Tech press — XDA among them — has been covering a pattern worth taking seriously if you buy storage anywhere other than a big-box retailer: heavily worn hard drives, cleaned up to look new, and sold at prices that undercut genuine stock. We were not part of the reporting and have not independently verified every detail, so we're treating the specifics as reported, not as our own findings. But the underlying mechanism is one we can speak to, because it's exactly the kind of drive that shows up on a recovery bench.
What's being reported
The trail traces back to a raid Seagate's own security team ran with Malaysian authorities on a warehouse outside Kuala Lumpur. Reporting puts the seizure at roughly 700 counterfeit drives — predominantly Seagate-branded, with some Kioxia and Western Digital units mixed in, in capacities reaching 18TB. The suspected source, per that reporting, was drives from decommissioned Chia cryptocurrency mining operations in China: hardware that spent its working life doing continuous, heavy sequential writes, then got recycled once mining Chia stopped being profitable. From there, the drives were reportedly relabeled and sold through regional marketplaces — Shopee and Lazada are the two named — as new, high-capacity surveillance and NAS drives, undercutting genuine retail prices enough to move volume.
We're not aware of a documented case tying this specific operation to drives sold in the US, and we won't claim one just because it would make a tidier warning. What we'd point out instead: the incentive behind this scheme — new high-capacity drives are expensive and hard to get, used drives are plentiful, and the gap between the two is money — is not unique to one region or one platform. We've already written about why new drives cost so much right now; this is the market response to that squeeze, just further along than "an honest used listing."
How a worn drive gets to look new
The part of this that's actually a recovery-relevant mechanism, rather than a retail-fraud story, is what gets tampered with: SMART attributes, and on newer drives the FARM log, which is where power-on hours, reallocated-sector counts, and other wear indicators live. Reporting on this scheme describes those values being reset so a heavily used drive reports close to zero hours, the same way a car's odometer can be rolled back. Some counterfeit firmware reportedly goes further and misreports capacity as well.
None of that changes what's physically true of the drive. Reallocated sectors that happened, happened. Head and media wear from months of continuous writing under mining load doesn't reverse because a counter got zeroed. What changes is only the number you'd have checked to catch it — which is the uncomfortable part.
Bought a 'new' high-capacity drive that's already acting up, or showing numbers that don't add up? Start with a free evaluation before you write anything else to it.
Can you actually catch this before it fails?
Partially, and it's worth doing even with that caveat. A few checks that reporting and drive vendors point to:
- Check SMART data with a tool like CrystalDiskInfo or HD Sentinel — but treat a clean reading as a data point, not proof. It's precisely the field the reported scheme tampers with. Running both isn't overkill; a disagreement between them is itself a flag.
- Verify the serial number against the manufacturer's own lookup tool where one exists, rather than trusting the label.
- Compare the box's manufacturing date to your purchase date. A "new" drive with a manufacturing date many months old is worth a second look.
- Be skeptical of a price that's meaningfully below other listings for the same capacity and model — the gap has to come from somewhere, and reporting suggests this is often where.
- Buy high-capacity drives from a retailer you can return to rather than a third-party marketplace listing, especially at helium-sealed capacities where an open drive is a one-way trip even for us.
- Check every drive individually if you're building or expanding an array. One worn member undermines the redundancy the whole array is supposed to provide — a spot-check on one or two drives out of a dozen tells you nothing about the rest.
None of this is a guarantee, and we're not going to pretend it is. The honest summary from the reporting itself is that resetting SMART is easy enough that a clean readout has stopped being reassuring on its own.
It's not just consumer drives — we've seen it in a server
The reported scheme is about consumer-facing counterfeiting: desktop drives dressed up as new surveillance or NAS drives for individual buyers. But the underlying problem — a heavily used drive changing hands without its real history being disclosed — isn't limited to that end of the market, and it isn't hypothetical for us. We've worked a case built on exactly that pattern at the enterprise end: a twelve-drive HPE SmartArray server, a five-drive RAID 5 plus a seven-drive RAID 6, built entirely from decommissioned data-center 1.8 TB SAS drives. Those drives had already logged roughly six years and nine months of prior duty — and their reallocation (spare-sector) reserve was already exhausted — before the server was ever switched on.
