Trezor Suite security and privacy
What the app protects, what the device protects, and what only you can protect — plus the settings that decide how much of your activity is visible to third parties.
How the security model works
Self-custody splits a job that banks used to do alone. The hardware wallet holds the keys and signs transactions; the software shows you what is happening and prepares the paperwork. Trezor Suite is written for that split: it assumes the computer or phone it runs on might be infected, and arranges itself so that a compromised machine still cannot spend your funds.
Three consequences follow, and they explain most of the app's behaviour:
- The app never needs your recovery seed. No screen in Suite asks for it, because signing happens inside the device.
- Every outgoing transaction is confirmed physically. The address and amount appear on the device screen, and only you can approve them.
- The client is open source. Its code can be inspected publicly, which matters because you are trusting it with the view of your finances.
The recovery seed: the only thing that really matters
Your recovery seed — usually 12, 20 or 24 words — is the mathematical reconstruction of every key in your wallet. It is generated by the device when you set it up, displayed once, and never leaves the device afterwards.
Two facts follow, and both are permanent:
- Anyone who has those words has your money. Not "might get access to" — has it, immediately, from anywhere in the world, with no amount of device security able to stop them.
- Nobody legitimate ever needs them. Not support, not an app update, not a wallet-recovery service, not a contest, not this site. Every request for your seed is an attack, however polished the page or friendly the messenger.
Storing the backup properly
- Paper is the baseline. The supplied recovery card, filled in by hand, stored somewhere private and dry. Write legibly and check the word order twice.
- Metal is the upgrade if fire, flood or decay are realistic risks where you live. Stamped letters survive what paper does not.
- Never digital. No photos, screenshots, password managers, cloud notes, emails to yourself or encrypted archives — every one of those has been the reason people lost funds.
- Consider splitting with Shamir backup where the device supports it. Multiple shares, stored separately, mean no single location holds a complete secret.
- Rehearse the recovery. A backup you have never restored is a hope, not a backup. Prove it works while the balance is small.
If your seed is ever exposed
Treat the wallet as compromised the moment those words touch a keyboard, a camera or a chat window. Set up a new wallet with a new seed on your device, move all funds to the new addresses, and stop using the old seed entirely. Do not wait for evidence of a theft — by the time it is visible, the funds are already gone.
PIN, wipe protection and genuine checks
The PIN is the everyday lock on the device. It is entered on the hardware wallet itself with a shuffled keypad, so malware recording your keystrokes learns nothing. Repeated wrong entries cause the device to erase itself, which turns a stolen device into a paperweight and makes guessing impractical.
Two verification features are worth knowing about because they address physical attacks and supply-chain tampering:
- Authenticity check. Suite can confirm that the connected device is a genuine Trezor rather than a clone or a modified unit built to leak keys.
- Firmware signature verification. Firmware must carry the vendor's signature to be accepted, so an attacker cannot install modified firmware that would quietly change what you see on the screen.
A practical habit when a new device arrives: check the packaging for tampering, set it up as a brand-new wallet following the on-device instructions, and be suspicious if anything arrives pre-configured or with a seed card already filled in.
Passphrases and hidden wallets
A passphrase is an additional word or phrase you type — on the computer or phone, not the device — that gets mixed into the key derivation. The same recovery seed plus a different passphrase produces a completely different wallet, with its own accounts and balances, and nothing on the device reveals that the hidden one exists.
Used well, it is a strong second factor: an attacker who steals your written seed still cannot reach the passphrase-protected wallet. Used carelessly, it is a way to lose access to your own funds.
- Every different passphrase is a different wallet. One typo means an empty wallet, not an error message.
- There is no passphrase recovery. If you forget it, the funds in that hidden wallet are unreachable. Permanently.
- Choose something long and unlikely, then back it up offline separately from your seed, so a single discovery does not hand over both.
- Consider a small test first. Create the passphrase wallet, send a modest amount, disconnect, and re-enter the passphrase to confirm it returns.
