TL;DR
Set up each hardware wallet as a new wallet: a PIN, a fresh 24-word seed you write down by hand and, if you want one, a passphrase. Two factory defaults need changing on the way.
What you need
- The three devices, packaging unopened
- Your signing computer with Trezor Suite, BitBoxApp and Ledger Wallet installed (step 2)
- The paper recovery cards that came in the boxes, and a pen
Steps
- Check the packaging, and the tamper seal where the device has one. Let each maker’s app run its authenticity check. A device that already has a seed on it goes back.
- Connect one device at a time, open its app and install the latest firmware.
- Choose create a new wallet and set a PIN. Use a different PIN on each device and don’t write any of them down next to a device.
- Trezor Safe 5: before you create the wallet, open the backup type menu and pick the legacy 24-word option. The default is a 20-word backup in a different standard (SLIP39) that your BitBox02 and Ledger can’t restore. You can’t convert it later. You’d have to start over with a new wallet.
- BitBox02: under Advanced options, choose to skip the microSD backup and write down the recovery words instead. The microSD card isn’t protected by a password, so anyone who finds it can restore your wallet.
- Ledger Nano S Plus: install the Bitcoin app, version 2.1 or newer, through Ledger Wallet. Don’t switch on Ledger Recover. Your backup is your own metal plate.
- Write down the 24 words each device shows, in order, and confirm them on the device when it asks.
- Give each device a letter (A, B, C) and write down which is which. You’ll use that in your notes later.
The seed rules
Most of the seed losses I’ve read about broke one of these.
- The words go on paper now, on metal in step 5, and back into a hardware wallet if you ever need to restore. Nowhere else.
- Never type them into a computer, phone, website or Sparrow. Never photograph them. Never store them digitally.
- Nobody legitimate will ever ask for them. Not support staff, not an exchange, not a “recovery service”.
Optional: a passphrase
A BIP39 passphrase is an extra word or sentence on top of the 24 words. The seed plus the passphrase opens a completely different wallet. Someone with only the words sees an empty one.
Be clear about what it protects against. It helps when a seed leaks remotely: a device that generated weak seeds (the Coldcard case from step 1), or a photo of a plate that ends up online. If you store the passphrase next to each seed, which I do so it can never become a separate thing to lose, it doesn’t help against someone who finds your boxes. You decide if that trade is worth it. Plenty of people skip it.
If you use one:
- Use the same passphrase on all three devices.
- Keep it to 50 characters of plain ASCII (the Trezor limit is 50). Four to six random words works well.
- Use something you’ve never used anywhere else.
- Trezor: enable passphrase in Trezor Suite, in the device settings. BitBox02: Settings → Manage device → Expert settings → Passphrase. Ledger: on the device, Settings → Security → Passphrase → Attach to PIN, which gives you a second PIN that opens the passphrase wallet.
A wrong passphrase gives no error
Every passphrase opens a valid wallet, including one with a typo in it. From here on, always unlock the passphrase wallet before you use a device with Sparrow. If you don’t, Sparrow gets the keys of the empty wallet and doesn’t warn you. Step 10 includes a check for exactly this.
Common mistakes
- Accepting the Trezor’s default 20-word backup.
- Keeping the BitBox02 microSD card “as an extra backup”.
- Taking a photo of the recovery card “for a minute”.