Skip to content
Sat, Jul 25 UTC 23:52:51 MKT CAP $1.99T
BitcoinBTC $64,381.99 +0.35% EthereumETH $1,875.04 +0.76% TetherUSDT $1.00 +0.00% BNBBNB $569.01 +0.78% XRPXRP $1.10 +0.59% USD CoinUSDC $1.00 +0.00% SolanaSOL $74.48 +0.72% TRONTRX $0.3316 +0.24% DogecoinDOGE $0.0718 +3.09% XMR $364.02 +0.35% CardanoADA $0.1646 +0.43% ToncoinTON $1.60 +0.95% StellarXLM $0.1781 +0.17% ChainlinkLINK $8.38 +0.50% DaiDAI $1.00 +0.00% Bitcoin CashBCH $209.70 -0.43%
Hardware Wallets

How to Buy a Hardware Wallet Safely (and Spot a Tampered One)

Where you buy a hardware wallet matters as much as which one you buy. Here is how to source a device safely, why a pre-filled recovery card is always a scam, and how the follow-up phishing works.

This article is for informational purposes only and is not financial advice.
How to Buy a Hardware Wallet Safely (and Spot a Tampered One) - illustration: a warm wooden parcel with an intact mulberry wax seal beside an identical parcel w

The quick version. Buy from the manufacturer, or from a reseller the manufacturer itself lists. Never second-hand, never a marketplace seller. If a device arrives already set up, or with a recovery phrase printed on a card, it is a scam without exception: return it, and do not put a single coin on it to “test” it.

The easiest attack is the box, not the chip

A hardware wallet is designed on the assumption that the computer it plugs into is hostile. The private key is generated inside the device, never leaves it, and every payment must be confirmed on the device’s own screen. A secure element makes extracting that key physically difficult.

All of that rests on one assumption: the secret inside was generated by the device, in your hands, and has never existed anywhere else.

An attacker who cannot break the chip attacks the assumption instead. Sell you a device whose recovery phrase they already hold, and the silicon becomes irrelevant. They need not act at the moment of sale either: they watch the addresses and take the balance whenever it suits them, months later if they like.

“Where did this device come from” is therefore a security question, not a shopping question.

Buy direct, or from a reseller the manufacturer lists

The safest purchase is the manufacturer’s own shop. The next safest is a reseller named on the manufacturer’s own website. The direction of trust matters: believe the manufacturer’s list of resellers, never a seller’s claim to be authorised.

  • Never second-hand. A used device is a device somebody else has held, and a reset you did not perform proves nothing.
  • Never a general marketplace listing, including one that looks like the brand’s storefront. Pooled inventory and third-party fulfilment mean nobody can tell you which hands the box passed through.
  • Never a giveaway device arriving as a prize, a conference freebie or a “free upgrade” you did not order.
  • Treat a steep discount as information. Margins are thin, and a price well below the manufacturer’s own is a reason to ask why.

How you reach the shop matters too. Type the address yourself or use a bookmark you made earlier, because look-alike storefronts have been placed in front of buyers through search adverts and social posts. That is the same family of trick covered in how to spot crypto scams.

The red flag that ends the conversation

If the device arrives already initialised — it has a PIN, it shows a balance, it asks you to confirm an existing wallet — or if the box contains a card with a recovery phrase already written or printed on it, stop there. No legitimate reason exists for either: not manufacturer convenience, not a reseller service, not a “pre-configured” option.

Every honest hardware wallet generates its recovery phrase on the device, on first use, in front of you, and asks you to write it down yourself. A phrase that arrived in the box is a phrase somebody else already has a copy of.

Safety: Never move a small amount onto a suspect device to see what happens. A pre-loaded phrase lets the sender sweep the balance the moment it lands, and a test that appears to work proves nothing except that the device switches on. Look up the seller’s contact details independently, return the unit, and start again from the manufacturer.

Check the packaging against the manufacturer’s guidance

Seals, shrink-wrap, holograms and tamper-evident bags are worth inspecting, but they are weak evidence alone. Stickers can be reproduced and bags resealed convincingly, so a seal that looks fine tells you little.

