Counterfeit hardware wallets
A hardware wallet only protects you if you were the first person to generate its keys. That single fact explains the whole category of attack, and it is also what makes the attack easy to check for. Here is how tampered devices reach buyers and what to look at when a box arrives.
Why this attack exists at all
When you set up a hardware wallet, the device generates a recovery phrase and shows it to you once. That phrase is the wallet. Anyone holding it can rebuild the wallet somewhere else and move the funds, without ever touching your device.
So a device that arrives already set up, or with its recovery card already filled in, is not a wallet you own. It is a wallet somebody else already owns, handed to you with an invitation to fund it. Everything you send to it is visible to whoever prepared the card, and there is no later step that fixes it. Nothing has to be hacked and no chip has to be modified for this to work, which is why it is worth a few minutes of attention at setup.
The reassuring half: because the attack depends on the seed already existing, a device that generates a fresh seed in front of you has not been prepared for you. That is the check the rest of this page is built around.
Where the risk actually enters
The risk is about custody of the device before it reached you, not about any particular seller being dishonest.
- Marketplace listings and third-party sellers. On large retail platforms, the listing and the seller are separate things. Ledger's own guidance is to exercise high caution on third-party online marketplaces and to favour its official storefronts or authorized resellers on those platforms. Trezor says plainly never to buy from an unauthorized third party, because you cannot tell who had access to the device before you.
- Secondhand and open-box devices. A returned or resold device has a history you cannot see, and the discount is small next to what it guards. This is not a claim about the seller. It is that the chain of custody is unverifiable in principle.
- Packages that arrive looking disturbed. Ledger says that if a package arrives appearing opened, altered or compromised, from any authorized reseller including Amazon, you should not use the device and should contact its support.
Both manufacturers set the same bar: their own store, or a reseller they list as authorized. Our recommendation is stricter than theirs, and it is ours rather than something they said. We think the manufacturer's own store is the only purchase route worth the small premium, because it is the only one where the chain of custody needs no verification at all.
What a prepared device looks like
These are checkable in a few minutes, before anything is plugged in.
- Packaging or seals that look opened or resealed. Trezor ships tamper-evident holographic seals over the connector and documents, per model, what the seal and the full box contents should look like. Compare against the manufacturer's own photographs rather than against your expectations.
- A recovery card that is already filled in, or shows any writing. Blank cards are the only correct state. A filled card is the clearest single sign that the device was prepared for you.
- A device that displays a recovery phrase instead of generating one. You should watch the phrase being created during setup. Trezor devices additionally ship with no firmware installed, so setup installs it and flags a device that already has firmware on it as one that should not be used.
- Instructions on a separate card or slip telling you to enter a phrase they provide. No genuine setup ever supplies you with a phrase. Ledger states that a genuine device never asks you to enter your recovery phrase on a computer, phone, app or website.
- A device you did not order. Covered on its own below.
What to do, in order
- Generate the seed yourself. Complete setup so the device creates a new recovery phrase in front of you, and never accept one that was provided.
- Run the manufacturer's own verification. Ledger builds a Genuine Check into its app: the app challenges the device, the device answers with a signature from a key injected at the factory, and the app checks it against Ledger's servers. Ledger is also clear about that check's limit, which is that it confirms a genuine secure element and cannot rule out physical modification around it. Trezor's bootloader verifies the firmware signature on every connection, and the device shows a warning on its own screen if unofficial firmware is present.
- Install the app from the manufacturer's site or the official app store, never a link. The verification only means something if the software doing the verifying is genuine.
- Never enter your recovery phrase anywhere but the device. Not a website, not an app, not a photo, not a cloud note, not a password manager. Ledger puts it flatly: there is never a good reason to type your recovery phrase into a computer.
- If anything looks wrong, stop and ask. Do not use the device, and contact the manufacturer's support directly through its own site. An unused device costs you a few days. A prepared one costs you everything on it.
A device you did not order
Two things are documented, separately, by Ledger itself. First, its July 2020 e-commerce and marketing breach exposed contact and order details for a subset of customers, including first and last name, postal address and phone number. Second, it currently documents an active campaign of physical letters sent by post to customers, prompting them to scan a code or visit a site and enter their recovery phrase, and it advises treating any postal letter presented as a Ledger communication as a phishing attempt.
Put together, the practical rule is ours rather than theirs, and it is simple: a hardware wallet that arrives without being ordered should never be plugged in. There is no legitimate reason for one to turn up unrequested, and the cost of ignoring an unexpected package is nothing. If one arrives, contact the manufacturer through its own website.
Buying direct is the whole answer
Every check on this page exists because a device passed through hands you cannot account for. Buy from the manufacturer's own store and there are no hands to account for, which is why the guidance here ends where our custody explainer already pointed. If you are still deciding whether a hardware wallet is the right tool at all, that is the question cold storage, explained works through, including which of the two devices fits which kind of holder.
Where to buy
We earn a commission if you buy through the links below. It costs you nothing extra and it does not change what we recommend. Separately, and for reasons that have nothing to do with us, both links go to the manufacturers' own stores, because that is the one purchase route this page does not ask you to verify.
Sources
- Ledger, Best practices to securely buy your Ledger device
- Trezor, Is my device safe to use?
- Trezor, Authenticate your Trezor Model One
- Ledger, Ongoing phishing campaigns
- Ledger, Addressing the July 2020 e-commerce and marketing data breach
This page is educational. It explains how these devices are verified and is not advice about your particular holdings, nor a recommendation to buy or sell any asset.