We use technologies like cookies to store and/or access device information. We do this to improve browsing experience and to show (non-) personalized ads. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Техническое хранение или доступ необходимы для законной цели хранения предпочтений, которые не запрошены подписчиком или пользователем.
The technical storage or access that is used exclusively for statistical purposes.
Техническое хранилище или доступ, который используется исключительно для анонимных статистических целей. Без повестки в суд, добровольного согласия со стороны вашего интернет-провайдера или дополнительных записей от третьей стороны информация, хранящаяся или полученная только для этой цели, обычно не может быть использована для вашей идентификации.
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
Hardware wallet with a preset seed phrase: risks
You order a hardware wallet from an online marketplace and receive a sealed box with holographic stickers. Inside is a scratch-off card with 24 words printed beneath the coating, and the instructions tell you to enter this “activation phrase” during setup. Using it restores a wallet whose keys are already known to whoever prepared the card, allowing that person to steal any funds you send to its addresses.
If you receive a wallet with a preset seed phrase, stop the setup and do not send it any funds. Sealed packaging and a highly rated seller do not make that phrase safe. This guide explains how scammers prepare devices for sale and what to do if you have already used the phrase supplied in the box.
How a seed phrase is generated during setup
When you choose to create a new wallet, the device generates random data known as entropy. The wallet uses this data to create its keys and a backup that lets you restore access to your funds. With wallets that use the BIP39 standard, you typically write down 12 or 24 words shown on the device’s screen. Modern Trezor devices also support 20-word backups based on SLIP39. Our guide to seed phrases and wallet recovery explains what these words are for.
Ledger, Trezor, BitBox, and Keystone use different methods to generate and back up wallets, but none requires words supplied by the seller to create a new wallet. The phrase must be generated when you set up the wallet yourself and remain unknown to the manufacturer, the seller, and anyone else.
Treat a preprinted phrase as compromised, because whoever prepared the card saw every word and could have kept a copy before covering it with the scratch-off coating.
New Trezor devices ship without firmware installed. You install it when you first connect the device, and the bootloader verifies its digital signature. If a newly purchased Trezor reports that firmware is already installed, the manufacturer advises contacting support before continuing with setup.
How scammers prepare a wallet for sale
A scammer only needs a genuine device and fake instructions to persuade a buyer to use a seed phrase the scammer already knows. The wallet may work normally and pass an authenticity check even though the attacker has a copy of its phrase. The process typically works like this:
A more sophisticated version uses a counterfeit device with modified firmware that pretends to create a new wallet while supplying words already known to the attackers. The buyer may write the phrase down directly from the screen without realizing it was chosen in advance.
Why the funds may not disappear immediately
If the wallet is not protected by an additional secret known as a passphrase, a copy of the seed phrase is enough to restore its keys, monitor incoming funds through a blockchain explorer or an automated script, and transfer them out. Changing the PIN does not change the seed phrase. A PIN protects access to a particular device, while the scammer can restore the same wallet on another device using their copy of the phrase.
The first small deposits may be left untouched because buyers often start by testing the wallet: they send a small amount, transfer it back, and move their main savings only after confirming that everything works. In the counterfeit Trezor Model T case investigated by Kaspersky, the attackers stole the funds a month after the first deposit.
Other scammers automate withdrawals and take the funds soon after they arrive. You cannot infer their intentions from what happens to the first few transfers: a successful test transaction does not prove that you are the only person with access to the wallet.
Documented cases of hardware wallet tampering
Scammers may tamper with the recovery card, the device itself, or the app used to set it up, as the following cases show.
A loss of 50 million yuan after buying a wallet through Douyin
In June 2025, SlowMist reported a case involving a buyer who lost crypto assets worth approximately 50 million yuan after purchasing a hardware wallet through the Chinese platform Douyin.
A counterfeit Trezor Model T with 20 preset phrases
In 2023, Kaspersky published an analysis of a counterfeit Model T bought through a classified ads website. Trezor clarified that the incident itself had occurred more than a year before publication. The device had the familiar interface but used a different microcontroller and modified firmware that selected one of 20 preset phrases when creating a wallet.
If the owner added a passphrase, the modified firmware used only its first character. That left 64 possibilities, including no passphrase at all, so the attackers only needed to check 20 × 64 = 1,280 combinations. Trezor confirmed that the device had been modified and noted that the seller was not authorized by the manufacturer.
