Security

Security & self-custody

Your crypto rests on a few words

Self-custody makes you the sole master of your funds — and the only one responsible. No customer service to reverse a transaction, no password to reset. The five non-negotiable principles, the attacks actually observed in the wild, the EAL scale and a self-audit to place your own level in two minutes.

  • 🔑 Seed = master key
  • 🛡️ PIN + passphrase
  • 👁️ On-device check
  • 🧊 Steel backup
  • ⚙️ Up-to-date firmware
SELF-CUSTODY
12/24
words are enough to restore
the whole of your keys
2
separate backup locations,
at a minimum
0
photo, cloud or screenshot
of your seed phrase
EAL6+
the level targeted by high-end Secure
Elements

The fundamentals

Five non-negotiable principles

Everything else follows from them. If these five points are respected, almost every loss-of-funds scenario observed in the ecosystem becomes powerless against you.

01

The seed phrase is the master key

These 12 or 24 words regenerate all of your private keys, on any device, anywhere in the world. Whoever holds them holds your funds. Never type them into a computer or a phone, never photograph them, never store them in a password manager. No support team, no manufacturer, no service will ever ask you for them.

02

The PIN and the passphrase do not protect the same thing

The PIN protects physical access to the device: it stops whoever steals it. The passphrase (the “25th word”) derives an entirely separate wallet from the same seed: it protects your funds even if your seed phrase is discovered. The trade-off: a forgotten passphrase is unrecoverable, exactly like a lost seed.

03

Check the address on the device screen

Malware is able to replace the destination address at the moment you copy and paste, without changing anything in your browser display. Only the hardware wallet screen, driven by signed firmware, shows the address that is actually signed. Compare at least the first six and the last six characters, on every send, including small amounts.

04

Back up offline, in two separate locations

Paper burns, gets wet and fades. Prefer an engraved or stamped steel plate. Spread it across two physically distinct locations, neither of which is your office. Keep the passphrase somewhere other than the seed. And above all: test the restore at least once a year on a blank device — a backup that has never been tested is not a backup.

05

Keep firmware and apps up to date

Security patches only work once they are installed. Download exclusively from the manufacturer's official sources, never from a link received in a message or found in an advertisement. Check the signature or the fingerprint whenever one is published, and back up before any major update.

Risk overview

What really makes people lose funds

The attacks that succeed rarely target the cryptography. They target the user, their inbox, their parcel or their computer. Every threat below has a simple countermeasure.

Phishing & address poisoning

Pixel-perfect cloned sites and apps, fake support, hijacked QR codes. A formidable variant: the attacker sends you a zero-value transaction from an address that looks like yours, so that you copy it back from your history.

FixType URLs by hand, never copy an address from your history, check it on the device screen.

SIM swap & social engineering

The attacker has your number transferred to their SIM card, intercepts SMS codes and takes control of your exchange accounts. Often preceded by a call from “technical support” to gather information.

FixReplace SMS-based 2FA with a physical key or a TOTP app. Never approve anything during an incoming call.

Malware & keyloggers

Infected browser extensions, pirated software, monitored clipboard. The goal: to make you blind-sign a transaction whose real destination you have not read.

FixA dedicated machine, or at least a separate browser profile, zero non-essential extensions, systematic refusal of blind signing.

Supply chain compromise

A device opened and modified before it reaches you, or worse: delivered with a “recovery card” already filled in. A new wallet never contains a pre-generated seed.

FixBuy from the manufacturer or an authorised reseller, inspect the seals, always generate a fresh seed yourself.

Evil maid — stealthy physical access

Someone gets a few minutes with your device or your backup: a hotel room, a shared office, a rented flat. No visible trace, the attack triggers later.

FixPassphrase enabled, device and backups kept out of sight, visual check of the seals on your return.

Fake airdrops & booby-trapped contracts

An unknown token appears in your wallet and invites you to “claim” it on a website. The signature requested does not send tokens: it grants an unlimited spending allowance.

FixIgnore unsolicited tokens, read what you sign, revoke granted allowances regularly.

