We use technologies like cookies to store and/or access device information. We do this to improve browsing experience and to show (non-) personalized ads. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Техническое хранение или доступ необходимы для законной цели хранения предпочтений, которые не запрошены подписчиком или пользователем.
The technical storage or access that is used exclusively for statistical purposes.
Техническое хранилище или доступ, который используется исключительно для анонимных статистических целей. Без повестки в суд, добровольного согласия со стороны вашего интернет-провайдера или дополнительных записей от третьей стороны информация, хранящаяся или полученная только для этой цели, обычно не может быть использована для вашей идентификации.
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
Hardware Wallet Firmware Update: When to Update and When to Wait
A hardware wallet is supposed to sit in a drawer and stay out of your way. Most of the time, that is exactly what it does—until its companion app tells you that a hardware wallet firmware update is available. That is where people tend to make opposite mistakes: some stay on firmware with documented vulnerabilities for years because “it still works,” while others panic over every “urgent update” email, click a link, install a fake app, and hand their seed phrase directly to scammers.
In this guide, we’ll look at what actually happens during a firmware update, what happens to your seed if the device fails halfway through, which vulnerabilities vendors fixed through firmware in recent years, and why sometimes installing the latest firmware is not enough. At the end, you’ll have a practical decision process: when to update right away, when it makes sense to wait a week or two, and when it is better to leave the device alone until you actually need it.
What firmware is and what it controls
Firmware is the low-level system software that acts as the operating system of a hardware wallet. It controls cryptographic randomness, key generation and use, transaction parsing, what the device shows on its screen, and the signing process after you approve an action. The exact architecture differs from one model to another, but firmware determines a large part of how the device behaves.
That leads to an important point: a Secure Element does not make firmware irrelevant. Different wallets draw the trust boundary differently. Some security-critical logic may run inside a protected chip, while other parts run on the main microcontroller. Compromised firmware can still manipulate what the device displays, bias randomness, or misuse operations that are legitimately allowed to access key material. A Secure Element can limit certain classes of attacks, but it does not replace trust in the boot chain or in the source of the firmware itself.
That is why a hardware wallet firmware update is a double-edged process. It is the channel vendors use to deliver security fixes, but it is also the channel through which the code you trust with your keys changes. The practical question is not simply “should I update?” It is where the release came from, what exactly it changes, and whether you need to act immediately.
How a hardware wallet firmware update works internally
Modern hardware wallets use a chain of trust during boot. The vendor cryptographically signs a firmware release, and the device verifies that signature before allowing the code to run. The exact implementation depends on the architecture. On modern Trezor devices, for example, the immutable root of trust is the boardloader, while the bootloader itself can be updated. So the simplified rule that “the bootloader is always immutable” does not apply to every hardware wallet.
The overall idea is similar across major vendors, but the details differ:
Another protection is anti-rollback: preventing a device from being downgraded to a version that is already known to be vulnerable. If release N fixes a serious flaw, an attacker should not have an easy way to convince you to “go back to a more stable older version” that still contains the bug. Blockstream enabled anti-rollback in Jade firmware 1.0.38 after fixing a real vulnerability in earlier releases.
What happens to your seed during an update
During a normal update, your seed and your addresses should not change. Firmware updates the system software running on the device; it does not move or recreate your wallet on the blockchain. Once the update finishes normally, you continue using the same keys, addresses, and balances.
But an update can fail. If power is lost, the connection drops, or something crashes mid-process, some devices may wipe their internal state and require recovery. Your coins do not disappear: they remain on the blockchain, and access can be restored from the correct seed phrase. The real problem begins when the backup is missing, incomplete, or written down incorrectly.
Why updates matter: security fixes from 2025–2026
Security research usually follows responsible disclosure: a researcher reports a vulnerability privately, gives the vendor time to fix it, and technical details are published later—either after the patch ships or after an agreed disclosure window. That means an old firmware release can eventually go from “battle-tested” to a documented target with known attack conditions.
Blockstream Jade, November 2025. Security researchers at DARKNAVY found a buffer overflow in the
register_descriptorRPC command, which had been introduced in firmware 1.0.24. On versions 1.0.24–1.0.35, malware running on a connected computer or phone could crash a Jade and, under certain conditions, achieve limited code execution. For 1.0.36, Blockstream confirmed the crash condition but did not claim a known code-execution path. QR-only use without that interface was not affected. Blockstream confirmed the issue within 24 hours of receiving the full report, released 1.0.37 with the fix, and then 1.0.38 with anti-rollback. The company said it found no evidence of real-world exploitation.Trezor Safe 3, March 2025. Ledger Donjon publicly demonstrated a voltage-glitching attack against the TRZ32F429 microcontroller. With physical access to a device before it reaches the user, the technique could bypass parts of the supply-chain protections and modify code on the main microcontroller while preserving the appearance of an authentic device. Trezor Safe 5 was not affected by this specific issue because it uses the newer STM32U5, which is more resilient to this class of attack. The key point is that this was an advanced physical attack scenario, not a remote internet exploit against every Safe 3.