Tampered Ledger devices mailed to customers after a data breach
A Ledger customer data breach in 2020 exposed more than a million email addresses, along with contact details for some buyers, including shipping addresses. The database did not contain seed phrases. In 2021, users reported receiving Nano X devices they had not ordered. These arrived in sealed packaging with a letter supposedly from Ledger CEO Pascal Gauthier, offering a “new secure device” following the breach.
A USB storage component containing malicious software had been soldered inside the tampered wallet. The instructions asked the recipient to enter their existing 24-word phrase into an app to “migrate” the wallet, sending the words to the scammers. Ledger describes this attack and warns against connecting devices you did not order.
A counterfeit Nano S Plus supplied with a malicious app
In April 2026, a researcher in Brazil published an analysis of a counterfeit Ledger Nano S Plus purchased from a Chinese marketplace. Inside, the researcher found an ESP32-S3 microcontroller with its markings erased, along with seed phrases and PINs stored in plaintext in the device’s memory. The seller also supplied a modified app called Ledger Live that sent data to the attackers.
The researcher clarified that this counterfeit cannot pass Genuine Check in the official Ledger app; the success message in the malicious app was hardcoded. A QR code included in the package directed the buyer to a cloned website to install that fake app.
Other ways scammers get you to use their phrase or reveal yours
Scams do not always involve a card with printed words. Other schemes ask buyers to use a wallet that has already been set up, install a fake app, or disclose their own phrase under the pretext of verification:
How scammers know your name and address
A fake letter may include your real details if scammers obtained them from an order database. In August 2026, Trezor reported a breach at its shipping partner ShipMonk, then clarified in September that some older orders were also affected. The exposed data included names, email addresses, phone numbers, and shipping addresses. Trezor said its own systems and devices had not been compromised and warned of targeted phishing. Knowing your name and address does not prove that a letter came from the manufacturer.
Wallet with a preset seed phrase: what to do when it arrives
If you receive a wallet with a preset seed phrase but have not sent it any funds, stop the setup and arrange to return the device. If its addresses already hold assets, first move them to a new wallet with a phrase generated during your own setup on a trusted device.
If, during “activation,” you entered your previous wallet’s phrase into a fake app, treat that phrase as compromised. Check all accounts and networks associated with it and move any accessible assets to a new wallet with a different phrase. Make the transfers using the official app on a trusted computer or smartphone where you have not run the suspicious software. Deleting the fake app does not remove the scammer’s copy of your phrase.
How to check your purchase and set up your wallet safely
Check the seller before paying, then follow the manufacturer’s instructions for your model when the device arrives. Once you have checked where it came from and completed the authenticity checks, proceed with creating your wallet:
If you are choosing a replacement for a suspicious purchase, see our hardware wallet comparison for 2026, which covers supported assets, smartphone connectivity, and security and recovery options.
Conclusion
A wallet with a preset seed phrase also gives whoever prepared that phrase access to its funds. A scratch-off coating, intact packaging, and successful test transfers do not change this. If you have already sent assets to its addresses, move them to a wallet with a new phrase generated on a trusted device.
Set up a new hardware wallet yourself using the official app and the manufacturer’s instructions. If the instructions supply ready-made words or a preset PIN, or ask you to enter your seed phrase on a website, stop the setup and contact official support.
Related Posts
Crypto cards in Ukraine: availability, fees and limits
Crypto cards in Ukraine in 2026 let you pay for purchases without first withdrawing funds to a bank card. Whether you can get one depends on where you live and whether you pass identity checks; what you ultimately pay depends on conversion rates and fees. We compare providers that explicitly list Ukraine as a supported …
The First 30 Minutes with a Hardware Wallet: What to Do Before You Fund It
The first 30 minutes with a hardware wallet matter more than the box itself. A hardware wallet does not protect your money on its own. Its protection is only as strong as what you do during the first half hour with the device in your hands. Almost every story that ends with “funds were stolen …
Ledger Flex setup: step-by-step guide from unboxing to your first transaction
Ledger Flex setup is best done step by step, from checking the box contents to completing your first test transaction. If you have just received a Ledger Flex, this guide will walk you through installing Ledger Wallet, running Genuine Check, creating a new wallet, writing down your Secret Recovery Phrase, and setting up your recovery …
Keystone 3 Pro setup: step-by-step guide from unboxing to your first transaction
Keystone 3 Pro setup should start with verifying the device and checking a few basic security settings. In this guide, we walk through the entire process step by step, from inspecting the box to signing your first transaction. We based the instructions on Keystone’s official documentation and kept menu labels exactly as they appear on …