Red flags — stop everything immediately

  • A seller gives you a seed phrase that is already written down, or asks you for your 24 words.
  • An installation link received in a private message, by SMS or through an advertisement.
  • An urgent request to sign a transaction “just to check”.
  • A wallet received with no seal, or with stickers that look as though they have been re-glued.
  • An app that refuses or bypasses address verification on the device.
  • A “technical support” service that contacts you first, whatever the channel.

Rule with no exception: nobody — not Neowalt, not a manufacturer, not an exchange — has any legitimate reason to know your seed phrase. A single request of this kind is enough to identify a scam.

Hardware security

Understanding the EAL scale

The Evaluation Assurance Level measures how rigorously a component has been evaluated, according to the international Common Criteria standard. The scale runs from 1 to 7; the “+” suffix indicates strengthened requirements beyond the base level.

EAL1
EAL2
EAL3
EAL4
EAL5
EAL6
EAL7
Minimal verificationHardware wallet zoneFull formal proof
Level
What is evaluated
Intended goal
EAL1
Minimal verification that the product works.
Show that there is no obvious flaw.
EAL2
Closer examination of the design and independent testing.
Moderate assurance on an existing product.
EAL3
Systematic verification of the security functions and of the development environment.
Guarantee that the product follows safe practices.
EAL4
Full examination of the design, in-depth testing, independent review.
A good balance between security and cost.
EAL5
Semi-formal design, supported by models and partial proofs.
High confidence for high-risk environments.
EAL6
In-depth mathematical analysis of the security mechanisms.
Very high level of assurance: defence, critical infrastructure.
EAL7
Complete mathematical proof of the design and of secure behaviour.
Maximum confidence: military or critical cryptographic systems.

Most hardware wallets rely on a Secure Element certified EAL5+ or EAL6+. One important nuance: the certification covers the chip, not the entire device. A high EAL is an excellent signal, but real security depends just as much on the firmware, on the product architecture — and on your own practices. A badly used EAL6+ protects you less than a well-used EAL5+. Compare the levels model by model →

Self-audit

Where do you really stand?

Twelve points, two minutes. Tick only what is true today — not what you intend to do. The score updates live and stays in your browser: nothing is sent, nothing is recorded on our side.

Seed phrase backup
Device & setup
Everyday habits

Not every item carries the same weight: the seed phrase backup counts for more than the rest, because it is the only element that nothing can recover once it is gone. 🔒 Score calculated and kept in your browser — no data leaves your device.

On arrival

The forty-five minutes that matter

A supply chain compromise plays out before your very first transaction. Here is the protocol to follow between opening the parcel and your first outgoing transfer.

1 · Opening the box

Seals intact, original packaging, a legible and matching serial number, all accessories present. No pre-filled recovery card should be inside the box: its mere presence disqualifies the device. If in doubt, do not set it up and contact the seller.

2 · Installation

Download the official app from the manufacturer's site, typed in by hand — never from a sponsored result or a link you were sent. Check the file's hash or signature whenever one is published, then let the device verify the authenticity of its own firmware.

3 · Initialisation

Generate a fresh seed phrase on the device, never anywhere else. Write the words down away from onlookers and cameras, on a durable medium. Enable the passphrase if you know how to manage it. Finish with a test transfer of a token amount before moving anything significant.

Backups & inheritance

Surviving loss, not just theft

The overwhelming majority of funds lost for good were not lost to a hacker, but to a single backup that was destroyed, forgotten or impossible to pass on. Choose the setup you will genuinely still know how to operate in five years.

Two locations

The baseline, within everyone's reach. Seed phrase in two separate places, passphrase in a third. None of the three is your main home alone.

Shamir

The seed phrase is split into shares, a subset of which is enough to rebuild it (2 of 3, for example). It spreads trust without multiplying points of failure.

Multisig

Several independent devices must sign in order to spend (2 of 3, 3 of 5). The standard for large amounts — it demands genuine operational discipline.

Inheritance

A sealed file: an inventory of holdings, restore instructions, contacts, a named executor. The seed phrase is never in it — only the path that leads to it.

Emergency plan

If the incident has already happened

In these three situations, speed matters more than perfection. Act in order, and treat any potentially exposed key as permanently compromised.

