# Hardware wallets: what the device protects and what it cannot check

A hardware wallet keeps signing keys in a dedicated device and authorizes transactions through its supported interface. A host application can prepare and broadcast payments without holding those keys. The device display helps you check what will be signed, but it cannot determine whether an outside recipient is honest. Backup exposure, unsupported transaction details and the device’s own security remain important.

Evidence: [Securing your wallet](https://bitcoin.org/en/secure-your-wallet); [Trezor’s Trusted Display](https://trezor.io/guides/trezor-devices/trezor-fundamentals/trezor-s-trusted-display-verify-every-address-on-your-device); [Partially Signed Bitcoin Transaction Format](https://raw.githubusercontent.com/bitcoin/bips/927b6de9915c9262615a6399de51b200f81e5aa4/bip-0174.mediawiki)

Canonical: https://degreesofsatoshi.com/encyclopedia/hardware-wallets-explained/
Published: 2026-10-02
Substantively modified: 2026-10-02
Independently verified by an automated reviewer: 2026-10-02T19:29:20.637Z
Data current through: 2026-10-02

AI-assisted research and drafting with a separate automated source-verification pass; no external expert or named human review is implied.

## Key facts

- **Device role:** Protect keys and authorize supported spends ([Securing your wallet](https://bitcoin.org/en/secure-your-wallet))
- **Host role:** Prepare requests and relay signed transactions ([Partially Signed Bitcoin Transaction Format](https://raw.githubusercontent.com/bitcoin/bips/927b6de9915c9262615a6399de51b200f81e5aa4/bip-0174.mediawiki))
- **Display limit:** It confirms transaction data, not a merchant’s honesty ([Trezor’s Trusted Display](https://trezor.io/guides/trezor-devices/trezor-fundamentals/trezor-s-trusted-display-verify-every-address-on-your-device))

## Keep the host and signer distinct

An online application can discover outputs, estimate a fee and propose a transaction. The signer needs enough information to check the inputs, outputs and authorization policy before approving. The signed result can then return to the host for broadcast.

Keeping keys away from the host reduces one exposure path. It does not make every file, firmware update or signing request safe, and it does not prevent the user from approving the wrong destination.

Evidence: [Partially Signed Bitcoin Transaction Format](https://raw.githubusercontent.com/bitcoin/bips/927b6de9915c9262615a6399de51b200f81e5aa4/bip-0174.mediawiki); [Trezor’s Trusted Display](https://trezor.io/guides/trezor-devices/trezor-fundamentals/trezor-s-trusted-display-verify-every-address-on-your-device)

## The screen should match the intended payment

Imagine a 75,000-satoshi request. Malware changes the destination before it reaches the device. The device may faithfully display that changed destination: its value is that you can compare the actual proposed spend with a trusted request. Approving without comparison defeats that protection.

For receiving, a supported device can display its own generated address. Compare that with the address the host asks you to share. Trezor’s documentation explicitly distinguishes these checks from knowing who controls an outside address.

Evidence: [Trezor’s Trusted Display](https://trezor.io/guides/trezor-devices/trezor-fundamentals/trezor-s-trusted-display-verify-every-address-on-your-device)

## Protect the backup as well as the device

A lost device is not necessarily lost funds if the required recovery material and wallet configuration survive. Conversely, someone with enough recovery secrets can bypass the need to steal the physical device. A device PIN and a mnemonic passphrase have different purposes.

Record the supported recovery procedure and any additional policy information. Do not assume every hardware wallet uses the same mnemonic format or that a single participant’s seed reconstructs a multisignature wallet.

Evidence: [Securing your wallet](https://bitcoin.org/en/secure-your-wallet); [Hierarchical Deterministic Wallets](https://raw.githubusercontent.com/bitcoin/bips/927b6de9915c9262615a6399de51b200f81e5aa4/bip-0032.mediawiki); [Mnemonic code for generating deterministic keys](https://raw.githubusercontent.com/bitcoin/bips/927b6de9915c9262615a6399de51b200f81e5aa4/bip-0039.mediawiki)

## Questions

### Are the bitcoins physically inside the hardware wallet?

No. Outputs are recorded on the chain. The device holds or derives keys used to satisfy spending conditions; the host can display the same public record without possessing those keys.

