A user receives a Ledger hardware wallet—either a Nano S Plus, Nano X, or Stax—and opens Ledger Wallet (formerly Ledger Live) on their computer or phone for the first time. The application immediately presents a setup flow that includes a critical step: Genuine Check. This feature verifies that the connected device is an authentic Ledger product manufactured by the company, not a counterfeit unit or compromised clone. The distinction matters because a counterfeit device might run modified firmware, contain backdoored key generation, or lack the Secure Element protections that make Ledger hardware valuable in the first place.
The Genuine Check process is not optional or deferrable. It is a mandatory part of initializing any new Ledger device with Ledger Wallet, and it is deliberately designed to happen before users proceed to create or import accounts, generate receive addresses, or approve transactions. For someone managing significant cryptocurrency holdings or NFTs, this verification step represents the first and most fundamental security checkpoint. Without confirming authenticity, all downstream operations—even those relying on the hardware signer’s physical confirmation—rest on an unverified foundation.
How Genuine Check Works Under the Hood
When a Ledger device connects to Ledger Wallet for the first time, the application does not simply read a serial number or trust a label on the physical box. Instead, it initiates a cryptographic handshake between the connected hardware and Ledger’s authentication infrastructure. The Ledger device contains a Secure Element—a tamper-resistant chip similar to those used in payment cards and government ID systems—that holds a unique private key assigned during manufacturing. This key never leaves the device.
Ledger Wallet sends a challenge to the device, which the Secure Element signs using its embedded private key. The application then verifies that signature against Ledger’s corresponding public key. If the signature is valid and the device’s certificate chain is properly issued by Ledger’s trusted Certificate Authority, the check passes. If the device is counterfeit, lacking the Secure Element, or running altered firmware that cannot perform the cryptographic operation, the verification fails and the application blocks further setup.
This architecture prevents several attack vectors simultaneously. A counterfeit manufacturer could clone the external casing and flash cloned firmware onto a regular microcontroller, but without access to the original Secure Element’s private key, they cannot produce valid signatures. Similarly, an attacker who intercepts a device in transit cannot silently modify it to redirect transactions or steal keys, because the Genuine Check will detect the tampering. The verification happens locally on the user’s device and does not require uploading keys or sensitive information to Ledger’s servers; the company learns only whether the check succeeded, not the details of the user’s setup.
The strength of this approach depends on two non-obvious assumptions. First, the user must perform Genuine Check on the same computer or phone where they will ultimately manage their cryptocurrency. If someone initializes the device on a public or compromised machine, then moves it to their secure device, Genuine Check has already authenticated the hardware but has not verified the integrity of the software environment where transactions will be approved. Second, Genuine Check happens once per device per software installation. If a user uninstalls and reinstalls Ledger Wallet, or uses the device with a second application on a different machine, they should expect to verify authenticity again rather than assuming that one earlier check is permanent.
Why Counterfeit Hardware Poses a Real Risk
The cryptocurrency market has attracted increasingly sophisticated counterfeiting operations. Fake Ledger devices have appeared on third-party marketplaces, in counterfeit retail packaging, and occasionally in supply chain compromises where legitimate-looking products arrived at resellers through unofficial channels. A convincing counterfeit might include a printed manual, a recovery sheet, and external hardware that feels nearly identical to the genuine article. The vulnerability is not that counterfeits exist, but that a non-technical user might not detect one until after they have already imported or created accounts.
The attack works in stages. First, the user receives and opens what they believe is a Ledger device. If they do not perform Genuine Check—or if they use an older or unofficial companion application that lacks the verification—they proceed to initialize the device normally. Unknown to them, the counterfeit firmware captures their recovery phrase or generates keys that the attacker also knows. In the worst case, the device’s random number generator is rigged or seeded in a predictable way, allowing the attacker to pre-compute derivation paths and drain funds as soon as they appear on receiving addresses the user thinks are private.
