If the address displayed on your hardware wallet doesn't match the one on your phone or computer, it's a serious warning sign—do not sign. Go through these 4 checks to confirm security before proceeding. The hardware device's "trusted display" is your only defense against malicious address tampering.

A leading global cryptocurrency platform,suitable for both beginners and experienced traders.
New user benefit: 20% off trading fees upon registration!!
1. First, confirm you aren't in the wrong wallet
This is the most common reason, especially for users who have used a mnemonic + passphrase combination. The address shown on the hardware device corresponds to the current wallet session, which may not be the same wallet you opened in your phone app.
Step 1: Check if you switched the passphrase
What to do: Confirm that the passphrase you entered on the hardware device matches the one for the wallet you want to access.
How to do it: According to Trezor's official documentation, even an extra space or a capitalization difference will generate a completely different wallet address. The same logic applies to devices like KeyPal: each "mnemonic + passphrase" combination corresponds to an independent wallet address. Switching to the correct passphrase will make the addresses match naturally.
Scenario A (you have never set a passphrase): Ensure the hardware device is in a "no passphrase" state, and don't accidentally open a passphrase-enabled wallet in the app.
Scenario B (you have set a passphrase): Re-enter the correct passphrase on the hardware device, then re-check the addresses displayed on both the app and the device.
Completion criteria: The address shown on the hardware device screen exactly matches the one on the app's receive page.
2. Check if the correct address type is selected
Bitcoin supports multiple address formats, each with completely different starting characters. If you select the wrong address type, the addresses will naturally look different.
Step 2: Verify that the address format types match
What to do: Check which address type you are viewing in the app and whether the hardware device displays the same one.
How to do it: Different Bitcoin address types start with different characters. Common ones are:
Taproot: starts with bc1p
Native SegWit (Bech32): starts with bc1q
Nested SegWit (P2SH): starts with 3
Legacy: starts with 1
If the type is incorrect, re-add the account with the correct type in the app, then compare again.
Completion criteria: Confirm that the app and hardware device are viewing the same address type and that the starting characters match.
3. Check if a derived address has been added
A single private key can generate multiple addresses (derived addresses) to enhance privacy. The app may have switched to a derived address, while the hardware device only shows the main address by default.
Step 3: Switch back to the original derived address in the app
What to do: If you have added multiple derived addresses in the app before, confirm which one you are currently viewing.
How to do it: Taking imKey as an example, if you previously used a certain derived address and later deleted it from the app, that address won't appear by default when you re-add the account. You need to manually add the derived address under the corresponding address type so that the app and hardware device match.
Completion criteria: The app displays the original derived address you used, matching the hardware device.

A leading global cryptocurrency platform,suitable for both beginners and experienced traders.
New user benefit: 20% off trading fees upon registration!!
4. If none of the above match — consider malware (highest risk)
If you've checked all three and the addresses still don't match, it's highly likely that your computer or phone is infected with malware that has tampered with the address during copying and pasting. Both Trezor's and Ledger's official documentation clearly warn of this attack: malware silently replaces the copied address, while the trusted display on the hardware device shows the genuine, untampered address.
Step 4: Trust the hardware device display, never sign
What to do: Stop all operations immediately. Do not sign, do not transfer funds.
How to do it: The hardware device screen is a "Trusted Display" — it is isolated from the internet and cannot be tampered with remotely. What it shows is the correct address. A mismatch means the program on your computer or phone is lying to you.
Run a full system scan with antivirus software on your computer or phone immediately.
Do not send any funds to the address shown in the app.
If you must proceed, first reinstall the wallet software on a different, clean device and restore it using your mnemonic phrase.
Completion criteria: You have confirmed that the issue is not due to the first three causes and have ruled out address spoofing risks before considering the next step.
Prerequisite: You have connected your hardware wallet to a wallet app and are preparing to receive or send funds.
Risk reminder: A known vulnerability (CVE-2023-7346) once allowed attackers to make Ledger devices display incorrect addresses via malicious policies. Although this vulnerability has been fixed, we recommend updating your wallet firmware and app to the latest version to guard against such risks. Never trust the computer screen; only trust the address on the hardware device screen.
After completing these checks, how do you confirm it's safe?
Check the receiving address on both the app and the hardware device simultaneously — if they match character for character, you are in the correct wallet, using the right address type and derivation path, and can proceed with confidence. If they don't match and you have already ruled out the first three causes, stop immediately. Switch to a clean device, restore your wallet, and try again.