What raises the value of the check is comparing what you received against the manufacturer’s own published description of a genuine sealed unit. Manufacturers document what is in the box and how their packaging works, and that documentation, not your instinct, is the reference.

Stronger still is the device’s own attestation. Many models run a cryptographic genuineness check against the manufacturer when first connected. Run it, using software downloaded from the manufacturer’s own domain, and follow their documented process rather than a leaflet that came with the parcel.

Then set the device up yourself, generating a fresh wallet and writing the words by hand. Our setup walkthrough covers that carefully.

The phishing wave that follows a customer-data leak

This industry has an awkward structural problem. Buying a hardware wallet usually means handing over a name, a delivery address, an email and often a phone number, and that record quietly says: this person probably owns crypto.

When such a list escapes, through a breach at a retailer, a shipping partner or a marketing provider, it becomes a targeting list. The follow-up is predictable in shape. Messages arrive referencing a genuine order, warning of a “security incident”, and directing you to a site that mirrors the manufacturer’s, where you are asked to enter your recovery phrase to “migrate” or “validate” your wallet.

Campaigns of this kind have escalated to printed letters and even unsolicited replacement devices posted to home addresses, with instructions to restore using an enclosed card. The physical channel feels more official, which is precisely why it is used.

One rule defeats every variant: your recovery words are entered nowhere except directly onto your own hardware wallet, during a recovery you started. No manufacturer, shop or support desk ever needs them. Treat unsolicited hardware as hostile and dispose of it rather than plugging it in.

Choosing a model, once sourcing is safe

With sourcing settled, picking a model is an ordinary comparison. What matters is how you will use it: phone or desktop, which coins you hold, whether the screen is big enough to check a full address, and how open the firmware is.

Our hardware wallet reviews are research-based rather than lab-tested, and say so in each one. Over a few years, a maker’s firmware update record matters more than any feature on the box.

Finally, budget for the backup as part of the purchase. The device protects the key day to day; a written or metal backup is what survives the device.

Key takeaways

  • Buy from the manufacturer or a reseller it lists. Second-hand and marketplace listings remove the one guarantee that matters.
  • A device that arrives initialised, or with a recovery phrase supplied, is a scam every time. Never test it with funds.
  • Seals are weak evidence. Compare against the manufacturer’s published guidance and run the device’s own genuineness check.
  • Customer-data leaks in this industry produce targeted phishing by email, phone and post, sometimes with replacement hardware.
  • Your recovery words go only onto your own device, during a recovery you started. Nobody legitimate ever asks for them.

Frequently asked questions

Is it safe to buy from a large online marketplace?

It is the weakest of the common options. Even where a brand runs a storefront there, inventory is often pooled and orders fulfilled from third-party stock, so the chain of custody between factory and your door cannot be established. The manufacturer’s own shop, or a reseller it names, closes that gap for a small difference in price.

The seal looked untouched. Is the device fine?

An intact seal is mildly reassuring, not conclusive, because packaging can be reproduced or resealed. Weight your judgement towards checks that are hard to fake: the device generating a brand new phrase in front of you, and the manufacturer’s genuineness check run from software you downloaded yourself. If the setup flow differs from the official documentation, stop.

I already set up a device that came with a printed phrase. What now?

Treat that wallet as compromised and assume anything sent to it can be taken. Set up a wallet you trust, ideally on a properly sourced device, generate a new phrase on it, and move funds there, checking the receiving address on the trusted device’s screen. Never reuse the supplied phrase.

Should I register the device with the manufacturer?

Registration and warranty schemes are convenient, and they create another record linking your identity to crypto ownership. Some people accept that trade-off for support; others prefer to minimise the data they hand over. Either way, assume such records may leak one day, and never trust an unsolicited message that quotes your order details back to you.

Educational content, not financial advice. Never share your seed phrase or private keys with anyone — including anyone claiming to be CoinCrafty.

Last updated Jul 25, 2026

Keep exploring