Hardware wallets are extremely good at what they were designed to do: keeping private keys inside a secure element and requiring physical confirmation for every signature. Almost every reported loss, therefore, happens somewhere else — in a search result, a support chat, a browser extension, a copied address, or a moment of urgency created by someone who wants you to act before you think.

This page is about that human layer. It contains no investment advice, no price discussion and no instructions that weaken a device's security.

The threat model in one paragraph

An attacker wants one of three things: your recovery phrase (which reproduces your keys anywhere), your authorisation (a signature or approval you did not understand), or your destination address (so funds go to them instead of where you intended). Everything below is a variation on obtaining one of those three things — usually by pretending to be the software, the support desk, or the recipient.

Attack patterns you should recognise

Threat How it usually appears What to do
Fake download page An advertisement or search result for wallet software that leads to a domain resembling the real one; the installer is modified Type the developer's domain by hand; verify the checksum against the published signature page before running anything
Fake support desk A "support" account in a chat, forum or social network offering to help, then asking for your recovery phrase or remote access Stop. No legitimate support process needs either. Report and block
Malicious browser extension An extension that reads or rewrites pages, swaps copied addresses, or injects wallet-related prompts Keep extensions to a minimum; check permissions; remove anything you do not recognise
Address-swapping malware Clipboard malware that replaces a copied destination address with the attacker's Verify the first and last characters of every address on the device screen before confirming
Fake wallet application A look-alike application in a store or an unofficial download site that asks for a recovery phrase during "setup" Genuine hardware-wallet software never asks for a recovery phrase. Delete and re-download from the official source
Recovery-phrase phishing A page, email, pop-up or form claiming that a "security update" or "migration" requires your recovery words Never enter recovery words anywhere except the device itself, and only during initial setup or recovery
Remote-support software A convincing "technician" asking you to install remote-access software so they can "fix" the wallet Never install remote-access tools at the request of an unsolicited contact
Fake transaction confirmation A prompt showing a benign description while the underlying transaction does something else Read the details on the device screen; if they differ from what you expected, reject
Urgency and authority Messages announcing an account freeze, a hack in progress, a mandatory migration or a limited-time security fix Legitimate security processes do not need you to hurry. Slow down; verify out of band
Malicious installer "helpers" A download page that first offers a "downloader", "accelerator" or "driver" Never install a helper to obtain an installer

Phishing and fake download pages

Phishing against wallet users is rarely crude. Expect correct branding, plausible copy, a padlock in the address bar, and even a working help section. What a fake page cannot easily fake is the domain and the file checksum.

  • Read the domain from right to left, character by character. wallet-example.com and wallet.example-secure.com are not the same site as example.com.
  • Treat advertisement placements as untrusted, even on search engines. Purchased placement is a delivery mechanism, not a recommendation.
  • Never install a "downloader" offered by a page. Legitimate distribution serves the file itself.
  • Verify the downloaded file against the developer's published signatures page. This is the step that converts "the page looked right" into evidence.

The full verification workflow, including the exact commands for Windows and macOS, is in recognising fake downloads.

Fake support representatives

A convincing support scam follows a script: they contact you first (or reply unusually fast), they use the product's vocabulary, they offer to "check your wallet", and they eventually need either your recovery phrase, a remote connection to your computer, or a "verification transfer".

A legitimate support process never requires these

No genuine support process needs your Secret Recovery Phrase, your private keys, your PIN, or a payment to an address for verification. It does not need remote access to your computer, and it does not need you to install a screensharing tool. Ledger's own support pages state plainly that they will never ask for the 24 words of your recovery phrase. Any request for them is the attack itself.

If you are the one who initiates contact, use the developer's own support site — reached by typing the domain — rather than a phone number or handle found in a search result, an advertisement or a reply to your post.

Browser extensions and your clipboard

Extensions run with the permissions you grant them, and a wallet-adjacent extension is a tempting target for a takeover. Practical hygiene:

  • Keep the number of extensions small, and remove anything you cannot name a use for.
  • Review permissions after updates; a "theme" extension does not need to read and change all your data on all sites.
  • Never install an extension that offers to "verify", "sync" or "recover" a wallet.
  • Verify addresses on the device screen, because clipboard contents are exactly what address-swapping malware targets.

Fake applications and modified installers

Repackaged wallet software exists for every popular wallet, and it usually behaves normally until it asks for a recovery phrase during "setup" or "restoration". Two habits neutralise this entire category:

  1. Install only from the developer's official source, verified by checksum.
  2. Never type a recovery phrase into software. It belongs on the device, and nowhere else.

Recovery-phrase theft: the one irreversible mistake

A recovery phrase is a complete, portable copy of your keys. Anyone who obtains it can restore your accounts on their own device and move everything, and no support desk, exchange, police report or recovery service can reverse that.

  • Store it offline, on paper or metal, in more than one physical location.
  • Never photograph it, never store it in a password manager, a cloud note, an email draft or a chat message.
  • Never type it into a computer, a website, a form, an installer or a "verification" page.
  • If a service offers to "check" or "validate" your phrase, the offer itself is the crime.
  • If you believe it has been exposed, treat the affected accounts as compromised and act on the assumption that they will be emptied — seek guidance from the developer's official support channel immediately.

Fake transaction confirmations and address swapping

Malware can alter what your computer shows without altering what the device signs. The device screen is the only reliable display of the transaction you are actually authorising. Before confirming:

  • Compare the recipient address on the device with the one you intended to pay — at minimum the first and last several characters.
  • Compare the amount and the network or asset.
  • If you did not initiate the transaction, or the details differ, reject it on the device.
The two habits that prevent most losses

Verify the file, then verify the address. Check the checksum of every installer before running it, and check the recipient on the device screen before signing. Almost every publicised loss involves one of these two checks being skipped under time pressure.

Remote-support and screensharing scams

An unsolicited "technician" who wants to see your screen is running the oldest play in the book. Remote-access software gives a stranger your keyboard. A wallet owner should never grant that access — no wallet problem is solved by letting an unknown person operate your computer.

If you have already installed remote-support software at someone's request: disconnect the computer from the internet, uninstall the software, move any significant holdings to a fresh account created on a device whose recovery phrase has never been typed into that computer, and review your accounts for unauthorised activity.

If you think you have been targeted

Stop interacting immediately

Close the chat, the pop-up and the page. Do not "prove" anything to anyone, and do not send funds to demonstrate that you are the owner.

Do not enter your recovery phrase, even to "check" it

There is no legitimate service that needs it, and entering it converts an attempt into a loss.

Disconnect and clean the machine if you installed something

Remove remote-access tools and unfamiliar extensions, run a full scan with your existing security software, and consider whether the computer should be trusted for wallet operations at all.

Move value to a newly created account if a phrase may have been exposed

Create a new account on the device (which produces a new phrase only if you reset and re-initialise it — follow the developer's official guidance), and transfer holdings there before the attacker acts.

Report through official channels

Use the developer's official support site and their published phishing-reporting process. Do not report through a chat account that contacted you first.

Record what happened

Note the domain, the handle, the file name and the checksum if you have them. This helps the vendor warn other users.

Red-flag checklist

Security red flags

Ticks are stored only in this browser, on your device, and are never transmitted to us.

Any single tick is worth acting on. Ticks on the first five mean you are very likely the target of an active attempt.