Firmware updates and device hygiene
Firmware is the operating system inside the hardware wallet. Updates add support for new assets, fix bugs and close security gaps, so staying current is a security practice rather than a chore.
- Install updates through the app, which delivers them signed and verified — never from a file someone sent you.
- Keep the device with you when travelling: it is small, and a PIN alone will not stop a determined thief with enough time and equipment.
- Retire old devices deliberately. Wipe them in the app before selling or discarding, and remember that a wiped device is harmless only if your seed was never exposed.
Privacy settings: Tor, your own node, and what leaves your computer
Security and privacy are different goals. A hardware wallet stops theft; privacy settings limit who can learn what you own and how you move it. Suite exposes several relevant controls.
- Tor. The desktop app can route its network requests through the Tor network, which hides your IP address from the servers your wallet talks to. Expect slower synchronisation in exchange.
- Your own full node. Point Suite at a Bitcoin node you run, and your balance queries and broadcasts go through your own infrastructure instead of a third party's servers.
- Third-party services are opt-in. Exchange rates, the buy and swap providers and similar integrations are separate connections with their own privacy policies. You can use the wallet without ever touching them.
- Labels stay with you. Your account names and transaction notes are wallet metadata, not blockchain data, and are not published anywhere.
- Address reuse is discouraged. Generating a fresh receive address for each payment is normal practice and reduces how easily transactions can be linked to each other.
- Coin control lets you decide which coins a payment spends, which is how you keep one funding source from being linked to another on-chain.
None of this is mandatory. A default installation is perfectly usable; these are the knobs to turn when you want to be harder to observe.
Scams aimed at hardware wallet owners
Because the device itself is hard to break, attacks target the person instead. The patterns repeat, and recognising them is most of the defence.
Fake websites and paid search results
Clones of the official site buy adverts for searches like "Trezor Suite download", offering an installer that steals keys or shows you a fake "seed verification" form. Reach the site from a bookmark you created yourself, and distrust adverts, lookalike domains and shortened links.
"Support" that asks for your seed
Fraudulent support agents contact people who post about problems, often on social media, and offer to help — then ask for the recovery words to "restore" the wallet. Real support never needs them, and no company will ever ask you to read them aloud or type them into a chat.
Free-crypto giveaways and urgent verification pages
Giveaways in the name of a hardware brand, fake security alerts, and "your wallet will be deactivated unless you verify" notices all funnel towards the same form: the one that wants your twelve words. The urgency is the tell.
Clipboard and address-swapping malware
Some malware silently replaces a copied address with the attacker's own. This is why you compare the recipient address on the device screen before approving — the one check the malware cannot fake.
Fake firmware and "unlock" tools
Offers to recover a lost wallet with third-party software, or to "unlock" a device, exist to harvest seeds. Firmware comes from the app; recovery comes from your own backup, entered on your own device.
The three questions that stop almost every scam
- Is anyone asking for my recovery seed? If yes, it is an attack.
- Did I arrive at this website by typing or bookmarked address, or by clicking something?
- Does the device screen agree with the app screen? If not, stop and investigate.
A maintenance routine worth keeping
- Monthly: check for app and firmware updates, and install them from inside the app.
- After every update: unlock the device once and confirm your accounts still appear.
- Twice a year: look at your physical backup, confirm it is legible and still where you left it.
- Before any large transfer: send a small test amount to the new destination first.
- Whenever your seed felt exposed: create a fresh wallet and migrate, no matter how small the doubt.
What no app can protect you from
Being explicit about limits keeps expectations honest: if you type your seed into a phishing page, approve a transaction you did not read on the device, or store your backup next to the device, software cannot undo it. Hardware wallets remove the largest attack surface — remote theft from an internet-connected machine — and leave the decisions that only a careful owner can make.
Next: see which models add which protections in the device comparison, or return to the setup walkthrough if you are installing for the first time.
Set the privacy options once, benefit for years
Route through Tor, connect your own node, and decide which third-party services you actually want switched on. The setup walkthrough shows where those settings live.