Actuator
← Back to Guides

How to Set Up Your Windows PC for Crypto Security

beginner~5 min read

This guide turns a Windows PC into a crypto appliance: a machine whose only job is to talk to your hardware wallet and a short list of verified sites. The reasoning lives in the Security Guide; this page is the doing. It matters more on Windows than anywhere else — the malware economy overwhelmingly targets Windows, and modern infostealers specifically hunt browser profiles and wallet extensions. Everything here is universal — no particular token, chain, or protocol required.

Time: about an hour, most of it waiting on updates.

Step 0 — The One Disqualifying Check

Press Win+R, type winver, press Enter.

  • Windows 11 — proceed.
  • Windows 10 — stop. Windows 10 left mainstream support in October 2025. Unless the machine is enrolled in Microsoft’s Extended Security Updates program (check Settings → Windows Update), it has been unpatched for months and must not touch crypto — and even ESU is a countdown, not a fix. If the hardware supports it (Win+R → tpm.msc should show TPM 2.0), upgrade to Windows 11 free via Settings → Windows Update. If it doesn’t, retire the machine from crypto duty — an unpatched OS outranks every other risk on this page.

(A new Windows laptop on an ARM chip — Snapdragon X — is fine: same Windows 11, same steps below.)

Step 1 — If This Will Be a Dedicated Machine, Start Clean

Settings → System → Recovery → Reset this PC → Remove everything, and choose Cloud download. A from-scratch Windows is the only way to be sure no past download rides along. Skip if hardening your everyday PC — the rest still applies.

One rule stated early because it decides everything: no pirated software, ever, on any machine that touches crypto. Cracked installers are the single largest delivery vehicle for the infostealers that empty wallets.

Step 2 — Update Until There’s Nothing Left

Settings → Windows Update → install, restart, check again — repeat until clean. Then turn on “Receive updates for other Microsoft products” and leave automatic updates alone forever.

Step 3 — Demote Yourself

Settings → Accounts → Other users → Add account — create a second account, then set your daily crypto account to Standard (not Administrator). Malware in a standard account can’t silently change the system; the elevation prompt is your alarm bell. (Windows needs at least one admin account to exist — it just shouldn’t be the one you live in.)

Step 4 — Turn On BitLocker

Settings → Privacy & security → Device encryption (or search “BitLocker”). Turn it on. One catch the Settings screen never mentions: on Windows 11 Home, Device encryption saves the recovery key to your Microsoft account automatically — there is no “write it down” prompt. After turning it on, open aka.ms/myrecoverykey in any browser, copy the 48-digit key onto paper with your physical backups, then delete the cloud copy — otherwise the account takeover we defend against in 2FA hands an attacker your disk key. (On Windows 11 Pro, search “Manage BitLocker” and choose “Print the recovery key” instead.) Then confirm in Settings that encryption shows as complete. A stolen PC becomes a brick instead of a leak.

Step 5 — Let Defender Do Its Job, and Add Smart App Control

  • Windows Security → Virus & threat protection — confirm real-time protection is ON. Microsoft Defender is genuinely good now; do not replace it with a third-party antivirus on this machine.
  • Windows Security → App & browser control → Smart App Control — ON. It blocks unsigned and untrusted programs outright. (It’s only available after a clean install — one more reason Step 1 matters.)
  • Same screen: Reputation-based protection — everything ON.

Step 6 — Strip It Bare

Uninstall everything you don’t recognize or need (Settings → Apps). The target state: Windows, one browser, your hardware-wallet software — nothing else. No email client, no Discord, no Steam, no utilities. Every program is attack surface, and on Windows the attackers have the biggest arsenal.

Step 7 — Install Only Two Things

  1. A browser — one, configured per the Browsers guide: bookmarks-only navigation, no extensions beyond your wallet.
  2. Your hardware-wallet software — downloaded by typing the vendor’s address yourself, never from a search result. Sponsored search ads impersonating Ledger and Trezor are a perennial, documented theft vector.

Step 8 — Build the Bookmark List, Then Never Type Again

Bookmark, from carefully typed addresses: your block explorer, the app(s) you use. This machine reaches the web only through those bookmarks from now on. Before any contract interaction, verify the address against the Manual’s Appendix A or the official docs.

Step 9 — The Habits That Keep It Sealed

  • Updates land the week they ship
  • No email, no browsing, no downloads, no exceptions
  • A VPN on this machine, always, even at home
  • The hardware wallet’s screen is the final word on every transaction — read it before approving

Prefer to sidestep the Windows malware ecosystem entirely? A minimal, auto-updating Linux installed on the same PC and used only for crypto is a real option — honest caveat: only if you’ll keep it current. The trade-offs are in the Security Guide.


Everything on this page is universal — send anyone the link — pointing people to the source beats forwarding copies (a file passed around is exactly what this site warns about; the address stays canonical and current). For the curious: this site documents Actuator.Finance on PulseChain — the one-page version is How It Works, and Start Here picks your path.

Suggest or Correct

Spotted an error? Have an idea? Found something missing? Let us know — this site is community-built and your input matters.

⚠ Never share your seed phrase or personal information.