If someone you didn't know approached Tuga in the garden and fastened something around her neck, you would want to know several things very quickly. Who are you. What is that. Why is it already adjusted to her size.
People perform the equivalent of this transaction constantly. They buy the device that will hold their savings from a marketplace seller with a good rating, because it was fifteen euros cheaper and arrived on Tuesday.
The hardware wallet is the one purchase in this entire hobby where the supply chain is the security model. Here's how not to get it wrong.
1. Buy Direct. That's the Rule.
From the manufacturer's own website, at full price, or from a reseller the manufacturer names on that site.
Not from a marketplace, even a large reputable one, because the listing and the fulfilment are frequently not the same company. Not from an auction site. Not from a forum. Not from a colleague who "never used it". Not a gift from anyone who isn't a person you'd hand your bank card to.
The discount you're chasing is smaller than the amount you're protecting, by several orders of magnitude. This is the cheapest decision in the whole process and the most consequential.
2. Why Used Is Never an Option
A hardware wallet is not a phone. Its resale value should be zero to you, no matter how honest the seller appears.
An attacker's play is simple: generate a seed themselves, set up the device, package it as new, sell it below market price. You receive a functioning wallet that works perfectly. You deposit funds. They already have the keys, and they wait — sometimes months — until the balance is worth the theft.
There's no way to prove a device hasn't been through this. The only reliable defence is provenance: it came from the manufacturer, sealed, to you.
3. Tamper Evidence Is Weak Evidence
Holographic stickers and sealed boxes feel reassuring. Treat them as one signal among several, not proof.
Seals can be reproduced. Boxes can be resealed. Several manufacturers have deliberately moved away from stickers precisely because they create false confidence — and instead rely on cryptographic attestation: the device proves to the official software that it is genuine, using a key baked in at the factory that cannot be extracted.
So: run the manufacturer's genuine-check when you first connect. Update firmware from the official application before doing anything else. And know that the packaging is the least important part of the verification.
4. The Device Must Generate the Seed. You Must Write It.
This is the non-negotiable one, and it catches beginners.
A new hardware wallet arrives with no wallet on it. You set it up, the device generates a recovery phrase using its own randomness, it displays the words on its own screen, and you write them down. That is the only correct sequence.
Every deviation is theft:
- A recovery card that arrives already filled in. This is the most common physical scam in bitcoin. There is no legitimate version of it.
- A device that shows you a seed before you've initialised it.
- Instructions — in the box, in an email, on a card with a QR code — telling you to visit a site and enter your phrase to "activate" or "verify" the device.
- Any "pre-configured for your convenience" wallet.
If a phrase existed before you created it, someone else has seen it. Set the device aside and contact the manufacturer.
5. The Part People Forget: Your Data
There's a second exposure that isn't about the device at all.
When you buy direct, you give a company your name, email and shipping address, and that company now holds a list of people who probably own bitcoin. This is not hypothetical: a major manufacturer's customer database leaked years ago, and buyers from that period still receive convincing phishing attempts — and, in some cases, threats referencing their home address.
Practical mitigations, in ascending order of effort: a dedicated email address for the purchase; a delivery point that isn't your home; paying in a way that doesn't broadcast the purchase. None of this is paranoia. It's recognising that the purchase itself creates a record, and records leak.
6. Then: Test It Before You Trust It
Before a meaningful amount goes anywhere near the device:
- Send a small amount in.
- Wipe the device.
- Restore it from your written phrase alone.
- Confirm the funds are there.
This takes twenty minutes and it validates the device, your backup, and your understanding of the process — the three things you're actually depending on. Do it once at the start and once a year afterwards.
The Point
The collar question is the right one: who gave it to her, what does it do, and why did it arrive already adjusted. Provenance is the whole answer, and it cannot be reconstructed afterwards by examining the object.
You are not buying a gadget. You are buying a chain of custody that ends with you generating a secret nobody else has ever seen. Anything that shortens that chain — a discount, a convenience, a favour, a pre-filled card — is the attack.
Buy it direct. Generate it yourself. Take nothing from strangers. 🐾⚡