Skip to content
FRP-154 Fraud & Financial Crime

What should I do with a hardware security key?

A hardware security key may provide access to accounts, devices or encrypted services and should be preserved as both a physical and digital-evidence item.

Avoid this assumption: It is only a small USB device with no evidential value beyond possession. A security key may be used for multi-factor authentication, passwordless login, account recovery or device unlocking.

Record where it was found, who had possession or control of it and what device, account or paperwork it was associated with.

Photograph the key, its packaging, labels, serial number, make, model, connector type and any attached ring, tag or adapter.

Do not insert it into a computer or phone simply to identify it. Connection may create logs, trigger authentication prompts or expose active accounts.

Do not press any button or touch-sensitive surface.

Some keys support several connection methods, including USB, NFC or Bluetooth. Record all visible capabilities.

If the key was already connected when found, record the host device, port, open application, logged-in account and any prompt before removal.

Disconnecting it may terminate access, lock a session or interrupt an authentication process.

Keep associated recovery codes, labels, instructions or packaging separate but clearly linked.

Do not assume the person carrying the key was the only person authorised to use it.

Where the key may control access to important accounts or encrypted material, seek specialist support before interaction.

Maintain continuity for the key as a distinct exhibit and protect it from damage, accidental connection and loss.

Operational takeaway

Preserve the hardware security key, its identifiers and account or device context, and do not connect, press or remove it without considering the access and evidential consequences.


Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.