Buy now

The question people ask before buying their first hardware wallet is usually some version of this one, and the answers they find are reassuring in a way that skips the mechanics. "Just restore from your seed phrase" is correct and it is not an answer, because it leaves out what the device was holding, why a dead one cannot give it back, and what you need to have arranged in advance for the restore to work at all.

So here is the full version, starting with the part that sounds alarming and is the reason the rest works.

A broken device does not give your keys back

Your private keys are generated inside the wallet's secure element and never leave it. That is the whole point of the design: no software on your phone or computer can extract them, and neither can anyone holding the device. The trade is that the manufacturer cannot extract them either, and nor can a repair shop.

When the device dies, those keys die with it. There is no recovery path that runs through the hardware, no diagnostic that pulls them off a damaged board, and no support ticket that restores access. Your coins are untouched, because they were never on the device in the first place; they are on the blockchain, and the wallet only held the authority to move them.

Which means the question is not whether your device can be fixed. It is whether your backup can rebuild that authority on a new one.

What "broken" covers, and what it does not

Worth separating, because people write off devices that are fine.

A flat battery is not a broken wallet. On the Ryder One, a device with no charge left still operates while sitting on its wireless charger, so a dead battery is a delay rather than an incident. Check this for whatever brand you own before you panic.

A cracked screen is sometimes survivable and often not. If you cannot read a transaction before approving it, the device has lost the function that makes it safer than a phone, so treat it as retired even if it still responds.

A forgotten PIN is a deliberate wipe, not a fault. Hardware wallets erase themselves after a set number of wrong attempts, which is the feature working. The device becomes blank and reusable; your access comes back through recovery.

Water, drops and heat are the ones that end a device. An IP67 rating covers dust and water resistance under defined conditions, and it is not a promise about a washing machine cycle.

Firmware that fails mid-update can brick a device. Rare, and it happens. The protection is the same as for everything above.

Lost or stolen is a different clock

A broken device is an inconvenience on your own schedule. A missing one might be in someone's pocket, so the response changes.

A hardware wallet is protected by its PIN and wipes itself after repeated wrong guesses, which is why a thief who grabs the device alone usually ends up with a brick. The risk is the combination: the device plus your written backup, or the device plus a PIN written somewhere near it. That is the scenario worth defending against, and it argues for keeping your backup somewhere other than the drawer with the wallet in it.

If the device is gone and your backup is intact, restore onto a new one and move the funds to a fresh wallet afterwards if you have any doubt about who handled the old device. If the device is gone and your backup is also gone, there is no process that recovers your crypto, and no service that can do it for you regardless of what they advertise.

What your backup has to survive, and what TapSafe does differently

Everything above lands on the same point: the device is replaceable and the backup is the thing carrying your wallet. The standard arrangement hands you twelve or twenty-four words on a card and leaves you to keep that card intact and secret for as long as you hold crypto.

Think about what that card has to get through. Paper tears, burns, fades and gets tidied away by someone who does not know what it is. Steel plates fix the fire problem, which is a sound upgrade, and they leave the underlying arrangement untouched: one object still reconstructs your whole wallet, so it has to survive everything and be found by nobody. Both versions concentrate your recovery into a single point of failure, which is the exact thing a hardware wallet was supposed to remove.

TapSafe Recovery splits it instead. Using a Shamir's Secret Sharing implementation we built, your Recovery Tag holds half of the recovery and your paired phone holds the other half, encrypted into your own iCloud or Google Drive rather than sitting on the handset, so losing the phone does not lose the share. Optional Recovery Contacts hold a quarter each and learn nothing about your holdings. Setting up a replacement device means tapping the Tag and confirming with your phone, and because no single share opens the wallet alone, losing any one of them is something you repair rather than something you report. The Recovery Tag itself carries no power source of its own, communicates over NFC, and is rated IP69K, which covers high-pressure water jets, dust and temperature extremes.

Your seed phrase stays available on the device as a last resort and follows the BIP-39 standard, so a Ryder One is never a requirement for getting your crypto back. You can restore to other hardware if you ever want to.

The test to run while everything still works

Nobody wants to find out their backup was wrong at the moment they need it, and that is exactly when most people find out. So check it on a calm afternoon instead.

If you hold a seed-phrase wallet, the test is to wipe the device deliberately and restore it from your written words. That sounds frightening and it is the only way to know the words are correct and in the right order, which is where transcription errors hide. Do it while your funds are small or after moving them temporarily, and do it once a year.

If you hold a Ryder One, run the equivalent: confirm your Recovery Tag reads, confirm your phone backup is present, and know where a second Tag is if you added one. A backup you have tested is the difference between a broken device being an annoyance and being a loss.

Buying with this in mind

If you are choosing a first wallet and this question is what brought you here, judge candidates on the recovery arrangement rather than the chip. Ask how many separate objects have to survive for you to get your wallet back, and whether any single one of them being destroyed or discovered ends you.

The Ryder One is 149 USD for the Starter Combo and 179 USD for the Super Safe Combo, with the Recovery Tag and wireless charger in the box. Keys are generated inside an EAL6+ certified Infineon SLC38 secure element and never leave the chip, the device is IP67 rated, and Halborn audited the firmware independently with the full report published. Devices break. That should be a bad afternoon rather than the end of your crypto. Get your Ryder One.

Meet Ryder One

Meet Ryder One
Meet Ryder One

The only crypto wallet you can install on a crowded subway.
Set it up in less than 60 seconds and just tap your phone to send, swap, and recover.

Learn More