How to Verify a Hardware Wallet Is Genuine
Check the source, the seals, and the software: how to confirm your hardware wallet is authentic and untampered before you trust it with crypto.

On this page
Verifying that a hardware wallet is genuine means checking three things: that you bought it from an official source, that the packaging and device show no signs of tampering, and that the maker's own software confirms it is authentic. A counterfeit or tampered device can be pre-loaded with a seed phrase an attacker already knows, so this check comes before you ever move a coin.
The good news is that modern devices make this easy, combining physical seals with a hardware-level authenticity check built into the official app. This guide walks through every step, from the box on your doorstep to the on-screen confirmation.
If a device arrives with a recovery phrase already written down, stop immediately. A genuine hardware wallet always generates your seed phrase in front of you, never before.
The single clearest sign of a fake
Start before you buy
The best defense against a counterfeit is where you buy it. Purchase only from the maker's official website or an authorized reseller listed on that site.
Authorized resellers are vetted, which is why buying direct is by far the safest route. Avoid third-party marketplaces, auction sites, and private sellers, where a device could have been opened, tampered with, or repackaged before it reached you. A used hardware wallet should never be trusted, no matter how good the deal looks. A steep discount from an unfamiliar seller is itself a warning sign, since genuine devices rarely sell far below the maker's price and the "savings" can cost you everything inside the wallet.
Check the packaging and seals
When the device arrives, inspect it before opening. Tampering usually leaves traces.
- Examine the shipping box for cuts, re-gluing, or a reseal.
- Check any holographic or tamper-evident seal. A genuine seal is intact, and some leave a "VOID" residue if peeled.
- Look for a tamper-evident bag where the maker uses one, and confirm it is still sealed.
Ripped, mismatched, or re-glued seals are a red flag. If anything looks off on arrival, do not set the device up; contact the manufacturer's support first.
Check what is in the box
The contents themselves are a giveaway. Cross-reference the box against the maker's official checklist, which typically lists the device, a cable, documentation, and blank recovery cards.
Those recovery cards matter most: they must be completely blank. If your backup cards arrive with words already written or printed on them, the device is compromised. Do not use it, and contact support, because a pre-filled phrase means someone else already holds the keys.
Inspect the physical device
Counterfeits often betray themselves in the build quality. Handle the device and look closely.
| Check | What genuine looks like |
|---|---|
| Construction | Clean, with no tool marks, sharp edges, or glue residue |
| Ports and buttons | USB port fits snugly; buttons or touchscreen respond correctly |
| Branding | Sharp, centered logo and text, not faded or misaligned |
| Fit and finish | Panels sit flush; nothing rattles or bends oddly |
Any unusual physical flaw, a wobbly port, a crooked seam, or blurry printing, is reason to pause and verify further before trusting the device.
Run the software authenticity check
This is the strongest verification, because it happens at the hardware level. Connect the device to the maker's official app, such as Ledger Live or Trezor Suite, downloaded only from the official website.
During manufacturing, each device is issued a unique certificate stored in its secure element chip. When you connect, the app, whether Trezor Suite or Ledger Live, sends a random challenge, the secure element signs it with that certificate, and the app verifies the signature against the maker's public keys. Genuine devices pass this check; tampered devices fail it. A genuine device passes silently; a fake or modified one triggers a warning. If you see any authenticity or firmware warning, disconnect and contact support at once.
Set it up yourself, from scratch
The final safeguard is doing the setup yourself. A genuine device always asks you to create a new wallet and generates the seed phrase on its own screen, in front of you.
- Confirm the device prompts you to set up as new, not to import an existing wallet.
- Let it generate a fresh seed phrase, and write it down yourself.
- Install only official firmware, and accept updates only through the official app.
For the complete first-time process, follow how to set up a hardware wallet.
What to do if something looks wrong
Stop and do not fund it
If seals are broken, cards are pre-filled, the build looks off, or the software flags the device, do not transfer any crypto to it. A tampered device may hand your funds straight to an attacker.
Contact the maker
Reach out to the manufacturer's official support with your order details and photos of the issue. If you bought from an unauthorized seller, treat the device as untrustworthy and replace it with one bought direct.
Official source, intact seals, blank cards, and a passing software check. Clear all four and your device is genuine; fail any one and stop.
