TL;DR
A supply chain attack targets the device before it reaches you, or tricks you with a fake one. The defences are simple: buy from the maker (or Amazon itself, or an authorised reseller), run the authenticity check, and always let the device create its own seed.
What these attacks look like
- Pre-seeded device: a wallet arrives already set up, with a recovery card filled in. The seller keeps a copy of the words.
- Tampered hardware: a device opened and modified on the way, for example by a marketplace seller.
- Fake replacement: after Ledger’s customer database leaked in 2020, some customers received tampered devices by post in 2021, with a letter saying their old one was unsafe.
- Fake apps: counterfeit versions of wallet software pushed through search ads.
How to protect yourself
- Buy from the maker’s own shop, Amazon itself (sold and shipped by Amazon) or an authorised reseller. The maker’s shop is safest
- Do the tamper check and the maker’s authenticity check
- Always create a new seed on the device. Never use words that came in the box
- Ignore unsolicited devices, letters and emails, however official they look
- Download apps only from addresses you type yourself, and verify them
Why multisig helps
Three devices from three makers, bought separately, means an attacker would have to compromise two unrelated supply chains to get a useful result.
Related: secure elements · where to buy (step 1)