If a thief gets your hardware wallet’s recovery phrase, nothing you do afterwards matters. That is why the most important security checks happen before you first press a button. On 10 October 2026, Ledger confirmed that one affected customer’s device contained “an unauthorized hardware implant” in a case where losses tied to wallets bought from a Southeast Asian reseller, CryptoBilis, have been estimated at $86–$93 million (Bitcoin.com News, 10 October 2026; the news report is here). This guide turns that case into eight checks you can run on any hardware wallet from any maker, explains what each check can and cannot catch, and scores them on the facts reported so far.

A note on scope. The facts of the case are still emerging, and this guide does not claim to know how the devices were modified. The checks below are based on the buying and verification guidance published by Ledger and Trezor, plus the desk’s own suggestions, which are labelled as such. They reduce risk; they do not remove it.

Check 1: buy from the maker or a reseller the maker lists

This is the check that matters most, because every later test is weaker than a clean supply chain. Ledger’s buying guide tells customers to buy from Ledger.com or an authorized reseller, names Fnac, Darty and Best Buy as examples, and lists resellers by region; on Amazon it says to check the “Sold by” name against the official Ledger storefront for your country because several sellers can appear under one listing (Ledger Academy). Trezor says the same in its own terms: buy from the Trezor Shop, a reseller listed on its site, or its Amazon store, and “never buy a Trezor from an unauthorized third party, as you can never tell who may have had access to it before you” (Trezor blog). The practical test: find the reseller on the maker’s own list by typing the maker’s address yourself, not by clicking a link in an ad or a search result.

Check 2: treat a low price or a second-hand unit as a red flag

A discount large enough to make you hesitate is information. So is any unit that has been used, “opened once” or resold. The desk’s suggestion is to rule out second-hand hardware wallets entirely for a store of value: the saving is a few tens of dollars, and the downside is the whole balance.

Check 3: inspect the packaging and seals

Ledger says that if a package looks opened, altered or compromised you should not use the device and should contact support. Trezor describes model-specific protections: holographic seals over the USB-C connector on the Safe 3, Safe 5, Safe 7 and Model T, a protective screen sticker on the Safe 7, and a box sealed with two holographic stickers on the Model One (Trezor support, is my device safe to use). Compare your box with the maker’s own pictures. Limit of this check: seals and boxes can be replaced by a careful attacker, and packaging is sometimes dented in transit, so it can raise suspicion but it cannot give assurance.

The video above, from the channel BTC Sessions and uploaded on 9 October 2026, discusses the first day of the Ledger story among other topics. It predates Ledger’s Saturday confirmation and is commentary rather than a source for the facts in this guide.

Check 4: the device must arrive blank

A genuine device does not come with a recovery phrase, a PIN or a card with words already printed. Ledger says that if you find a pre-set phrase or PIN, or setup instructions containing one, you should not use that phrase, not send crypto to any account it generates and not use the device. Trezor says its devices ship without firmware and that if firmware is already installed the device should not be used (Trezor support). Ledger also says it does not send replacement devices unsolicited. Decrypt’s explanation of one possible attack in the CryptoBilis case is exactly this: a device shipped with a recovery phrase the attacker already knows (Decrypt). Be careful with the wording, though: CoinDesk notes there is no confirmation that pre-generated phrases caused the losses (CoinDesk). The Bitcoin.com News report describes a different mechanism, a hidden circuit that could capture the phrase as the device shows it. Check 4 would catch the first mechanism and not the second.

Check 5: run the maker’s authenticity test, and know its limit

Both major makers provide one. Ledger Wallet runs a Genuine Check during setup: the app sends a challenge and the device’s secure element answers with a signature that is verified against Ledger’s servers. Trezor devices ship without firmware; the bootloader verifies the firmware signature on every connection, and Trezor Suite accepts the device only if the firmware is signed by SatoshiLabs; unofficial firmware triggers a warning on the screen. Run the test on your own computer, with the app downloaded from the maker’s official site or an official app store.

The limit is stated by Ledger itself: its Genuine Check cannot detect unauthorized physical modifications if the original secure element is intact, and it cannot verify a device’s supply-chain history (Ledger Academy). That sentence is the heart of the CryptoBilis case. If the reported implant sits beside a genuine secure element, passing the test proves the chip is real, not that nothing else was added. A pass is good news; it is not a clean bill of health.

The video above is published by Trezor, a hardware-wallet maker, on 18 June 2025; it describes that company’s own authenticity checks and is shown as a manufacturer’s explanation, not independent testing.

