Skip to main content
Don't invest unless you're prepared to lose all the money you invest. This is a high-risk investment, and you should not expect to be protected if something goes wrong. Take 2 min to learn more.

How to Move Crypto to a Hardware Wallet

The device is the easy part. The steps people skip are buying it from the right place, initialising it yourself, and checking the address on the device screen rather than the computer's.

beginner5 min readWritten by Dan Clarke
Hero image for how-to-move-crypto-to-a-hardware-wallet

TL;DR

  • Buy direct from the manufacturer. After Ledger's 2020 breach exposed 272,000 customer records, criminals posted tampered devices to those home addresses.
  • Initialise the device yourself. A wallet that arrives with a recovery phrase already printed is a trap, without exception.
  • The step that does the work: confirm the receiving address on the device's own screen, not in the app on your computer.
  • Send a small test amount, wait for it to confirm, then send the rest. The test costs a network fee and buys certainty.

Moving crypto to a hardware wallet takes about ten minutes. Roughly nine of those are the parts nobody films for the unboxing video, and every serious loss happens in one of them.

This assumes you already know what cold storage is and how a transfer works in general, so here we are doing the specific job. Educational guide, not financial advice.

Step 1: Buy the device from the manufacturer

Direct from Ledger, Trezor, Coldcard or whoever you have chosen, not a marketplace listing, not eBay, not a discounted one from a seller with good feedback, and never a used one at any price.

The reason is documented rather than theoretical: in July 2020 Ledger's e-commerce database was breached, exposing around 272,000 records containing names, phone numbers and home addresses, later dumped publicly. In 2021 criminals used that list to post people tampered devices in shrink wrap, with convincing letterhead, instructing the recipient to enter their recovery phrase into the replacement. The hardware had been modified to send the phrase straight to them.

A hardware wallet that arrives unexpectedly is not a gift. It is an attack, and it has a postal address because of a leak.

Step 2: Initialise it yourself

Power it on and let the device generate a new recovery phrase in front of you, twelve or twenty-four words shown once on the device's screen.

If a device arrives with a phrase already written on a card in the box, it is compromised, and there is no legitimate version of this. Manufacturers never pre-set a recovery phrase, because the entire security model rests on nobody but you ever having seen it.

Write the words on paper, in order, then let the device test you on a few of them. Do not photograph the phrase, and do not type it into a password manager, a notes app or an email to yourself. Anything with a camera or a cloud sync attached defeats the point of having bought the device.

Step 3: Install the app and get the receiving address

The manufacturer's desktop or phone app connects the device to the network. Add the coin you are moving, and the app will show you a receiving address for it.

Confirm you are on the right network: an Ethereum address starting 0x is not somewhere to send bitcoin, and the account for one chain will not show funds sent on another.

Step 4: Verify the address on the device screen

This is the step, and everything else is admin.

Address-swapping malware sits quietly on a computer, watches for a crypto address on the clipboard or in a browser window, and swaps it for the attacker's. The screen then shows you what the malware wants you to see, your eyes confirm it, you paste it, and the money goes elsewhere.

A hardware wallet defeats this because it has its own screen, and the computer cannot write to it. So: display the address in the app, press the button to show it on the device, and compare. Character by character: first six, last six, and a couple in the middle at minimum.

If they differ, stop. Do not send anything, and treat the computer as compromised.

Step 5: Send a small amount first

From the exchange or wallet holding the crypto, withdraw a small amount to the verified address, enough to be worth confirming and small enough not to matter if something is wrong.

Wait for it to appear on the hardware wallet, not for the sending platform to say sent but for the balance to actually show on the device's app. Depending on the network this is seconds or tens of minutes.

The test costs one network fee, and it buys the knowledge that the address, the network and the account all line up, which is worth considerably more than the fee on any amount you would bother protecting.

Step 6: Send the rest

Same address, larger amount, and re-verify on the device screen anyway, because addresses can be regenerated between sessions on some setups and the habit is cheap.

If you are moving a large holding and the network fee is trivial, splitting it into two or three transfers costs almost nothing and limits the damage of any single mistake.

Afterwards

  • Store the phrase away from the device, because both in one drawer means one burglary, one fire, one problem, so different buildings if the amount justifies it.

  • Test recovery before you need it by wiping the device and restoring it from the phrase, ideally while you still hold only the test amount, because a backup you have never restored is a hope.

  • Remember which is replaceable, because the device is a 60-pound piece of plastic you can buy again tomorrow, but the recovery phrase is the money, and people protect the wrong one.

  • Nobody legitimate will ever ask for the phrase. Not support, not the manufacturer, not a firmware update, not a person in a Telegram group who is being unusually helpful.

Keep a note of the transaction hashes for the transfers. If anything needs tracing later, that is what does it.

Frequently Asked Questions

Buy direct from the manufacturer instead. Marketplace listings pass through hands you cannot check, and tampered devices are a real attack rather than a theoretical one. After Ledger's 2020 data breach, criminals posted modified wallets to leaked customer addresses with instructions to enter the recovery phrase.

Because malware on a computer can replace a crypto address shown in the browser or held on the clipboard with an attacker's. The hardware wallet has its own screen that the computer cannot write to, so comparing the two is what catches the substitution. It is the single step that gives the device its value.

It costs one network fee and confirms the address, the network and the account all match before the full amount moves. Given that a mistaken transfer is usually unrecoverable, the test is cheap insurance on anything you would be upset to lose.

Do not use it. Manufacturers never pre-set a recovery phrase, so a pre-filled card means somebody else knows the words and can empty the wallet whenever they choose. Contact the manufacturer and report it.

Usually yes, and on some networks a fresh address is generated each time for privacy. Both are normal. Whichever address the app gives you, confirm it on the device screen before every meaningful transfer rather than trusting a copy you saved earlier.

Buy another one and restore from the recovery phrase; the crypto lives on the blockchain, not on the hardware. This is also why the phrase must be stored separately from the device, and why testing a restore before you rely on it is worth the half hour.

About the author — Dan Clarke
Dan Clarke

Dan Clarke is the author of Bitcoin: The Complete Guide and a former content lead at Binance Academy, where he wrote crypto education for readers arriving with no background in the subject. He has worked in the cryptocurrency industry since 2017. His rule for these guides: plain language first, precision where it matters, no cheerleading.