Malicious Firmware Address Hijacking Scam: Tampered Hardware Wallets Hide Backdoors to Steal Funds via Modified Receiving Addresses
Victims are predominantly new cryptocurrency investors who bought into the idea that hardware wallets are the safest method for self-custody of assets, yet lack a deep understanding of device underlying firmware and signing mechanisms. Such individuals typically search e-commerce platforms for discounted or low-priced hardware wallets to save costs, lacking the ability to vet store qualifications and reviews. Driven by an intense psychological desire to protect their crypto assets, they remain completely unaware that the security device they purchased is itself a compromised trap. Upon initial activation and entry of the seed phrase, not only is the seed phrase stolen, but receiving addresses are secretly altered during transfers, causing their assets to plummet to zero instantly.
Key Fields
FIELD STAMPSWho Gets Targeted
Victims are predominantly new cryptocurrency investors who bought into the idea that hardware wallets are the safest method for self-custody of assets, yet lack a deep understanding of device underlying firmware and signing mechanisms. Such individuals typically search e-commerce platforms for discounted or low-priced hardware wallets to save costs, lacking the ability to vet store qualifications and reviews. Driven by an intense psychological desire to protect their crypto assets, they remain completely unaware that the security device they purchased is itself a compromised trap. Upon initial activation and entry of the seed phrase, not only is the seed phrase stolen, but receiving addresses are secretly altered during transfers, causing their assets to plummet to zero instantly.
骗局怎么运作
- Attackers open stores on major comprehensive e-commerce or second-hand trading platforms, selling well-known brand crypto hardware wallets at prices 20% to 30% below official retail guidance, claiming they are overseas purchasing agents or clearance stock. These stores often manufacture a facade of high reputation through fake transaction boosting to attract price-sensitive novice buyers. Upon placing an order, buyers receive a device with intact outer packaging that has actually been unsealed and injected with tampered firmware.
- Attackers professionally disassemble or directly counterfeit original hardware wallets, flashing them with modified malicious firmware. The firmware appears to run normally on the surface, featuring a user interface and setup flow nearly identical to official devices, but conceals a covert backdoor code in its underlying logic. When the user performs the initial operation to generate or import a seed phrase, the device secretly records the plaintext seed phrase in secure storage, awaiting network synchronization to transmit it.
- When victims receive the device, they complete seed phrase generation under the guidance of the malicious firmware. Some advanced firmware even pre-sets an already generated seed phrase and includes a forged scratch-off factory seed card inside the packaging, tricking users into directly using the pre-configured seed phrase. Because this set of words is already controlled by the attacker, as soon as the user transfers funds into the wallet, the assets fall entirely under the attacker's control.
- During subsequent transfer operations by the user, the malicious firmware executes an address hijacking attack. Although the device screen displays the correct receiving address entered or scanned by the user, the actual transaction data signed at the underlying level secretly replaces the destination with a malicious address controlled by the attacker. After verifying that the screen matches their intent, the user confirms the signature, causing funds to be sent directly into the attacker's pocket.
- Sometimes the tampered firmware is bundled with modifications to the official desktop bridge software configuration or accompanied by driver CDs containing viruses. When the user connects the hardware wallet to a computer, the compromised companion software not only assists the firmware in completing the encrypted upload of seed phrase data, but also monitors the user's system clipboard in the background, replacing any detected cryptocurrency address instantly to further increase the risk of address hijacking and asset theft.
红旗信号(看到这些快跑)
- 🚩 The purchase price is significantly lower than the official channel guidance price. For example, a well-known hardware wallet officially retailing for nearly 1,000 yuan is sold on an e-commerce store for only 300 to 400 yuan, and the seller cannot provide official authorized sales credentials or legitimate proof of procurement channels.
- 🚩 The outer packaging of the received device shows subtle traces of re-sealing, anti-counterfeiting labels may be forged or show signs of secondary pasting, and accessories inside the packaging—such as data cables or instruction manuals—feature rough textures with color variations in printed fonts compared to official versions.
- 🚩 When the device is powered on for the first time, the setup flow differs from official tutorials, such as forcing the user to use a pre-set seed phrase provided on an included card instead of generating a brand new seed phrase randomly on the device via a trusted random number generator.
- 🚩 When the user attempts to verify device firmware through official status-checking pages or official software, the device fails official firmware-signing security verifications, or the software interface displays warning alerts indicating the device may have been tampered with or the firmware version is unrecognizable.
