Background: Security of Hardware Wallets
It is a best practice in digital asset management to “use hot wallets for small amounts and cold wallets for large amounts.”
Hardware wallets (generally cold wallets) keep private keys and sensitive data completely offline, significantly improving asset security. Therefore, buying a hardware wallet is the preferred choice for users with higher security needs. However, certain risks remain during the purchase and use process that may compromise this protection.
Findings
imKey has discovered unauthorized sellers on online marketplaces such as JD.com and Pinduoduo offering “activated” imKey hardware wallets.
This situation poses a risk of social engineering attacks and potential fraud.
Normally, a hardware wallet should be unactivated — that is, during the first use, the user should personally activate the device, create a wallet, back up the mnemonic, and set a PIN code.
What Is a Social Engineering Attack?
A social engineering attack occurs when an attacker exploits human psychology — using deception, impersonation, or manipulation — to trick victims into revealing sensitive information or taking specific actions that compromise their security.
Through further investigation, imKey discovered that some unauthorized sellers not only sold “pre-activated” hardware wallets but also tampered with the user manual to mislead customers into depositing funds into wallets pre-created by malicious actors.
imKey has reported these incidents to platform customer service teams and is actively cooperating with law enforcement.
If you purchased your imKey device from an unauthorized store, please take the following precautions:
How to Check Your Device
When using imKey for the first time, ensure that you personally perform the following key steps:
1️⃣ Activate the device (activation is irreversible; each device can only be activated once)
2️⃣ Set and back up your PIN code and binding code
3️⃣ Create and back up your mnemonic phrase
If any of these steps were not performed by you, your wallet may be compromised — please remain vigilant.
You can refer to the official tutorial:
👉 imKey + imToken Pairing Guide
You can also verify your device via the official verification portal:
👉 https://imkey.im/pages/verify
Verification includes:
- Appearance Check: Pay attention to the manual — if it includes a pre-set PIN, the device is unsafe.
(Unsafe manual with pre-set PIN)
-
Activation Status Check: Enter your SN number to view activation time; a new device should display “Not yet activated.”
- Check your SN number here: https://imkey.im/pages/sn-check
What to Do If You’re at Risk
- Transfer any assets from the potentially compromised wallet address to a new secure wallet.
- If you have questions, contact us via the official email: support@imkey.im
How to Safely Purchase imKey Hardware Wallets
To ensure product authenticity and quality after-sales service, please purchase only through official channels.
Currently, imKey offers three authorized purchase options:
1️⃣ Youzan Store – For Mainland China users.
Products are delivered domestically via SF Express with fast and reliable shipping.
🔗 https://j.youzan.com/S0w1J1
2️⃣ Amazon Stores – For overseas users.
Purchase through the official imKey Amazon store (verify the seller name: IMKEY CO., LTD.).
3️⃣ Official Website – For overseas users as well.
🔗 https://store.imkey.im/
⚠️ Only imKey devices purchased from official channels guarantee product authenticity, asset safety, and official after-sales support.
We cannot guarantee the safety or service quality of products purchased elsewhere.
About imKey
imKey Pro is the first hardware wallet in the industry to adopt a CC EAL6+ certified secure chip, providing the highest level of security.
It is also among the first to support Bluetooth connection, making it convenient and easy to use.
imKey deeply integrates with imToken, allowing seamless access to supported DApps and on-chain services.
After years of market validation, imKey Pro has earned widespread trust and recognition from users and industry professionals alike.
We understand that user feedback plays a crucial role in combating fraudulent activities from unauthorized stores. Therefore, we sincerely invite all users to participate actively — if you discover any unauthorized sellers or suspicious fraudulent behavior, please report it through the following channels:
Report Email: support@imkey.im
Report Details: Please include the name and website link of the unauthorized store so that we can verify and take action promptly.
Important Notice:imKey sells physical security hardware products only and does not provide any virtual asset trading, custody, or funds-related services. References to third-party wallets, exchanges, or decentralized applications are for compatibility purposes only; related functions and services are provided independently by third parties.
0 comments
Article is closed for comments.