Trezor Safe 7, June 2026. Ledger Donjon used a laser fault-injection attack against TROPIC01 in a lab and was able to bypass part of the chip’s firmware-signature verification under carefully controlled conditions. Tropic Square later described additional defense-in-depth measures and prepared a new silicon revision. But there is an equally important second half to the story: Trezor said the attack does not give an attacker the PIN, wallet backup, or access to funds, and Safe 7 owners were not asked to take urgent action. It is a good example of why security disclosures need to be read in full rather than reduced to a headline about a “signature verification bypass.”
COLDCARD, July 2026. This case had real-world consequences. Because of a firmware integration bug, affected versions could use a weak software PRNG—a pseudorandom number generator—during new seed generation instead of the intended hardware source of randomness. Attackers were able to recover weakened private keys offline and steal real funds. Coinkite released fixed firmware, but emphasized one critical point: updating the firmware does not repair a seed that was already created with insufficient entropy. If a seed falls into the affected category, the funds need to be migrated to a completely new, safely generated seed. We cover the incident in detail in our separate article on how COLDCARD was compromised and why affected seeds need to be migrated.
This is an important limit to the rule “install the patch and the problem is solved.” Sometimes the update only fixes how the device behaves from that point forward, while something created by the old version remains unsafe. After a serious security advisory, do not stop at the new version number. Read the vendor’s instructions and check whether you also need to replace a seed, key, PIN, or another secret that already exists.
There is also a classic historical example. In 2018, researcher Saleem Rashid demonstrated a firmware-substitution attack against the Ledger Nano S, and Ledger addressed the issue in firmware 1.4.1. Vulnerabilities can be discovered years after a device launches, and firmware updates remain the main way to deliver software fixes to hardware that is already in users’ hands.
Why you should not install every release on day one
There is a valid argument on the other side too: not every update is a security fix. A new release may add features, redesign the interface, or change part of the device’s internal logic. Sometimes those changes matter more than a routine changelog suggests.
The best-known example is Ledger Recover. In May 2023, Ledger announced the upcoming recovery service and added the required support in Ledger OS 2.2.1 for the Nano X. After a strong community reaction, the company delayed the launch, published additional technical material, and ultimately launched Ledger Recover in October 2023. The service remained optional: users have to sign up for it separately and approve the process on the device.
When enabled, the Secure Element encrypts the material used to recover the Secret Recovery Phrase, splits it into three encrypted fragments, and sends them through protected channels to three providers—Ledger, Coincover, and EscrowTech. Recovery is tied to identity verification. Simply installing the firmware does not automatically send your seed anywhere, but Recover made one trust boundary much more visible to many users: vendor-signed firmware can implement new operations involving secret material inside the Secure Element after the user authorizes them.
That was the core of the controversy. Earlier Ledger communication had often been understood to mean that the seed could never leave the Secure Element in principle. During the Recover debate, the company clarified that the firmware users trust had always been part of that security model. The broader lesson goes beyond one brand: a major feature release can change the trust model of a device even when it does not fix a vulnerability.
That is why waiting a week or two after a major feature release can make sense. It gives early bug reports, GitHub discussions, and vendor explanations time to appear. If the release notes do not contain a critical security fix and your device is working normally, waiting a few days usually costs you nothing. Security releases and feature releases should not be treated the same way.
Fake updates: why the source matters more than the version number
Even the best secure boot implementation cannot help if a user is tricked into installing a fake companion app and typing the seed phrase into it. That is why phishing “updates” remain one of the most practical ways to attack hardware-wallet owners. A scammer does not need to break a Secure Element if the victim hands over the recovery secret voluntarily. We explain this attack pattern in more detail in our article on crypto phishing and fake emails that look legitimate.
September 2025, Blockstream Jade. Jade owners began receiving emails pretending to come from Blockstream and claiming that an urgent firmware update was required. The messages looked convincing and included version numbers and branded design. After public warnings, Blockstream confirmed that it does not email users firmware files or update links and does not ask for a recovery phrase. The company did not report confirmed Jade compromises from that campaign.
November 2023, fake Ledger Live in the Microsoft Store. A fraudulent app called Ledger Live Web3 appeared in Microsoft’s store, imitated the real interface, and asked users to enter 24 words “to restore access.” Microsoft removed it after ZachXBT raised the alarm on November 5, but by then addresses associated with the scam had received at least about $768,000 in stolen crypto.
April 2026, fake Ledger app in the Mac App Store. A malicious app passed Apple’s review process and, between April 7 and April 13, was linked to roughly $9.5 million in stolen assets from more than 50 victims. The mechanism was the same: during “setup,” users were asked to enter their 24-word recovery phrase. No Ledger device had to be hacked. The attackers only needed the seed.
