Hardware wallets
Intended reader: someone who wants keys held on a dedicated device rather than in a browser. Goal: signing on hardware, with the extension used only to build and broadcast. Prerequisites: a Keystone device. Safety: verify every address and every amount on the device screen, not in the browser.
What is available
Section titled “What is available”| Device | State in this build |
|---|---|
| Keystone | Connectable. Air-gapped QR, and USB. |
| Ledger | Listed, and disabled. The connect control shows coming soon and cannot be used. |
| Trezor | Listed, and disabled, the same way. |
| Any other device | Not integrated. Use the watch-only flow and sign elsewhere. |
Why hardware helps
Section titled “Why hardware helps”The private keys stay on a device that has no browser, no extensions, and no web pages. Even a fully compromised computer cannot extract them. What it can still do is show you a transaction that is not what you think it is, which is why the device screen matters more than the browser screen.
Steps, Keystone
Section titled “Steps, Keystone”- Open the wallet and add a hardware wallet.
- Choose Keystone.
- Connect over USB, or scan the QR sequence the device shows for the air-gapped path.
- Select the account and address type. See Address types.
- Verify the first address shown in the extension against the device screen.
Signing
Section titled “Signing”- Build the transaction in the extension as usual.
- The extension hands it to the device, over USB or as a QR sequence.
- Read the transaction on the device screen. Amount, destination, fee.
- Approve on the device.
- Return the signature to the extension, which broadcasts it.
Expected result
Section titled “Expected result”A wallet whose keys are on the device. The extension can build transactions and show balances, and cannot sign anything on its own.
Common failures
Section titled “Common failures”| What you see | What it means | What to do |
|---|---|---|
Ledger or Trezor is disabled, reading Coming soon | Not implemented as a connection in this build | Use Keystone, or watch-only |
| The device is not detected over USB | Browser permission, cable, or firmware | Try the air-gapped QR path instead |
| Addresses differ between device and extension | Address type or derivation path mismatch | Fix before receiving anything |
| The QR sequence will not complete | Screen brightness, camera focus, or a partial scan | Restart the sequence from the beginning |
Recovery path
Section titled “Recovery path”A hardware wallet has its own recovery phrase, held by the device, not by Universe Wallet. Losing the device is survivable if you have that phrase. Losing the phrase is not, exactly as described in Backup and recovery.