Hardware wallet onboarding, explained

Trézor.io/Start: Set Up Your Trezor® Hardware Wallet the Safe Way

Trezor.io/Start is the starting point for every new Trezor device: it is where you install Trezor Suite, flash the official firmware, create your wallet and back up your recovery seed. This guide walks through that process step by step — in plain language, with the security habits that keep your coins out of reach of thieves.

  • 10–15 minute setup
  • Model One → Safe 5
  • No seed phrase is ever requested here
Backlit computer keyboard in blue and teal light, representing secure hardware wallet setup on a computer
Golden rule of setup Your recovery seed is created on the device and stays offline. No website, app or support agent ever needs to see it.

The starting point

What is Trezor.io/Start?

Trezor.io/Start is the official onboarding entry point for a new Trezor hardware wallet. Instead of asking you to configure the device by hand, it hands you off to Trezor Suite — the desktop and web application that talks to your device — and then guides you through firmware installation, wallet creation and your first backup.

1. It installs the official software

From there you download Trezor Suite for Windows, macOS or Linux, or use the browser version. Suite is the only tool you need for the rest of the journey — no third-party wallet app is required, and using one from an unknown source is a common way people lose funds.

2. It flashes verified firmware

A factory-fresh device ships without firmware. Suite checks the firmware's cryptographic signature before it is written, so a tampered file cannot be installed silently. Firmware updates later in the life of the device follow the same verified path.

3. It creates your wallet on the device

Your private keys and your recovery seed are generated by the device's own random number generator and never leave it. The computer you plug into only ever sees public information — addresses, balances and signed transactions.

This site is an independent guide

Trezor Start Guide is an educational resource that explains the official onboarding flow. It is not affiliated with, endorsed by or operated by SatoshiLabs. Always download software from the official trezor.io/start address, and never from an advertisement, a search result you are not sure about, or a link sent to you in a message.

At a glance

Your first Trezor setup in six moves

This is the short version. The full Trezor.io/Start setup guide expands every step, including what to do when a device is not detected or a firmware install stalls.

Step 01

Check the box before you open it

Inspect the packaging for a damaged seal and look for a pre-filled recovery card. A genuine device never arrives with a seed phrase already written down.

Step 02

Get Trezor Suite from the official site

Type trezor.io/start into the address bar yourself, then download Suite or open the web app. Bookmark the page you landed on so the next visit cannot be hijacked.

Step 03

Install firmware

Connect the device with the cable that came in the box and let Suite install the signed firmware. Keep the device plugged in until the progress bar finishes.

Step 04

Write down your recovery seed

The device shows the words one by one. Copy them onto the supplied cards in order, on paper, offline — never as a photo, a screenshot, a note app or a cloud document.

Step 05

Set a device PIN

Choose a PIN you do not use anywhere else and enter it on the device itself. The PIN locks the hardware, not the blockchain, and it is confirmed on-screen so malware cannot read it.

Step 06

Test with a small amount first

Receive a small amount, check that the address shown in Suite matches the address shown on the device screen, then send it back out. Confidence beats guessing.

Preparation

What to have ready before you start

Ten minutes of quiet, uninterrupted time is worth more than any tool. Setup involves writing down words you will only see once, so do it somewhere private — not in a café, not on a shared screen, and not on a remote-desktop session.

  • Your Trezor device and the USB cable from the box.
  • A computer or phone with a free USB port or the ability to connect the device directly.
  • A pen and the recovery seed cards included in the packaging.
  • The official address — typed by hand: trezor.io/start.
  • A private space where nobody can photograph your screen or your seed card.
Three things that are always a red flag
  • Anyone asking for your recovery seed — including "support", "migration" or "validation" teams.
  • A device that arrives with the seed already written on a card in the box.
  • Software downloaded from an advert, a shortened link, or a file sent by a stranger.
Buy from a source you can trace

Ordering from the official store or an authorised reseller keeps the supply chain short. Second-hand devices can be made to look new, and a device someone else has handled may already have a seed that they know.

How the protection works

Three layers between a thief and your crypto

A hardware wallet is not magic — it is three separate protections stacked together. Understanding what each one does makes the security advice much easier to remember.

The device PIN

The PIN protects the hardware itself. It is entered on the device, so malware on your computer cannot capture it. After a set number of wrong attempts the device wipes itself, and you restore from your backup — which is exactly why the backup matters.

More on PIN protection

The recovery seed

Twelve to twenty-four words that rebuild your wallet on any compatible device if yours is lost, stolen or destroyed. Whoever holds the words holds the money — so the words live on paper or steel, offline, and are never typed into a computer.

More on seed backups

The passphrase (optional)

An advanced setting that adds a secret word of your own on top of the seed, creating a hidden wallet. Powerful, but unforgiving: lose the passphrase and the hidden wallet is gone, seed or no seed. Learn it fully before you rely on it.

More on passphrases

Which device do you have?

Setup is the same, the buttons are not

The onboarding flow in Trezor Suite covers every model. What changes is how you confirm things on the hardware: the entry-level models use two buttons and a screen-shown keypad, while the touchscreen models let you tap the PIN directly.

Model One

Two-button control, monochrome screen, USB micro-B. The most budget-friendly entry into a hardware wallet.

Model T

A colour touchscreen and USB-C. Comfortable for entering longer PINs and passphrases on the device.

Safe 3

Current-generation hardware with a certified secure element and USB-C, still button-driven.

Safe 5

Large colour touchscreen, haptic feedback and the same certified chip — the most intuitive to set up.

Security habits

Six rules that never change, whatever your setup

  • Download from one address only. Type the official Trezor address yourself, and keep the bookmark.
  • Never type your seed into anything electronic. No website, no app, no "restore" pop-up, no chatbot.
  • Read the device screen every time. The amount and the address on the hardware must match what Suite shows.
  • Never photograph your seed or keep a copy in a password manager, cloud note or email draft.
  • Never buy a device with a suspicious seal — return it instead and order again.
  • Never trust a support message that arrives first. Real support does not open the conversation.
If you think your seed has been exposed

Treat the wallet as compromised. Create a new wallet with a freshly generated seed on your device, move your funds to the new addresses, and only then destroy the old backup. Changing your PIN does not help — the PIN does not change the seed. See the recovery plan.

Quick answers

Questions people ask before their first setup

Is Trezor.io/Start the official setup page?

Yes — it is the onboarding address published by SatoshiLabs for new Trezor devices, and it leads into Trezor Suite. This website is an independent guide explaining that flow; it is not the official page and never asks for any wallet information.

Can I set up a Trezor without a computer?

You still need a device to run Trezor Suite and to install firmware, but a phone works for many setups. A desktop or laptop is usually the smoothest option for the first run, and it avoids the risks of typing on a device full of other apps.

How long does the setup take?

Most people finish in ten to twenty minutes: a few minutes for the download, a few for the firmware, and the rest for writing down the seed carefully. Rushing the seed step is the single most expensive mistake you can make.

What happens if I lose the device?

You buy a replacement and restore your wallet from the recovery seed, which puts your coins back in reach. The seed is the wallet; the device is only the keyring that unlocks it.

Ready to set up your device?

Move through the steps in order, take your time on the recovery seed, and test with a small amount before you move real money. That is the whole method.