BTC…ETH…ETH gas…Fear & Greed…Live data · not advice

Crypto Lexicon

Counterfeit Hardware Wallets

The commonest fake arrives already initialised. Why tamper seals prove nothing, what a genuine check actually attests, and where the trust chain starts.

The Pre-Seeded Device

A hardware wallet only protects anything if the recovery phrase is generated on the device, in your hands, and seen by nobody else. The pre-seeded scam breaks that at step one. The device arrives already set up, or the box contains a helpful card presenting "your recovery phrase" ready to use.

Because the attacker generated that phrase, they can derive every address the wallet will ever produce. Nothing looks wrong. The device works perfectly, which is the point. The sweep comes later, once you have had time to fund it properly. Ledger's own guidance is blunt that a legitimate device never ships with a recovery phrase or PIN already configured.

Why the Seal Proves Nothing

The instinct is to inspect the packaging, and the packaging is the one part designed to be inspected. Ledger's own security laboratory states that classic anti tampering and holographic seals are trivial to clone and can be opened and closed without damage.

A teardown of a counterfeit Trezor examined by Kaspersky shows how thorough this gets. The genuine microcontroller had been swapped for a different part, the case was held together with glue and tape rather than ultrasonic bonding, and the firmware did not generate a random seed at all: it picked one of twenty phrases the attacker had baked in. The holographic stickers on the box and the device were all present and undamaged, doing their job beautifully.

What a Genuine Check Actually Proves

Modern devices can attest to their own authenticity, which is worth having, but it is narrower than people assume. The check confirms the secure element is authentic, that its key was signed by the manufacturer at production, and that the chip can prove it holds the matching private key.

The same Ledger document notes the check cannot detect unauthorised physical modifications elsewhere in the hardware if the original secure element is intact, which is exactly the attack described above. Trezor takes a different route: its devices ship with no firmware installed, so firmware already present at setup is itself the alarm.

The practical rule: buy from the manufacturer or an authorised reseller, never from a marketplace listing, an auction or a helpful stranger, because the trust chain starts at the seller and no later check repairs it. Then generate the phrase yourself, on the device. If a device offers you a phrase rather than asking you to write down a new one, it is compromised, and no amount of pristine packaging changes that.

Knowledge check

Three quick questions on this entry. Pick an answer to see whether it is right.

Question 1 of 3Which description matches Counterfeit Hardware Wallets?

Question 2 of 3What does a device's genuine check actually prove?

Question 3 of 3Which of these also belongs to Wallets & Security?

Frequently asked question

What is Counterfeit Hardware Wallets?

The commonest fake arrives already initialised. Why tamper seals prove nothing, what a genuine check actually attests, and where the trust chain starts.

The Letter

One clear letter, every week.

Plain analysis of crypto infrastructure, markets and security. No price calls, no referral links, no hype.

Unsubscribe at any time. Read the privacy notice.

Reader reviews

Did you like what you just read?

Tell other readers what worked, what did not, and who you would recommend it to. Every review is read by a human before it is published, and critical reviews get the same treatment as glowing ones.

Leave a review →