Should You Buy a Used Hardware Wallet? Is a Factory Reset Safe?

 / 
1

Buying a second-hand hardware wallet is not recommended. A factory reset does not equal safety—risks of physical tampering and pre-installed backdoors are real.

Prerequisites

  • You clearly know what a seed phrase (recovery phrase) is and how it works.
  • You understand the core principle of a hardware wallet—private keys never leave the device.
  • You do not have the original proof of purchase for this device.

What a Factory Reset Can and Cannot Do

A factory reset (reset device) can clear the private keys, PIN, and binding relationships stored in the device's memory. After resetting, the device returns to a blank state; you generate a new seed phrase, and the old private keys become invalid.

However, a factory reset cannot solve two types of problems:

Physical Tampering of the Device Itself

Trezor has disclosed a vulnerability: its older Safe 3 model's microcontroller was susceptible to voltage glitching attacks. An attacker could open the device, tamper with the chip, and reseal it to extract private keys or implant malicious firmware. Although such attacks require high expertise and usually target high-value assets, the risk is real. You cannot trace the supply chain of a second-hand device—you don't know who touched, opened, or soldered it before it reached you.

Pre-installed Seed Phrases or Backdoored Firmware

SlowMist security team disclosed a real case: a user bought a cold wallet from an unofficial channel. The packaging was intact, but after opening it, the wallet guided the user to activate the device using a pre-set seed phrase, eventually leading to approximately 50 million yuan (about $7 million) worth of assets being stolen. Tangem has also explicitly warned: some third-party sellers sell "pre-activated" wallets with a "setup password"—such devices are absolutely unsafe.

Risk reminder: Ledger has explicitly stated that all new devices come with blank seed phrase cards and never come pre-filled. If a second-hand device you buy claims to be "already initialized for you" or comes with a pre-set seed phrase, it is 100% a trap. Anyone who proactively contacts you to "help check your device's security" is a scammer.

Determine If the Device Source Is Trustworthy

You cannot determine if a device has been tampered with solely by appearance, seals, or packaging. Attackers can re-seal packages, and seals can be forged.

Case A: Device from unofficial channels (personal resale, second-hand platforms, unauthorized dealers)—just give up the purchase. Multiple wallet brands and SlowMist consistently advise: buy only from the brand's official website or authorized channels. The security chain of a second-hand device is broken; you don't know what it has been through.

Case B: Device from official channels but then resold as a return or exchange. Some platforms may repackage returned devices for sale, theoretically meaning they could have been handled by someone. If the price is significantly lower than an official discount, be suspicious.

Completion standard: You can 100% confirm that the entire supply chain of this device is within a trusted scope.

If You Already Bought a Used Device, Perform Integrity Verification

Don't assume "if I unbox it, I must use it." Verify first, then decide.

Step 1: Inspect the physical appearance. Are the LED, screen, screws, and seals intact? Are there scratches or soldering marks on the USB port? Is there any sign of prying on the back of the device?

Step 2: Power on. A brand-new hardware wallet should show "Initial Setup" or "Set up as new device" on the first boot—never "Enter PIN" or display an existing seed phrase. If it boots into recovery mode or shows a wallet address, the device has been activated; stop using it immediately.

Step 3: Connect to the official management software and check firmware integrity. Some official software includes a verification step that checks whether the firmware is the latest official version.

Completion standard: No physical anomalies + Shows initial setup on boot + Passes official software verification.

How to Verify the Setup

After completing the above checks, select "Set up as new device" in the official software and let the device generate a brand-new seed phrase. Then note down the first receiving address generated, send a tiny test amount to it, and then initiate an outgoing transaction to confirm that the device can properly sign transactions. Only after both steps succeed is the device considered "safe to use."

Next steps: If any step fails, treat the device as e-waste—never deposit any assets into it. The entire verification process takes about 15-20 minutes. Verification channels: the "Device Status" page and "Firmware Version" info in the brand's official management software.