Start your 3-day free trial
Sign up to experience all premium features at no cost.
*Available only to new users. Each user is limited to one trial.


If you have a lost hardware wallet, first determine whether only the device is missing or whether its PIN, recovery backup, passphrase, or unlocked session may also be exposed. A locked device with a strong PIN and a safe backup is different from a stolen device plus photographed recovery words. Restore only with trusted hardware and verified software; create a new wallet and move assets when secret exposure is plausible.
Key Takeaways
- Losing the device does not remove assets from the blockchain and does not automatically expose the keys.
- Preserve the recovery backup, but never type it into a website, chat, form, or unverified application.
- If the PIN or recovery secret may be known, restore safely and migrate to addresses controlled by a new backup.
- If both the device and the only backup are gone, do not erase a remaining authenticated session until you understand whether it can still authorize a rescue transfer.
- Ignore direct messages offering “wallet recovery”; legitimate helpers do not need your seed words.
Classify the incident before touching the backup. The wrong reaction can turn a recoverable loss into permanent loss—for example, entering a seed into a fake recovery site or resetting the only device that still has access.
| Situation | Immediate risk | Appropriate next move |
|---|---|---|
| Device lost; backup safe; PIN not exposed | Lower, but not zero | Monitor addresses, obtain trusted replacement, restore and verify |
| Device lost; PIN may be exposed | Higher physical-access risk | Restore promptly and move to a new wallet |
| Recovery backup copied, photographed, or disclosed | Keys may already be compromised | Create a new wallet from new entropy and migrate immediately |
| Backup lost; working device or session remains | Future recovery is at risk | Carefully create a new wallet and transfer while access remains |
| Device and only backup both lost | Access may be permanently lost | Preserve any remaining session and seek official device-specific guidance |
Ledger explains that a lost device can be replaced and accounts restored with the recovery phrase, while its PIN protects access to the missing device.[1] That does not make every loss harmless: PIN strength, device state, passphrase use, firmware, and physical possession all affect risk.
Write down what is missing, when and where it disappeared, who may have had access, and whether the device was unlocked. Do not include the recovery words in those notes. Check for recent outgoing transactions using a trusted wallet in watch-only mode or a reputable block explorer reached through a known address.
If theft is possible, preserve serial numbers, purchase records, travel details, and any police or venue report. Contact the device vendor through its official domain if a device-specific vulnerability or erase feature may apply. Do not install a “tracker,” “recovery utility,” browser extension, or firmware package sent by a stranger.
Avoid repeated guesses at the PIN. Hardware wallets commonly limit attempts and may wipe local key material. A wipe can be acceptable when a verified backup exists, but disastrous when it does not.
Separate four items: the physical signer, the PIN that unlocks it, the recovery phrase or other backup, and any optional passphrase or additional share. A backup without the correct passphrase may open a different empty wallet. A device-specific backup format may require a compatible recovery flow.
Inspect the backup's condition without photographing, dictating, uploading, or typing it into a networked note. Confirm that all required words or shares are present and in order. Trezor's recovery troubleshooting distinguishes missing or invalid backup words, passphrase mismatches, and different wallet-backup types.[2] Use the official instructions for the exact model and backup scheme.
If the backup is in a place another person may have opened, treat confidentiality as uncertain even if it is still physically present. A copied seed leaves no visible trace.
Monitoring is reasonable only when the device was locked, the PIN was strong and private, the backup and passphrase remain confidential, and you can tolerate the residual risk while obtaining a replacement. Add the known public addresses to a watch-only wallet; never import the seed merely to watch balances.
Restore when you need normal access and the existing recovery secret is still trusted. Obtain hardware from the manufacturer or an authorized channel, inspect packaging and device guidance, install software from a typed or bookmarked official domain, and verify its signature or checksum if the vendor provides that process. Initialize recovery on the hardware device itself whenever the documented workflow supports it.
Migrate when the PIN, recovery phrase, passphrase, or authenticated signing session may be exposed. On a separate trusted device, generate a completely new wallet and a new backup. Verify a receiving address on its trusted display. Send a small test, confirm it at the new wallet, then move the remaining assets according to priority and network fees.
Do not “change” one word in an old seed or reuse an exposed passphrase. New addresses must be controlled by fresh secret material that the suspected attacker never saw.
Use the manufacturer's official recovery procedure. Ledger's recovery-phrase guidance says the phrase should remain offline and should never be entered on a computer or smartphone or shared with anyone.[3] If an application, support agent, website, or browser prompt asks for all words, stop.
During recovery:
An empty balance does not immediately prove that the seed is wrong. The wrong passphrase, account index, derivation path, network, or wallet type can display different addresses. Stop and compare official compatibility guidance instead of trying the seed on random web tools.
Prioritize assets by value, liquidity, and attack risk. Native coins needed for network fees may have to move before tokens. Token approvals and smart-contract positions can complicate migration; do not sign an unknown “rescue” transaction. If there are credible unauthorized transfers, follow the evidence-preservation steps in the crypto hacks guide.
Treat each destination as a complete instruction. Verify network, address, memo or tag, and amount using the deposit-address checklist. After the move, revoke unnecessary approvals from the old account where doing so is safe, update allowlists, and keep the old addresses in watch-only monitoring.
Do not destroy the old backup until all intended assets, tokens, NFTs, staking positions, and contract claims have been accounted for. Some assets may be hidden on another supported network or account path.
If you still have an unlocked wallet application paired with the device, do not sign out, reset, update, or delete it impulsively. Determine whether the device is actually required to sign. A watch-only application cannot move funds, but a mobile or desktop signer might still have usable key material depending on the architecture.
If no valid key, device, share, backup, or recovery mechanism remains, the blockchain cannot recognize identity documents as a replacement signature. A manufacturer usually cannot reconstruct a seed. Be skeptical of paid tools that claim otherwise; they may steal remaining information or install malware.
The self-custody versus exchange guide explains why recovery authority differs between wallets and custodial accounts. If a stranger claims to be support, use the recovery scam guide before replying. The broader online security guide provides a general account and device checklist.
A lost hardware wallet is an incident to classify, not a reason to expose the backup in panic. Secure the remaining factors, observe public addresses without importing secrets, and use official hardware recovery if the seed remains trusted. When any signing secret may be exposed, create a fresh wallet on trusted equipment and migrate after verifying a test. If every access path is gone, preserve evidence and reject guaranteed-recovery claims.
No. The blockchain records the assets; the device protects keys used to authorize transactions.
A strong PIN raises the barrier on the device, but risk depends on the model, its state, and whether the recovery secret was also exposed.
Only follow the vendor's verified device-based recovery workflow. Never enter it into a website, chat, browser extension, or unsolicited app.
Not always. Compatibility depends on the backup standard, derivation paths, assets, and passphrase features. Follow official documentation for both devices.
Not necessarily. Migration is most urgent when the PIN, seed, passphrase, unlocked state, or supply-chain trust may be compromised.
Stop and check passphrase, backup type, account path, and network. Do not test the seed on random websites.
Conventional self-custody vendors generally cannot recreate a seed they never received. Managed recovery products have different terms and trust assumptions.
Only after you have confirmed every relevant asset and contract position under the new wallet and no longer need the old signing path.
Disclaimer: This article provides general security information, not legal, financial, investment, or asset-recovery advice.
Sources checked 8 September 2026.
Sign up to experience all premium features at no cost.
*Available only to new users. Each user is limited to one trial.