The reason Genuine Check is mandatory in Ledger Wallet is that this scenario is otherwise almost invisible until it is too late. A counterfeit device will display a recovery phrase, accept transaction approvals, and function in all surface respects like a real Ledger. The only difference is that the attacker holds copies of the keys. By the time a user notices unexpected transactions or missing funds, they have already completed setup and transferred cryptocurrency into what they believed were secure addresses. Genuine Check is the only practical way to detect the substitution before that point.
When and How to Run Genuine Check
Genuine Check is initiated automatically when a user connects a Ledger device to Ledger Wallet for the first time on a given installation. The device must have sufficient battery (if battery-powered, like Nano X), must be connected via USB or Bluetooth, and must be responsive. If the device is uninitialized (meaning it has never been set up with a PIN or recovery phrase), it may also prompt the user to proceed with initial setup before the check completes. If the device has already been initialized on another application or computer, Genuine Check will still occur as part of the Ledger Wallet onboarding flow.
Users should not bypass or skip this step, even if it seems tedious. The entire purpose of Ledger’s hardware security model is the assumption that the Secure Element is genuine and trustworthy. Once that assumption is violated, no other security measure—including the physical confirmation button on the device—can be trusted. The Genuine Check feature is where that foundational assumption is actually verified. Skipping it because the user is impatient or trusts the retailer is akin to verifying a physical signature on a document while deliberately not looking at it.
If Genuine Check fails, Ledger Wallet will display an error and block setup. The user should immediately stop, disconnect the device, and contact the retailer or Ledger support. A failed check is rare when the device is genuine and purchased through official channels, but it can occur if the device is genuinely counterfeit, if firmware is corrupted, or if there is a communication glitch between the hardware and the application. In the case of a communication issue, restarting Ledger Wallet and retrying may help. If the failure persists, the device should be considered compromised until proven otherwise.
Genuine Check and Watch Mode: Important Distinctions
Ledger Wallet can operate in two modes: connected mode and Watch Mode. Connected mode requires a Ledger device to be physically linked and authenticated via Genuine Check. Watch Mode allows users to monitor cryptocurrency balances and generate receive addresses without a device present, relying only on extended public keys (xpub) that the user has previously exported from their hardware signer. Watch Mode is useful for portfolio monitoring on a phone while the actual hardware stays secure elsewhere, or for checking balances across multiple wallets.
However, Watch Mode does not perform Genuine Check because no device is connected. The security model is fundamentally different. In Watch Mode, the application is entirely dependent on the accuracy of the xpub values entered or imported. If an attacker tricks a user into importing a malicious xpub—one that the attacker can actually derive—Watch Mode will display those addresses as if they belong to the user’s real wallet, potentially causing the user to send funds to attacker-controlled addresses. Genuine Check cannot prevent this because it only authenticates hardware devices, not imported keys.
The implication is that Watch Mode should be used carefully and only with xpubs obtained directly from a verified, genuine Ledger device. If a user is setting up Watch Mode for the first time, they should do so by exporting the xpub from their Ledger device during a connected session in the same Ledger Wallet installation where Genuine Check has already passed. This creates a traceable link between the Watch Mode portfolio and an authenticated hardware source. Users should not import xpubs from other applications, websites, or sources they cannot directly verify, regardless of how trustworthy those sources appear.
Genuine Check in a Multi-Device Setup
Many users manage multiple Ledger devices—for instance, a Nano S Plus for daily use and a Stax for backup or a Nano X for mobile access. Each device has its own Secure Element and its own unique private key. Genuine Check must pass independently for each device before that device is used with Ledger Wallet. If a user has three Ledger devices, they should expect to see the Genuine Check process three separate times, once per device during its initial connection to the application.
This approach has both advantages and drawbacks. On the positive side, it means that if one device is compromised or counterfeit, the other devices remain protected and can still be verified. A compromise of a single hardware signer does not automatically invalidate the entire backup strategy. On the negative side, managing and remembering the status of Genuine Check across multiple devices requires discipline. A user might remember checking the first device but forget to verify a second one, especially if they are distracted or in a hurry during backup setup.
