Trezor Suite

SatoshiLabs / wallet interface

Trezor Suite explained, from device pairing to daily use

Trezor Suite is the official application that SatoshiLabs builds for its Trezor hardware wallets. It is the screen where you watch balances, build and broadcast transactions, label accounts, and install firmware, while the private keys that authorize anything at all stay sealed inside the device in your hand. On its own, Trezor Suite can look but never move.

Trezor Suite replaced the older browser-based Trezor Wallet interface and became the default working environment for a Trezor device after its public release in 2021. Trezor Suite runs as an installed desktop program on Windows, macOS, and Linux, as a web app in browsers that support direct USB access, and as a lighter mobile companion.

There is no account to register, no email address to hand over, and no password held on someone else's server. Your wallet is a seed generated by the device; Trezor Suite is simply the lens you view it through, which is why the same funds remain reachable from other standards-compatible software if you ever stop using this one.

This page walks through what Trezor Suite actually does, how the division of labor between app and device works, which privacy and security controls are worth switching on, and the questions people ask most often in the first week of ownership. If you are deciding whether Trezor Suite belongs in your setup, the comparison and setup sections further down are the practical parts.

How Trezor Suite and the device split the work

The split matters more than any feature list. Trezor Suite is deliberately the untrusted, replaceable half of the pair: it downloads blockchain data, assembles unsigned transactions, and draws the charts. The device is the trusted half, holding the seed, deriving keys, displaying what you are about to approve, and producing signatures. Trezor Suite never receives a private key and cannot make the device sign anything without a physical confirmation on the device's own screen.

To show balances, Trezor Suite asks the device for extended public keys, one per account. From an extended public key it can derive every receiving and change address in that account, then query a blockchain index for their history. That is why Trezor Suite can display a portfolio while the device is unplugged, using cached data, but cannot produce a valid outgoing transaction without it.

Sending follows a fixed sequence. Trezor Suite selects inputs, calculates a fee, and hands the draft to the device. The device shows the destination address and amount on its own display, you compare them with what you intended, and only then does it return a signature. Trezor Suite broadcasts the finished transaction. Malware on a computer can lie to Trezor Suite, but it cannot change what the device screen prints.

Blockchain data has to come from somewhere. By default, Trezor Suite queries index servers operated by SatoshiLabs, which see the addresses you ask about even though they never see your keys. If that trade-off bothers you, the Trezor Suite settings let you point Bitcoin and several other networks at your own node or index server instead.

Communication with the device is USB. The desktop build of Trezor Suite talks to it through a bundled transport layer, so nothing extra needs installing; the web build of Trezor Suite relies on the browser's direct USB access, which is why browser choice matters more on the web than on desktop.

Signing path

  1. 01 Trezor Suite builds the unsigned transaction
  2. 02 Device displays address, amount, and fee
  3. 03 You confirm with a physical button or touch
  4. 04 Signature returns to Trezor Suite, which broadcasts it

Account derivation paths

m/84'/0'/0' / native segwit (bc1q...)

m/86'/0'/0' / taproot (bc1p...)

m/49'/0'/0' / segwit compatibility (3...)

m/44'/0'/0' / legacy (1...)

Standard paths, so the same seed opens the same accounts in other compatible wallets.

Trezor Suite on desktop, in the browser, and on mobile

There are three doors into the same wallet. The installed desktop build of Trezor Suite is the fullest one, the browser build removes the install step, and the mobile companion is a read-oriented view for checking on things away from your computer. All of them show the same accounts because all of them derive from the same seed on the same device, so switching between versions of Trezor Suite changes nothing about your funds.

The desktop version of Trezor Suite is the one most people should default to. Because it is a signed application rather than a page loaded over the network, there is no risk of a lookalike site intercepting your session, and it is where the network-level privacy options live, including routing traffic over Tor. Firmware installation, wallet setup, and backup creation all work here, and Trezor Suite keeps working through browser updates that occasionally disturb USB access.

The web build is useful on a machine where you cannot install software, or as a fallback when something in the desktop install goes wrong. Trezor Suite in a browser needs a browser that exposes direct USB device access, which in practice means a Chromium-based browser on most systems. Functionally it covers the same ground, though Trezor Suite cannot bundle its own network transport inside a browser tab.

Trezor Suite Lite, the mobile companion, is built around watching rather than spending. It lets you follow balances and generate receiving addresses on a phone, while transaction signing stays where the device is. Treat it as a portfolio window, not a replacement for the full Trezor Suite app.

