Security alert · 30 Jul 2026: a seed-generation flaw in Coldcard devices was disclosed. What to do →

Tamper check for a new hardware wallet

Do this every time a new hardware wallet arrives, before you set it up. It takes five minutes.

  1. Check where it came from: the manufacturer’s own shop, Amazon.com itself (“Ships from and sold by Amazon.com”), or an authorised reseller listed on the manufacturer’s website. If it came from anywhere else, such as a third-party seller or a second-hand offer, send it back unopened. Buying straight from the manufacturer is the safest of these.
  2. Look at the box. Torn wrapping, reglued flaps or a damaged seal where the maker uses one are reasons to contact the maker before you continue.
  3. Look inside. A recovery card that’s already filled in, or a note telling you to use certain words, means it’s a scam. Never use words someone else chose.
  4. Connect it to your signing computer and open the maker’s own app. Let it run its authenticity check and install the latest firmware.
  5. Start the setup. The device must offer to create a new wallet. If it already has one, or asks you to restore from words that came in the box, stop.

Anyone who gives you words is stealing from you

A real hardware wallet always creates its own seed, on its own screen. Words that came with the device, from support staff, or from a “recovery service” belong to a thief.

Then continue with step 4 of the setup guide.