Practical security tips & common mistakes (read this)
This section expands on key, real-world advice that protects you beyond the initial setup. Security is not a single action; it’s a set of habits. Below are practical tips, illustrated by explanations of why they matter.
Never type your recovery phrase
Typing your 24-word recovery phrase into a computer or phone exposes it to clipboard theft, keyloggers, and malware. The only safe way to enter the phrase is on a trusted device during a controlled restore. When not in use, store the recovery phrase physically on paper or — better — in a metal backup designed for seed phrases.
Prefer hardware backups
Paper degrades. Consider a stainless-steel plate or purpose-built backup product that resists fire, water, and corrosion. This significantly reduces the chance of losing the phrase over years or decades.
Verify addresses on-device
Before you confirm an outgoing transaction, always check the address shown on your Ledger screen. Malware can alter a pasted address in your browser. Your device is the final authority; if the on-device display doesn’t match the expected destination, cancel the operation.
Use PINs and passphrase prudently
Your Ledger device uses a PIN to prevent unauthorized physical use. Additionally, advanced users can use a passphrase (a 25th word) to create hidden wallets. Only use this if you understand the trade-offs and backups required.
Be skeptical of unsolicited links
Phishing is common. Bookmark official Ledger pages and never follow unknown links that claim to be “support” or “update” unless you verified the source. Ledger will never ask for recovery phrases through a web page or support chat.
Following these principles will dramatically reduce the chance of theft and give you long-term peace of mind managing crypto assets.