The device arrived looking perfect: retail box, shrink wrap, and — helpfully — a card with the recovery words already filled in, "for your convenience". Buyers who funded wallets from those pre-initialised devices, sold through marketplace resellers in the scam wave of 2017 and 2018, watched their coins swept within hours: whoever wrote the words on the card had kept a copy, and a seed known to anyone else is not yours. No cryptography was broken. The attack was a piece of stationery and the reasonable-sounding assumption that hardware ships ready to use. A genuine signing device never ships with a seed — generating one, on the device, in your own hands, is the entire point of buying it.
Be precise about what the gadget is for. A hardware signer exists to keep private keys off internet-connected, general-purpose computers — machines that run browsers, mail clients and whatever came with the last download. The keys are generated on the device, never leave it, and every spend is signed inside it, with the details shown on its own small screen so malware on the laptop can neither read the keys nor quietly swap the destination address. That is the whole job. It is a wall against remote attackers — and the rest of this module is about the ways a wall can be delivered to you pre-breached.
Choose along one axis before all others: verifiability. Open-source firmware means the code that touches your keys can be read by anyone; reproducible builds mean independent parties can compile that source and confirm the shipped binary matches it, closing the gap between "the code we published" and "the code on your device". Ken Thompson showed in 1984 that you cannot fully trust code you did not create — reproducible builds are the practical ceiling on how close a consumer can get. Prefer devices that show full transaction details on their own screen, support dice-roll entropy so you can contribute randomness the vendor cannot fake, and run bitcoin-only firmware: every extra coin and feature is attack surface that has nothing to do with your savings.
The purchase is part of the threat model. Buy directly from the manufacturer, never from marketplace resellers, however reputable the platform looks — the pre-filled seed card was only the crudest of the reseller games; tampered firmware and swapped devices are the subtler ones. Treat tamper seals as theatre: a sticker proves nothing a competent adversary cannot reproduce. The real integrity checks are the ones cryptography can back — verify the firmware signature against the vendor's published key on first boot and on every update, and initialise the device yourself, from scratch, generating a fresh seed with your own entropy mixed in. Anything the box "helpfully" did for you, undo.
The vendor itself is in your threat model, twice over. First, its code: firmware updates are a standing channel into the device, which is why signature checks and reproducible builds matter on every update, not just the first. Second, its database: Ledger's 2020 breach leaked no keys at all — "just" the names, home addresses and phone numbers of some 272,000 customers, which promptly became a targeting map for years of phishing and worse. Minimise what the vendor knows: a collection point or PO box instead of your home address, an email alias instead of your main account, and no real phone number if the form allows it. Where you live is a secret worth keeping from anyone who knows you hold bitcoin.
Finally, keep the device in its place. It is a tool, not a talisman: it does not protect you from phishing that persuades you to type your seed into a website, from a backup you never tested, or from its own vendor's mistakes — the Cipher School's entropy module documents an air-gapped, security-first device whose broken randomness cost users over a thousand BTC without a single device being touched. The defences there are the ones already named: your own dice entropy at generation, verification against a second offline implementation, and — the subject of the next module — a seed backup that would survive the device, the vendor, and the house.
INTERACTIVE · THE BACKUP DRILL
STEP 1 / 7Put the drill in order.
Tap the steps in the order the wipe-and-recover drill actually runs. The order is the lesson.
“You can't trust code that you did not totally create yourself.”
“Given enough eyeballs, all bugs are shallow.”
READING LADDER
Climb at your own pace.
FIELD TEST · SIGN-IN REQUIRED
Take the quiz. Track the curriculum.
The module text is open to everyone: no account required to read. The 3-question field test and the curriculum-wide graduation stamp need a free account so we can record your progress.
SIGN IN TO TAKE THE QUIZFREE · NEW ACCOUNT TAKES 30 SECONDS
