How I Got Scammed on an EVGA NVIDIA GeForce RTX 3090

Amazon EVGA NVIDIA GeForce RTX 3090 That Was A 3070 EVGA Box 1
This week I acquired an Amazon Prime Day buy EVGA NVIDIA GeForce RTX 3090, however there was a catch. The GPU being bought as “new” by appeared to have been a buyer return that had its safety seals damaged and had one other card substituted as a substitute. While Amazon has been good in regards to the return to date, this expertise has profound {hardware} safety and {hardware} provide chain safety implications.
Video Version
For this, we even have a video model that you will discover right here:

There are a number of pictures which are in that model that aren’t on this, simply given the timing of each. As at all times, we advise opening the video in its personal tab, browser, or app for a greater viewing expertise.
How I Got Scammed on an EVGA NVIDIA GeForce RTX 3090
Followers of my private account on Twitter this week might have seen the tweet that got here out in disbelief of what occurred. On Amazon Prime Day I ordered a brand new EVGA NVIDIA GeForce RTX 3090 FTW3 Ultra version and issues didn’t go as deliberate.

Scammed by Amazon. Bought a brand new @TEAMEVGA @NVIDIA RTX 3090 (Amazon vendor.) It arrived. Box seals damaged. Inside was a RTX 3070. 🙁
— Patrick J Kennedy (@Patrick1Kennedy) July 21, 2022

