Key facts
- A tampered wallet is the one attack that works on careful people. You can pick a strong PIN, store your phrase in steel and never touch a phishing link, and still lose everything — if the device was compromised before it reached you.
- The clearest warning sign is a recovery phrase you did not create. If words are already written on the card, printed in the manual, or shown to you on a slip of paper, the wallet is not yours. Stop there.
- Seals are not a universal check, and they differ by brand. Ledger deliberately does not depend on them. Trezor does use them, but the placement is not the same on every model.
- Trezor devices ship with no firmware installed. A Trezor that boots straight into a ready-to-use wallet has had something done to it.
- Where you buy decides most of your risk. Almost every tampered device we have ever been shown came from a marketplace listing or a private seller, not from a distributor.
Most security advice for crypto assumes the attacker comes to you — a fake website, a message from support that is not support, a link that should not have been clicked. Those attacks are common, and they are survivable, because they all need you to make a mistake.
A tampered hardware wallet does not need you to make a mistake. It only needs you to do exactly what the instructions say. That is what makes it the attack worth understanding properly, and it is the question we get asked most often across the counter: how do I know this one is clean?
Why tampering is the attack that actually works
A hardware wallet has one job. It generates a secret, keeps that secret off your computer and phone, and signs transactions without ever letting the secret out. Every other security property follows from that.
The entire design assumes one thing: that the secret was created by the device, in front of you, and that nobody else has ever seen it. Break that assumption and nothing else in the product matters. The secure chip still works. The PIN still works. The screen still shows the right address. And the attacker still empties the wallet, at a time of their choosing, because they have had a copy of your recovery phrase since before you opened the box.
This is why a tampered device is not simply "a security problem". It is a total loss, and it is a silent one. There is no failed login, no alert, no moment where the wallet behaves oddly. Funds arrive normally for weeks. Then one day they are gone, usually all at once.
The scam that keeps coming back
The most common version of this attack has barely changed in years, because it keeps working.
Someone buys a genuine hardware wallet. They generate a recovery phrase on it and write those words down for themselves. They then repackage the device and sell it as new — through a marketplace, a classifieds listing, a friend of a friend, a shop that sourced it from somewhere cheap. Included in the box is a recovery card with the words already filled in, and a note explaining that this is your recovery phrase and you should keep it safe.
The buyer transfers their coins to the address the device shows them. The address is real. The balance is real. And the seller, who has held those same words the whole time, waits.
A more sophisticated version skips the pre-filled card and instead includes a "setup guide" that instructs you to enter a phrase supplied in the packaging, framed as restoring or activating the wallet. The wording is deliberately reassuring. The result is identical.
There is one rule that defeats every variant of this, and it is worth committing to memory before any of the physical checks below:
Your recovery phrase must be generated by the device, shown only on the device's own screen, and written down by you. A phrase that arrives with the product is not a recovery phrase. It is somebody else's wallet.
What to check before you power it on
The box
Look at the packaging before you open it. You are checking for signs that it has been opened and closed again: torn or re-glued flaps, a seal that has been lifted and pressed back, adhesive residue around the edges, a shrink wrap that fits loosely or has a seam in an odd place, or a box that has clearly been taped shut a second time.
Be aware of what this check is and is not worth. Packaging can be replaced. Seals can be reproduced. A determined attacker with a supply of blank boxes will pass a visual inspection. Treat the box as the first filter, not the verdict.
The device
Check the casing for gaps along the seam, screws that look burred or turned, glue where there should not be glue, or a screen that sits slightly proud of the housing. Compare it against the product photos on the manufacturer's own site if anything looks unfamiliar.
Then check what the device does when it starts. A new hardware wallet should behave like a new hardware wallet: it asks you to set it up. It should not open into a configured wallet, it should not already hold a PIN, and it should not display a balance.
The recovery card
The recovery card in the box should be blank. Every time. There is no legitimate product, from any manufacturer we carry, that ships with the words already on it.
If there is any writing on that card — printed, handwritten, on a sticker, on a separate slip, in the manual, or in a QR code you are told to scan — the device is compromised. Do not set it up. Do not send a test amount to check. Do not use it for a small holding.
Seals differ by brand, and one brand has none on purpose
This is where most published checklists go wrong. They describe "the holographic seal" as though every hardware wallet has one in the same place. They do not, and assuming otherwise leads people to reject a genuine device or accept a tampered one.
Ledger
Ledger does not rely on a tamper-evident seal, and this is a deliberate decision rather than an oversight. Their position is that seals of this kind give a false sense of security: they are straightforward to clone, and a package can often be opened and closed without visibly damaging one. Any tape on the packaging is there for packing purposes.
Instead, Ledger puts the authenticity check inside the device. The Genuine Check, run through Ledger's own app, is a cryptographic test of the secure element itself: a Ledger server issues a challenge, and the chip must return a correct signature to prove it is a genuine Ledger secure element that has not been altered. A cloned or modified device cannot produce that signature.
So for a Ledger, the meaningful check is not the packaging. It is running the Genuine Check with the app downloaded from Ledger's own website or an official app store — never from a link, QR code or installer supplied by whoever sold you the device.
Trezor
Trezor does use holographic seals, but the placement depends on the model, and this catches people out.
