Tampered Hardware Wallet Backdoor Scam: E-commerce Platforms Selling Modified Cold Wallets with Hidden Data-Stealing Modules
The primary victims are high-net-worth investors holding significant crypto assets and newcomers to the space. While they generally possess basic security awareness—knowing that hardware wallets should be used to store private keys offline—they lack knowledge of hardware supply chain attacks and hold a naive belief that cold wallets are inherently secure. When purchasing, they tend to search for the lowest prices on e-commerce platforms rather than buying from official channels. Upon receiving the device, they rarely inspect internal components and remain unalert to anomalies like pre-installed firmware or pre-set recovery phrases, ultimately transferring assets into wallet addresses already controlled by scammers.
Key Fields
FIELD STAMPSWho Gets Targeted
The primary victims are high-net-worth investors holding significant crypto assets and newcomers to the space. While they generally possess basic security awareness—knowing that hardware wallets should be used to store private keys offline—they lack knowledge of hardware supply chain attacks and hold a naive belief that cold wallets are inherently secure. When purchasing, they tend to search for the lowest prices on e-commerce platforms rather than buying from official channels. Upon receiving the device, they rarely inspect internal components and remain unalert to anomalies like pre-installed firmware or pre-set recovery phrases, ultimately transferring assets into wallet addresses already controlled by scammers.
骗局怎么运作
- Scammers open shops on mainstream e-commerce platforms, listing well-known hardware wallets like Ledger or Trezor at 30% to 50% below official prices. These shops often use fake reviews to build credibility and leverage social media to drive traffic, claiming the low prices are due to customs seizures, factory overstock, or overseas purchasing agents.
- One tampering method involves secretly embedding an ultra-thin 4G modem module between the device casing and the circuit board. This module activates automatically when powered on, silently transmitting the user's recovery phrase via encrypted SMS to a server controlled by the scammer. The user remains unaware, as the device looks identical to a genuine one, making detection difficult.
- A second method involves modifying the device firmware before sale, forcing the random number generator to select seeds from a limited pool of pre-set values rather than using a true secure random source. Scammers can easily derive all recovery phrase combinations from these known parameters and drain the funds as soon as the user transfers assets to the wallet.
- A third method involves pre-setting a recovery phrase on the device at the factory and including a fake 'Quick Start Guide' that instructs the user to restore the wallet using the pre-set phrase instead of generating a new one. Since the private keys for these pre-set phrases are held by the scammers, the user effectively hands over their assets the moment they deposit funds.
- Some advanced tampered versions include a delayed transfer script. After the user deposits a large amount and a set time passes, the script automatically transfers all assets to a scammer-controlled address. This method is highly covert, as the delay prevents triggering alerts during small initial tests, ensuring the victim only realizes the theft after depositing significant capital.
- Once funds are obtained, scammers use mixers, cross-chain bridges, and privacy coins to launder the money, increasing the difficulty of on-chain tracking. E-commerce shops often close after accumulating a certain number of victim orders, only to open new ones elsewhere, creating a cycle of fraud enabled by platform regulatory lag.
红旗信号(看到这些快跑)
- 🚩 Prices are significantly lower than official brand channels (30% to 50% discount), and the seller cannot provide official authorization proof.
- 🚩 The packaging lacks anti-counterfeiting stickers or QR codes that fail to verify on the official brand website, or the print quality is noticeably poor.
- 🚩 The device prompts the user to import an existing recovery phrase upon activation, or pre-set phrases appear, which is a classic sign of a backdoor.
- 🚩 The device feels abnormally light, the ports are poorly finished, the casing seams are uneven, or there are non-original soldering marks near the USB interface.
- 🚩 Purchased from non-authorized third-party sellers where a large number of positive reviews were generated in a very short time, suggesting fake reviews.
- 🚩 The firmware version cannot be found in the brand's official code repository or technical documentation, indicating it has been modified.