On July 12, 2022, I ordered the GPU. Although NVIDIA despatched us our unique GeForce RTX 3090 for overview, we would have liked one other one for a take a look at platform for a number of of our different collection on STH. The EVGA card was bought by Services LLC and was listed in New situation. This was bought by way of the Add to Cart/ Buy Now field, not by searching for used items.
Amazon EVGA NVIDIA RTX 3090 Invoice Redacted Small
The unit shipped on July 13, 2022, after which issues began to go awry.
First, the unit was shipped, requiring a signature supply. I was heading to Zurich, Switzerland that weekend, however in response to the estimated arrival date, I was to be round for the cargo. Instead, Amazon batched the cardboard with different gadgets so it as an alternative would arrive after I left for Europe. That meant I needed to spend $10 to get UPS to ship the package deal at a later date when I may very well be there to signal for it. When the package deal arrived, it regarded prefer it had a tricky life.
Amazon EVGA NVIDIA GeForce RTX 3090 That Was A 3070 Shipping Box 1
It appears as if this package deal was open sooner or later throughout transit. When it was opened, it appeared that somebody had folded the flaps over one another. Then a copious quantity of clear plastic tape was used to seal the field. You can see it on the doorstep at supply within the video, however the reverse facet was opened to realize entry to merchandise simply to protect this packaging masterpiece.
Amazon EVGA NVIDIA GeForce RTX 3090 That Was A 3070 Shipping Box 3
The contents appear to have arrived, however the GeForce RTX 3090, destined for a take a look at node, had a curious function. EVGA makes use of safety tape to seal its packaging. On this package deal, each EVGA seals have been already damaged.
Amazon EVGA NVIDIA GeForce RTX 3090 That Was A 3070 Security Seal 2 Broken
In addition to the 2 damaged seals, there was a LPN PM sticker. Often Amazon makes use of the LPN RR stickers for returns put again into inventory, so this regarded comparable. Also, there’s a sticker underneath that LPN sticker with the mannequin data and a “NewItem” printed on the label.
Amazon EVGA NVIDIA GeForce RTX 3090 That Was A 3070 Security Seal 1 Broken
Here is one other have a look at the label on the top of the field, this time opened.
Amazon EVGA NVIDIA GeForce RTX 3090 That Was A 3070 EVGA Box 2 With Return Label
Inside the field was a standard inside field with the froth provider.
Amazon EVGA NVIDIA GeForce RTX 3090 That Was A 3070 Foam 1
Removing the highest foam made us see the ICX3 cooler model that EVGA makes use of on a variety of its playing cards. If somebody processing a return noticed this, they’d see the cardboard on the entrance of the field and assume the identical card was sitting there.
Amazon EVGA NVIDIA GeForce RTX 3090 That Was A 3070 In Box
Even the EVGA badge and the non-model particular EVGA GeForce set up information was included.
Amazon EVGA NVIDIA GeForce RTX 3090 That Was A 3070 EVGA Badge And Manual
EVGA makes use of branded ESD baggage, and this card was utilizing the EVGA bag with an ESD seal nonetheless on the bag.
Amazon EVGA NVIDIA GeForce RTX 3090 That Was A 3070 ESD Seal 1
The one view, aside from tracing the serial numbers that may give this away was wanting on the prime of the cardboard that claims “RTX 3070” as an alternative of “RTX 3090”. That single 7 versus 9 digit change is the one giveaway one would fairly see when inspecting this package deal to inform that this was the unsuitable card.
Amazon EVGA NVIDIA GeForce RTX 3090 That Was A 3070 See Model Through Bag 1
That “3070” is commonly hidden by the froth provider within the field. Being empathetic, it’s not too laborious to grasp how this might occur. Someone that didn’t know the distinction between a RTX 3070 and a RTX 3090 would miss this in the event that they have been underneath time stress to validate a earlier return. When opening the field and seeing the cardboard that regarded just like the field cowl, I initially assumed it was the suitable card, and I noticed the ESD sticker sealing the cardboard. It was solely later that I realized this was a 3070.
Amazon EVGA NVIDIA GeForce RTX 3090 That Was A 3070 See Model Through Bag 3
My greatest guess is that somebody bought an EVGA RTX 3070 and a 3090. They then saved the 3090 and returned the 3090 packaging with the RTX 3070 model inside. Amazon processed the return of an costly card and the individual checking missed the 7 versus 9 on the highest of the cardboard, and didn’t have a approach to validate serial numbers. They then noticed the ESD bag seal and determined that it might go in new inventory as an alternative of a used queue.
I opened the return with Amazon and spoke to somebody on the cellphone to clarify what occurred and this card is now on its approach again to Amazon. I wished to get on the cellphone as a result of I was sending again a RTX 3070 in a 3090 field, and if somebody does correct checks, they’ll see this isn’t the cardboard that matches the packaging. I was a bit apprehensive about doing this kind of return since it’s a mismatch.
Amazon EVGA NVIDIA GeForce RTX 3090 That Was A 3070 EVGA Box 1
In the top, assuming the refund is processed, I might be out a few week placing collectively the system we’ll use to check the Project TinyMiniMicro nodes and for our STH Mini PC collection. I even have the chance of getting to do the return and having an concern as a result of there’s a mismatched product. Further, I needed to cease by the UPS retailer and drop off the package deal, and that could be a 15+ minute one-way journey. The constructive is that pricing on the RTX 3090 has fallen since then, so I in all probability will find yourself a bit higher off with the return aside from all the misplaced time.
The eye-opening influence is absolutely the {hardware} safety side of this story.
Why This is an Important Hardware Security Story
Bloomberg’s discredited spy chip article and a follow-up piece that I interviewed their major supply who disagreed with Bloomberg’s reporting, whereas pretend information did one thing for the business. It helped spotlight the challenges with {hardware} safety and provide chains. This story is a extra sensible and harmful story from a {hardware} safety perspective.
One of the large challenges with {hardware} safety is that gadgets will be intercepted throughout transport. We assume this was only a package deal that Amazon didn’t correctly fill and that received crushed and re-taped by UPS. Compared to some tales of methods being intercepted throughout cargo, it is a poor cover-up job. Still, it’s not utterly unusual to see Amazon packages take a number of bumps alongside the best way.
Amazon EVGA NVIDIA GeForce RTX 3090 That Was A 3070 Shipping Box 2
The greater concern is that it looks as if a unit bought by and never a third occasion vendor was not new. Instead, even with safety seals being damaged, it was positioned again into NewItem inventory and bought as “New” per the bill above.
Amazon EVGA NVIDIA GeForce RTX 3090 Box With Return Label And Broken Security Seal 1
Taking a step again for a second, if the cardboard was really an EVGA GeForce RTX 3090 and with the ESD bag nonetheless sealed, I in all probability would have used it being in a time crunch to get the brand new system on-line. If your entire card will be substituted and undergo Amazon’s return logistics course of, ending up as “new” inventory, then what if somebody had extra nefarious intentions? What if somebody tampered with the GeForce RTX 3090 and received it accepted again as new inventory by Amazon?
Amazon EVGA NVIDIA GeForce RTX 3090 That Was A 3070 Card Back
The downstream purchaser would possibly use the compromised RTX 3090 of their system. This is a card the place the PCB isn’t uncovered since there are followers, heatsinks, and shrouding masking your entire card. It can be inconceivable with out disassembly to see if the cardboard was tampered with earlier than set up. That compromised RTX 3090 can be plugged into the PCIe slot in a motherboard. PCIe gadgets bodily put in into motherboards have very low-level system entry because of their natures. This is probably one of many scariest sorts of assaults since it might enable an enormous quantity of entry to a system.
The key right here is that by taking a beforehand bought laptop product and reselling it, by as the vendor as “new,” most patrons have the cheap expectation that the unit went from the producer to a distributor to Amazon or on to Amazon. Having the potential of muddling returned laptop merchandise into this new merchandise pool signifies that that chain of custody can’t be assured.
Instead, we had a 3rd occasion tamper with the GPU Services LLC bought us as new. Then, one thing occurred in transport resulting in the package deal being accessible en route. This story, given Amazon’s giant presence, ought to make laptop {hardware} safety specialists very nervous because it has all the parts to be disastrous for finish customers.
Final Words
Again, the chain of occasions is easy to grasp. I am a bit disheartened by the inconvenience of this. I will say that Amazon has been simple to provoke the return on so I haven’t any complaints at this level on the return course of (we might have an replace if that adjustments.)
Amazon EVGA NVIDIA RTX 3090 Invoice Redacted Small
Still, given Amazon’s market presence and the truth that it’s letting extremely tampered merchandise into its provide chain and promoting them as new, the {hardware} safety points of this are mind-boggling. For Amazon, the problem is that the choice is that taking returns on these merchandise and mechanically not placing them right into a used/ refurbished inventory will be pricey. However, if this apply continues, it turns into laborious to belief one of many world’s largest laptop element resellers. I doubt AWS would settle for this in its {hardware} provide chain, so there’s a little bit of a “do unto others” that I can’t escape feeling right here.
Amazon EVGA NVIDIA GeForce RTX 3090 That Was A 3070 See Model Through Bag 3
Originally, I was not going to jot down up this story, a lot much less do a video. The Twitter publish was all I deliberate on doing. At the identical time, I assume that our readers have to be conscious that one thing like this may occur. From a {hardware} safety and provide chain perspective, the field was dangerous, however there’s baby can do to point out tampered {hardware} can get by way of right into a reseller’s “new” inventory greater than having a product that has been substituted within the package deal.
For the business and our readers, Amazon’s laptop element provide chain being this compromised and passing tampered packages as new and bought by Amazon, not a 3rd occasion vendor, needs to be a wake-up name. This is as dangerous, or worse, than what we present in Dude this could NOT be in a Dell Switch or HPE Supercomputer.

Recommended For You