SECURITY & ONBOARDING GUIDE
Step-by-step verification, best practices for cold storage setup, and critical precautions to protect your recovery seed.

Securing digital assets requires moving critical private keys off internet-connected devices into dedicated cold storage. When unboxing your hardware wallet, the onboarding procedure begins by connecting the device via a verified USB cable and accessing the official desktop client. Always ensure you verify that your browser or application is downloading genuine firmware directly from authentic, cryptographically signed sources before continuing with any device initialization.
Never type your 12, 18, or 24-word recovery seed phrase into any website, web browser, phone notepad, or desktop application. Authentic hardware wallets will exclusively display and verify the recovery seed directly on the physical hardware screen. Any website requesting your seed phrase is attempting unauthorized access to your funds.
Before plugging in any cold storage unit, inspect the packaging for tamper-evident holographic seals. If a device arrives with a pre-printed recovery seed card or displays an already initialized state when plugged in, do not use it under any circumstances. A genuine hardware wallet always arrives completely blank without pre-installed firmware or generated addresses, requiring a fresh firmware flash initiated by the user through the verified official suite application.
During setup, the hardware device relies on its internal true random number generator (TRNG) to create your master private key according to standard BIP-39 specifications. Write down every seed word carefully in numerical sequence on physical paper or stamp them into an archival metal plate. Keep multiple offline backups in geographically separated, waterproof, and fireproof locations. Never take photographs of your seed phrase or store digital scans on cloud drives.
Once your recovery phrase is securely archived, set up a strong numeric PIN directly on the hardware screen to protect against physical theft. For advanced protection against coercion or physical access vectors, activate optional BIP-39 passphrases. A passphrase functions as an unwritten twenty-fifth word, creating entirely separate hidden wallet partitions and delivering robust defense against unauthorized access.