Protect the recovery phrase
Your 12/18/24‑word phrase is your wallet. Anyone with it can move your funds. Store it offline in at least one secure place; many users choose two separate locations for resilience against fire, flood, or theft.
Device screen = source of truth
When sending or receiving, compare the address on your computer with the one shown on the device. If they differ, cancel immediately and investigate.
Keep firmware and apps up to date
Updates deliver security fixes and compatibility improvements. Apply them via Ledger Live, read prompts carefully, and avoid rushed clicks.
Segment your holdings
Use separate accounts for spending, savings, and testing. Consider additional privacy strategies such as using fresh addresses and avoiding public address reuse when possible.
Phishing and social engineering
No employee or website should ask for your recovery phrase, PIN, or to “synchronize” your wallet by entering the phrase into a form. Those are scams. Close the page and return via your own bookmark.
Physical security
Don’t leave the device unlocked and unattended. Enable auto‑lock. If traveling, keep the device separate from any written backups.