Independent platform · No upfront fees · We are not a recovery firm

Home › Knowledge Hub › Hardware wallet scams

Hardware wallet scams: fake devices, fake apps, fake support

By Golan Ben Moshe · Co-founder, Chain Pursuit · 9 min · Last updated 1 October 2026

Buying a hardware wallet does not complete the job, and several frauds target the gap between buying one and using it safely. A device supplied with a recovery phrase already written down is compromised. A wallet app downloaded from an advertisement may be a copy. An urgent update prompt asking for your phrase is theft in two steps. All three are caught by the same discipline: obtain everything from the manufacturer directly, and never type a recovery phrase into anything.

The rule that covers all of it

No hardware wallet, and no legitimate support process, ever needs your recovery phrase.

Not for setup. Not for verification. Not for migration. Not for a firmware update. Not to restore a wallet you already control. Not to check whether your device is affected by a security issue.

Every scam on this page ends at the same place: a prompt asking you to type those words into something. Recognising that one moment is worth more than recognising any individual scam.

Pre-configured devices

The most direct version, and it works because the packaging is convincing.

A device arrives with a recovery phrase already supplied. It may be printed on a card, hidden behind a scratch panel, or written on a slip of paper tucked into the box. The instructions tell you to use that phrase to set up the wallet.

Someone else already has those words and is waiting for you to fund it. The transfer usually happens within minutes of the first deposit.

A new device generates its own phrase, on the device, in front of you, during setup. If yours did not, stop. Do not fund it, and contact the manufacturer through their official site.

This has appeared repeatedly over the years and continues to work, which is why every manufacturer prints a warning about it and why most people still miss it.

Two setups, side by side
A GENUINE DEVICEA COMPROMISED ONEGenerates its phrase in front of youBought from the maker or a listed resellerUpdates only through the official appNever asks for your phrase, everArrives with a phrase suppliedCame from a marketplace or unsolicitedPrompts you to update via a linkAsks you to 'restore' or 'verify'Every scam in this category ends with a field asking for your recovery phrase.
The left column is what a genuine device does without being asked. The right is what every version of this fraud has in common.

Where you buy from

Buy from the manufacturer directly, or from a reseller listed on the manufacturer's own website. Not a marketplace, not an auction listing, not a discounted third-party seller.

A device that has passed through unknown hands cannot be reasoned about. Tampering does not have to be sophisticated, and the seller does not have to be the person who tampered with it.

Tamper-evident seals are weak evidence. They can be reproduced convincingly. Treat an intact seal as mildly reassuring and a broken one as disqualifying, rather than the reverse.

Never accept a hardware wallet as an unsolicited gift. Devices arriving in the post, presented as a replacement, an upgrade, a prize or a security measure, have been used to distribute tampered hardware. If you did not order it, do not use it.

Fake wallet applications

Hardware wallets need companion software, and copies of that software appear regularly.

In app stores, including the official ones. This is the part usually understated. In April 2026 a counterfeit Ledger Live application on Apple's official App Store took around $9.5 million from more than 50 victims over six days, across Bitcoin, Ethereum, Tron, Solana and XRP. Blockchain investigator ZachXBT documented it and Apple removed the app. Days earlier, the musician Garrett Dutton lost 5.9 BTC to a comparable fraudulent application.

Checking the publisher name, download count and review history is still worth doing, and it is weaker advice than it sounds, because a listing that passed official review displays exactly the signals you are being told to check.

The stronger habit is not to search an app store at all. Go to the manufacturer's website by typing the domain, and follow its own download link. That way the store listing is one you were sent to, not one you found.

In search results. Phishing operations buy advertising against wallet brand names, so the fake result sits above the genuine one. Scroll past the adverts, or type the domain yourself.

Through direct links. Any link to wallet software in a message, email or social post should be ignored regardless of who appears to have sent it.

The habit: reach wallet software by typing the manufacturer's domain. Bookmark it. Use the bookmark thereafter.

Fake update prompts

A standing lure, and effective because updates are necessary.

A message appears, by email, in a browser pop-up, or as a notification, saying your device requires an urgent security update. Perhaps a vulnerability has been discovered. Perhaps your funds are at risk. The link goes to a page that looks like the manufacturer's, and the process asks you to enter your recovery phrase to "restore" or "verify" the wallet.

That is the whole attack. Urgency, a plausible reason, and a phrase field.

Update firmware only through the manufacturer's official application, opened by you, reached by typing the address. Never through a link you were sent.

Genuine firmware updates never require your recovery phrase. The device updates itself; the phrase is not part of the process.

Fake support

You post publicly about a problem with your wallet. Within minutes, accounts reply or message you privately, presenting as official support, with correct terminology and matching branding.

Then the ask: your recovery phrase for verification, remote access to diagnose, a small transaction to confirm ownership, or your credentials.

Real support never needs any of those. No exception exists.

A habit that removes the entire category: never discuss a wallet problem in a private message initiated by someone who approached you. Open a ticket through the manufacturer's own website.

This overlaps with impersonation scams more generally, and the defence is the same: end the contact, look the organisation up yourself, and reach them through a channel you found.

When the device is the weak point

The harder category, because these do not require deceiving you at all.