The four-point verification
Why this check matters
Counterfeit and tampered hardware wallets exist because they are one of the few ways to beat cold storage. A device is normally immune to remote attacks, so criminals target the supply chain instead, hoping you set up a wallet whose keys they already control.
The pre-loaded seed attack
The classic version ships a device with a seed phrase the attacker generated. You receive it, move your crypto in, and the attacker, holding the same phrase, sweeps the funds. Generating your own seed phrase on a verified device defeats this entirely, which is why the blank-cards and set-up-as-new checks matter so much.
Verify the software you download too
Authenticity is not only about the device. Download the companion app only from the maker's official domain, typed by hand rather than from a search ad, since fake apps are a common trick. Both major makers publish checksums for their desktop software, so advanced users can confirm the downloaded file matches the official hash before installing.
Common signs of a fake hardware wallet
| Warning sign | What it means |
|---|---|
| Recovery cards already filled in | Someone else may control the wallet; do not use |
| Broken or re-glued seal | The package may have been opened |
| Device asks you to import a seed | A genuine new device generates its own |
| Software shows an authenticity warning | The device may be counterfeit or modified |
| Bought used or from a marketplace | Untrusted supply chain; replace it |
When in doubt, buy a fresh device from the best hardware wallets round-up and start clean. A brand-new device that costs a little is always far cheaper than the funds a fake one could quietly steal.
Frequently asked
How do I verify a hardware wallet is genuine?
Check three things: that you bought it from the maker's official site or an authorized reseller, that the packaging and device show no tampering, and that the maker's official app passes its hardware authenticity check. Also confirm the recovery cards are blank and set it up yourself.
What is the clearest sign a hardware wallet is fake?
A recovery phrase that is already written on the backup cards or shown on the device. A genuine wallet always generates your seed phrase in front of you during setup. A pre-filled phrase means someone else already controls the wallet, so do not use it.
Where should I buy a hardware wallet to be safe?
Only from the maker's official website or an authorized reseller listed there. Authorized resellers are vetted. Avoid marketplaces, auction sites, and private or used sellers, where a device could have been opened or tampered with before reaching you.
How do I check the tamper-evident seal?
Inspect the shipping box for cuts or re-gluing, and check any holographic seal or tamper-evident bag is intact. Some seals leave a VOID residue if peeled. Ripped, mismatched, or re-glued seals are a red flag, so contact support before setting up.
What should come in the box of a genuine hardware wallet?
Typically the device, a cable, documentation, and blank recovery cards. Cross-reference against the maker's official checklist. The recovery cards must be completely blank; if they have words on them, the device is compromised.
How does the software authenticity check work?
Each device is issued a unique certificate in its secure chip at manufacture. When you connect it to the official app, the app sends a random challenge, the device signs it with that certificate, and the app verifies the signature against the maker's keys. A fake triggers a warning.
Can a counterfeit hardware wallet steal my crypto?
Yes. A tampered device can be pre-loaded with a seed phrase an attacker knows, or run modified firmware, so any funds you send go to them. That is why verifying authenticity and generating your own seed phrase before funding it are essential.
Is it safe to buy a used hardware wallet?
No. A used device could have a pre-set seed phrase or modified firmware that you cannot reliably detect. Always buy new, direct from the maker or an authorized reseller, and set it up from scratch yourself.
What does the software show if the device is not genuine?
The official app displays an authenticity or firmware warning instead of connecting normally. If you see any such warning, disconnect the device immediately, do not enter or generate a seed phrase, and contact the manufacturer's support.
How can I spot a fake by looking at the device?
Check the build quality: genuine devices have no tool marks, sharp edges, or glue residue, a snug USB port, responsive buttons, and sharp centered branding. Wobbly ports, crooked seams, or faded or misaligned logos suggest a counterfeit.
Do I need to verify the firmware too?
Yes. Install only official firmware and accept updates only through the maker's official app, never from a link. The app checks the firmware when the device connects, and any unexpected firmware warning is a reason to stop and contact support.
What should I do if my hardware wallet seems tampered with?
Do not transfer any crypto to it. Contact the manufacturer's official support with your order details and photos of the issue. If you bought from an unauthorized seller, treat the device as untrustworthy and replace it with one bought directly.
See which wallets we actually recommend
Every wallet in the register was bought at our own cost and scored on one fixed standard.
Read the register →