KeyHaven

Independent self-custody guide

Own your keys.
Understand the whole path before you move a single coin.

KeyHaven walks you from unboxing to your first verified transaction — device configuration, an offline backup you can actually trust, privacy settings worth changing, and the habits that keep an account safe for years rather than weeks.

  • Offline key storage
  • On-device verification
  • Backup discipline
  • Portfolio clarity

Four rules this whole site is built around

  • The backup is the asset
  • The screen you sign on is the screen you trust
  • Privacy is a setting, not an accident
  • Nobody legitimate asks for your words

Start here

A setup path in four deliberate steps

Each step takes minutes. Skipping any one of them is how most losses begin — not with a broken device, but with a rushed afternoon.

  1. 01

    Unbox and inspect

    Buy from a source you can trace. Check the seal, the packaging and the device shell for tampering, and confirm that no recovery words arrived pre-printed. A device that ships with a "ready" seed phrase is a device to return.

  2. 02

    Install the companion app

    Download the desktop or mobile app only from the vendor's own site, and verify the release signature where one is published. The app is a window into your accounts — it never needs to hold your keys to show you a balance.

  3. 03

    Create the backup offline

    Let the device generate the recovery words and write them by hand, in order, on paper or stamped metal. No photo, no cloud note, no password manager entry. Then run the built-in recovery check so you know the set is complete before you fund anything.

  4. 04

    Send a test and verify it

    Move a small amount first. Watch the address and the amount on the device screen, approve there, and confirm the balance updates. Only then transfer the rest — the muscle memory you build on a small transaction is the point.

What a good companion app gives you

Convenience on the outside, custody on the inside

A wallet app should make your holdings easier to read without ever making them easier to take.

On-device verification

Every address and amount is confirmed on the wallet screen, where malware on your computer cannot reach it.

Portfolio in one place

Accounts, balances and history across chains, read-only by design so nothing can be moved from the dashboard.

A passphrase layer

An optional word you memorise adds a hidden account: a stolen backup alone no longer opens your funds.

Privacy controls

Point the app at your own node, avoid address reuse, and choose how much it tells the wider network about you.

Device management

Firmware updates with a signed changelog, PIN changes, and a clear view of which accounts live on which device.

Backups you can test

Rehearse a restore on a spare device before you need it. Practised recovery is the difference between calm and panic.

Security model

Two habits carry almost all the weight

Hardware removes the most common attack — a key sitting on a machine that is online all day. What it cannot do is protect a phrase you typed somewhere, or an amount you approved without reading. Everything below follows from those two facts.

Read the questions people ask first
  • Write the words by hand.Paper or metal. In order, stored where a passport would live.
  • Never digitise the backup.No photos, no cloud notes, no chat messages, no password managers.
  • Buy direct or from a traceable seller.Resold and marketplace devices are where tampering hides.
  • Read the device screen, every time.If the app and the device disagree, stop and start again.
  • Treat urgency as a warning sign.Pressure, countdowns and "verify your wallet" links are the tell.
  • Expect zero legitimate requests for your words.Not from support, not from a wallet app, not from an exchange.

Journal

Self-custody, explained without the theatre

Why your recovery phrase should never touch a keyboard

A hardware wallet does one job that matters more than any screen or chart: it keeps your private keys somewhere the internet cannot reach. Everything else — portfolio tracking, price alerts, transaction history — is convenience layered on top of that single guarantee.

The most common mistake is not a sophisticated hack. It is a moment of panic or haste. A convincing email arrives, a support chat opens with a friendly tone, and someone types twelve words into a website that looks exactly like the one they trust. No device, however well built, can protect a phrase that has already been copied.

Treat those words like the deed to a house. Write them by hand, in order, on paper or metal. Store them somewhere you would keep a passport. Never photograph them, never paste them into a password manager, never email them to yourself, and never read them aloud on a call. Nobody legitimate will ever ask for them — not support staff, not an exchange, not a wallet app.

Verifying on the device itself is the other half of the habit. The screen you trust should be the one you sign on: confirm the address, confirm the amount, then approve. If the two screens disagree, stop and start again.

Self-custody is not about eliminating risk. It is about making sure the risk stays yours to control.

Published by the KeyHaven editorial desk · independent, non-commercial education

FAQ

The questions people ask first

Does a hardware wallet need to be online?

No. The device stays offline and connects only when you sign a specific transaction. The approval happens on its own screen, which is the part your computer cannot fake or reach.

Should I keep a photo of my recovery phrase?

No. A photo syncs, backs up, and gets shared without you deciding to share it. Write the words by hand and keep them offline.

What happens if the device is lost or damaged?

A tested backup set restores access on a replacement device. That is why the backup — not the device — is the thing worth protecting most carefully.

Do I still need a passphrase if I already have a PIN?

A PIN protects a device you hold. A passphrase protects against a backup someone else has found. They solve different problems, and many people use both.

Is this an official wallet manufacturer's website?

No. KeyHaven is an independent educational resource. It is not affiliated with, endorsed by, or operated by any hardware wallet manufacturer, and it never asks for recovery words, keys, or seed entry of any kind.

Start with step one, not with a transfer

Twenty quiet minutes now saves a very loud afternoon later.

Begin the setup path