Comparison — decide in five minutes
Hardware or software? Three questions decide it
Most articles on this turn into a lecture about hot and cold wallets. You don't need the lecture. You need to know which one fits how much you hold and how you actually behave — and both answers are short.
- NZ$2k Roughly where a device starts to pay for itself
- NZ$99 Cheapest credible device stocked in NZ
- Free Every software wallet worth using
- Both The answer for most active holders
Question one: how much is actually there?
Not how much you plan to hold. Not what it might be worth if the cycle cooperates. How much is in the wallet today, in New Zealand dollars.
A hardware wallet is insurance, and nobody sensibly buys insurance costing a quarter of the insured asset. If you hold NZ$400 of crypto, a NZ$120 device is a poor allocation and a good non-custodial app is the right answer. Somewhere around NZ$2,000 the arithmetic flips decisively — the device becomes a small percentage, the amount becomes worth stealing, and the calculation stops being close. Above NZ$20,000 the question changes again, from "should I have a device" to "should I have more than one key", which is where multisig enters.
We give ranges rather than a single number because the threshold is genuinely personal. A student in Dunedin with NZ$1,500 in crypto and no other savings should probably protect it properly; someone in Queenstown with NZ$1,500 in crypto and a property portfolio can reasonably treat it as pocket money. The useful test is not the balance, it is how you would feel if it vanished tomorrow.
Question two: how often do you touch it?
This is the question that actually determines whether your setup survives, and almost nobody asks it before buying.
If you buy and hold and look at the price occasionally, a hardware wallet is pure upside. You will plug it in twice a year. The friction is irrelevant because you have almost no interactions to be frustrated by.
If you swap tokens, sign into applications, collect NFTs or move funds most weeks, a hardware-only setup will fail — not technically, behaviourally. Plugging in a device and confirming details on a small screen for every interaction gets old, and the workaround people invent is always worse than the thing they avoided. They leave "a bit" in a hot wallet for convenience. Then the bit grows. Then most of the portfolio is sitting in the exact place the device was bought to avoid.
The answer for that person is both, split by purpose, with a hard rule about what lives where. That is not a compromise; it is the correct architecture for an active user, and it is what we run ourselves.
Question three: what happens if you're hit by a bus?
Nobody asks this, and it destroys more crypto than every hack combined. A recovery phrase that exists only in your head, or in exactly one place in your house, is a single point of failure with no recovery path — and unlike a bank account, there is no process for your estate to follow.
Solving it properly tends to push people toward hardware, because devices come with a documented, standardised backup story: twelve or twenty-four words that any compatible wallet can restore, which means your executor does not need to know which brand you bought. Software wallets use the same standard, but the habits around them are looser — the phrase gets screenshotted, or skipped entirely because the app let you get started without writing it down.
If you take nothing else from this page: whichever category you choose, write the phrase on paper, put a second copy in a different building, and leave a sealed note with your will explaining what exists and how to reach it. The cold storage guide covers the mechanics.
Head to head
What each category is genuinely better at
Neither wins outright. They win on different axes, and knowing which axes you care about is the whole exercise.
| Property | Hardware wallet | Software wallet |
|---|---|---|
| Key ever on a networked device | Never | Always |
| Survives laptop or phone malware | Yes | No |
| Trusted display for verification | Yes | No |
| Upfront cost | NZ$99–NZ$780 | Free |
| Convenience for frequent use | Moderate | High |
| Works with DeFi and dApps | Via a companion app | Natively |
| Protects against approval scams | No | No |
| Protects against phrase phishing | No | No |
| Physical theft resistance | PIN + optional passphrase | Device passcode |
| In-wallet staking | Some chains | Widely |
Two rows in that table deserve emphasis because they are the ones people misunderstand. Neither category protects you from approval scams or phrase phishing. If you connect a hardware wallet to a malicious application and approve an unlimited token allowance, the device signed exactly what you told it to — it did its job perfectly and your funds left anyway. If you type your recovery phrase into a convincing support page, the secure element is irrelevant because you handed over the master key voluntarily.
This is why we keep saying that the device is the easy part. Hardware solves remote key extraction, completely and elegantly. It does nothing about decisions, and decisions are where the losses are. Read the scams and wallet drains guide whichever category you land in.
How each category actually fails
Failure modes are more useful than feature lists, because they tell you what you are actually signing up to manage.
Software wallets fail through the host device. An infostealer picks up a keystore file. A malicious browser extension reads the extension wallet's storage. A fake app downloaded from a paid search result was never a wallet at all. A screenshot of the recovery phrase syncs to a cloud account protected by a password that leaked from an unrelated site three years ago. Every one of those is a real, common mechanism, and none requires any sophistication.
