys and authorize supported spends",
      "sourceIds": [
        "x425-btc-secure"
      ],
      "id": "device-role",
      "claimId": "hardware-wallets-explained-fact-device-role"
    },
    {
      "label": "Host role",
      "value": "Prepare requests and relay signed transactions",
      "sourceIds": [
        "x425-btc-bip174"
      ],
      "id": "host-role",
      "claimId": "hardware-wallets-explained-fact-host-role"
    },
    {
      "label": "Display limit",
      "value": "It confirms transaction data, not a merchant’s honesty",
      "sourceIds": [
        "x425-btc-trezor-display"
      ],
      "id": "display-limit",
      "claimId": "hardware-wallets-explained-fact-display-limit"
    }
  ],
  "prerequisites": [
    "bitcoin-wallets-explained",
    "partially-signed-bitcoin-transactions"
  ],
  "sections": [
    {
      "id": "boundary",
      "heading": "Keep the host and signer distinct",
      "sourceIds": [
        "x425-btc-bip174",
        "x425-btc-trezor-display"
      ],
      "paragraphs": [
        "An online application can discover outputs, estimate a fee and propose a transaction. The signer needs enough information to check the inputs, outputs and authorization policy before approving. The signed result can then return to the host for broadcast.",
        "Keeping keys away from the host reduces one exposure path. It does not make every file, firmware update or signing request safe, and it does not prevent the user from approving the wrong destination."
      ]
    },
    {
      "id": "review",
      "heading": "The screen should match the intended payment",
      "sourceIds": [
        "x425-btc-trezor-display"
      ],
      "paragraphs": [
        "Imagine a 75,000-satoshi request. Malware changes the destination before it reaches the device. The device may faithfully display that changed destination: its value is that you can compare the actual proposed spend with a trusted request. Approving without comparison defeats that protection.",
        "For receiving, a supported device can display its own generated address. Compare that with the address the host asks you to share. Trezor’s documentation explicitly distinguishes these checks from knowing who controls an outside address."
      ]
    },
    {
      "id": "recovery",
      "heading": "Protect the backup as well as the device",
      "sourceIds": [
        "x425-btc-secure",
        "x425-btc-bip32",
        "x425-btc-bip39"
      ],
      "paragraphs": [
        "A lost device is not necessarily lost funds if the required recovery material and wallet configuration survive. Conversely, someone with enough recovery secrets can bypass the need to steal the physical device. A device PIN and a mnemonic passphrase have different purposes.",
        "Record the supported recovery procedure and any additional policy information. Do not assume every hardware wallet uses the same mnemonic format or that a single participant’s seed reconstructs a multisignature wallet."
      ]
    }
  ],
  "faq": [
    {
      "question": "Are the bitcoins physically inside the hardware wallet?",
      "answer": "No. Outputs are recorded on the chain. The device holds or derives keys used to satisfy spending conditions; the host can display the same public record without possessing those keys.",
      "sourceIds": [
        "x425-btc-dev-transactions",
        "x425-btc-bip32"
      ]
    },
    {
      "question": "Can a hardware wallet stop me from paying a scammer?",
      "answer": "It can help verify the transaction it signs, but a valid destination can belong to a scammer. You must establish the intended recipient independently and check that the displayed payment matches that intent.",
      "sourceIds": [
        "x425-btc-trezor-display"
      ]
    }
  ],
  "claims": [
    {
      "id": "hardware-wallets-explained-quick-answer",
      "articleSlug": "hardware-wallets-explained",
      "statement": "A hardware wallet keeps signing keys in a dedicated device and authorizes transactions through its supported interface. A host application can prepare and broadcast payments without holding those keys. The device display helps you check what will be signed, but it cannot determine whether an outside recipient is honest. Backup exposure, unsupported transaction details and the device’s own security remain important.",
      "sourceIds": [
        "source-ccf126c494bfe748",
        "source-6d1aa1923394141c",
        "source-5790dff0294c8035"
      ],
      "sourceLocators": [
        {
          "sourceId": "source-ccf126c494bfe748",
          "locator": "Be careful with online services; Backup your wallet; Encrypt your wallet; Offline wallet for savings; Hardware wallets; Keep your software up to date"
        },
        {
          "sourceId": "source-6d1aa1923394141c",
          "locator": "Trusted display article: on-device verification steps and limits of what the device verifies"
        },
        {
          "sourceId": "source-5790dff0294c8035",
          "locator": "Roles; Creator; Signer; Transaction Extractor"
        }
      ],
      "scope": {
        "collection": "bitcoin",
        "dataAsOf": "2026-10-02",
        "blockHeight": null
      },
      "qualification": "Educational explanation. Product-specific behavior is scoped to the cited documentation, checked 2026-10-02.",
      "evidenceStatus": "documented",
      "verification": {
        "status": "verified",
        "method": "independent automated source review",
        "checkedAt": "2026-10-02T19:29:20.637Z",
        "reviewer": "Independent automated verification — Codex /root/verify_ethereum_100, separate from the Bitcoin drafting agent",
        "notes": [
          "Checked signer/host separation using BIP174 and Trezor device display guidance. The draft avoids repeating the manufacturer’s absolute security language; a correctly displayed wrong recipient remains wrong, and backup/passphrase assumptions are scoped."
