Your devices
Decide which of your devices should ever be allowed to touch a private key, and secure them accordingly.
About 8 minutes.
Why the bottom layer decides the rest
Every control above this one assumes the machine underneath is honest. Two-factor authentication, a hardware wallet, a careful reading of a transaction — all of it is reported to you through a screen and a keyboard you are trusting completely. If the device is compromised, it can show you one transaction and sign another, and nothing further up the stack will notice.
That is why the physical layer comes first. It is not the most interesting layer and it is rarely where the exciting attacks happen, but it is the layer that decides whether anything else you do is meaningful.
Hardware wallets, and what they actually protect
A hardware wallet keeps the private key inside a chip that will not export it. Malware on your laptop can ask the device to sign, but it cannot copy the key and use it later at leisure. That is a genuine and large improvement, and everyone holding meaningful value should be using one.
It is not a force field. The device signs what you approve, so an attacker who cannot steal your key will instead work on getting you to approve something. This is why the screen on the hardware wallet matters: it is the one display the malware on your computer cannot edit. If you approve without reading that screen, you have thrown away most of what you paid for.
Buy from the manufacturer directly. A second-hand or gifted device may arrive with a seed phrase the seller already knows, and the packaging will look perfect, because the seller resealed it.
Separation
The single most effective habit at this layer costs nothing: keep one device that does not do everything. A cheap laptop or a spare phone used only for signing, never for email, never for browsing, never for downloading a PDF someone sent you, is worth more than any product you can buy.
If that is not practical, the next best thing is a separate browser profile with no extensions, used only for wallet activity. It is a weaker boundary than a separate machine, but it is a real one.
Physical access
Lock devices when you step away, use full-disk encryption, and store hardware wallets and seed backups somewhere a visitor to your home will not find them. A surprising proportion of losses are not remote attacks at all: they are a housemate, a builder, a relative, or a hotel cleaner who found a card with twelve words on it in a bedside drawer.
Worth remembering.
- Every other control assumes the device is honest. If it is not, nothing above it holds.
- A hardware wallet stops key theft, not approval of a bad transaction. The device screen is the part that matters.
- Buy hardware wallets from the manufacturer. Never use one that arrived pre-configured.
- A dedicated signing device, or at minimum a dedicated browser profile, is the highest-value habit at this layer.
2 of 3 to pass.
Connect your wallet to sit the assessment. Results are recorded against the address, which is what the certificate and the Guild role are issued to.
Question 1 of 3
Malware is running on your laptop and you sign a transaction with a hardware wallet. What protects you?
Question 2 of 3
Someone offers you a sealed, boxed hardware wallet at a discount through a marketplace listing. What is the risk?
Question 3 of 3
You cannot afford a second machine for signing. What is the most useful thing you can do instead?