- 🚩 During transfer testing, even after carefully verifying the receiving address on the device screen, assets from a small test transfer fail to reach the target destination correctly, or the actual receiving address displayed on the block explorer completely differs from the address entered by the user.
真实案例
- According to security media reports such as BlockWeeks, hardware wallet supply chain attack cases involve bad actors selling tampered hardware wallets through e-commerce channels. After users import or generate seed phrases for the first time, backdoors embedded in the firmware cause seed phrases to be silently sent to attacker servers upon computer connection, leading to massive cryptocurrency theft with victims having no recourse afterward. (Source: [https://blockweeks.com/article/149781](https://blockweeks.com/article/149781))
- According to security news platform Security KER, in a major incident dubbed the shattering of the cold storage myth, the source of attack for victims stemmed precisely from using unverified hardware wallet devices. Investigations revealed that the device firmware was not the official original version, but had been tampered with when purchased through non-standard channels, causing generated seed phrases to be in a predictable state, ultimately resulting in over 100 million yuan worth of Bitcoin evaporating overnight.
- According to a report cited by the Internet Data Research Information Center from Galaxy Research, throughout 2026, malicious tampering and backdoor implantation in hardware wallet firmware resulted in asset theft across 4,585 independent addresses, with total losses reaching 88.6 million dollars. This data highlights systemic risks stemming from unreliable device sources, with address-hijacking firmware tampering accounting for a considerable proportion. (Source: [https://www.199it.com/archives/1843489.html](https://www.199it.com/archives/1843489.html))
- In June 2025, blockchain security firm SlowMist disclosed a hardware wallet supply chain theft incident: a user purchased a tampered Ledger cold wallet on the Douyin platform, with private keys suspected of being stolen during wallet initialization, and approximately 50 million yuan in crypto assets transferred away via the Huiwang platform. SlowMist reminded users to ensure they purchase cold wallets only through official, legitimate channels. (Source: [https://news.qq.com/rain/a/20250614A04RY500](https://news.qq.com/rain/a/20250614A04RY500))
- In July 2025, BlockTempo reported a hardware wallet supply chain theft incident: a user purchased an imToken cold wallet advertised as an official genuine product on the JD.com platform for 618 yuan, and 4.35 deposited BTC were transferred away in batches by hackers within two hours, totaling over 510,000 dollars in losses. On-chain tracking indicated hackers had acquired the seed phrase or private key even before the wallet reached the user's hands. (Source: [https://www.blocktempo.com/cold-wallet-supply-chain-scam-jd/](https://www.blocktempo.com/cold-wallet-supply-chain-scam-jd/))
Official Stance
- Hardware wallet manufacturers have repeatedly issued phishing and hardware security warnings, explicitly pointing out that devices purchased through unofficial channels carry the risk of compromised firmware, and warning users never to buy hardware wallets from unauthorized e-commerce platforms or individual sellers.
- The Internet Data Research Information Center issued an early warning in 2026 noting a surge in losses caused by hardware wallet vulnerabilities, and security agencies strongly advise users to purchase devices directly from official brand websites or strictly certified retailers to avoid complex supply chain tampering risks.
- Blockchain security organizations warned in a special feature titled "Hardware Wallet Supply Chain Attack Cases and Prevention" that numerous crypto asset loss incidents in recent years stem from devices pre-embedded with malicious firmware or network communication backdoors, explicitly emphasizing never to trust brand-new unsealed devices sold on second-hand platforms or low-cost agency-purchasing channels.
How to Protect Yourself
- ✅ Purchase devices exclusively through hardware wallet brand official websites, official flagship stores, or offline regular retail channels with explicit official authorization, rejecting ultra-low-priced goods backed by any excuses such as low-cost proxy purchasing, customs-seized items, or second-hand brand-new unsealed units.
- ✅ Inspect outer packaging anti-counterfeiting seals and shrink-wrap integrity carefully upon receiving the device. During power-on initialization, avoid using any pre-configured seed phrases under any circumstances, and enforce generating a brand-new seed phrase directly on the device while securing it offline physically.
- ✅ When installing companion computer software or mobile apps, be sure to download the latest version client directly from the official hardware wallet website, strictly prohibiting the use of installation CDs or unknown drivers that may be included inside the device packaging box.
- ✅ Perform a small test transfer before executing your first large-scale transfer. Transfer a tiny amount of assets first, and attempt to send them out to another wallet to verify whether the receiving address matches. Proceed with large-scale operations only after confirming funds can move in and out normally.