It's when thieves tamper with something you trust before it reaches you: a wallet update, a hardware wallet from a reseller, or code a website borrows from another company. Protect yourself by getting wallets straight from the maker and checking the whole address on your hardware wallet's screen before you send.
Go deeperApps, websites, and devices are built from parts made by other companies. Break into one part, and everyone who uses it gets the bad version, even through an official store. In December 2025, thieves used a stolen publishing key to push a fake update of Trust Wallet's Chrome extension that drained about $8.5 million from about 2,500 wallets. In July 2026, a hacked ad script from Adform, running on ordinary websites, swapped Bitcoin addresses people copied for the thief's. In 2023, Kaspersky examined a counterfeit Trezor bought from an online reseller: its chip and firmware had been swapped so the thieves could guess its seed words. In October 2026, Ledger began investigating drained wallets among people in Southeast Asia who bought its devices from one reseller, with analysts estimating losses above $70 million. Ledger said devices bought directly from it weren't affected, had the reseller stop selling, and told those buyers to move their funds to a new device with new seed words. The cause was still under investigation. To protect yourself, buy hardware wallets straight from the maker, never used, and run the device's authenticity check. If a device arrives with seed words already filled in, don't use it. Install wallet apps only from a link on the maker's own site. Keep savings on a hardware wallet, which keeps your keys off your computer. Read the whole address on the device's screen before you approve, since some malware picks a look-alike address. Advanced users can verify downloads: Bitcoin Core releases are rebuilt and signed by many independent developers, so anyone can check them.
Last checked Oct 9, 2026