A defect in the device itself. In July and August 2026, attackers drained Coldcard hardware wallets using a firmware flaw from March 2021 that weakened seed phrase randomness, making the resulting keys brute-forceable without any access to the device. More than 7,300 wallets were affected and losses topped $130 million. Nothing the owners did wrong caused it, and updating the firmware did not protect a seed already generated. Our cold wallet guide covers what affected owners should do.

Supply chain compromise.

In December 2023, a compromise of a widely-used wallet connection library allowed malicious code to be served to users of several applications. The device itself was not counterfeit and the user did nothing careless; the software layer between the site and the wallet had been altered.

What this means practically. You cannot fully defend against this by being careful, which is uncomfortable but true. What you can do is limit exposure: keep long-term holdings in a wallet that does not connect to applications, verify destinations on the device screen, and treat any transaction whose contents the device cannot describe as one to decline.

Our guide on verifying what you are signing covers that discipline, and the Bybit theft of February 2025 shows what happens when the interface itself is the compromised layer.

Checks before you fund a new device

Red flags

What not to do

If you already entered your phrase

Assume the wallet is compromised permanently. Changing a PIN or password does nothing, because the phrase is the wallet.

Create a new wallet on a device you trust and move everything to it now. Attackers commonly automate sweeping a compromised address, so anything arriving there afterwards is likely lost.

Then preserve what you have. Our evidence checklist covers what matters, and the country guides explain which reporting channel can lead to an investigation.

Expect an approach afterwards from someone offering to recover the funds. Read how to spot a crypto recovery scam before replying to anyone.

What this guide cannot do

These checks catch the common frauds. They do not make a hardware wallet immune, and supply chain compromise in particular can defeat a careful user. Nothing here guarantees your funds are safe.

This is general information, not legal or financial advice.

Use Chain Pursuit's free tools to understand your options, preserve evidence, and identify possible recovery scams. Do not share your seed phrase or private keys with anyone.

Sources

MetaMask, Crypto Security Report: April 2026, May 2026. https://metamask.io/news/crypto-security-report-2026

TRM Labs, The Largest Hardware Wallet Exploit of 2026: Inside the USD 116 Million Coldcard Hack, August 2026. https://www.trmlabs.com/resources/blog/the-largest-hardware-wallet-exploit-of-2026-inside-the-usd-116-million-coldcard-hack

TechCrunch, Hackers steal over $130M by exploiting bug in offline hardware wallets, 4 August 2026. https://techcrunch.com/2026/08/04/hackers-steal-over-130-million-by-exploiting-bug-in-offline-hardware-wallets/

Loss figures for the Coldcard incident vary between roughly $116 million and above $130 million depending on the source and publication date, as researchers continued identifying affected addresses after disclosure.

Frequently asked questions

An app was on the official App Store. Doesn't that mean it was checked?

Review catches a great deal and is not a guarantee. In April 2026 a counterfeit Ledger Live app on Apple's App Store took around $9.5 million from more than 50 people before removal. Reach wallet software from the manufacturer's own website rather than by searching a store.

Can a hardware wallet be compromised even if I do everything right?

Yes, though it is uncommon. The Coldcard incident of 2026 came from a firmware defect shipped in 2021 that weakened key generation, and affected owners had shared nothing and connected nothing. It is a reason to keep firmware current and to watch manufacturer security notices, not a reason to avoid hardware wallets.

My hardware wallet came with a recovery phrase already written down. Is that normal?

No. It means the device is compromised and someone else holds those words. A genuine device generates its phrase on the device during setup, in front of you. Do not fund it. Contact the manufacturer through their official website.

Is it safe to buy a hardware wallet on a marketplace or second-hand?

No. Buy from the manufacturer or a reseller listed on the manufacturer's own site. A device that has passed through unknown hands cannot be verified, and tamper-evident seals can be reproduced.

A hardware wallet arrived that I did not order. Should I use it?

No. Unsolicited devices have been used to distribute tampered hardware, sometimes with convincing letters explaining that your existing device needs replacing for security reasons. Do not connect it.

How do I know if a wallet app is genuine?

Reach it by typing the manufacturer's domain rather than searching or following a link, then download from there. In app stores, check the publisher name and review history rather than the app name and icon, which are easy to copy.

My wallet says it needs an urgent security update. Is that real?

Check by opening the manufacturer's official application yourself. Genuine updates appear there. Any update process that asks for your recovery phrase is an attack, without exception, regardless of how official the page looks.

Can a hardware wallet be hacked remotely?

The keys do not leave the device, which removes most remote attacks. The realistic risks are approving a malicious transaction, exposing your recovery phrase, a tampered device, or a compromise in the software layer between a site and your wallet.

Someone from support messaged me about my wallet. Is that normal?

No. Manufacturers do not initiate private messages to users about account problems. Anyone doing so is impersonating them. Open a ticket through the official website instead.

What happens if my hardware wallet manufacturer goes out of business?

Your funds are on the blockchain, not in the device, and most wallets follow common standards, so a recovery phrase can generally be restored into another compatible wallet. This is a reason to keep your phrase safe rather than a reason to worry about the company.

If you already entered your phrase somewhere

Ten questions showing what can realistically be done in your case.

Recovery pathway assessment

Keep reading