        ]
      }
    },
    {
      "id": "hardware-wallets-explained-fact-device-role",
      "articleSlug": "hardware-wallets-explained",
      "statement": "Device role: Protect keys and authorize supported spends",
      "sourceIds": [
        "source-ccf126c494bfe748"
      ],
      "sourceLocators": [
        {
          "sourceId": "source-ccf126c494bfe748",
          "locator": "Be careful with online services; Backup your wallet; Encrypt your wallet; Offline wallet for savings; Hardware wallets; Keep your software up to date"
        }
      ],
      "scope": {
        "collection": "bitcoin",
        "dataAsOf": "2026-10-02",
        "blockHeight": null
      },
      "qualification": "",
      "evidenceStatus": "documented",
      "verification": {
        "status": "verified",
        "method": "independent automated source review",
        "checkedAt": "2026-10-02T19:29:20.637Z",
        "reviewer": "Independent automated verification — Codex /root/verify_ethereum_100, separate from the Bitcoin drafting agent",
        "notes": [
          "Checked signer/host separation using BIP174 and Trezor device display guidance. The draft avoids repeating the manufacturer’s absolute security language; a correctly displayed wrong recipient remains wrong, and backup/passphrase assumptions are scoped."
        ]
      }
    },
    {
      "id": "hardware-wallets-explained-fact-host-role",
      "articleSlug": "hardware-wallets-explained",
      "statement": "Host role: Prepare requests and relay signed transactions",
      "sourceIds": [
        "source-5790dff0294c8035"
      ],
      "sourceLocators": [
        {
          "sourceId": "source-5790dff0294c8035",
          "locator": "Roles; Creator; Signer; Transaction Extractor"
        }
      ],
      "scope": {
        "collection": "bitcoin",
        "dataAsOf": "2026-10-02",
        "blockHeight": null
      },
      "qualification": "",
      "evidenceStatus": "documented",
      "verification": {
        "status": "verified",
        "method": "independent automated source review",
        "checkedAt": "2026-10-02T19:29:20.637Z",
        "reviewer": "Independent automated verification — Codex /root/verify_ethereum_100, separate from the Bitcoin drafting agent",
        "notes": [
          "Checked signer/host separation using BIP174 and Trezor device display guidance. The draft avoids repeating the manufacturer’s absolute security language; a correctly displayed wrong recipient remains wrong, and backup/passphrase assumptions are scoped."
        ]
      }
    },
    {
      "id": "hardware-wallets-explained-fact-display-limit",
      "articleSlug": "hardware-wallets-explained",
      "statement": "Display limit: It confirms transaction data, not a merchant’s honesty",
      "sourceIds": [
        "source-6d1aa1923394141c"
      ],
      "sourceLocators": [
        {
          "sourceId": "source-6d1aa1923394141c",
          "locator": "Trusted display article: on-device verification steps and limits of what the device verifies"
        }
      ],
      "scope": {
        "collection": "bitcoin",
        "dataAsOf": "2026-10-02",
        "blockHeight": null
      },
      "qualification": "",
      "evidenceStatus": "documented",
      "verification": {
        "status": "verified",
        "method": "independent automated source review",
        "checkedAt": "2026-10-02T19:29:20.637Z",
        "reviewer": "Independent automated verification — Codex /root/verify_ethereum_100, separate from the Bitcoin drafting agent",
        "notes": [
          "Checked signer/host separation using BIP174 and Trezor device display guidance. The draft avoids repeating the manufacturer’s absolute security language; a correctly displayed wrong recipient remains wrong, and backup/passphrase assumptions are scoped."
