July 2020. A breach of Ledger's e-commerce and marketing systems exposed roughly 272,000 postal addresses and phone numbers, along with more than a million email addresses.
No keys. No funds. The wallets are non-custodial and the private keys were never on Ledger's servers, and that is worth saying plainly because this incident is constantly misdescribed.
What leaked was a list of people's home addresses, annotated with the fact that they own a hardware wallet.
May 2021. Criminals used that list to mail counterfeit Nano devices to customers' homes.
The packages were shrink-wrapped. Sealed bags carrying the Ledger logo. A letter on convincing letterhead explaining that the recipient's existing device had to be replaced for security reasons.
Inside the counterfeit unit: a flash drive, soldered in. The instructions directed the victim to enter their existing recovery phrase into it.
Now read what that defeats. Every tamper-evident signal a buyer is taught to check was present, and every one of them had been manufactured. The seal was intact. The packaging was branded. The letter was plausible. The address was correct, because it came from a real leak.
Provenance cannot be established by inspecting an object. It can only be established by controlling where the object came from.
The setup is a ceremony, and it is one of the few moments in self-custody where doing it right once removes a whole category of risk permanently. It takes about thirty minutes. Most people spend five.
Before the box: provenance
Buy direct from the manufacturer. Their own site, reached by typing the address yourself per F111-04, not from a search result and not from a link.
Not a marketplace. Not Amazon, not eBay, not a reseller, even one that appears to be the manufacturer's own storefront, because those listings are fungible and the fulfilment path is not one you control. A pre-configured device is trivially cheap to produce and indistinguishable from a new one until your funds move.
Never a device somebody sent you. The autopsy is the whole argument. A device arriving unsolicited is hostile, without exception, regardless of what the letter says.
Never a gift or a hand-me-down, unless you personally watch it being wiped and reinitialised, and even then you are trusting the firmware.
The uncomfortable implication of the 2020 breach is that buying direct also means giving a company your home address, which F106-04 tells you becomes a target list when it leaks. Use a delivery address that is not your home if that matters in your threat model, and understand that you are choosing between two real exposures rather than avoiding one.
It is not useless, and it is nowhere near as strong as it feels.
Seals, shrink wrap and holographic stickers all exist in the counterfeit supply chain, because they are ordinary manufactured goods. The devices mailed to Ledger customers had all of them.
What actually protects you is different and stronger: the device generates the seed itself, in front of you, and only you ever see it. That is a property of the procedure, not of the packaging, and it does not care whether the box was opened before it reached you.
If the device generates a fresh seed during your setup and you are the only party who has ever seen those words, then even a device that passed through hostile hands can only be running hostile firmware, which is a real risk and a much smaller one than a pre-seeded device.
The setup
1. Initialise the device yourself. Set it up from scratch. If it powers on already configured, or asks you to confirm a wallet that already exists, stop and contact the manufacturer through their site.
2. Set a PIN nobody could guess. Not a birthday, not a repeated digit. It protects against physical theft and it is the only thing standing between a thief and an unlocked device.
3. Let the device generate the seed. This is the load-bearing step, and F103-01 explains why: the entropy at the top caps everything below it. A dedicated device with a hardware random number generator is doing this better than you can arrange otherwise.
4. Write the words down, on paper, now. Paper is fine at this stage. Metal is F104-04, and doing that properly takes time you should not spend with the device sitting mid-setup.
5. Confirm the phrase on the device. It will ask you to re-enter some words. This is not bureaucracy. It is the only check that what you wrote matches what the device holds, and it catches the transcription error that would otherwise surface in five years.
6. Decide on a passphrase, deliberately. F103-02 covered it. Adding one means a second unrecoverable secret, backed up with equal discipline in a different place. If you cannot commit to that today, do not add one today.
7. Install the companion software from the manufacturer's site, typed by you. This is the course autopsy: a fake companion application in an official app store drained about $9.5M from fifty people who all owned working hardware wallets.
8. Update firmware through the official application. New devices ship with old firmware, and updates fix real problems.
The two instructions that mean hostile
Everything above compresses into two red lines, and both are absolute.
"Here is your recovery phrase." On a card, in the box, in a letter, in an email, printed anywhere. Real setup never supplies a seed, because a seed that existed before your setup has been seen by whoever created it.
"Enter your existing recovery phrase into this new device." This is the counterfeit-mailing script verbatim, and it is also the fake application in the course autopsy. Legitimate restoration exists, and you initiate it, on a device you bought, from a backup you wrote. Nobody contacts you to prompt it.
The direction is the tell. Real setup goes device to you: the screen shows words, you write them down. Every attack goes you to device: something asks you to type words in.
Verify before you fund
The final step, and the one everybody skips.
Send a small amount. Confirm it arrives and appears on the device.
Then wipe the device and restore it from your written backup. Confirm the same address returns and the funds are visible.
That second half is the whole point. Until you have restored from the backup, you have a device that works and an untested claim that you can recover it. F103's opening survey found only 15 percent of holders had ever tested their recovery, and F104-05 is a lesson about exactly that gap.
Do it now, with a trivial amount on the device, when a failure costs you nothing.
A device that arrives sealed and unopened is safe to use.
This is the belief the counterfeit mailings were built to exploit, and it is worth understanding why it fails rather than just being told it does.
Sealing is a manufacturing capability, not a security primitive. Anybody who can produce a convincing device can produce convincing packaging, because both come from the same kind of factory. The attacker's cost of adding a seal to a fake box is close to zero.
What genuinely narrows the risk is that the seed is generated on the device during your setup and never travels. A tampered device could still run malicious firmware and generate a predictable seed, which is a real and much rarer attack, and it is exactly the F103-01 entropy failure in physical form.
The defences that work against that are provenance, buying direct, and the manufacturer's own genuineness check performed through software you obtained yourself. The defence that does not work is looking at the box, and looking at the box is the one everybody performs.
Provenance comes from controlling the source, not from inspecting the object, because seals and branded packaging are manufactured goods and counterfeit devices arrived with all of them. Buy direct, never from a marketplace, and treat any device that arrives unsolicited as hostile. Then run the ceremony so the device generates the seed and you are the only party who has ever seen it, and remember the direction that gives every attack away: real setup shows you words to write down, and every attack asks you to type words in. Finally, wipe and restore from your written backup before you fund it, because until you have done that you own a device that works and an untested claim that you can recover it.