Feature availability across the desktop, web, and mobile versions of Trezor Suite
Capability Trezor Suite desktop Trezor Suite web Mobile companion
Portfolio and balance overview Yes Yes Yes
Sign and broadcast transactions Yes, device connected Yes, device connected No
Firmware install and update Yes Yes No
Built-in Tor routing Yes Not in a browser tab No
Custom backend or own node Yes, in settings Yes, in settings No
Works without installing software No Yes App store install

What you can do inside Trezor Suite

The Trezor Suite dashboard is the landing view: total portfolio value across every account you have added, a value graph over a chosen period, and a list of recent activity. Because Trezor Suite groups holdings by account rather than by a single global address, the numbers stay meaningful even when you keep separate accounts for separate purposes.

Accounts are added per network and per address type. You can hold several Bitcoin accounts side by side, one for savings and one for spending, and Trezor Suite will discover any that already contain history when you connect the device. New empty accounts can be created in Trezor Suite once the previous one has been used.

Receiving is where Trezor Suite insists on care. Trezor Suite shows a fresh address, then asks you to confirm the same characters on the device display before you copy or share it. That step exists because clipboard-swapping malware is one of the cheapest attacks in circulation, and the device screen is the only surface an infected computer cannot rewrite.

Sending in Trezor Suite gives you fee levels from economical to high, a custom rate in satoshis per byte, and, for Bitcoin, the option to bump a stuck transaction with replace-by-fee rather than waiting it out. Coin control is available in Trezor Suite for anyone who wants to choose exactly which unspent outputs fund a payment, which is the practical tool for keeping unrelated coins from being spent together.

Labeling turns a wall of hashes into something you can actually read. You can name accounts, outputs, and individual transactions, and Trezor Suite encrypts those labels with a key derived from your device so they are not readable by whatever storage they sit in. Labels can stay local or be synced to a personal cloud drive if you want them on more than one machine.

Smaller conveniences round out Trezor Suite: a discreet mode that blurs amounts when someone is looking over your shoulder, light and dark themes, a choice of display currency, message signing and verification, and per-network settings that let you hide the chains you never touch.

Coin control

Pick individual UTXOs for a payment instead of letting the wallet choose. Useful for keeping coin histories separate.

Fee bumping

Replace-by-fee on Bitcoin lets a pending transaction be resent with a higher rate when the mempool is busy.

Encrypted labels

Account and transaction names are encrypted with a device-derived key before they are written to disk or a cloud drive.

Privacy controls in Trezor Suite

Self-custody solves the question of who controls your coins; it does not automatically solve the question of who can watch them. Trezor Suite treats that as a separate problem with its own switches, and the useful ones sit in Trezor Suite settings rather than on the dashboard.

The first is Tor. Enabling it in the desktop build of Trezor Suite routes blockchain queries through the Tor network, so the servers answering them see a relay rather than your home connection. Initial sync is slower, which is the honest cost of the trade.

The second is where your data comes from. Pointing Trezor Suite at your own full node or index server removes the third party from the loop entirely, because the machine resolving your address queries is one you control. This is the strongest privacy setting available, and it is the reason many long-term holders keep a node running alongside Trezor Suite.

The third is metadata hygiene. Trezor Suite does not require an identity to work, so there is no profile tying your accounts to a name. When you use the integrated exchange partners inside Trezor Suite, however, those companies apply their own identity rules and see their own side of the trade, which is a separate relationship from the wallet itself.

Finally there is coin control again, viewed as a privacy tool rather than a fee tool. Deliberately not mixing coins with different origins in one transaction avoids linking them on a public ledger, and Trezor Suite exposes that choice directly in the send flow.

Worth knowing

A wallet reveals no keys but plenty of interest. Anyone answering the balance queries that Trezor Suite sends learns which addresses you care about. Choosing your own backend, or Tor, is what closes that gap.

For general background on how wallets, keys, and addresses relate, see the reference article on the cryptocurrency wallet.

The security model behind Trezor Suite

Security here is layered, and each layer answers a different threat. The seed never leaves the device, which answers malware. The PIN answers a stolen device. The optional passphrase answers coercion and discovery. The device display answers a compromised computer. Trezor Suite orchestrates all of it but is trusted with none of it.

Your backup is created during setup, on the device, as a list of recovery words written on paper or a metal plate. Depending on the model, that may be a single 12, 20, or 24 word list, or a Shamir-style backup split into several shares where a threshold of them restores the wallet. Trezor Suite walks you through the process, but the words themselves are never typed into a computer.

The passphrase feature deserves its own paragraph because it surprises people. Entering a passphrase alongside your seed produces an entirely different wallet, and Trezor Suite treats each one as its own set of accounts. There is no reset and no hint: a mistyped passphrase silently opens a different empty wallet rather than throwing an error, so it must be recorded as carefully as the seed itself.

Firmware is checked rather than assumed. The device only runs firmware signed by the manufacturer, and when you connect a new unit Trezor Suite runs an authenticity check before setup. Updates are delivered through the app, always with confirmation on the device, and Trezor Suite will tell you plainly when the installed version is behind.

