Fake Hardware Wallet Packaging
A device that arrives pre-initialised, with a card of words in the box. Every part of this is the attack, and it is sold through legitimate marketplaces.
Priya Raman · 2 min read
Hardware wallets are the recommended answer to storing meaningful amounts. The recommendation comes with a condition that is frequently omitted: buy from the manufacturer.
The attack
An attacker obtains devices, initialises them with a seed phrase they control, repackages them, and sells them through marketplaces, resellers or classified listings, usually at a discount.
The buyer receives what appears to be a new device. It comes with a card showing a recovery phrase, sometimes described as the pre-configured backup, sometimes with instructions saying to use these words during setup.
The buyer funds the wallet. The attacker, who has the same phrase, empties it. The timing varies: some drain immediately, some wait until the balance is substantial.
The variants
Pre-initialised device with an included phrase card. The most common.
Modified firmware. A device whose software has been altered to generate predictable phrases or to leak them. More sophisticated and rarer.
Replaced internals. A genuine case containing different hardware.
Fake device entirely. A non-functional imitation that displays a phrase and stores nothing securely.
Phishing packaging. A genuine device with an inserted card directing the user to a fake support site.
The rule that defeats all of them
A genuine hardware wallet never arrives with a recovery phrase.
It generates one, in front of you, on first setup. There is no legitimate scenario in which a phrase is supplied with a device.
If words came in the box, on a card, in a letter, or in any other form, the device is compromised and must not be used.
The other rules
Buy from the manufacturer directly. Not a marketplace, not a reseller, not a discounted listing. The saving is not worth the category of risk.
Check the packaging seals against what the manufacturer documents, and be aware that seals can be replicated.
Update firmware through the official application before setup. Genuine devices verify firmware authenticity cryptographically.
Initialise it yourself. Generate the phrase on the device.
Test the restore before funding. Wipe, restore from your written phrase, confirm the address matches.
What to do if a device seems suspicious
Do not fund it. Contact the manufacturer, who generally have a process for verifying authenticity and an interest in identifying compromised supply.
Do not use the included phrase for anything, ever, including on a different device.
The broader lesson
Self-custody moves the trust from a company to your own procedures. That is the point and it means the procedures have to be right.
Buying from the manufacturer and refusing any device that arrives with a phrase are two rules that cost nothing and eliminate an entire category.
For the working balance where self-custody procedures are not involved, the equivalent question is simply whether the venue is regulated and reachable, which platforms such as a licensed exchange with a published address publish openly.
Move any remaining funds to a wallet with a newly generated seed phrase before anything else. Then revoke token approvals, and report the incident to your local authorities and the exchange involved. Do not pay anyone who promises to "recover" your coins. That is a second scam, aimed at victims of the first.