Lost or stolen device

  1. Stay calm: without the PIN, the device holds. Your funds are not immediately accessible.
  2. Restore your seed phrase on a new device, in a safe place.
  3. Transfer all of the funds to a wallet derived from an entirely new seed phrase.
  4. Dispose of the old backup once the transfer is confirmed.

Potentially exposed seed phrase

  1. Treat it as compromised, even on the slightest doubt. There is no middle ground here.
  2. Immediately generate a new seed phrase on a clean device.
  3. Move all of the funds, across every network, without exception.
  4. Take the opportunity to move to multisig or Shamir if the amounts justify it.

Suspected malware or phishing

  1. Cut the machine's network connection and isolate it.
  2. From another, clean device, change the passwords of the exposed accounts.
  3. Revoke the spending approvals granted to unknown contracts.
  4. Reinstall the system cleanly, or switch to a dedicated machine.

Glossary

The vocabulary in plain terms

SeedSeed phrase

A sequence of 12 or 24 words (the BIP39 standard) that regenerates all your private keys. To be kept offline, always.

PassphraseSecret phrase

An extra word or phrase that derives a separate wallet from the same seed phrase. It protects you if the seed phrase is discovered — but forgetting it means losing the funds.

Air-gapPhysical isolation

Data exchange with no direct connection, typically by QR code. It removes the USB and Bluetooth attack surfaces.

MultisigMulti-signature

Several independent keys are required to spend (2 of 3, 3 of 5). No single device is a point of failure.

ShamirSecret sharing

The seed phrase is divided into N shares, of which M are enough to rebuild it. It distributes trust with no single complete copy.

Secure ElementSecure element

A hardened, certified chip that stores the keys and resists physical attacks. It is the chip, not the whole device, that the EAL certification measures.

Frequently asked questions

What we are asked most often

Can a hardware wallet be hacked remotely?
Private keys never leave the secure element: they are not exposed to your computer, even an infected one. In practice, losses almost always come from elsewhere — a seed phrase entered on a phishing site, a transaction signed without checking the address shown on the device, or a backup that was photographed. The device protects the key; protecting the backup and checking what you sign is up to you.
Paper or steel for writing down my seed phrase?
Steel, without hesitation, as soon as the amounts go beyond the symbolic. Paper survives neither water damage, nor fire, nor fifteen years of damp in a cellar. An engraved or stamped plate costs a fraction of what it protects. Paper remains acceptable as a temporary copy, while you wait for a durable medium — no longer than that.
Should I enable a passphrase?
It brings real additional protection: even a discovered seed phrase gives access to nothing. But it adds a secret you must never forget, and a lost passphrase is exactly the same as a lost seed phrase. Our recommendation: enable it if you have a clear method for backing it up separately and for passing it on. Otherwise, focus first on a flawless seed phrase backup.
Is EAL6+ necessarily safer than EAL5+?
More rigorously evaluated, yes. Safer in practice, not necessarily. The certification covers the chip, not the complete device: the firmware, the product architecture and the type of interface (USB, Bluetooth, QR) weigh just as much. An air-gapped EAL5+ with a proper backup protects better than an EAL6+ whose seed phrase is lying around on a sheet of paper. The comparison tool details these criteria model by model.
Can I buy a second-hand hardware wallet?
No. This is supply chain compromise in its most direct form: nothing guarantees that the device has not been modified, or that the seller is not keeping a copy of the seed phrase they hand over to you. A hardware wallet is bought new and sealed, from the manufacturer or an authorised reseller. The money saved bears no relation to the risk taken on.
What happens if the manufacturer disappears?
Nothing for your funds. Your seed phrase follows the BIP39 standard: it can be restored on any compatible wallet, from another brand, or in open-source software. That is precisely the point of open standards — you depend on no company to recover your holdings. Simply check, before you buy, that the model really does follow BIP39 or BIP32.

The right wallet is the one you will know how to use properly

Certification level, connection type, battery life, compatibility, backup handling: our comparison tool puts these criteria side by side across the whole range, so that your choice follows from how you actually use a wallet rather than from a marketing sheet.