Evidence: [Transactions](https://developer.bitcoin.org/devguide/transactions.html); [Hierarchical Deterministic Wallets](https://raw.githubusercontent.com/bitcoin/bips/927b6de9915c9262615a6399de51b200f81e5aa4/bip-0032.mediawiki)

### Can a hardware wallet stop me from paying a scammer?

It can help verify the transaction it signs, but a valid destination can belong to a scammer. You must establish the intended recipient independently and check that the displayed payment matches that intent.

Evidence: [Trezor’s Trusted Display](https://trezor.io/guides/trezor-devices/trezor-fundamentals/trezor-s-trusted-display-verify-every-address-on-your-device)

## Claims and scope

### hardware-wallets-explained-quick-answer

A hardware wallet keeps signing keys in a dedicated device and authorizes transactions through its supported interface. A host application can prepare and broadcast payments without holding those keys. The device display helps you check what will be signed, but it cannot determine whether an outside recipient is honest. Backup exposure, unsupported transaction details and the device’s own security remain important.

Educational explanation. Product-specific behavior is scoped to the cited documentation, checked 2026-10-02.

Scope: {"collection":"bitcoin","dataAsOf":"2026-10-02","blockHeight":null}

### hardware-wallets-explained-fact-device-role

Device role: Protect keys and authorize supported spends

Scope: {"collection":"bitcoin","dataAsOf":"2026-10-02","blockHeight":null}

### hardware-wallets-explained-fact-host-role

Host role: Prepare requests and relay signed transactions

Scope: {"collection":"bitcoin","dataAsOf":"2026-10-02","blockHeight":null}

### hardware-wallets-explained-fact-display-limit

Display limit: It confirms transaction data, not a merchant’s honesty

Scope: {"collection":"bitcoin","dataAsOf":"2026-10-02","blockHeight":null}

## Sources

- [Securing your wallet](https://bitcoin.org/en/secure-your-wallet) — Bitcoin.org. Backup scope, online exposure, offline signing, custody and software update practices. Locator: Be careful with online services; Backup your wallet; Encrypt your wallet; Offline wallet for savings; Hardware wallets; Keep your software up to date. Retrieved: 2026-10-02T18:53:53.659Z.
- [Trezor’s Trusted Display](https://trezor.io/guides/trezor-devices/trezor-fundamentals/trezor-s-trusted-display-verify-every-address-on-your-device) — Trezor. Manufacturer explanation of device display checks and the limits of a host-computer screen. Locator: Trusted display article: on-device verification steps and limits of what the device verifies. Retrieved: 2026-10-02T18:53:56.900Z.
- [Partially Signed Bitcoin Transaction Format](https://raw.githubusercontent.com/bitcoin/bips/927b6de9915c9262615a6399de51b200f81e5aa4/bip-0174.mediawiki) — Bitcoin Improvement Proposals. Offline signing workflow, UTXO information and separate signing/finalization/broadcast steps. Locator: Roles; Creator; Signer; Transaction Extractor. Retrieved: 2026-10-02T18:53:54.151Z.
- [Hierarchical Deterministic Wallets](https://raw.githubusercontent.com/bitcoin/bips/927b6de9915c9262615a6399de51b200f81e5aa4/bip-0032.mediawiki) — Bitcoin Improvement Proposals. Deterministic key derivation, backup scope and public/private child derivation. Locator: Motivation; Extended keys; Security. Retrieved: 2026-10-02T18:53:54.013Z.
- [Mnemonic code for generating deterministic keys](https://raw.githubusercontent.com/bitcoin/bips/927b6de9915c9262615a6399de51b200f81e5aa4/bip-0039.mediawiki) — Bitcoin Improvement Proposals. Entropy and checksum table, intended computer-generated randomness and NFKD seed derivation. Locator: Generating the mnemonic; From mnemonic to seed. Retrieved: 2026-10-02T18:53:54.120Z.
- [Transactions](https://developer.bitcoin.org/devguide/transactions.html) — Bitcoin developer documentation. Inputs, outputs, authorization, change, coinbase exceptions and fee accounting. Locator: Introduction; Spending An Output; P2PKH Script Validation; Multisig; Transaction Fees And Change; Avoiding Key Reuse. Retrieved: 2026-10-02T18:53:53.759Z.

## Revision history

- 2026-10-02: First publication after primary-source research and separate automated verification.

## Cite this entry

Degrees of Satoshi editorial project. “Hardware wallets: what the device protects and what it cannot check.” Published 2026-10-02; updated 2026-10-02. https://degreesofsatoshi.com/encyclopedia/hardware-wallets-explained/