真实案例
- Counterfeit Ledger with hidden 4G modem: Security researchers dismantled a suspected counterfeit Ledger purchased on an e-commerce platform and found an ultra-thin 4G modem module hidden between the casing and the circuit board. The module automatically sent recovery phrases via encrypted SMS to a remote server upon power-up. Technical analysis was disclosed by the HTX information platform, detailing the physical module and data transmission paths.
- ColdCard random number generator vulnerability: In July 2026, a critical security flaw in the ColdCard hardware signer's random number generator was exposed, causing generated recovery phrases to be non-random. Attackers could derive private keys, leading to the theft of 1,755 BTC (approx. $110 million or 743 million RMB). Security platforms like Anquanke and Odaily reported the incident, and ColdCard issued a security warning on July 30, 2026. (Source: https://www.anquanke.com/post/id/315945)
- Trezor logistics provider phishing scam: A breach at a Trezor logistics provider led to the exposure of 13,689 customers' shipping information. Scammers used this data to send fake letters claiming the user's device had a security vulnerability and required an urgent replacement, including a tampered wallet with a pre-set recovery phrase. Bitcoin News reported on this incident.
- In July 2025, TechFlow reported that a gray market for hardware wallets had formed on domestic e-commerce platforms. An investor purchased an imKey wallet from an unofficial JD.com shop, only to find it had been pre-initialized with a recovery phrase and fake instructions. The 4.35 BTC deposited was drained immediately upon activation. A similar chain of events led to the theft of 50 million RMB from a user via a Douyin channel. (Source: https://www.techflowpost.com/article/27290)
- In July 2026, three Bitcoin holders sued Apple in California, alleging the App Store allowed counterfeit Sparrow Wallet apps to thrive and receive promoted placement. One plaintiff lost 7.4 BTC (approx. $875,000) after entering their recovery phrase. Kaspersky researchers previously identified 26 scam apps in the Apple ecosystem impersonating MetaMask, Ledger, Trust Wallet, and Coinbase. (Source: https://cryptoslate.com/apples-app-store-security-promise-faces-test-as-fake-crypto-wallets-keep-getting-through/)
Official Stance
- ColdCard Security Warning (July 30, 2026): btcstudy.org reposted the official ColdCard warning regarding a seed generation vulnerability in third-generation devices, advising users to check firmware versions and assess recovery phrase security.
- Galaxy Research 2026 Hardware Wallet Security Report: The report states that hardware wallet vulnerabilities in 2026 led to $88.6 million in losses across 4,585 addresses, calling for stronger supply chain security audits and user education. Published by 199IT.
- Ledger Official Phishing Warning: Ledger and other manufacturers issued warnings regarding tampered hardware wallets and phishing emails from unofficial channels, emphasizing the importance of purchasing only through authorized vendors. Reported by HTX.
How to Protect Yourself
- ✅ Purchase hardware wallets only from official brand websites or authorized distributors. Never buy 'discounted' or 'factory overstock' units from third-party sellers at prices significantly below official rates.
- ✅ Verify the anti-counterfeiting code and firmware version on the official website immediately upon receipt. Ensure the firmware matches the latest version in the official code repository before activation.
- ✅ Inspect the packaging for signs of tampering, check if the device weight matches official specifications, and examine the port quality. If anything seems abnormal, stop using the device and contact official support.
- ✅ Never use recovery phrases pre-set on the device or provided in a 'Quick Start Guide.' Always generate a new recovery phrase on the device itself, back it up offline by hand, and ensure it never touches the internet.
- ✅ Before transferring large amounts, perform a test transfer with a very small amount to confirm that you have independent control over the recovery phrase and that deposits/withdrawals function correctly.
- https://www.htx.com/zh-tc/news/inside-a-fake-ledger-how-a-4g-modem-is-secretly-embedded-in-SDGUuCWp/
- https://www.anquanke.com/post/id/315945
- https://news.bitcoin.com/zh/security/trezor-wuliu-fuwushang-daizhi-13689-ming-jiamihuobi-kehu-zaoyu-zhapian/
- https://www.btcstudy.org/2026/08/01/coldcard-mk3-seed-generation-warning/
- https://www.199it.com/archives/1843489.html
- https://blockweeks.com/article/149781