The habit that protects you most costs nothing: read the device screen. Every receiving address, every outgoing amount, every firmware action is printed there for comparison. If what Trezor Suite shows and what the device shows disagree, stop and trust the device.

Safety notice

Trezor Suite will never ask you to type your recovery words into the app, and no legitimate support channel or update prompt will ask for them either. Recovery words are entered on the device during recovery, never into a browser, a form, a chat, or a spreadsheet. Download wallet software only from the official source, and treat any unexpected message about your wallet as hostile until proven otherwise.

Coins, tokens, and account types in Trezor Suite

Coverage falls into two groups. A set of networks is handled natively inside Trezor Suite, with balances, sending, receiving, and history all in the app. A much wider set is supported by the device itself but reached through third-party wallets that use the device as a signer, so Trezor Suite is not the only window onto what the hardware can do.

Bitcoin is the deepest implementation in Trezor Suite, including modern Taproot and native SegWit accounts alongside legacy types for recovering older wallets. Ethereum and other EVM-compatible networks come with token support, so ERC-20 balances appear under their parent account, and Trezor Suite handles the gas settings that those chains require.

Beyond that sit long-standing networks such as Litecoin, Bitcoin Cash, Dogecoin, and XRP, plus newer additions handled natively in current versions. Exact coverage changes with releases, so the Trezor Suite coin settings are the reliable answer rather than any list written elsewhere.

One deliberate variation is worth knowing about: a Bitcoin-only firmware exists for people who want the smallest possible codebase on the device. Install it and the device handles Bitcoin alone, with everything else switched off. Trezor Suite recognizes that firmware and adjusts its interface to match.

Examples of how different asset groups are handled
Asset group Handled in Trezor Suite Notes
Bitcoin Natively Taproot, native SegWit, SegWit, and legacy account types; coin control and fee bumping
Ethereum and EVM chains Natively Tokens listed under the parent account; gas limit and price adjustable
Other supported networks Natively Includes Litecoin, Bitcoin Cash, Dogecoin, XRP and others; see in-app coin settings
Assets outside the app Via third-party wallets Device signs, another interface displays; confirmation still happens on the device

Buying, swapping, and staking through Trezor Suite

Alongside the wallet functions, Trezor Suite embeds a marketplace of third-party providers. You can compare offers to buy crypto with conventional money, sell back out, or swap one supported asset for another, and the purchased coins land directly on an address belonging to your device rather than in an exchange account.

The distinction to hold onto is that these are other companies' services shown inside Trezor Suite. Each provider sets its own rates, fees, regional availability, and identity verification requirements, and the app is presenting their quotes rather than making a market itself.

Staking appears for a small number of networks where Trezor Suite integrates a provider, letting you delegate or stake without leaving the interface while the device authorizes each action. Rewards, lock-up behavior, and unstaking delays are set by the network and the provider, not by Trezor Suite, so read what the flow tells you before committing funds.

None of this is mandatory. Plenty of people use Trezor Suite purely as a wallet, buying elsewhere and withdrawing in, and the trading panels can be ignored entirely without affecting anything else in the app.

Trezor Suite compared with other ways to hold crypto

Comparisons only help if they compare the right thing. Trezor Suite is not an exchange and not a browser extension; it is an interface bolted to a signing device, and its advantages and inconveniences both follow from that. The table below sets Trezor Suite against the two alternatives most people actually weigh it against.

The pattern is consistent. Custodial accounts are the most convenient and the least sovereign. Software wallets sit in the middle, holding keys on a device that also browses the web. Trezor Suite with a hardware wallet costs you a purchase and a plug-in step, and in exchange the key material is never exposed to the machine running the software.

It is also not exclusive. The same device works with other interfaces, so treating Trezor Suite as your default view while occasionally signing elsewhere is a normal, supported way to work.

Comparison of the hardware wallet app, a software wallet, and a custodial exchange account
Criterion Trezor Suite with device Software or extension wallet Custodial exchange account
Where private keys live Offline in the device On the connected computer or phone With the company
Address shown on a trusted screen Yes, on the device No, same screen as the malware Not applicable
Identity verification to use the wallet None None Required
Choice of blockchain data source Default servers or your own node Varies, often fixed None
Recovery if the app disappears Standard seed restores elsewhere Usually a standard seed Depends on the company
Cost to start Free app, paid device Free Free account, trading fees

How to get started with Trezor Suite

First-time setup with Trezor Suite takes fifteen to thirty minutes, most of it spent writing down recovery words properly. Do it when you are not rushed, at a desk, alone, with a pen and no camera pointing at you.

  1. Step 01 / install

    Get Trezor Suite from the official source only, downloading the desktop build for your operating system, and verify you are on the genuine site before installing. Fake downloads are the most common way people lose funds with an otherwise sound setup.

