Buy your hardware wallet direct, and distrust any device you did not order
Thieves have mailed pre-tampered wallets to breach victims and sold counterfeit units through marketplaces. Both routes end with your recovery phrase in the attacker's hands.
A hardware wallet protects you only if the device in your hand is genuine and unmodified. The route the device took to reach you, the supply chain, is itself an attack surface, and it has been exploited in two distinct ways worth studying before you buy.
The device that arrives uninvited
In June 2021, per BleepingComputer, criminals mailed altered Ledger Nano X units to people whose home addresses had been exposed in Ledger's 2020 customer-data breach and later posted to a hacking forum. Inside each fake was a small flash drive soldered onto the USB connector. A counterfeit letter told the recipient the device was a mandatory security replacement and instructed them to run an included app and enter their existing recovery phrase to move their wallet across.
That instruction is the tell. A genuine setup never asks you to type an existing recovery phrase into software to activate a new device. Ledger's own guidance is that the phrase should be entered only directly on the device you are recovering, never into an app or computer that reached you unsolicited.
The counterfeit on the marketplace
The second route is a fake that looks authentic. Kaspersky documented a counterfeit Trezor Model T, bought through a classifieds site, that was identical on the outside but carried a different microcontroller, an STM32F429 with its read-out protection disabled, in place of the genuine STM32F427. Its modified firmware did not generate a random seed; per Kaspersky it assigned the user one of just 20 pre-generated phrases the attackers already held. They waited about a month after the wallet was funded, then drained it. Kaspersky's conclusion was to buy only from an official vendor.
- Buy only from the manufacturer's own store or a reseller listed as authorized on the manufacturer's site; avoid third-party marketplaces and classifieds.
- Refuse any wallet you did not order, however convincing the packaging or letter, and never enter a phrase to "migrate" to a surprise device.
- Inspect the device for signs of tampering: fresh solder, mismatched screws, or seals that look reapplied.
- Set it up as new so the device generates a fresh seed on its own screen; never import a phrase that came packaged with the device.
- Confirm firmware authenticity in the vendor's official app before funding, and never type your recovery phrase into a computer.
The common thread is simple. Both attacks depend on the phrase leaving the safety of a genuine device, either typed into malware or already known to the seller. Control where the device comes from and where its seed is generated, and both schemes collapse.
— Sources: [BleepingComputer](https://www.bleepingcomputer.com/news/cryptocurrency/criminals-are-mailing-altered-ledger-devices-to-steal-cryptocurrency/) · [Kaspersky](https://www.kaspersky.com/blog/fake-trezor-hardware-crypto-wallet/48155/)
NOT FINANCIAL ADVICE · VERIFY EVERYTHING