Check 6: watch the seed and the setup (the desk’s suggestion)

Generate the recovery phrase on the device, write it only on the backup card or your own offline medium and never type it into a computer, phone or website; Ledger repeats that anything prompting for it is a scam. Then add a habit the makers do not require but that costs little: set up the wallet, wipe it, and set it up again so the final phrase is the second one generated. This does nothing against an implant that records whatever phrase is shown, and it cannot defeat firmware that fakes its randomness, but it defeats the simplest form of a pre-loaded phrase, a card or setup screen that simply hands you words. Also compare the word count with the maker’s documentation: Trezor, for example, lists 12, 20 or 24 words depending on the model, and says a SLIP39 backup showing 65 words instead of 20 indicates a tampered or counterfeit device (Trezor blog).

Check 7: test small, restore elsewhere, then move the balance (the desk’s suggestion)

Before depositing a serious amount, send a small test sum to the device’s first address. Then restore the same recovery phrase into a different, independent wallet program or a second device from another purchase, and confirm that it shows the same addresses and balance. This verifies that the phrase you wrote down really is the one controlling your coins. It does not detect an implant that has already copied the phrase, but it catches a whole class of errors and some counterfeits. Stage the balance: small first, large only after a waiting period during which you leave the test sum untouched. The desk’s Field Guide #51 covers the exchange-withdrawal side of this process.

Check 8: do not let one device be the single point of failure

A clean purchase and a passed test are probabilities, not guarantees. The structural defence is to design so that one compromised device is not fatal. In a multisignature setup the wallet requires two or three signatures from different devices, so an attacker who has compromised one unit still cannot move the coins. Using devices from different makers, bought from different sellers at different times, makes a single supply-chain attack much less likely to reach every key. Multisig adds complexity and has its own failure modes, so it fits larger balances better than small ones; the desk’s self-custody playbook with multisig explains the trade-offs, and how random is your seed covers the generation side.

Scoring the checks on the reported case

CheckWould it catch a pre-loaded recovery phrase?Would it catch a hidden circuit that captures the phrase?Main limit
1. Buy from maker or listed resellerYes, by avoiding the channelYes, by avoiding the channelYou must verify the reseller yourself; whether CryptoBilis was on Ledger’s list is not stated in the coverage reviewed
2. No low prices, no second-handMostlyMostlyFakes can be priced normally
3. Packaging and sealsSometimesSometimesSeals can be replaced; transit damage causes false alarms
4. Device arrives blankYesNoDoes not see hidden hardware
5. Authenticity testNot designed toNot if the real secure element is intact (Ledger’s own caveat)Cannot verify supply-chain history
6. Wipe and regenerate the seedYes, for the simple versionNoAn implant may record the new phrase
7. Small test and independent restorePartlyNoCannot detect a copied phrase
8. Multisig, mixed vendorsYes, one device is not enoughYes, one device is not enoughMore complex to run and recover

Two lessons stand out. First, the checks that depend on the buyer’s own testing (4 to 7) are strongest against the pre-loaded-phrase mechanism and weakest against a hardware implant, which is why Checks 1 and 8, provenance and structure, carry the most weight. Second, none of this makes hardware wallets a bad idea. Ledger says it has sold more than 7 million devices (CoinDesk), and the reported thefts are tied to one reseller’s units. The right conclusion is to treat the purchase as part of the security model.

If you already bought from CryptoBilis or from a seller you cannot verify

  • Do not set up the device if you have not already; Ledger’s advice to CryptoBilis buyers of the past 90 days.
  • If you have set it up, Ledger says to consider moving your assets to a new signer with a new seed. Buy the new device from the maker or a listed reseller, set it up on a clean computer and follow the order of operations in the desk’s migration guide.
  • Ignore anyone who contacts you first. Ledger will never ask for your 24-word phrase. Impersonation emails commonly follow stories like this one.
  • Report it. Ledger has invited anyone with relevant information to contact its bounty programme and says it is cooperating with authorities, according to Bitcoin.com News.

Sources: Ledger Academy, best practices to securely buy a Ledger signer; Trezor blog and Trezor support, device authenticity pages; Bitcoin.com News (10 October 2026); CoinDesk and Decrypt (9 October 2026). Checks 6 and 7 and the multisig recommendation are this desk’s suggestions, not manufacturer instructions. This guide is educational and does not replace the maker’s current instructions for your model.

Disclaimer: This article is for informational purposes only and does not constitute investment advice. Bitcoin and other cryptocurrencies are volatile and you can lose some or all of the money you put in. Nothing here is a recommendation to buy, sell or hold bitcoin, any exchange-traded fund, any listed security or any other asset, and the technical levels, probabilities and scenarios discussed are descriptions of published data, not forecasts. Do your own research and consult a licensed financial advisor before making investment decisions.