Can a Hardware Wallet Be Tampered With Before Purchase?
A hardware wallet's security depends on the device being genuine before it reaches you — a risk that exists before setup even begins. Here's what to check.
A hardware wallet's entire value proposition rests on the assumption that the device itself is genuine and untampered when it reaches you. That assumption can fail before the device ever leaves the supply chain — a risk entirely separate from anything that happens after you start using it.
Why the Supply Chain Is a Viable Attack Point
A hardware wallet is a physical product that passes through manufacturing, shipping, and often third-party retailers before reaching a buyer — any point in that chain where the device could be intercepted, opened, and modified represents a potential opportunity to compromise it before the legitimate owner ever uses it.
What Tampering Could Actually Involve
A compromised device could be modified to record or transmit the seed phrase generated during setup, to generate a seed phrase from a predictable or already-known source rather than genuine randomness, or to include hardware or firmware modifications that undermine the device's core security guarantees in some other way.
Why Buying From Unofficial Third-Party Sellers Increases This Risk
A device purchased through a general marketplace, an unofficial reseller, or a secondhand listing has passed through additional, unverified hands compared to one bought directly from the manufacturer or an explicitly authorized reseller — each additional, unverified point of contact is an additional opportunity for tampering.
Why Physical Tamper-Evidence Features Exist
Many hardware wallet manufacturers include physical tamper-evident seals or packaging features specifically designed to reveal if a device has been opened before reaching the buyer — checking these carefully upon receipt, and comparing them against the manufacturer's own documentation of what genuine, untampered packaging looks like, is a direct verification step.
Why Generating a New Seed Phrase Yourself Matters
A genuine hardware wallet should have you generate your own seed phrase during initial setup, displayed only on the device's own screen — a device that arrives with a seed phrase already written on an included card, or that doesn't let you generate your own from scratch, is a significant warning sign regardless of how legitimate the packaging appears.
Why Verifying Firmware Authenticity Is a Separate Step Worth Taking
Beyond physical packaging, checking that a device's firmware matches the manufacturer's official, verified version — many manufacturers provide a way to verify this directly through their official setup process — adds a layer of verification beyond what physical inspection alone can confirm.
What to Do to Minimize This Risk
Purchasing hardware wallets exclusively from the manufacturer's own official website or explicitly authorized retailers, checking tamper-evident packaging features against official documentation upon arrival, and generating your own seed phrase directly on the device rather than accepting one that arrived pre-written.
Verify a hardware wallet's authenticity through the manufacturer's official setup process before trusting it with significant funds — supply chain tampering is a risk that exists before you ever open the box.