Your keys
Your key, out of reach
of your computer.
Your bitcoin isn't stored in a box: it's recorded on a public ledger, and what decides it's yours is a long string of characters, your private key. Whoever holds it can spend it. A wallet installed on your phone or computer keeps that key on the same machine as your browser, your email, and everything else installed there: it only takes one program getting the right permissions to read it, and you'll see nothing.
A hardware wallet is a small device, often the size of a USB stick, whose sole job is to keep this key out of reach of any computer. The transaction is prepared on your usual screen, but it's signed inside the device, after you've read the amount and the address on its own screen. An infected machine can therefore ask you to pay; it can't sign in your place, nor copy your key. This screen is also the only place where the address shown isn't one a piece of software chose to show you, that's the most common fraud, and a software wallet can do nothing against it.
NODECOVE doesn't sell this device: we document which one to get, where to buy it without giving your name, and how to set it up.
Where the key comes from, and the twelve words to write down at first startup
The key is born inside the device, at first startup, drawn at random by the device alone: it has never existed anywhere else, and it never comes out. No manufacturer, no software, no service knows it, so no one can take it from you, and no one can recover it for you if you lose everything.
At first startup, the device also has you write down twelve or twenty-four words. That's your key in readable form, and your only recourse if the device is lost, stolen, or destroyed: those words restore your wallet on any other device. Write them on paper or engrave them in metal; never photograph them, never type them into a phone or a password manager, and no one, not the manufacturer, not us, needs to know them. Whoever reads them empties your wallet without ever touching the device.
That leaves choosing which one. The usual question, which device is most secure, fills five hundred websites and adds nothing new. We ask a different one: what does the manufacturer know about you, and can you verify it? The best device is the one that never learned your name.
The 2020 leak: a million addresses, 272,000 records with the delivery address
In 2020, one major manufacturer's customer database leaked, then was published in plain text: roughly a million email addresses, and nearly 272,000 full records with name, postal address, and phone number. People who bought a device to protect their wealth ended up on a public list of likely bitcoin owners, with their delivery address. These records still circulate today.
We therefore recommend a device whose firmware is open and verifiable, and that works without depending on a service run by the manufacturer. Open, because the program that handles your key must be readable by people other than the one who wrote it. Without a service, because a device that requires the maker's own app to function becomes useless the day the company closes, and chatty for as long as it exists.
The one we mention, and why
On these criteria, the Blockstream Jade holds up well: open firmware, bitcoin-focused, and above all reproducible, the manufacturer's published procedure lets you recompile, on your own machine, the image installed on the device and verify that it matches the published code. You don't have to take their word for it. It's not the only serious device, and we don't sell any.
We have no referral link to this manufacturer, and we get nothing if you buy it. We mention what we use ourselves; our business is the node and the VPN, not reselling hardware.
Whatever the device: buying it with a card in your name and having it delivered to your home creates exactly the link you were trying to avoid. Pay in bitcoin, have it delivered somewhere other than home, or buy it in person. We compare eight devices, license by license, on the Protecting your keys page.