Compromised computer
Malware intercepts unsigned transactions and proposes altered ones. Defence: every transaction is signed inside the Secure Element and shown on the device screen. The computer never sees the key, only the signed output.
Security model
Hardware wallets eliminate the largest technical attack surface — the internet-connected device holding your keys. But they shift the risk to physical security. Understanding both sides keeps you safe.
The scenarios hardware wallets defend against — and the ones they don’t.
Malware intercepts unsigned transactions and proposes altered ones. Defence: every transaction is signed inside the Secure Element and shown on the device screen. The computer never sees the key, only the signed output.
A tampered device shipped with pre-generated keys. Defence: buy only from ledger.com or authorised resellers; check the anti-tamper seal; verify the device generates its own phrase during first setup. A genuine device never ships with a pre-set recovery phrase.
An attacker poses as Ledger Wallet support and requests the 24-word phrase to “verify” the wallet. Not a hardware defence — only your knowledge that no one ever legitimately needs this phrase protects you.
Device stolen and PIN is guessable or known. Defence: use a non-trivial PIN and optionally activate a BIP-39 passphrase (25th word) that adds a separate layer the device cannot see and the thief cannot brute-force.
The setup guide covers where each habit applies during your first Ledger Wallet setup.