Issue 169•

Supply Chain Attacks Target Your Hardware Wallet Before You Open the Box

Hardware WalletCrypto Security

Supply Chain Attacks Target Your Hardware Wallet Before You Open the Box

The threat does not always arrive through your screen

Sometimes it arrives in the post.

A hardware wallet is only as trustworthy as the chain of hands it passed through before reaching you.

Supply chain attacks happen when a device is tampered with during manufacturing, storage, or shipping. The goal is to either extract your seed phrase after setup or replace the device with a counterfeit that looks identical.

What tampering can look like

Not all tampered devices are obvious fakes. Some are real devices that have had firmware modified before packaging. Others have had physical components replaced.

Common signs that something may be wrong:

  • The box seal is broken, peeled, or looks re-applied
  • The device came with a pre-filled seed phrase written on a card inside the box
  • Setup instructions prompt you to enter a recovery phrase that was "pre-generated for you"
  • The device firmware version does not match what the manufacturer publishes

The most dangerous scenario is not a cracked box. It is a device that looks completely normal but has been silently modified.

Where the risk is highest

The risk is not uniform. It rises when you buy from unofficial channels.

Resellers without direct manufacturer authorisation may source stock from secondary distributors. Each additional step between factory and buyer is an opportunity for interference.

Third-party marketplace listings carry real risk. A listing with good reviews does not mean the device is genuine.

Reading through the hardware wallet primer before buying helps you understand what to look for in a legitimate device.

A real world scenario

A user purchased a hardware wallet from a third-party marketplace listing.

The box looked sealed and the packaging appeared genuine.

Inside, a card listed a 24-word recovery phrase and instructed the user to load this phrase during setup rather than generate a new one.

The user followed the instructions and transferred a significant amount of crypto to the wallet.

Within days, the funds were swept by whoever had generated that seed phrase before the device was ever shipped.

How to reduce this risk

Buying from the right source removes most of this risk before you ever open the box. But verification steps still matter.

  • Buy only from the manufacturer's official website or an authorised reseller
  • Check the manufacturer's website for a list of approved resellers in your region
  • Inspect physical tamper-evident seals before opening
  • Never use a seed phrase that came pre-written inside the box
  • Always generate your own seed phrase during the device's first setup
  • Verify firmware version against the manufacturer's published release after setup

Where hardware wallets fit in

A genuine, unmodified hardware wallet keeps your private keys isolated from internet-connected devices. That protection only works if the device itself has not been compromised.

Manufacturers like Trezor use open source firmware with signed releases, which means you can verify that the firmware on your device matches what the manufacturer published. Open source hardware wallets with signed firmware make this verification accessible even to non-technical users.

Buying from an authorised source is the first line of defence. Verifying the firmware is the second.

Unsure where to buy safely in Singapore

Some users buy from the cheapest listing they can find.

Others prefer to buy in person from a local source they can verify.

The right approach depends on how much confidence you want in the device before trusting it with your funds.

You can use our wallet selector to find a suitable hardware wallet based on your setup and security preferences.

Find the right wallet in under a minute

Final thought

A hardware wallet purchased from the wrong source can be less safe than no hardware wallet at all. Source carefully, then verify.

Crypto Compass is published by Bitcoin Wallet SG, a Singapore authorized hardware wallet reseller.

Never miss an issue

Get practical self custody guidance delivered to your inbox every week.

Subscribe to Crypto Compass