Skip to main content

How are supply chain risks checked after receiving UKey equipment?

U
Written by UKey Wallet

UKey Device Security

Supply chain attacks can occur during the production, transportation, sale, repair, or delivery of equipment. Attackers may replace devices or packaging, pre-initialize wallets, or induce users to use fake software and recovery materials. After receiving UKey equipment, the risk should be comprehensively judged through multiple signals such as the source of purchase, visual inspection, independent initialization, and official verification.

Let's look at the conclusion first:If the device comes with a preset PIN, a pre-written mnemonic phrase, a download link from an unknown source, or the official verification results are abnormal, please stop using it. Do not enter existing mnemonic phrases into suspicious devices, web pages, clients, or customer service conversations, and do not transfer assets to addresses managed by the device.

What information should I check first after receiving the device?

  1. Check purchasing channels:Confirm that the order comes from UKey official or clearly authorized channels, and avoid second-hand, resale or privately traded equipment from unknown sources.

  2. Check the packaging:Pay attention to damage, repeated pasting, abnormal glue marks, inconsistent packaging or missing accessories. When an abnormality is discovered, take photos first and keep the order and logistics vouchers.

  3. Check the appearance of the device:Check the model and accessories, and check whether there are signs of prying, replacement or abnormal wear on the casing, interfaces, buttons, screen and seams.

  4. Check the accompanying materials:Be wary of cards and instructions asking to visit unfamiliar websites, scan unknown QR codes, download group files, or use "activation codes" or "official mnemonics."

If the packaging seal is intact, it only means that there are no obvious signs of tampering. Seals may be copied and packaging may be replaced in its entirety, so visual inspection is not a substitute for device verification and autonomous initialization.

When turning on the device for the first time, what situations require an immediate stop?

When creating a new wallet, the PIN should be set by the user and the mnemonic phrase should be generated and backed up on a trusted device following official procedures. Initialization should be stopped if any of the following conditions occur:

  • A PIN has been set on the device, or the seller has provided a ready-to-use PIN;

  • There are already wallet accounts or transaction records after booting;

  • The package comes with a pre-written or printed mnemonic phrase;

  • The web page, client or customer service requires entering a mnemonic phrase to complete activation, verification or upgrade;

  • The software requires downloading clients, plug-ins or firmware from unknown sources.

Safety red line:UKey Customer service does not require users to provide mnemonic phrases. Anyone who obtains a complete mnemonic phrase may be able to recover and control the corresponding account in other compatible wallets.

Use the official portal to complete device verification

Before entering existing recovery data or transferring assets, please follow the official process to verify the device. For specific steps, seeHow do I verify that a UKey device is genuine?.

Passed verification is an important signal, but it does not alone prove that the packaging has never been opened, that all internal components have not been altered, or that the device will not have security issues in the future. The serial number, seal, or primary verification result should be judged together with the source of purchase, device status, and autonomous initialization.

What should I do if verification is abnormal or the device has been outside my custody?

  1. Stop operation:Do not continue initializing, signing, upgrading, or entering an existing mnemonic phrase.

  2. Keep evidence:Record verification prompts, photograph packaging and equipment abnormal locations, and save order and logistics information; do not publicly release complete serial numbers or personal information.

  3. Check entrance:Enter the official UKey website and help center manually, without using links provided in wrappers, ads, private messages, or group chats.

  4. Contact official support:Submit device information and abnormal phenomena through official public channels and wait for verification or after-sales processing.

  5. Assess existing wallet risks:If the suspicious device has been exposed to existing mnemonic phrases, or has managed important assets, please consider the recovery data as potentially exposed, and follow official guidance to create a new wallet and migrate assets on another trusted device.

A device being outside your custody during transportation, repair, use in a shared space, or after being lost does not necessarily mean it was tampered with, but the original basis of trust has changed. Before official verification is completed, it is not appropriate to continue to use it as a trusted signature device for important assets.

Related safety instructions

Summary

Checking supply chain risks cannot rely on a single seal, serial number or verification result. It is more reliable to buy from trusted sources, check the packaging and device status, reject preset PINs and pre-written mnemonic phrases, Use the official verification portal, and immediately stop operation and contact official support when an exception occurs.

Did this answer your question?