Security checklist — Steps to secure a Nano X for long-term storage

Try Tangem secure wallet →

Security checklist — Steps to secure a Nano X for long-term storage

Table of contents


Why follow a ledger security checklist?

A short, disciplined setup reduces risk. I believe a clear checklist prevents the small errors that lead to big losses. Hardware wallet security is about layers: device integrity, seed phrase safety, firmware authenticity, and operational habits. This ledger security checklist focuses on those layers with practical, step-by-step controls for long-term storage (self-custody).

What I’ve found in my testing is that users who skip the basics—like verifying firmware or testing a recovery—create single points of failure. Avoid that. Follow a methodical approach.

Related reading: Unboxing & first impressions and Where to buy safely.


Before you open the box: supply-chain & unboxing checks

If you have concerns, stop and contact support through official channels listed on the manufacturer site. See our supply chain and tamper guide for more.

And don't plug the device into random computers until you finish the setup steps below.


Step by step: First-time setup (PIN, seed generation)

How to initialize a Nano X (step by step):

  1. Power on and follow on-screen prompts. Confirm language and choose "Initialize as new device" if you want a fresh seed.
  2. Set a PIN code. Make it memorable but not trivial; avoid birthdates.
  3. When the device generates the seed phrase, write it down exactly as shown. Confirm each word when prompted.
  4. Do not store a photo or digital copy of the seed phrase. Never enter your seed into a computer or phone.
  5. Verify the device prompts the expected number of words (12 or 24) and that each confirmation step matches what’s on the screen.

I noticed during my first runs that people often rush through the word confirmations. Don’t. This is your master key. Think of your seed phrase like the master key to a safe deposit box: treat it accordingly.

For a full setup walkthrough see first-time setup and nano-x-setup.


Ledger seed phrase storage checklist: Where and how to store the recovery phrase

Ledger seed phrase storage checklist (practical rules):

Comparison: backup methods

Method Durability Tamper resistance Cost Best for
Paper (handwritten) Low Low Low Short-term or interim backup
Metal plate High Medium-High Medium Long-term, fire/water protection
Shamir (SLIP-39) High High Medium-High Distributed backup, recovery resilience

Shamir (SLIP-39) is an alternative known for splitting a secret into multiple shares. If you want that, research compatible wallets and workflows—do not assume every hardware wallet supports it. See seed phrase management and geo-distribution storage.

But remember: any backup is only as good as the processes around it. If you hide it but forget the location, that’s effectively destruction.


Firmware and verification — ledger verify firmware

Firmware keeps the device trusted. Always verify before updating. Ledger verify firmware steps include checking the official update channel and confirming the device's on-screen fingerprint or checksum (follow the official verification flow). Never install firmware files from unofficial sources.

Step-by-step guidance:

  1. Check the official release notes and firmware hashes via the manufacturer's verified channels.
  2. Use the companion app (official tool) to initiate the update; confirm that the device prompts match the update version.
  3. After the update, verify the device boots normally and that your accounts are present (no seed exposure required).

If you’re unsure how to proceed, see how to update firmware steps and firmware updates verification.


Connectivity and daily-use security: Bluetooth vs USB vs air-gapped

Connections matter. Bluetooth is convenient for mobile use but increases the attack surface compared to a direct USB connection. Air-gapped signing (no network connection) is the most restrictive option for transaction signing, but it requires compatible workflows.

Quick comparison:

Connection Convenience Attack surface Good use case
Bluetooth High Medium Mobile, on-the-go access
USB Medium Lower Desktop use, fewer wireless threats
Air-gapped Low Lowest High-security cold storage (PSBT workflows)

Turn off Bluetooth when you don't need it and prefer USB or air-gapped workflows for large, long-term holdings. See connectivity Bluetooth/USB and daily usage for practical tips.


Multisig, passphrase (25th word), and advanced long-term strategies

Multisig (multi-signature) setups add security by splitting signing authority across devices or locations. They reduce single-point-of-failure risk, especially for large balances or organizational holdings. However, multisig increases setup complexity and requires compatible wallets and clear recovery plans.

Passphrase (often called a 25th word) creates a hidden wallet derived from your seed phrase plus the passphrase. Pros: extra security and plausible deniability. Cons: if you lose the passphrase, funds are unrecoverable; inheritance becomes harder.

If you plan multisig or passphrase usage, practice recovery and document procedures for trusted heirs. See multisig setup and passphrase 25th word.


Final pre-storage checklist: Step-by-step before you put the device away

  1. Confirm firmware is up to date and verified. (/how-to-update-firmware-steps)
  2. Test a full seed recovery on a spare device or software wallet. (/restore-recovery)
  3. Create at least two independent backups and store them geographically separate. (/geo-distribution-storage)
  4. Disable Bluetooth if you won't use it. (/connectivity-bluetooth-usb)
  5. Note serial numbers and keep purchase records in a secure record file (not adjacent to the device or backups).
  6. Set an inheritance plan and record emergency access instructions with a trusted attorney or executor. (/inheritance-planning)

Common mistakes and recovery planning

Common mistakes: buying from unofficial sellers, photographing the seed phrase, testing recovery without wiping the device first, and relying on a single backup location. What happens if the device breaks? Test recovery; if you can restore from the seed onto another hardware wallet or compatible software wallet, you’re safe. See recover if broken.

What happens if the company goes bankrupt? Your seed phrase controls the keys, not the company. Still, plan for software compatibility and export paths. See company bankrupt.


FAQ

Can I recover my crypto if the device breaks?

Yes—if you have a valid seed phrase and passphrase (if used). Restore the seed on a compatible hardware wallet or a verified non-custodial wallet. Practice this ahead of time: a recovery test is worth the effort. (/restore-recovery)

What happens if the company goes bankrupt?

Your keys belong to you. The device maker going away doesn't remove your access to funds—as long as you have your seed phrase and compatible software/hardware remains available. Consider export and compatibility planning. (/company-bankrupt)

Is Bluetooth safe for a hardware wallet?

Bluetooth is generally safe if the device implements a secure pairing protocol, but it increases the attack surface. For long-term storage, minimize wireless exposure. (/connectivity-bluetooth-usb)


Conclusion & next steps

A disciplined ledger security checklist reduces risk and gives you confidence to store crypto for the long term. In my experience, the small extra steps—verify firmware, test recovery, and use robust backups—pay off over time. Want a deeper walkthrough? Read the full Nano X review, follow the setup guide, and check the firmware update steps.

But if you need help planning multisig or inheritance, see our guides on multisig setup and inheritance planning.

If you follow the checklist above you’ll be a lot safer. And that peace of mind is the point.


Related pages: Unboxing & setup, Seed phrase management, Connectivity & security.

Try Tangem secure wallet →