What is a hardware wallet?
A hardware wallet is a small device that generates and stores private keys offline and signs cryptocurrency transactions inside the device, so the key never reaches the computer or phone. The crypto-assets stay on the blockchain. A hardware wallet is a cold wallet and a tool for self custody. The German term is Hardware-Wallet.
Hardware wallets in brief
| Term | Hardware wallet. Meaning: a cold wallet in the form of a device. German: Hardware-Wallet. |
|---|---|
| What it stores | Private keys. The backup is a separate list of words. |
| Core chip | Often a secure element, the chip type of bank cards and passports. |
| A number | Common Criteria rates chips on 7 evaluation assurance levels (EAL); vendors cite EAL5+ and EAL6+ for their secure elements (Ledger, January 29, 2026). |
| EU law | Making or selling a device is no custody under MiCA when the vendor has no access to the keys (BaFin, January 3, 2025). |
| Supervisors | BaFin in Germany, FMA in Austria, FINMA in Switzerland. |
How does a hardware wallet work?
A hardware wallet works by keeping the private key inside the device and signing there. The principle is known from bank cards: the secret stays in the chip, and the terminal only receives the result. The vendor Trezor describes the flow: the transaction details go to the device, "which then securely signs the transaction inside the device using your private key". The signed transaction goes back to the computer or phone, which sends it to the network (Trezor).
Signing takes four steps, explained here in order: wallet software on the computer builds the transaction; the device shows amount and address on its own screen; the owner confirms with a button or touch; the device signs. The device's screen matters because malware can alter what the computer displays. The vendor Ledger calls this "what you see is what you sign" (Ledger).
What is a secure element in a hardware wallet?
A secure element is "a tamper-resistant chip designed to securely store secrets and enforce access controls", in Trezor's definition, and "the same type of chip used in credit cards and passports" (Trezor). It checks the PIN in hardware. After a set number of wrong PIN entries, 16 on some devices, it erases its secret and the device resets; the owner then restores the wallet from the backup.
Ledger lists the attacks the chip is built to resist: side-channel attacks that read power use or radiation, fault attacks with lasers or voltage glitches, and attempts to load other software. A third-party lab certifies the chip under Common Criteria.
Hardware wallet vs software wallet: what is the difference?
A hardware wallet differs from a software wallet in where the key lives, and from an exchange in who holds it.
| Feature | Hardware wallet | Software wallet | Exchange account |
|---|---|---|---|
| Who holds the key | The owner | The owner | The exchange |
| Where the key lives | In a separate device, offline | On a computer or phone that is online | In the exchange's systems |
| Type | Cold, non-custodial | Hot, non-custodial | Custodial |
| Main risk | Loss or theft of the backup | Malware on the device | Failure of the exchange |
A hardware wallet and a cold wallet differ in scope. Trezor defines a cold wallet as one "where private keys are generated and stored offline"; a hardware wallet is one device for this, and cold storage is the practice of keeping keys offline. A hardware wallet is a tool for self custody and therefore non-custodial: the owner holds the key. The page What is a crypto wallet? covers the other wallet types.
What does a hardware wallet protect against, and what not?
A hardware wallet protects the private key against malware on the connected computer and makes physical attacks on a stolen device hard. Trezor recalls that in the early days of cryptocurrency, keys sat in encrypted files on computers and malware emptied whole wallets. Today it states that "even if your computer or smartphone is compromised, the private keys stored in your hardware wallet remain safe".
It does not protect the backup. The same vendor warns that anyone with the backup "can access your wallet without needing your Trezor", and that the biggest risk often comes from phishing aimed at the backup. It also does not stop blind signing, which Ledger defines as "the act of approving a digital transaction without being able to verify its full details in a human-readable format" (Ledger, April 16, 2026). A device that shows only "Data Present" gives the owner nothing to check. The vendor cannot restore a lost backup either.
Hardware wallets in Germany, Austria and Switzerland
A private person who buys a hardware wallet needs no license, and the vendor needs none as long as it has no access to the keys (BaFin, January 3, 2025). A bank or asset manager that uses such devices to hold keys for clients provides custody under MiCA, which applies directly in Germany and Austria. A credit institution notifies BaFin or the FMA under Article 60(1) at least 40 working days before the start. The client agreement must describe "the security systems used" under Article 75(1)(e).
DORA adds duties for the keys and the devices that store them. Article 7 of Delegated Regulation (EU) 2024/1774 requires controls that protect keys "against loss, unauthorised access, disclosure, and modification" and a register of certificates and "certificate-storing devices" for assets that support critical or important functions. BaFin supervises under the KMAG.
Institutional custodians use cold storage on a larger scale. BitGo Europe GmbH, based in Frankfurt, received a MiCA license from BaFin on May 12, 2025 and offers custody from regulated cold storage to firms across the EU (BitGo, May 12, 2025).
Switzerland is outside the EU, so MiCA and DORA do not apply there. FINMA Guidance 08/2023 states that a bank may keep crypto-assets off its balance sheet as custody assets only if they are "held in readiness for the customer at all times"; otherwise payment tokens count as deposits with capital requirements. This page gives no legal advice.
Sources
- Trezor: Trezor hardware wallets and their advantages, retrieved September 29, 2026
- Trezor: Secure Elements in Trezor Safe devices, retrieved September 29, 2026
- Ledger: The Secure Element Chip: How It Keeps Your Ledger Secure, updated January 29, 2026
- Ledger: Blind Signing, updated April 16, 2026
- European Union: Regulation (EU) 2023/1114 on markets in crypto-assets, May 31, 2023
- European Commission: Delegated Regulation (EU) 2024/1774 on ICT risk management tools, methods, processes and policies, March 13, 2024
- BaFin: Merkblatt: Hinweise zu den Kryptowerte-Dienstleistungen nach MiCAR, January 3, 2025
- Federal Republic of Germany: Kryptomärkteaufsichtsgesetz (KMAG), December 27, 2024
- FINMA: FINMA publishes guidance on staking services, with Guidance 08/2023, December 20, 2023
- BitGo: BitGo Secures MiCA License from BaFin to Expand Digital Asset Services Across the European Union, PR Newswire, May 12, 2025
About Finance Loop: hardware wallets
Finance Loop is the meeting place for custody and IT security teams at banks and asset managers who decide which client keys go into cold storage. In Frankfurt, BitGo Europe received a MiCA license from BaFin on May 12, 2025, and offers custody from regulated cold storage to firms across the EU.
Finance Loop was a partner of the Crypto Assets Conference 2026, which Frankfurt School and Deutsche Börse Group hosted in March 2026 at Frankfurt School. Its program for the financial industry covered regulation, custody, tokenization and market infrastructure.