On the Trezor Model One, there are two seals on the box. There is no seal over the USB port. Someone expecting one and not finding it may wrongly conclude the device has been interfered with.
On the Trezor Model T, the seal is over the USB-C connector, applied with deliberately strong adhesive. It cannot be removed cleanly — peeling it destroys the hologram and leaves a visible residue.
Trezor's stronger protection, though, is the same kind of idea as Ledger's. Trezor devices are shipped with no firmware installed at all. You install it yourself during setup, and the bootloader verifies that the firmware carries a valid SatoshiLabs signature every time the device starts. A Trezor that arrives ready to use, with firmware already on it, is telling you something happened to it between the factory and your hands.
The check that outranks all the physical ones
Packaging can be faked. Seals can be sourced. Casings can be swapped. What cannot be faked is the cryptographic relationship between the chip and the manufacturer, and what cannot be faked is a phrase that was generated in front of you.
So the order of operations that actually protects you is this:
Inspect the box and device for the obvious signs. Then run the manufacturer's own authenticity check, using software you fetched yourself from the manufacturer's own domain. Then set the device up from scratch, let it generate a new recovery phrase, and write those words down yourself. If the device will not let you do that last step — if a phrase already exists, or setup is already complete — stop and treat the device as compromised regardless of how convincing the packaging was.
If you have any doubt at all and the device supports it, wipe it and start again. A factory reset followed by a fresh setup, on a device that passes its manufacturer's genuine check, puts you back in a known state.
Two devices we are happy to recommend on this basis
Both of these make the authenticity check straightforward, which matters more than any spec comparison if this is the risk you are worried about.
Ledger
฿4,200
- Authenticity confirmed by cryptographic Genuine Check, not by a sticker
- Secure element chip, with the recovery phrase generated on the device
- Connects by Bluetooth, so it works with a phone as well as a computer
Run the Genuine Check in Ledger's own app before you transfer anything.
Trezor
฿9,900 ฿19,900-50%
- Holographic seal over the USB-C connector, which cannot be peeled cleanly
- Ships with no firmware — you install it, and the bootloader checks the signature
- Colour touchscreen, so the phrase and addresses are read on the device itself
The seal leaves a visible residue if removed. That is by design.
Where you buy decides most of your risk
Every check above is a way of detecting a problem after it has already been introduced. Buying properly stops it being introduced at all, and it is by far the cheapest security measure available to you.
A hardware wallet is not a product where a discount is a good sign. The margins are thin and the retail prices are set by the manufacturers. When a listing is well below the going rate, that gap is being paid for by something, and on a marketplace you have no way of knowing what.
What an authorized distributor gives you is a supply chain with names attached to it. The device comes from the manufacturer to us and from us to you. Nobody in that chain has a reason to open it, and if something is ever wrong, there is a company to hold responsible rather than a seller account that can be deleted.
We are an authorized reseller for the brands we carry, which is the whole reason we can say anything useful about where a specific unit came from. It is also why we would rather you bought a genuine wallet from a competitor than a cheap one from a marketplace listing.
If you think your device may have been tampered with
Do not move funds onto it, and do not move funds off it using that device. If coins are already on a wallet you no longer trust, the safe path is to set up a completely different device, generate a new recovery phrase on it, and move the funds to the new wallet's addresses.
Treat the old recovery phrase as public from that moment on. If someone else has a copy, changing the PIN or resetting the device does not help — the phrase alone is enough to recreate the wallet anywhere in the world.
If you bought from us and something looks wrong, bring it in or message us before you do anything else. We would much rather check a device that turns out to be fine than hear about it afterwards.
Common questions
My Ledger box had no security seal. Is it fake?
Almost certainly not. Ledger does not use tamper-evident seals as its authenticity mechanism, by choice — their view is that seals are easy to clone and give false reassurance. The check that means something is the Genuine Check run in Ledger's own app, which tests the secure element cryptographically.
My Trezor One had no sticker over the USB port. Should I worry?
No. The Model One carries two seals on the box, and none over the port. The Model T is the one with a seal over its USB-C connector. Checking for the wrong model's seal is a common reason people think a genuine device has been opened.
Can I just buy second-hand and reset it?
We would not, and we would not advise it. A factory reset clears the phrase currently on the device, and for a device that is otherwise genuine and unmodified this does put you in a clean state. The problem is that a reset cannot tell you whether the hardware or firmware itself was altered before it reached you. On a purchase where the downside is the loss of everything held on it, the saving is not worth the uncertainty.
The seller sent a recovery phrase separately, not in the box. Is that different?
No, it is the same attack with an extra step. It does not matter whether the words arrive by message, in an email, on a card, or read out over the phone. If you did not generate them on the device yourself, somebody else has them.
Does a genuine check protect me from everything?
It protects you from a cloned or modified device, which is the main risk in this category. It does not protect you from writing your phrase somewhere insecure, from being talked into revealing it, or from typing it into a website. Those are separate problems, and the phrase itself is where they all lead — which is why how and where you store it deserves as much thought as which device you buy.






Share:
Ethereum vocabulary worth knowing before you invest
What is NB-IoT, and how will it change farming and business?