Skip to main content

Never Type Your Hardware Wallet's Recovery Phrase Into Lace (or Any App)

Why You Should Never Type Your Hardware Wallet's Recovery Phrase Into Lace (or Any App)

If you own a hardware wallet, you already understand something important: your keys should never touch an internet-connected device. That's the entire point of "cold storage."

So it might seem harmless to type your hardware wallet's recovery phrase into a software wallet like Lace, especially if your device isn't currently supported. It isn't harmless. Here's why.

A recovery phrase is just your keys, in words

Your recovery phrase (usually 12 or 24 words) is your private key, represented in a human-readable format. Whoever has the phrase has full control of the funds it protects, no device required.

Hardware wallets don't generate a special, protected version of a recovery phrase. It's the same phrase you'd use to recover the wallet on any compatible software wallet, hardware wallet, or recovery tool.

So what happens when you type it into Lace?

Lace will faithfully do what it's told: recreate a wallet using those keys. But it recreates it as a software wallet, one where the private key is derived and used inside your browser or device, not inside a separate, isolated piece of hardware.

You now have two wallets with identical access to the same funds:

  • Your original hardware wallet (keys never leave the device)
  • A new software wallet in Lace (keys are processed on your computer)

The funds are the same, however, the security is not.

Why this matters

Hardware wallets exist specifically to keep your private keys isolated from internet-connected devices, protecting them from malware, phishing, and clipboard hijackers. Entering your hardware wallet recovery phrase into Lace or any software wallet does not automatically mean your funds are stolen on the spot. However, doing so immediately breaks cold storage security by exposing your seed phrase to a connected environment. Once a phrase touches an online device, its inherent offline protection is permanently compromised, making it far more vulnerable to future security breaches. For this reason, you should never enter your recovery phrase into Lace; always use the dedicated hardware wallet pairing method instead.

This isn't a Lace-specific issue, it's true of any software wallet, on any platform.

What to do instead

  • If your hardware wallet is supported by Lace, connect it directly through Connect Hardware Wallet - Lace will never ask for or see your recovery phrase in this flow.
  • If your hardware wallet isn't currently supported, don't work around this by entering the recovery phrase into Lace or any other software wallet, even temporarily.
  • Instead, check our [supported hardware wallets] page for updates, or reach out to us - we track this kind of demand and it helps us prioritize.
  • If you've already entered a hardware wallet phrase into a software wallet, treat that phrase as burned, not the funds. Move your funds to a new wallet with a freshly generated recovery phrase (ideally back on supported hardware) as soon as possible, then stop using the old phrase entirely.

There are a few ways to store your recovery phrase securely, such as:1. Written on paper, and into the specific hardware wallet it belongs to

2. Added to a metal case (CryptoSteel)

3. Using multiple hardware devices configured with same seed

For further information on Hardware wallets and recovery phrase queries, check out our FAQ section.



Team Lace