The Bitcoin Pocket GuideAsk a question
Security

What is a supply chain attack, and how do I avoid one?

Quick answer

It's when thieves tamper with something you trust before it reaches you: a wallet update, a hardware wallet from a reseller, or code a website borrows from another company. Protect yourself by getting wallets straight from the maker and checking the whole address on your hardware wallet's screen before you send.

Go deeper

Apps, websites, and devices are built from parts made by other companies. Break into one part, and everyone who uses it gets the bad version, even through an official store. In December 2025, thieves used a stolen publishing key to push a fake update of Trust Wallet's Chrome extension that drained about $8.5 million from about 2,500 wallets. In July 2026, a hacked ad script from Adform, running on ordinary websites, swapped Bitcoin addresses people copied for the thief's. In 2023, Kaspersky examined a counterfeit Trezor bought from an online reseller: its chip and firmware had been swapped so the thieves could guess its seed words. In October 2026, Ledger began investigating drained wallets among people in Southeast Asia who bought its devices from one reseller, with analysts estimating losses above $70 million. Ledger said devices bought directly from it weren't affected, had the reseller stop selling, and told those buyers to move their funds to a new device with new seed words. The cause was still under investigation. To protect yourself, buy hardware wallets straight from the maker, never used, and run the device's authenticity check. If a device arrives with seed words already filled in, don't use it. Install wallet apps only from a link on the maker's own site. Keep savings on a hardware wallet, which keeps your keys off your computer. Read the whole address on the device's screen before you approve, since some malware picks a look-alike address. Advanced users can verify downloads: Bitcoin Core releases are rebuilt and signed by many independent developers, so anyone can check them.

A supply chain attack: a thief tampers with the parts or the delivery of a wallet, so you get a bad version from a source you trust. Protect yourself: buy and download from the maker, keep savings on a hardware wallet, and check the whole address on its screen.HOW A SUPPLY CHAIN ATTACK WORKSA thief tampers hereMakerthe walletPartscode, chipsDeliverystore, mailYoutrust itYou get a bad version from a source you trust.It steals your keys or swaps the address you pay.HOW TO PROTECT YOURSELF1Buy and download from the makerNever a used or resold hardware wallet2Keep savings on a hardware walletIts keys never touch your computer3Check the whole address on its screenNot just the first and last few characters

Last checked Oct 9, 2026

Search all questionsSend sats