        ]
      }
    }
  ],
  "sources": [
    {
      "id": "x425-btc-secure",
      "label": "Securing your wallet",
      "publisher": "Bitcoin.org",
      "url": "https://bitcoin.org/en/secure-your-wallet",
      "locator": "Be careful with online services; Backup your wallet; Encrypt your wallet; Offline wallet for savings; Hardware wallets; Keep your software up to date",
      "note": "Backup scope, online exposure, offline signing, custody and software update practices.",
      "checkedAt": "2026-10-02T18:53:53.659Z",
      "contentSha256": "b6017f869461de2150d6b3b328f2ff75aedcd888d7a66cc311acbc243d6ead49",
      "recordId": "source-ccf126c494bfe748",
      "version": null
    },
    {
      "id": "x425-btc-trezor-display",
      "label": "Trezor’s Trusted Display",
      "publisher": "Trezor",
      "url": "https://trezor.io/guides/trezor-devices/trezor-fundamentals/trezor-s-trusted-display-verify-every-address-on-your-device",
      "locator": "Trusted display article: on-device verification steps and limits of what the device verifies",
      "note": "Manufacturer explanation of device display checks and the limits of a host-computer screen.",
      "checkedAt": "2026-10-02T18:53:56.900Z",
      "contentSha256": "b88fbc2dd8d7eb309d6c6aaba742dbedf7dec05e2ac57a230770e14bd2b2d14d",
      "recordId": "source-6d1aa1923394141c",
      "version": null
    },
    {
      "id": "x425-btc-bip174",
      "label": "Partially Signed Bitcoin Transaction Format",
      "publisher": "Bitcoin Improvement Proposals",
      "url": "https://raw.githubusercontent.com/bitcoin/bips/927b6de9915c9262615a6399de51b200f81e5aa4/bip-0174.mediawiki",
      "locator": "Roles; Creator; Signer; Transaction Extractor",
      "note": "Offline signing workflow, UTXO information and separate signing/finalization/broadcast steps.",
      "version": "Pinned BIPs revision",
      "checkedAt": "2026-10-02T18:53:54.151Z",
      "contentSha256": "f2a8e1a9c9e31cc7f607b3c7e2419c63eeccc4bd5b725968cde54ab8cfa1d410",
      "recordId": "source-5790dff0294c8035"
    },
    {
      "id": "x425-btc-bip32",
      "label": "Hierarchical Deterministic Wallets",
      "publisher": "Bitcoin Improvement Proposals",
      "url": "https://raw.githubusercontent.com/bitcoin/bips/927b6de9915c9262615a6399de51b200f81e5aa4/bip-0032.mediawiki",
      "locator": "Motivation; Extended keys; Security",
      "note": "Deterministic key derivation, backup scope and public/private child derivation.",
      "version": "Pinned BIPs revision",
      "checkedAt": "2026-10-02T18:53:54.013Z",
      "contentSha256": "e5e00a8289db2f681052cf24a745320afc225e66b25d1e489a7c884d2fc7f11f",
      "recordId": "source-225ce32b9f96878c"
    },
    {
      "id": "x425-btc-bip39",
      "label": "Mnemonic code for generating deterministic keys",
      "publisher": "Bitcoin Improvement Proposals",
      "url": "https://raw.githubusercontent.com/bitcoin/bips/927b6de9915c9262615a6399de51b200f81e5aa4/bip-0039.mediawiki",
      "locator": "Generating the mnemonic; From mnemonic to seed",
      "note": "Entropy and checksum table, intended computer-generated randomness and NFKD seed derivation.",
      "version": "Pinned BIPs revision",
      "checkedAt": "2026-10-02T18:53:54.120Z",
      "contentSha256": "afcbcbed36fe9eb734bd607398a8c124683ded2a75c3830e1b16c47b043a9134",
      "recordId": "source-a7583e32275982ab"
    },
    {
      "id": "x425-btc-dev-transactions",
      "label": "Transactions",
      "publisher": "Bitcoin developer documentation",
      "url": "https://developer.bitcoin.org/devguide/transactions.html",
      "locator": "Introduction; Spending An Output; P2PKH Script Validation; Multisig; Transaction Fees And Change; Avoiding Key Reuse",
      "note": "Inputs, outputs, authorization, change, coinbase exceptions and fee accounting.",
      "version": "Developer guide; historical implementation details require qualification",
      "checkedAt": "2026-10-02T18:53:53.759Z",
      "contentSha256": "2f3fc474d51880e6c7fd4c25f747f8d8d8da49a493ab82af8ff4916fa490d6b8",
      "recordId": "source-b282fdecc069b74d"
    }
  ],
  "related": {
    "articles": [
      "bitcoin-wallets-explained",
      "partially-signed-bitcoin-transactions",
      "bitcoin-wallet-passphrases",
      "bitcoin-hot-wallet-vs-cold-wallet"
    ],
    "dossiers": [],
    "wallets": []
  },
  "revisionHistory": [
    {
      "date": "2026-10-02",
      "kind": "published",
      "summary": "First publication after primary-source research and separate automated verification."
    }
  ],
  "citation": "Degrees of Satoshi editorial project. “Hardware wallets: what the device protects and what it cannot check.” Published 2026-10-02; updated 2026-10-02. https://degreesofsatoshi.com/encyclopedia/hardware-wallets-explained/"
}
