A GoCheckMy site
GoCheckMyCrypto Crypto, checked.
Learn · explainer

Counterfeit hardware wallets

A hardware wallet only protects you if you were the first person to generate its keys. That single fact explains the whole category of attack, and it is also what makes the attack easy to check for. Here is how tampered devices reach buyers and what to look at when a box arrives.

Why this attack exists at all

When you set up a hardware wallet, the device generates a recovery phrase and shows it to you once. That phrase is the wallet. Anyone holding it can rebuild the wallet somewhere else and move the funds, without ever touching your device.

So a device that arrives already set up, or with its recovery card already filled in, is not a wallet you own. It is a wallet somebody else already owns, handed to you with an invitation to fund it. Everything you send to it is visible to whoever prepared the card, and there is no later step that fixes it. Nothing has to be hacked and no chip has to be modified for this to work, which is why it is worth a few minutes of attention at setup.

The reassuring half: because the attack depends on the seed already existing, a device that generates a fresh seed in front of you has not been prepared for you. That is the check the rest of this page is built around.

Where the risk actually enters

The risk is about custody of the device before it reached you, not about any particular seller being dishonest.

Both manufacturers set the same bar: their own store, or a reseller they list as authorized. Our recommendation is stricter than theirs, and it is ours rather than something they said. We think the manufacturer's own store is the only purchase route worth the small premium, because it is the only one where the chain of custody needs no verification at all.

What a prepared device looks like

These are checkable in a few minutes, before anything is plugged in.

What to do, in order

  1. Generate the seed yourself. Complete setup so the device creates a new recovery phrase in front of you, and never accept one that was provided.
  2. Run the manufacturer's own verification. Ledger builds a Genuine Check into its app: the app challenges the device, the device answers with a signature from a key injected at the factory, and the app checks it against Ledger's servers. Ledger is also clear about that check's limit, which is that it confirms a genuine secure element and cannot rule out physical modification around it. Trezor's bootloader verifies the firmware signature on every connection, and the device shows a warning on its own screen if unofficial firmware is present.
  3. Install the app from the manufacturer's site or the official app store, never a link. The verification only means something if the software doing the verifying is genuine.
  4. Never enter your recovery phrase anywhere but the device. Not a website, not an app, not a photo, not a cloud note, not a password manager. Ledger puts it flatly: there is never a good reason to type your recovery phrase into a computer.
  5. If anything looks wrong, stop and ask. Do not use the device, and contact the manufacturer's support directly through its own site. An unused device costs you a few days. A prepared one costs you everything on it.

A device you did not order

Two things are documented, separately, by Ledger itself. First, its July 2020 e-commerce and marketing breach exposed contact and order details for a subset of customers, including first and last name, postal address and phone number. Second, it currently documents an active campaign of physical letters sent by post to customers, prompting them to scan a code or visit a site and enter their recovery phrase, and it advises treating any postal letter presented as a Ledger communication as a phishing attempt.

Put together, the practical rule is ours rather than theirs, and it is simple: a hardware wallet that arrives without being ordered should never be plugged in. There is no legitimate reason for one to turn up unrequested, and the cost of ignoring an unexpected package is nothing. If one arrives, contact the manufacturer through its own website.

Buying direct is the whole answer

Every check on this page exists because a device passed through hands you cannot account for. Buy from the manufacturer's own store and there are no hands to account for, which is why the guidance here ends where our custody explainer already pointed. If you are still deciding whether a hardware wallet is the right tool at all, that is the question cold storage, explained works through, including which of the two devices fits which kind of holder.

Where to buy

We earn a commission if you buy through the links below. It costs you nothing extra and it does not change what we recommend. Separately, and for reasons that have nothing to do with us, both links go to the manufacturers' own stores, because that is the one purchase route this page does not ask you to verify.

Sources

This page is educational. It explains how these devices are verified and is not advice about your particular holdings, nor a recommendation to buy or sell any asset.