Hardware

Trezor Safe: first-time setup

Why the device arrives with no firmware on it, how to record a backup you can actually restore, and which of the extras to leave switched off.

Beginner About 35 minutes Updated Aug 17, 2026

Trezor's setup has one unusual property worth understanding before you start: the device arrives with no firmware installed at all. Plug it in and it will tell you so, then install firmware and check the manufacturer's signature before it runs.

That is not an oversight or a cost saving. Firmware installed at the factory would be firmware you have to take on trust; firmware you install yourself, verified against a signature the device checks, is one fewer thing a tampered supply chain can hide in. If your device boots straight into a working wallet on first connection, something is wrong.

Set aside about half an hour. The parts that need care are the backup and the passphrase decision, and neither should be rushed.

A Trezor Safe still sealed in its packaging with the holographic seal clearly visible across the opening, on a plain dark surface.

Image to come

Check the seal before you open it. It is the first step of the setup, not the packaging.

Before you start

  • A Trezor Safe, unopened, bought from trezor.io or an authorised reseller.
  • Trezor Suite, downloaded from trezor.io typed by hand rather than reached from a search result.
  • The supplied backup cards and a pen, or a metal backup plate.
  • An uninterrupted half hour, somewhere private, with no camera pointing at the desk.
  • No bitcoin. Nothing here needs funds, and none should be moved until the backup check at the end passes.

1Check the seal, then let the device install its own firmware

Inspect the holographic seal for cuts, lifting, residue, or a second seal laid over the first. Look at the case seam and screen edge for the scratches that suggest something has been prised open.

Then connect it and let Trezor Suite walk you through installing firmware. The device verifies the signature itself before running anything.

  • A Trezor that arrives with firmware already installed, already showing a wallet, or already holding a PIN has been tampered with. Stop and contact the vendor.
  • Install firmware only through Trezor Suite. Files offered by a link, an email, or a support agent are the attack, not the fix.

2Choose Bitcoin-only firmware if bitcoin is all you hold

Trezor publishes a Bitcoin-only firmware edition alongside the standard one. Same hardware, with support for every other asset removed.

Less code is less to go wrong: a smaller attack surface, and no possibility of an unrelated coin's handling logic affecting your bitcoin. If bitcoin is what you own, take the Bitcoin-only edition. Switching later is possible but means restoring from your backup, so it is easier to decide now.

3Create the wallet and write the backup by hand

Choose to create a new wallet rather than recovering one. The device generates the seed itself and displays the words on its own screen — they never appear on your computer, which is the entire point of the arrangement.

  • Select create new wallet, never recover, unless you are deliberately restoring an existing one.
  • Write the words down in order, by hand, on the supplied cards or a metal plate.
  • Complete the confirmation step the device runs afterwards. It catches transcription errors while they are still fixable.
  • Keep the backup and the device in different places once you are finished.
  • Never photograph the words, type them into a computer or phone, or store them in a password manager.
  • Nobody legitimate will ever ask for them — not Trezor, not support, not a wallet-validation page.

4Standard backup, or Shamir shares

Safe models offer a second backup format: instead of one list of words, your key is split into several shares, of which a threshold is needed to rebuild it. You might create three shares and require any two.

The appeal is real. No single piece of paper is sufficient on its own, so one share found in a drawer does not compromise you, and one share lost in a fire does not lock you out.

Shamir shares are not multisig, and the difference matters

Shamir splits one key into pieces. When you recover, those pieces are reassembled into that single key, which exists whole again on the device at that moment. Multisig uses several genuinely independent keys, and no single key is ever sufficient or ever assembled anywhere. They protect against different things, and Shamir is not a substitute for multisig.

  • If you use Shamir, store every share in a different place. Two shares in one house is a standard backup with extra steps.
  • Record the threshold in writing — a future you who finds three envelopes needs to know how many are required.
  • Test the recovery with only the threshold number of shares, not all of them.
  • If any of that sounds like more than you want to manage, the standard single backup is a perfectly good choice.

5Set the PIN

The PIN protects the device against someone who physically has it. Set one during the guided setup, choose something you can recall under stress, and record it somewhere durable and separate from your recovery words.

On models with a touchscreen the PIN is entered on the device itself, so a keylogger on your computer never sees it. Wrong guesses trigger an increasing delay, which makes brute-forcing impractical rather than merely slow.

The PIN is not what keeps your bitcoin safe

Anyone holding your recovery words can rebuild this wallet without ever touching the device or knowing the PIN. The PIN buys you time if the device is stolen. The backup is the thing that has to stay secret.

6Turn off what you are not using

Premium models add conveniences — Bluetooth, wireless charging, a battery — and each one is a feature you may not want on a device whose job is to sit in a drawer and be boring.

Bluetooth in particular can be disabled. If your Trezor lives at home and only ever connects by cable, there is no reason to leave a radio enabled on it. This is not a claim that the radio is broken; it is the ordinary principle that a capability you never use should not be switched on.

7Decide about a passphrase — carefully

A passphrase creates an additional wallet reached by your recovery words plus that phrase. Trezor calls these hidden wallets, and they are genuinely useful: the words alone lead to a separate, ordinary-looking wallet, so a backup found by someone else does not reveal everything.

They are also the most common way people lose funds through their own configuration, and are worth reading about properly before you commit to one. A passphrase is not a password on an account — there is no reset, no hint, and no error message. A single wrong character silently opens a different empty wallet that looks exactly like a wallet you have emptied.

  • Do not add a passphrase on a first setup unless you already understand how to recover from one.
  • If you use one, record it as carefully as the seed, stored separately so finding one does not hand over both.
  • Write down the fact that you used a passphrase at all. People have restored the words alone, seen an empty wallet, and concluded the backup failed.

8Verify an address, then check the backup

Two checks before this wallet holds anything meaningful, and neither is optional.

  • Generate a receive address and display it on the device screen. Compare the full string against what the computer shows — malware that swaps addresses in the clipboard is common, and the device screen is the display it cannot rewrite.
  • Run the backup check in Trezor Suite. It has you re-enter the words and confirms whether they match the key on the device, without overwriting anything.
  • Send a small test amount, confirm it arrives, and send it back out again.
  • If you set a passphrase, run both checks against the passphrase wallet as well — that is the wallet you will actually use.

The backup check is comparing, not restoring, so it is safe to run at any time. What it does not prove is that you could rebuild the wallet on different hardware — for that, do a full restore onto a spare device at least once before the amount gets serious.

What this setup does not protect against

Trezor's design is open source, which means its security properties are examined publicly rather than asserted. That is a real advantage, and it also means the limits are documented rather than hidden.

  • A passphrase you cannot reproduce. Nothing in the device can help you here. This remains the most likely way to lose a correctly set-up wallet.
  • Approving a bad transaction. If you confirm a payment to an attacker's address on the device screen, everything worked exactly as designed. Verification is your job, and it happens before you press confirm.
  • A backup stored badly. The device cannot know that your recovery card is in the same drawer as the Trezor.
  • Sophisticated physical attacks. Secure elements raise the cost of extracting a key from a device someone is holding, considerably. They do not make it impossible, which is a reason to treat physical loss as urgent rather than merely annoying.

Before you fund it properly

Run the full drill in test your recovery. A wallet you have never restored is the one part of this setup that has not actually been checked — and it is the part everything else depends on.

Model lineups, firmware editions, and menu wording change between releases. Confirm the current setup flow against Trezor's own documentation before following any step here that does not match what your device is showing you.

Do not guess

Stuck on a step?

If the screen in front of you does not match the guide, stop. Review the related walkthroughs or get a second set of eyes before exposing recovery words or approving a transaction.