ACCEPTING CASES · MON–FRI 9:00AM–5:00PM
Certified Data Recovery Professional · Phoenix, AZ ☎ (602) 686-2622

Counterfeit Hard Drives Are Flooding the Market. Here's What That Means If Yours Fails.

We already flagged the risk in passing: with new drives scarce and expensive, the used-drive market is booming, and a used drive can carry more power-on hours than the listing admits. Recent reporting describes something a step past that — used drives with the wear erased from their own SMART data and sold as new. Here's what's actually being reported, and what it means if a drive like that ends up on your desk.

Free evaluation · No data, no fee · Talk directly with a technician.

Tech press — XDA among them — has been covering a pattern worth taking seriously if you buy storage anywhere other than a big-box retailer: heavily worn hard drives, cleaned up to look new, and sold at prices that undercut genuine stock. We were not part of the reporting and have not independently verified every detail, so we're treating the specifics as reported, not as our own findings. But the underlying mechanism is one we can speak to, because it's exactly the kind of drive that shows up on a recovery bench.

What's being reported

The trail traces back to a raid Seagate's own security team ran with Malaysian authorities on a warehouse outside Kuala Lumpur. Reporting puts the seizure at roughly 700 counterfeit drives — predominantly Seagate-branded, with some Kioxia and Western Digital units mixed in, in capacities reaching 18TB. The suspected source, per that reporting, was drives from decommissioned Chia cryptocurrency mining operations in China: hardware that spent its working life doing continuous, heavy sequential writes, then got recycled once mining Chia stopped being profitable. From there, the drives were reportedly relabeled and sold through regional marketplaces — Shopee and Lazada are the two named — as new, high-capacity surveillance and NAS drives, undercutting genuine retail prices enough to move volume.

We're not aware of a documented case tying this specific operation to drives sold in the US, and we won't claim one just because it would make a tidier warning. What we'd point out instead: the incentive behind this scheme — new high-capacity drives are expensive and hard to get, used drives are plentiful, and the gap between the two is money — is not unique to one region or one platform. We've already written about why new drives cost so much right now; this is the market response to that squeeze, just further along than "an honest used listing."

How a worn drive gets to look new

The part of this that's actually a recovery-relevant mechanism, rather than a retail-fraud story, is what gets tampered with: SMART attributes, and on newer drives the FARM log, which is where power-on hours, reallocated-sector counts, and other wear indicators live. Reporting on this scheme describes those values being reset so a heavily used drive reports close to zero hours, the same way a car's odometer can be rolled back. Some counterfeit firmware reportedly goes further and misreports capacity as well.

None of that changes what's physically true of the drive. Reallocated sectors that happened, happened. Head and media wear from months of continuous writing under mining load doesn't reverse because a counter got zeroed. What changes is only the number you'd have checked to catch it — which is the uncomfortable part.

Why this matters for recovery: a drive with a hidden prior life isn't starting from the same baseline as a genuinely new one when something goes wrong. Wear that should have shown up in SMART months ago may show up instead as an earlier, less predictable failure — and the drive's own diagnostics may not be a reliable guide to what's happening inside it.

Bought a 'new' high-capacity drive that's already acting up, or showing numbers that don't add up? Start with a free evaluation before you write anything else to it.

Can you actually catch this before it fails?

Partially, and it's worth doing even with that caveat. A few checks that reporting and drive vendors point to:

None of this is a guarantee, and we're not going to pretend it is. The honest summary from the reporting itself is that resetting SMART is easy enough that a clean readout has stopped being reassuring on its own.

It's not just consumer drives — we've seen it in a server

The reported scheme is about consumer-facing counterfeiting: desktop drives dressed up as new surveillance or NAS drives for individual buyers. But the underlying problem — a heavily used drive changing hands without its real history being disclosed — isn't limited to that end of the market, and it isn't hypothetical for us. We've worked a case built on exactly that pattern at the enterprise end: a twelve-drive HPE SmartArray server, a five-drive RAID 5 plus a seven-drive RAID 6, built entirely from decommissioned data-center 1.8 TB SAS drives. Those drives had already logged roughly six years and nine months of prior duty — and their reallocation (spare-sector) reserve was already exhausted — before the server was ever switched on.

Nothing about those drives was disguised the way the reported counterfeit scheme disguises SMART data; the wear was genuinely there to read, if anyone had looked. The drives simply should not have gone into production in that condition, and nobody checked first. That's a distinct failure from a reset-SMART counterfeit — no tampering, just an undisclosed history and a buyer who didn't verify — but the lesson is the same one this whole post is built on: what a drive reports about itself, or what a reseller tells you about it, is not a substitute for checking.

Putting a heavily used drive into a RAID or server raises the stakes past a single desktop drive failing. An array's fault tolerance assumes every member still has real margin — spare sectors it can remap into when something goes wrong in normal use. A drive that has already burned through that margin has none left, so a new bad sector simply can't be remapped, and the array is running degraded from day one without anyone knowing it. When a second or third member starts failing months later, as happened in that case, there's no cushion left to absorb it.