Nothing about those drives was disguised the way the reported counterfeit scheme disguises SMART data; the wear was genuinely there to read, if anyone had looked. The drives simply should not have gone into production in that condition, and nobody checked first. That's a distinct failure from a reset-SMART counterfeit — no tampering, just an undisclosed history and a buyer who didn't verify — but the lesson is the same one this whole post is built on: what a drive reports about itself, or what a reseller tells you about it, is not a substitute for checking.
Putting a heavily used drive into a RAID or server raises the stakes past a single desktop drive failing. An array's fault tolerance assumes every member still has real margin — spare sectors it can remap into when something goes wrong in normal use. A drive that has already burned through that margin has none left, so a new bad sector simply can't be remapped, and the array is running degraded from day one without anyone knowing it. When a second or third member starts failing months later, as happened in that case, there's no cushion left to absorb it.
If a drive like this has already failed
The same rules apply here as to any failed drive, with one addition: tell us where and how you bought it. That doesn't change the mechanics of imaging a drive, but it can matter for what we expect to find — pre-existing weak sectors, an unusual failure pattern for the drive's supposed age, or a capacity mismatch if the firmware was misreporting size.
- Stop using it. Continued writes on a drive that may already be carrying hidden wear only shrink the window.
- Don't run a manufacturer "repair" or low-level format tool hoping it fixes a wrong capacity or a SMART warning. Those tools are built to reinitialize a drive, not diagnose one, and on a drive that already has real data, that's a write you can't take back.
- Don't assume a bad SMART reading now means the drive was always fine and something you did broke it. If the drive's own history was tampered with before it reached you, the diagnostics you're looking at were never a full picture.
The job, when it's possible, is the same as any hard drive case: identify what's actually wrong, image what can be read, and reconstruct from there. We don't advertise a success rate, and a drive with unknown prior mileage doesn't change that — it just means the evaluation matters more, not less. We don't have a confirmed counterfeit-labeled, SMART-reset case in our public case log as of this writing — but we do have the related, non-counterfeit version described above, and we won't invent anything beyond what's already published there.
What to do right now
- If the drive is still working: check SMART data, verify the serial number if the manufacturer offers a lookup, and keep the receipt and listing — you'll want them if something goes wrong later.
- If it's already failing or showing the wrong capacity: power it down and stop writing to it.
- Don't reformat, repartition, or run a vendor repair tool to make the numbers look right.
- Get it evaluated, and mention where you bought it. The technician on your case will tell you honestly what's recoverable before any chargeable work. Free evaluation, no data, no fee.
If you're mailing it in, pack it like any other failed drive — how to ship a failed drive safely. For the work itself, see our hard drive data recovery service. If the drive is simply aging rather than suspect, common hard drive failures covers the more everyday version of this. And if what actually brought you here is sticker shock on a replacement drive, that's the shortage post, not this one.
Counterfeit & relabeled hard drives — FAQ
What are people actually reporting about counterfeit hard drives?
How does resetting SMART data make an old drive look new?
Can I trust a tool like CrystalDiskInfo or HD Sentinel to catch a fake?
Is this only a problem with cheap marketplace listings overseas?
Does this only matter for a single drive, or does it get worse in a RAID or server?
I think I already bought one of these. Does that change how a failure gets handled?
Do you have a case like this in your public log?
What should I do right now?
Bought a "new" drive that's failing early or reporting the wrong capacity? Start with a free evaluation. We'll tell you honestly what's recoverable before any chargeable work.
Request free evaluation →Free evaluation · No data, no fee · Talk directly with a technician.