The practical rules are simple:
Dark Skippy: what malicious firmware can do
A good illustration of how dangerous malicious firmware can be is Dark Skippy, a proof of concept published in August 2024 by Lloyd Fournier, Nick Farrow, and Robin Linus.
When a Bitcoin transaction is signed, the signer uses a one-time value called a nonce. In Dark Skippy, malicious firmware constructs that nonce in a way that covertly encodes fragments of secret entropy associated with a 12-word seed phrase inside the signatures. Those signatures are public, so an attacker can observe them on-chain, apply a specialized algorithm to recover the weak nonces, and reconstruct the secret. In the basic demonstration, two signatures are enough.
The disturbing part is that the transactions look normal, and the seed does not have to have been generated on the compromised device. Importing the seed and signing the required transactions with malicious firmware can be enough. There are no public reports of Dark Skippy being used against real users, but the technique demonstrates why firmware authenticity matters just as much as protecting the private key in storage. We also cover device checks, official software, and first-time setup in our first 30 minutes with a hardware wallet checklist.
One way to reduce this class of risk is through anti-exfil protocols. BitBox02 uses a mechanism called anti-klepto: the nonce is created with input from both the hardware wallet and the companion app, so the signer cannot unilaterally choose a value and quietly encode a secret into it. Jade also supports anti-exfil in certain signing flows, although that is not a universal guarantee for every possible signing path.
The practical takeaway is straightforward: an unofficial firmware file does not become safe just because it claims to be the latest version. If you cannot verify the release through the vendor’s official channel, do not install it.
The right firmware update process, step by step
Regardless of the brand, a safe update process looks broadly similar.
When to update, when to wait, and when to leave the device alone
Here is a quick reference for the most common situations:
There is also a different model: Tangem uses immutable firmware. The code is written to the chip during manufacturing and cannot be updated after the card is produced. That removes the post-sale firmware-update channel entirely, along with some of the risks that come with future firmware delivery. The trade-off is equally clear: if a serious flaw is discovered in code that is already on the card, it cannot be fixed with a normal patch on that existing card. This is not automatically “better” or “worse”; it is a different security trade-off.
Conclusion
After the security incidents of 2025–2026, the simple advice “always update immediately” or “never touch stable firmware” is no longer good enough. Jade showed why security fixes should not be ignored; COLDCARD showed that a firmware bug can lead to real losses and that a patch does not always repair a seed that was already generated; fake Ledger apps showed that the correct version number means nothing if the software came from the wrong source.
So the rule for a hardware wallet firmware update is straightforward. If the release fixes a vulnerability, verify it through an official channel and update without unnecessary delay. If the vendor says an old seed or key may already be compromised, follow the full migration process rather than installing the firmware and stopping there. If it is a major feature release with no urgent security fix, waiting a week or two gives you time to see real bug reports and clarifications.
For a wallet that spends most of its time offline, it is better to update well before planned use rather than five minutes before an important transfer. Before every update, verify your backup, and open the release only through the vendor’s official app or website.
One rule has not changed at all: never type your seed phrase into a computer or smartphone “to update the firmware.” A legitimate firmware update does not need it. If software asks for 12 or 24 words, the problem is no longer the firmware version—you are dealing with phishing or malicious software.
We follow the same routine ourselves: we do not delay security releases without a reason, we give major feature releases a few days for early feedback, and we verify the backup before updating even when we are “sure everything is fine.” In this area, the best outcome is for the process to remain boring maintenance rather than turn into a recovery story.
Related Posts
Hardware Wallet vs Exchange: Where Is It Actually Safer to Store Crypto?
Cryptocurrencies often gets stored on an exchange simply because it’s convenient. But in practice, that’s not storage — it’s trusting your funds to an exchange that controls the private keys. Sometimes that works for years. Sometimes it lasts until the first incident. Even large exchanges can be hacked: in February 2025, the FBI officially linked …
Will stablecoins replace traditional money? Where it’s already happening — and why not everywhere
A few years ago, stablecoins were mostly a topic for crypto enthusiasts. Today, they increasingly come up in conversations among freelancers, business owners, and people sending money to family abroad. Some headlines make it sound as if stablecoins have already replaced banks and the whole world is paying with digital dollars. The reality is much …
Using a Smartphone as a Cold Wallet: Why It’s a Bad Idea
Why is using a smartphone as a cold wallet a bad idea? We look at the numbers, reports, and CVE records to explain why ZachXBT’s advice to replace a hardware wallet with a dedicated iPhone does not hold up from an architectural perspective. On July 16, 2026, on-chain investigator ZachXBT wrote on Telegram that all …
Ledger Flex setup: step-by-step guide from unboxing to your first transaction
Ledger Flex setup is best done step by step, from checking the box contents to completing your first test transaction. If you have just received a Ledger Flex, this guide will walk you through installing Ledger Wallet, running Genuine Check, creating a new wallet, writing down your Secret Recovery Phrase, and setting up your recovery …