Hardware wallet security and supply chain: reduce recovery cases before they exist
Buy only from authorized channels
Reseller markets, “open box” deals, and second-hand devices increase tamper risk. Prefer first-party stores or authorized retailers with intact tamper-evident packaging. Compare packaging against vendor documentation; attackers have shipped devices with pre-generated seeds printed inside fake “setup cards.” If anything instructs you to use a pre-printed seed, it is malicious—initialize a new wallet yourself on-device.
Firmware and companion apps
Install updates only through official vendor applications. Verify checksums when vendors publish them. Avoid side-loaded APKs from Telegram links. After firmware updates, confirm your receive addresses on-device before receiving large transfers—some attack classes target update workflows, though rare compared to social engineering.
Address verification beats trust on screen
Clipboard malware swaps addresses in browser UIs. Always confirm the recipient address on the hardware screen, character by character for high-value sends. This habit alone prevents a surprising fraction of “wrong address” losses that are not recoverable on-chain.
When to rotate to a new seed
If you typed your seed into a compromised computer, if a drainer interacted with your machine, or if you suspect physical access to your backup, migrate funds to a freshly generated seed on clean hardware. “Wait and see” preserves attacker access. If you are locked out without compromise suspicion, see wallet access recovery before destroying old backups.
Enterprise and family offices
Use multisig or policy-based approvals for treasury sizes that justify operational overhead. Our multisig incident response post outlines communication patterns when something moves unexpectedly.