Best practice is to document the outcome of each Genuine Check—not as a stored file, but as a mental note or secure personal record. For example: “Nano S Plus verified on my laptop, June 12. Nano X verified on my iPad, June 14.” This simple practice reduces the risk of accidentally using an unverified device. It also helps if a user is ever unsure whether they completed the verification on a particular machine. If the device has been connected to Ledger Wallet and Genuine Check passed without error messages, the device is genuine as of that software installation.
Recovery and Re-Verification
What happens if a user reinstalls Ledger Wallet, switches computers, or restores their operating system? The Genuine Check cache is tied to the software installation, not to the user’s account or the device itself. When Ledger Wallet is installed fresh on a new machine, connecting an existing (and genuine) Ledger device will trigger the Genuine Check process again. This is by design. Each software environment is treated as potentially untrusted until the connection is authenticated.
This requirement might seem redundant if the user has already verified the device on another computer. However, it serves an important purpose. Between the first verification and the second, malware could have compromised the original computer, or the user’s threat model could have changed. Re-verifying on a new machine ensures that even if the previous environment was unsafe, the current one still gets a fresh cryptographic confirmation that the device is authentic. The cost is a few seconds of setup time; the benefit is that compromises in one software environment do not automatically carry over.
Users can learn how to re-initialize or verify their Ledger device through Ledger’s official support documentation and tutorials. These resources explain the specific steps for different device models and operating systems, as well as troubleshooting procedures if Genuine Check encounters issues. Consulting official documentation rather than third-party tutorials is important because the exact interface and process have evolved with Ledger Wallet updates, and outdated instructions could lead to confusion or missed security steps.
Genuine Check as Part of a Broader Security Framework
Genuine Check is a necessary but not sufficient security measure. Verifying that a device is authentic addresses the risk of counterfeit hardware, but it does not protect against other threats. A genuine Ledger device can still be lost, stolen, or damaged. A genuine device in the hands of an attacker can be forced to sign transactions through physical duress or social engineering. A genuine device that has not been properly initialized—for example, with a weak or reused PIN—can be compromised through brute force if physically accessed.
The Genuine Check feature is most effective when combined with other practices. The user should set a strong PIN that is not written down or shared. The recovery phrase should be stored securely offline, separate from the device itself, and never entered into any computer or application other than a trusted hardware signer. When using Ledger Wallet, transactions should be reviewed carefully on the device’s own screen before physical confirmation, since the device’s screen is more difficult to compromise than the computer running Ledger Wallet. For large or unfamiliar transactions, waiting a day or using a second device to verify the recipient address externally can catch mistakes or social engineering attempts.
Genuine Check is the foundation of this framework, not the entire structure. Without it, none of the downstream security measures—physical button confirmation, Secure Element isolation, or transaction review—can be trusted. With it, the hardware is verifiably genuine, and the other measures can work as intended. The combination is what provides genuine security, not the Genuine Check feature alone.
Frequently asked questions
What does it mean if Genuine Check fails?
A failed Genuine Check indicates that the connected device could not produce a valid cryptographic signature using the Secure Element’s embedded private key. This usually means the device is counterfeit, the firmware is corrupted, or there is a communication fault. Stop using the device immediately and contact your retailer or Ledger support. Do not proceed with importing or creating accounts.
Can I use a Ledger device without performing Genuine Check?
No. Ledger Wallet requires Genuine Check to pass before a new device can be set up or imported. This is mandatory because the entire security model depends on verifying that the hardware is authentic. If you absolutely must use your Ledger device with a different application, be aware that you are bypassing this critical verification step and accepting significantly higher counterfeit risk.
Do I need to re-run Genuine Check every time I connect my device?
No. Once Genuine Check passes for a device on a specific Ledger Wallet installation, subsequent connections to the same installation do not re-run the verification. However, if you reinstall Ledger Wallet, use a new computer, or restore your operating system, you will need to perform Genuine Check again when you connect the device to the fresh installation.