If a drive like this has already failed

The same rules apply here as to any failed drive, with one addition: tell us where and how you bought it. That doesn't change the mechanics of imaging a drive, but it can matter for what we expect to find — pre-existing weak sectors, an unusual failure pattern for the drive's supposed age, or a capacity mismatch if the firmware was misreporting size.

The job, when it's possible, is the same as any hard drive case: identify what's actually wrong, image what can be read, and reconstruct from there. We don't advertise a success rate, and a drive with unknown prior mileage doesn't change that — it just means the evaluation matters more, not less. We don't have a confirmed counterfeit-labeled, SMART-reset case in our public case log as of this writing — but we do have the related, non-counterfeit version described above, and we won't invent anything beyond what's already published there.

What to do right now

  1. If the drive is still working: check SMART data, verify the serial number if the manufacturer offers a lookup, and keep the receipt and listing — you'll want them if something goes wrong later.
  2. If it's already failing or showing the wrong capacity: power it down and stop writing to it.
  3. Don't reformat, repartition, or run a vendor repair tool to make the numbers look right.
  4. Get it evaluated, and mention where you bought it. The technician on your case will tell you honestly what's recoverable before any chargeable work. Free evaluation, no data, no fee.

If you're mailing it in, pack it like any other failed drive — how to ship a failed drive safely. For the work itself, see our hard drive data recovery service. If the drive is simply aging rather than suspect, common hard drive failures covers the more everyday version of this. And if what actually brought you here is sticker shock on a replacement drive, that's the shortage post, not this one.

Counterfeit & relabeled hard drives — FAQ

What are people actually reporting about counterfeit hard drives?
Tech outlets, including XDA, have been covering reports that heavily used hard drives — some reportedly pulled from decommissioned Chia cryptocurrency mining rigs — are having their SMART data reset to hide the wear, then getting relabeled and resold as new, high-capacity drives. The reporting traces back to a raid Seagate's security team ran with local authorities on a warehouse near Kuala Lumpur, where roughly 700 counterfeit drives were reportedly seized, mostly Seagate-branded but including Kioxia and Western Digital units, in capacities up to 18TB.
How does resetting SMART data make an old drive look new?
SMART (and the newer FARM log some drives keep) records things like power-on hours and reallocated-sector counts — the numbers you'd check to see how hard a drive has been run. Reporting on this scheme describes those values being reset or overwritten so the drive reports as barely used. The physical wear on the platters and heads does not go away; only the reading that would have warned you about it does.
Can I trust a tool like CrystalDiskInfo or HD Sentinel to catch a fake?
It is worth checking, but treat it as one data point, not proof. The same reporting that describes this scheme also notes that SMART and FARM values are exactly what gets tampered with, and some counterfeit firmware can misreport capacity too. A drive that reads clean on SMART is not automatically a genuine, low-mileage drive — it is a drive whose firmware says so. Running more than one tool (CrystalDiskInfo and HD Sentinel disagree occasionally, and a mismatch is itself a flag) is better than trusting a single clean readout.
Is this only a problem with cheap marketplace listings overseas?
The raid covered in the reporting was in Malaysia, and the drives were reportedly sold through regional marketplaces (Shopee and Lazada) as surveillance and NAS drives. We are not aware of a documented case tracing this specific operation into the US market, and we will not claim one. What we would say is the incentive is not geography-specific: any marketplace with third-party sellers and steep discounts on high-capacity drives carries the same risk, wherever it is.
Does this only matter for a single drive, or does it get worse in a RAID or server?
It gets worse in an array. A RAID or server's fault tolerance assumes every member drive has real spare-sector margin left. A resold or relabeled drive that has already burned through that margin has none — so when it develops a new bad sector under array duty, there is nothing left to remap it into. We have seen this play out firsthand, not just in reporting: see the next question.
I think I already bought one of these. Does that change how a failure gets handled?
It can. A drive with a hidden prior life may already be carrying wear, weak sectors, or firmware quirks a genuinely new drive would not have, on top of whatever caused it to fail this time. That is useful context for us, not a reason to assume the worst — tell the technician on your case where and how you bought the drive, and let an evaluation confirm what is actually going on.
Do you have a case like this in your public log?
Not a counterfeit-labeled one — we have not had a case land on our bench where SMART data was confirmed to have been deliberately reset. We do have the related, non-counterfeit version: a twelve-drive HPE SmartArray server built from decommissioned data-center SAS drives that had already logged roughly six years and nine months of prior duty, with their spare-sector reserve exhausted before the server was ever switched on. Nothing there was disguised the way the reported scheme disguises SMART data — the wear was genuinely readable. The drives simply should not have gone into production in that condition, and nobody checked first. We will not invent a case ID, model, or outcome beyond what is already published.
What should I do right now?
If a "new" high-capacity drive is behaving oddly — early failure, wrong capacity, or numbers that do not add up — power it down and stop writing to it. Do not reformat it or run a manufacturer repair tool to "fix" the reading. Get it evaluated, and mention where you bought it. See how to ship a failed drive safely.

Bought a "new" drive that's failing early or reporting the wrong capacity? Start with a free evaluation. We'll tell you honestly what's recoverable before any chargeable work.

Request free evaluation →

Free evaluation · No data, no fee · Talk directly with a technician.