When you purchase a new hardware wallet device you don't expect to receive modified fake device with malicious code, but that is always possible as one of many
Attack Vectors for Hardware Wallets.
Important thing is to order hardware wallets only from official website or official resellers , but you should do few more steps to verify integrity of hardware wallet, packaging and content inside, to avoid being scammed with fake device.
First follow the link
Check if your Ledger wallet device is genuine and take a good look for content inside, recovery sheet paper should always be blank with space for 24 seed words.
Box for
Ledger Nano S box is containing a wallet, cable, 3 paper cards, Getting started card, Did you notice card with blank Recovery sheets; keychain and a lanyard:
Box for
Ledger Nano X box is containing a wallet, cable, 5 paper cards, Getting started card, Use, Care and Regulatory Statement; blank Recovery sheets, keychain and stickers:
You can also
Check hardware integrity but last time I checked images of PCB boards on website, they didn't match the latest update and state on actual hardware device.
Trezor packaged their hardware wallets in such way that you must destroy the box to open it and use Trezor device, so it's very hard for scammers to repack and resale it, unless they make their own boxes.
Trezor packaging timeline is showing evolution of their boxes and they tried with various holographic seals that scammers easily made fake and sold as original, and In 2018 Trezor wrote an
article to address fake devices and packages
Trezor Model One is containing the wallet, cable, 2 Recovery seed cards and stickers:
Trezor Model T Box is containing the wallet, magnetic dock, cable, 2 Recovery seed cards and stickers:
You can check
Unboxing page and
Tamper-evident hologram to avoid fake devices.
If you have any doubt with hardware wallet you purchased, directly contact wallet manufacturers support and ask them to confirm if device is authentic.
ColdCard wallet is using several supply chain protections, like tamper-evident plastic bag with unique number matching the number onsecure element, they have clear plastic case and inside is filled with eopxy material that makes it much harder or remove chips and change anything inside.
Example of FAKE hardware wallet devices:
-
Ledger fake device Warning!