Everything you need to know about unlocking a Trezor hardware wallet through Trezor Suite — how the desktop app works, how the browser app works, what happens on the device screen, and how to keep your keys safe while you do it.
A hardware wallet has no online account. There is no website where you type a password and reach your coins, and no legitimate software will ever ask you to type your recovery seed to log in. Anyone who asks for your 12, 20 or 24 words — on a page, in an email, in a chat, or on the phone — is trying to empty your wallet.
With a normal online service, logging in proves that you know a password. With a hardware wallet, the login is a physical act. Your private keys never leave the small device plugged into your computer; the device itself signs whatever needs signing, and the wallet software on your screen is only a window onto the blockchain. The "login" is really an unlock: you let the device use its keys for a session, and when you unplug it they are sealed away again. Nothing you type into a browser tab can move funds on its own.
Trezor Suite is the official companion application made by SatoshiLabs, the Czech company behind Trezor. It replaced the older browser-based Trezor Wallet and exists in two forms: a downloadable desktop program and a web version. Most owners should use the desktop build.
Suite also has a mobile app focused on the essentials; the desktop program covers the full feature set — coin control, labelling, buy and exchange integrations, and portfolio charts.
The web app runs at the company's own domain in a supported browser — convenient on a computer where you cannot install software. The trade-off is that you must be certain the address is right and that the browser can speak to the device.
Browser support matters more than people expect. WebUSB, which lets a page talk directly to a USB device, exists in Chromium-based browsers such as Chrome, Edge and Brave. Firefox and Safari do not offer it, so the web app cannot see a plugged-in Trezor there. On those browsers, and on older Windows machines, you need the Trezor Bridge helper service, a small background program that relays the connection between browser and device.
| Aspect | Suite Desktop | Suite Web |
|---|---|---|
| Installation | Download and install once | None — open a page |
| Browser needed | No | Chromium-based for direct access |
| Extra helper | Not required | Trezor Bridge on Firefox, Safari, older Windows |
| Firmware updates | Fully supported | Supported |
| Tor mode | Yes | No |
| Best for | Everyday long-term use | Quick access on a borrowed or locked-down computer |
Whichever version you open, the sequence is almost identical. The device is doing the security work; the app is only asking.
Your recovery seed is typed only into the hardware device itself, only during setup or recovery. No login, no update, no support agent and no "wallet validation" page needs it. Treat any request for those words as an attack in progress.
A password lives on someone else's server, which means someone else can lose it, leak it or reset it. Your keys live on a chip in your desk drawer, so the only credential that matters is possession plus the PIN. Three consequences follow naturally:
| Feature | Model One | Model T | Safe 3 | Safe 5 |
|---|---|---|---|---|
| Released | 2014 | 2018 | 2023 | 2024 |
| Interface | Mono screen, 2 buttons | Colour touchscreen | Mono screen, 2 buttons | Colour touchscreen, haptics |
| PIN entry | Buttons on device | On device glass | Buttons on device | On device glass |
| Secure element | No | No | Yes | Yes |
| Shamir backup | No | Yes | Yes | Yes |
| Connector | micro-USB | USB-C | USB-C | USB-C |
Firmware releases for the oldest hardware eventually slow down, so an early Model One owner sees fewer new features. The unlock flow, though, stays familiar across every generation.
The shuffled keypad means the position you click tells a watcher nothing — not even a screen recorder can rebuild the PIN from those coordinates.
A passphrase creates a separate wallet from the same seed, so anyone who forces you to open your device sees only the wallet you choose to reveal.
Payments, addresses and firmware signatures are approved on the trusted screen, so malware on the computer can propose but never approve.
Suite refuses firmware not signed by the manufacturer. Supported models can also split a backup into shares, so no single written copy restores the wallet alone.
| Symptom | Usual cause | What to try |
|---|---|---|
| Device not detected | Charge-only cable, or a bad port | Use the supplied cable, try another port, avoid unpowered hubs |
| Web app sees nothing | Browser without WebUSB | Switch to a Chromium-based browser, or install Trezor Bridge |
| Permission prompt ignored | Blocked device access | Reconnect, then allow the prompt; check site permissions |
| PIN pad does not appear | Stale Suite session | Fully quit and reopen the app, then reconnect |
| Wrong PIN warning | Wrong wallet unlocked | Recheck carefully; the countdown grows and a wipe follows ten failures |
| Different addresses after unlocking | A passphrase wallet behaving as intended | Hidden wallets look empty by design — that is the feature |
| Untrusted firmware message | Non-genuine or corrupted build | Do not proceed; reinstall official firmware through Suite |
Yes. The device travels, the keys stay on the chip, and the software reads nothing more than what you approve. On a computer you do not trust, prefer the device's own touchscreen for PIN entry and always check the confirmation screen.
Because a fixed keypad would let malware record which positions you clicked and reconstruct the code. The device and the screen agree on a random layout that changes every time.
No. The PIN unlocks the device itself. The passphrase, typed at the wallet level, opens a hidden wallet derived from the same seed. Losing the passphrase loses that wallet permanently.
The device wipes itself back to factory state. Your funds are untouched on the blockchain — restoring with the seed brings them back, which is why that seed must be backed up properly.
Never. The seed is used once, during setup or recovery, typed on the device. Any page asking for it during a normal unlock is a phishing attempt.
Logging in to a hardware wallet is deliberately awkward in one way: it insists a human presses a button on a physical object. That friction is the security. Every convenient alternative — a stored password, an extension holding keys, a page that "verifies" your seed — trades away the thing you bought the device for.
Use the desktop application day to day, keep the web app for borrowed machines, confirm everything on the device screen, and keep the seed offline. Then the login becomes what it should be: a two-minute routine quietly protecting everything behind it.