Hardware wallets fail through the backup and the supply chain. The phrase was never tested and does not restore. The phrase and the device were in the same drawer when the house was burgled. A passphrase was enabled once and forgotten. Or the device was bought second-hand and arrived pre-initialised with a seed the seller already had — which is the single most effective attack against a careful person, because everything looks correct while the wallet was never yours.
Notice the asymmetry. Software failures are mostly remote and happen to you. Hardware failures are mostly operational and happen because of a shortcut you took. That is arguably an argument for hardware, since operational discipline is something you can control and other people's malware is not.
The tampered-device attack
Buy hardware only from the manufacturer or an authorised reseller. Never second-hand, never from a marketplace listing. After the 2020 Ledger customer data leak — roughly 270,000 names, phone numbers and home addresses — some owners received unsolicited counterfeit devices in the post, modified so that connecting one installed malware. If a device you did not order arrives, do not plug it in.
The New Zealand cost reality
One reason this decision looks different from here is that every device is an import, so the sticker price is not the landed price. In practice the gap is smaller than people fear.
Overseas suppliers with more than NZ$60,000 in annual New Zealand sales have charged 15% GST at checkout since December 2019, which means the tax is usually already included in what you see. From 1 April 2026, New Zealand Customs applies a Low-Value Goods levy — NZ$2.21 for air freight, NZ$2.09 for sea, plus GST — per consignment valued at NZ$1,000 or less; above that threshold duty and GST are assessed at the border. For a NZ$150 hardware wallet, the incremental cost of importing is a couple of dollars plus shipping.
You can also avoid importing entirely, which is our preference for a reason that has nothing to do with money: buying locally keeps your street address out of an overseas retailer's customer database. GROOV in Christchurch is an authorised Ledger reseller dispatching within 24 business hours for one to three day delivery. The Bitcoin Shop dispatches Bitcoin-only devices and steel backups from Tauranga. PB Tech, Mighty Ape and Computer Lounge stock Ledger entry models. All of those also bring you under the Consumer Guarantees Act 1993, which a direct import does not. Our buying guide covers each route.
From our testing notes
The most common pattern we see among people who have been doing this for years is not purism in either direction. It is a hardware wallet holding the bulk, one phone wallet with a deliberately small balance, and total discipline about which is which. The people who fail are rarely the ones with the wrong device. They are the ones who never decided what each wallet was for.
Hot vs cold FAQ
Hardware versus software questions
What is the difference between a hot wallet and a cold wallet?
A hot wallet keeps the private key on a device that is connected to the internet — a phone, a laptop, a browser extension. A cold wallet keeps the key on a device that is not, and cannot be read by one. That single difference determines whether remote malware can ever reach your key. It is not about brand, price, or whether the wallet is "official"; a free open-source app on your phone is hot, and a NZ$99 USB device is cold.
Do I need a hardware wallet or is a software wallet enough?
It depends on the amount and how often you transact. Our rough thresholds: under about NZ$2,000, a well-maintained non-custodial app with a properly backed-up recovery phrase is a reasonable trade-off — the device would cost a meaningful fraction of the holding. Between NZ$2,000 and NZ$20,000, buy one hardware wallet; it is the highest-leverage security purchase available. Above that, add a passphrase and a second backup location, and consider multisig.
Can I use both a hardware and a software wallet?
Yes, and most people should. The pattern that works is a hardware wallet for the savings tier and a software wallet for the working balance, with a firm rule that they do not mix. This solves the real failure mode of pure cold storage — that the friction eventually pushes you into leaving "just a bit" somewhere convenient, and the bit grows. See how many wallets you actually need.
Is a software wallet safe if I never connect it to anything?
Better, but not equivalent to cold storage. The key was generated on a networked device, which means at the moment of creation it was theoretically reachable. Airplane mode afterwards does not undo that, and phones and laptops do not stay offline in practice. If you want the guarantee rather than the probability, the key has to be born inside a device that has no network stack at all — which is what a hardware wallet is.
Are hardware wallets worth it in New Zealand given the import cost?
Usually, and the import cost is smaller than people expect. Overseas suppliers with over NZ$60,000 of New Zealand sales charge 15% GST at checkout, so tax is normally already in the displayed price, and from 1 April 2026 Customs adds a Low-Value Goods levy of NZ$2.21 for air freight plus GST per consignment under NZ$1,000. You can also skip importing entirely: GROOV in Christchurch stocks Ledger from around NZ$99, PB Tech and Mighty Ape carry entry models, and The Bitcoin Shop in Tauranga stocks Bitcoin-only devices. Details in our GST and customs guide.
Next in this cluster