  2. Step 02 / connect and check

    Plug in the device with its cable and let Trezor Suite run its authenticity check and install the latest firmware. Confirm each prompt on the device screen, not just in the Trezor Suite window.

  3. Step 03 / create the backup

    Create a new wallet in Trezor Suite and write the recovery words down in order, on paper or metal, exactly as the device shows them. Never photograph them, never type them into any device, and store the record somewhere a flood or a house guest will not reach it.

  4. Step 04 / set a PIN and add accounts

    Choose a PIN that is not a date, then let Trezor Suite discover or create the accounts you need for the networks you actually use. Hide the rest so the dashboard stays readable.

  5. Step 05 / test small, then move

    Send a small amount in first, confirm the receiving address on the device, and check that Trezor Suite shows it arriving. Only then move the rest. If you plan to use a passphrase, decide now and record it with the same discipline as the seed.

Once that is done, day-to-day use is unremarkable: open the app, plug in when you need to spend, unplug when you are finished. Trezor Suite will keep showing your portfolio between sessions from cached data, and the moment anything needs authorizing it asks for the device again.

Key takeaway

The recovery words are the wallet. The device and Trezor Suite can both be replaced; that written list cannot. Anyone who reads it owns your funds.

Session status example

device connected / firmware current

accounts discovered: 4

backup: verified offline

tor: enabled

Keeping Trezor Suite and firmware healthy

Two things update independently: Trezor Suite on your computer and the firmware on the device. Trezor Suite notifies you about both, and firmware updates always require confirmation on the device. Neither kind of update touches your seed, though a backup should exist before you start any firmware work, as it should before any maintenance on a wallet.

The most frequent complaint is a device that does not appear. In order, the things to check are the cable, then the port, then the software. Charging-only cables carry no data, unpowered hubs are unreliable, and front-panel ports on desktop machines are often the weakest. Trezor Suite cannot see hardware that the operating system has not enumerated.

If the Trezor Suite desktop app sees nothing and the web version does, or the reverse, the issue is transport rather than hardware. Restarting the app, then the computer, resolves most of it, and a reinstall of Trezor Suite handles the rest. On Linux, device permission rules sometimes need to be in place before a non-root user can access the device at all.

Balances that look wrong are usually a data problem, not a loss. An account showing zero in Trezor Suite after a restore commonly means the wrong address type: a wallet created as legacy will not appear under a native SegWit account, so check the other account types before panicking. Missing or stale history often clears after switching backend or re-syncing.

A pending transaction that will not confirm is a fee problem. If it was sent with replace-by-fee enabled, Trezor Suite can rebroadcast it at a higher rate; otherwise waiting is the only option, since a transaction sitting in the mempool has not moved your coins anywhere.

For anything the app cannot explain, the built-in Trezor Suite logs and device information panel are the places to look first, and the support links inside the app point to guides maintained alongside each release rather than to older third-party write-ups that may describe a version no longer shipping.

Frequently asked questions

Is Trezor Suite free to use

Yes. Trezor Suite costs nothing to download or use; you pay for the hardware wallet itself. Network fees go to miners or validators, and any buy, sell, or swap fees belong to the third-party provider you choose inside the app.

Do I have to use Trezor Suite with my device

No, but you should for setup. Firmware installation, backup creation, and authenticity checks are handled here. Afterwards the device works with various third-party wallets, and many people keep Trezor Suite as their main interface while signing occasionally elsewhere.

Does Trezor Suite ever hold my keys or coins

Never. Keys are generated and kept on the device, and signing happens there. Trezor Suite handles public data, prepares transactions, and broadcasts signed ones. It is not a custodian and cannot spend anything by itself.

Can I use it offline

Partly. Trezor Suite can show cached balances and let you inspect your accounts without a connection, but fetching new history and broadcasting a transaction both need the internet. The signing step itself happens entirely on the device.

Is the code open for review

The source code for Trezor Suite is published in public repositories, in keeping with the project's long-standing open development approach. That means the build you run can be examined by independent researchers rather than taken on trust.

Can I restore a wallet from another brand

Usually yes. Standard 12 or 24 word recovery phrases can be restored onto the device, after which Trezor Suite discovers the accounts. Check the address type if balances look missing, and remember that any seed previously typed into a computer should be considered exposed.

Can I manage several wallets or devices

Yes. Multiple devices can be used with one installation, and passphrases create additional hidden wallets on a single device. Trezor Suite keeps each wallet's accounts and labels separate, and switching between them means reconnecting and unlocking.

What if the app stops being maintained

Your coins are on public blockchains and your keys derive from a standard seed format, so a compatible wallet can restore them without Trezor Suite existing at all. That portability, not the app itself, is what makes self-custody durable.