When verifying a hardware wallet address, the only trustworthy reference is the complete address shown on your hardware device's screen. The address on your computer or phone screen, no matter how complete or clear it appears, cannot be used as the final confirmation. Screen truncation is not a bug—it is a deliberate design choice by device manufacturers to force you into the habit of trusting only the device screen.

A leading global cryptocurrency platform,suitable for both beginners and experienced traders.
New user benefit: 20% off trading fees upon registration!!
Why Software-Side Addresses Are Not Trustworthy
The core security assumption of a hardware wallet is that your computer may already be compromised. Malware does not need to crack your private key. It only needs to silently swap the address during your copy, paste, or confirmation steps to make you send funds to an attacker.
This type of attack is called clipboard hijacking. You copy a deposit address from an exchange, and malware replaces it with the attacker's address before you paste it. The address you see—and believe you copied—was never correct from the start.
Even more troublesome is address poisoning. Attackers generate fake addresses that match the beginning and end of your target address. If you only check the first four and last four characters, you will never notice that the middle section has been replaced. The Wintermute hack in 2022, which resulted in a loss of approximately $160 million, involved using vanity addresses that matched the first and last characters to bypass checks.
This is why official documentation from Ledger, Trezor, KeepKey, BitBox, and other manufacturers repeatedly emphasizes the same thing: treat the device screen as the only source of truth.
What Is Screen Truncation?
If you use a Ledger, you may notice that Ledger Live or the browser extension displays addresses in a shortened format like "first few characters + … + last few characters." This is not a display error. Ledger intentionally changed its display strategy in recent updates to prevent users from over-trusting the full address shown on the software side.
The problem is that this design creates practical difficulty: you cannot directly copy the full address from the software side to compare it elsewhere. What remains for verification is only the full address scrolling on the device screen, plus the original source where you first obtained the address—such as an exchange's withdrawal page.
For Trezor, similar issues appear with certain address types or xpub displays. Some content may be truncated or split across pages, requiring button presses to view the full string. Different models and firmware versions behave slightly differently, but the core logic is the same: what ultimately appears on the device screen is what matters.
How to Verify When Sending
Sending is the most dangerous moment because your funds are leaving.
Step 1: View the full address on the device screen. When you initiate a send through software, the address is transmitted to the hardware device. The device independently displays this address without going through your computer's rendering. If the address is long, the device screen usually provides scrolling or pagination. Ledger devices support horizontal scrolling to see the full address; some Trezor models require button presses to move to subsequent parts.
Step 2: Compare character by character, not just the beginning and end. Compare the address shown on the device screen with the original source where you first obtained it. If you are withdrawing from an exchange, check against the address on the exchange page. If someone gave you the address, check against the original message they sent you.
The method of comparison matters. Checking only the first six and last six characters is useless because address poisoning attacks specifically match the beginning and end. You need to view the full address, or at least cover the middle section. The device screen is small and requires scrolling—this is inconvenient, but that is exactly the point of this security mechanism: it forces you to slow down and actually read.
Step 3: If any single character does not match, stop immediately. Do not retry. Do not think "let me try again just to see." A mismatch between the device screen and the source address means the software on your computer has likely been tampered with. Cancel the transaction, disconnect the device, and run a full malware scan on your computer.
Verify When Receiving Too
It is fine for others to see your receiving address. But if the receiving address displayed by the software has been swapped with an attacker's address, and you send that fake address to the payer, the funds go straight into the attacker's pocket.
The logic is symmetric to sending: display the receiving address on the device screen, confirm it matches the address you intend to use in the software, and only then give the address to the other party.
KeepKey's documentation explicitly states this: when displaying a receiving address, confirm it on the device screen before sharing it. Otherwise, malware could display an attacker's address for you to forward to the payer.
The BitBox02 workflow with Sparrow Wallet is also a good reference: click "Display Address" in Sparrow, and the address appears on the BitBox02 screen. Only after confirming it matches can you copy and use it in the software.
What If the Device Screen Also Cannot Show the Full Address?
When small-screen devices display long addresses, pagination or scrolling is normal. What you need to confirm is whether you can see all characters of the address using the device's available controls.
If you have pressed every button and tried scrolling, but some characters are still not visible, you should not proceed with the transaction. Do not blindly confirm just because "it should be fine." Check whether the device firmware is up to date, and review the manufacturer's official documentation on address display for your model. Some older app or firmware versions do have incomplete display issues that can be resolved by updating.
But if the address still cannot be fully displayed after updating, and you are making a large transfer, it is reasonable to switch to another verification method—such as using a QR code. Some devices support displaying the address as a QR code on screen. You can scan it with another trusted device and compare it with the source. If even the QR code cannot be verified, pausing the operation is safer than confirming blindly.
A Practical Alternative
If scrolling through the full address on a small device screen every time feels too tedious, there is a compromise: use an address book.
With the device connected, save your confirmed frequently used addresses—such as your own exchange deposit address—into the software wallet's address book with an easily recognizable label. Next time you send, select the entry from the address book instead of pasting from the clipboard every time. This reduces the chance of clipboard hijacking.
But note: the address book itself is stored on your computer and could theoretically be tampered with. So the first time you save an address, you still need to verify it completely on the device screen. After saving, periodically spot-check one or two address book entries to see if the device-side display matches what was saved.
What Counts as Complete Verification?
A send operation is fully verified when you have read a complete address character by character on the device screen, and that address exactly matches the original source you independently obtained. Only then do you press confirm on the device.
If you merely saw a string of characters on the software, pressed confirm, and the device lit up green, that does not count as verification. A green light on the device only means it signed something—it does not mean it signed the address you wanted.
For receiving, the standard is: the address the payer receives is the full address you personally confirmed on the device screen.
The device screen is the only display interface in the entire process that you can physically control. Software can be spoofed, the clipboard can be tampered with, history records can be replaced—but what appears on the device screen is independently generated by the device based on the transaction it will sign. Use this screen. Do not bypass it.

A leading global cryptocurrency platform,suitable for both beginners and experienced traders.
New user benefit: 20% off trading fees upon registration!!
References
- Emmy's Crypto Insider·Ledgerでアドレスが省略表示される時の確認手順と注意点, published or updated: 2026-07-10; verified: 2026-09-29.
- GitHub·Behaviour of the xpub displaying should be aligned with address displaying · Issue #3047 · trezor/trezor-firmware, published or updated: 2023-05-30; verified: 2026-09-29.
- KeepKey·Trust Your Device Screen, published or updated: 2026-07-16; verified: 2026-09-29.
- KeepKey·Send & Receive, published or updated: 2026-07-16; verified: 2026-09-29.
- Ledger·Verify transaction details, published or updated: 2026-05-12; verified: 2026-09-29.
- Ledger·What is clipboard hijacking?, published or updated: 2026-05-13; verified: 2026-09-29.
- Ledger·Use your Ledger device to verify transactions and avoid address replacement attacks, published or updated: 2026-05-13; verified: 2026-09-29.
- GitHub·Change default screen in data signing to show shortened data · Issue #6597 · trezor/trezor-firmware, published or updated: 2026-03-16; verified: 2026-09-29.
- BitBox·How to receive Bitcoin (BTC) using Sparrow Wallet and BitBox02, published or updated: 2026-02-24; verified: 2026-09-29.
- MyCryptoHQ·ledger-hardware-wallet-missing-characters-from-address.md, published or updated: 2017-12-11; verified: 2026-09-29.


