Guides

Where to Buy a Ledger Safely (and Why Never From Amazon)

Buying a hardware wallet is a supply-chain decision. Where to buy, how to check a device is genuine, why marketplace listings are dangerous, and what to do if yours arrived from a reseller.

Where to Buy a Ledger Safely (and Why Never From Amazon)

A hardware wallet is the one purchase where the seller is part of the threat model. A tampered device - or a genuine device shipped with a pre-generated recovery phrase - is a wallet whose keys someone else already holds, waiting patiently for you to deposit.

The good news: avoiding this is easy, and the check takes one minute.

Buy direct. That is the whole rule.#

Order from the manufacturer's own online store, or from an authorised reseller listed on the manufacturer's own site. Type the URL by hand rather than searching for it - fake wallet shops buy search ads, and they look immaculate.

That is it. Everything below is why.

Why not Amazon, eBay or a marketplace#

The problem is not the platform's honesty; it is commingled inventory and anonymous third-party sellers.

  • Marketplace sellers are effectively anonymous. Anyone can list a "new, sealed" hardware wallet.
  • Amazon commingles stock. Identical items from different sellers can be pooled in the same bin, so "Sold by Amazon" does not guarantee which seller's unit ships to you.
  • Returns get resold. A device that was opened, modified and returned can go back on the shelf.
  • Counterfeits exist and are convincing. Fake units with modified firmware, and genuine units packed with a pre-filled recovery card, have both been documented repeatedly.

The saving is a few dollars. The downside is your entire balance. This is not a close call.

The unsolicited-package scam#

Ledger's 2020 customer database leak put names, emails and home addresses of likely crypto owners into public circulation. One documented follow-up: victims received unsolicited replacement devices in the post, with a plausible letter explaining that their old wallet was affected by the breach.

The devices were tampered with. The instructions walked people into entering their existing recovery phrase.

If a wallet arrives that you did not order, it is an attack. Not a gift, not a warranty replacement, not a promotion. Bin it.

Verifying a device is genuine#

Two checks, in order:

1. The box. No pre-written recovery words. No pre-set PIN. No instruction card telling you to "restore" using words provided. Ledger deliberately does not rely on holographic seals, because stickers are trivial to counterfeit - so their absence proves nothing either way.

2. The cryptographic genuine check. Connect the device and let Ledger Live run its verification. The app challenges the secure element to prove it holds a key provisioned by the manufacturer at the factory. This is the check that matters - a counterfeit cannot pass it.

Then, regardless of the result:

  • Choose Set up as new device.
  • Generate your own 24 words on the device screen.
  • If it ever asks you to enter words you did not just generate, something is wrong.

What about used devices?#

Never. Not from a friend, not from a marketplace, not "factory reset, I promise."

You cannot verify what firmware or hardware modification a previous owner left behind, and the price difference is trivial against the risk. A hardware wallet is the last thing to buy second-hand.

Should I worry about shipping and the address?#

A little, and there is a reasonable middle ground:

  • Use a work address, a parcel locker, or a pickup point if you would rather your home address not sit in a wallet company's database. The 2020 breach is the reason this is not paranoid.
  • Use a unique email alias for the purchase, so you can tell later which vendor leaked.
  • Do not tell delivery drivers, or anyone, what is in the box.

Some people pay in crypto for extra privacy. Card payment is fine too - the leak risk that matters is the address, not the payment method.

Buying accessories#

While you are there, add a steel recovery backup. Stamped or engraved steel survives the house fire that paper does not, and it is the highest-value purchase in self-custody - considerably more useful than a bigger screen.

Steel plates from third parties are fine, by the way. They contain no electronics, so there is nothing to tamper with. The supply-chain caution applies to devices, not to metal.

If you already bought from a marketplace#

Do not assume the worst, but do this before funding it:

  1. Run the genuine check in Ledger Live.
  2. Update to the current firmware.
  3. Reset the device and set it up as new, generating fresh words.
  4. Do a small test transaction and watch it settle.
  5. If anything is odd - unexpected screens, pre-written words, a device that arrived already initialised - stop and replace it.

If the amount you plan to store is significant, the safest move is simply to buy a second device direct and use that. The cost of a new device is small next to the cost of being wrong.

FAQ#

Is it safe to buy a Ledger on Amazon?#

No, and this is the near-universal recommendation from security-minded users. Third-party sellers are anonymous, inventory can be commingled, and returned units get resold. Buy direct from the manufacturer instead.

How can I tell if my Ledger is genuine?#

Run the genuine check in Ledger Live, which cryptographically verifies the secure element against the manufacturer's factory key. Physically, the box must contain no pre-written recovery phrase and no pre-set PIN.

Can a hardware wallet be tampered with before delivery?#

Yes, which is exactly why supply chain matters. The realistic attacks are a counterfeit device with modified firmware, or a genuine device supplied with a recovery phrase the attacker already knows.

Should I buy a used hardware wallet?#

Never. You cannot verify what a previous owner did to it, and the savings are trivial compared with the potential loss.

What do I do if I received a Ledger I did not order?#

Do not connect it. Unsolicited wallets have been used to attack customers whose addresses leaked in the 2020 breach. Dispose of it and, if you want, report it to the manufacturer.

Disclosure. Some links on this site may be affiliate links. If you buy through them we may earn a commission at no extra cost to you. It never changes our verdict — we say when a product is a bad fit. Vaultwise is an independent publication. We are not affiliated with, endorsed by, or sponsored by Ledger SAS, Trezor/SatoshiLabs, or any wallet manufacturer. Product names and trademarks belong to their respective owners.

Keep reading

Get the self-custody checklist

One email a month: new scam patterns, firmware notes worth reading, and the mistakes that actually cost people money. No token shilling, ever.

Replace the form action with your own Formspree / ConvertKit / Buttondown endpoint in src/layout.mjs.