{"id":73204,"date":"2026-09-25T20:32:00","date_gmt":"2026-09-25T17:32:00","guid":{"rendered":"https:\/\/lwallet.com.ua\/?p=73204"},"modified":"2026-09-25T20:32:00","modified_gmt":"2026-09-25T17:32:00","slug":"hardware-wallet-firmware-update","status":"publish","type":"post","link":"https:\/\/lwallet.com.ua\/en\/hardware-wallet-firmware-update\/","title":{"rendered":"Hardware Wallet Firmware Update: When to Update and When to Wait"},"content":{"rendered":"\r\n\r\n\r\n<p class=\"wp-block-paragraph\"><strong>A hardware wallet is supposed to sit in a drawer and stay out of your way.<\/strong> Most of the time, that is exactly what it does\u2014until its companion app tells you that a <strong>hardware wallet firmware update<\/strong> is available. That is where people tend to make opposite mistakes: some stay on firmware with documented vulnerabilities for years because \u201cit still works,\u201d while others panic over every \u201curgent update\u201d email, click a link, install a fake app, and hand their seed phrase directly to scammers.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">In this guide, we\u2019ll look at <strong>what actually happens during a firmware update<\/strong>, what happens to your seed if the device fails halfway through, which vulnerabilities vendors fixed through firmware in recent years, and why sometimes installing the latest firmware is not enough. At the end, you\u2019ll have a practical decision process: when to update right away, when it makes sense to wait a week or two, and when it is better to leave the device alone until you actually need it.<\/p>\r\n\r\n\r\n\r\n<h2 class=\"nm-block-heading wp-block-heading\">What firmware is and what it controls<\/h2>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Firmware is the <strong>low-level system software that acts as the operating system of a hardware wallet<\/strong>. It controls cryptographic randomness, key generation and use, transaction parsing, what the device shows on its screen, and the signing process after you approve an action. The exact architecture differs from one model to another, but firmware determines a large part of how the device behaves.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">That leads to an important point: <strong>a Secure Element does not make firmware irrelevant<\/strong>. Different wallets draw the trust boundary differently. Some security-critical logic may run inside a protected chip, while other parts run on the main microcontroller. Compromised firmware can still manipulate what the device displays, bias randomness, or misuse operations that are legitimately allowed to access key material. A Secure Element can limit certain classes of attacks, but it does not replace trust in the boot chain or in the source of the firmware itself.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">That is why a hardware wallet firmware update is a double-edged process. <strong>It is the channel vendors use to deliver security fixes, but it is also the channel through which the code you trust with your keys changes.<\/strong> The practical question is not simply \u201cshould I update?\u201d It is where the release came from, what exactly it changes, and whether you need to act immediately.<\/p>\r\n\r\n\r\n\r\n<h2 class=\"nm-block-heading wp-block-heading\">How a hardware wallet firmware update works internally<\/h2>\r\n\r\n\r\n<div class=\"wp-block-image wp-block-image size-large is-style-default blog-img\">\r\n<figure class=\"aligncenter\"><img decoding=\"async\" width=\"1024\" height=\"573\" src=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-firmware-update-for-hardware-wallet-24-09-2026-content-pic2-1024x573.jpg\" alt=\"Hardware wallet firmware update \u2014 digital signature verification\" class=\"wp-image-73180\" title=\"\" srcset=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-firmware-update-for-hardware-wallet-24-09-2026-content-pic2-1024x573.jpg 1024w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-firmware-update-for-hardware-wallet-24-09-2026-content-pic2-300x168.jpg 300w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-firmware-update-for-hardware-wallet-24-09-2026-content-pic2-1536x860.jpg 1536w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-firmware-update-for-hardware-wallet-24-09-2026-content-pic2-766x429.jpg 766w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-firmware-update-for-hardware-wallet-24-09-2026-content-pic2-349x195.jpg 349w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-firmware-update-for-hardware-wallet-24-09-2026-content-pic2-679x380.jpg 679w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-firmware-update-for-hardware-wallet-24-09-2026-content-pic2.jpg 1631w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\r\n<\/div>\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Modern hardware wallets use a <strong>chain of trust during boot<\/strong>. The vendor cryptographically signs a firmware release, and the device verifies that signature before allowing the code to run. The exact implementation depends on the architecture. On modern Trezor devices, for example, the immutable root of trust is the boardloader, while the bootloader itself can be updated. So the simplified rule that \u201cthe bootloader is always immutable\u201d does not apply to every hardware wallet.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">The overall idea is similar across major vendors, but the details differ:<\/p>\r\n\r\n\r\n\r\n<ul class=\"nm-block-list wp-block-list\">\r\n<li><strong>Ledger<\/strong> updates through Ledger Wallet, formerly Ledger Live. The app performs a Genuine Check, where the device\u2019s Secure Element cryptographically proves its authenticity to Ledger\u2019s servers. Separately, the Secure Boot chain controls which code is allowed to execute on the device.<\/li>\r\n\r\n\r\n\r\n<li><strong>Trezor<\/strong> updates through Trezor Suite, while the device\u2019s own boot chain verifies firmware. Unofficial firmware triggers clear warnings, and on some models or in certain scenarios, installing custom firmware can also wipe device data. The exact behavior depends on the model.<\/li>\r\n\r\n\r\n\r\n<li><strong>Keystone and other devices that update via microSD<\/strong> let you move the firmware file without maintaining a direct USB connection during the update. On supported Keystone models, the official process also lets you compare the file\u2019s SHA-256 hash before installing it. We have a separate <a href=\"https:\/\/lwallet.com.ua\/en\/how-to-update-keystone-3-pro-firmware\/\">step-by-step guide to updating Keystone 3 Pro firmware via microSD or USB<\/a>.<\/li>\r\n\r\n\r\n\r\n<li><strong>Blockstream Jade<\/strong> updates through Blockstream\u2019s official app or official firmware files. Blockstream has also explicitly warned users that it does not email firmware files or \u201curgent update\u201d download links.<\/li>\r\n<\/ul>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Another protection is <strong>anti-rollback<\/strong>: preventing a device from being downgraded to a version that is already known to be vulnerable. If release N fixes a serious flaw, an attacker should not have an easy way to convince you to \u201cgo back to a more stable older version\u201d that still contains the bug. Blockstream enabled anti-rollback in Jade firmware 1.0.38 after fixing a real vulnerability in earlier releases.<\/p>\r\n\r\n\r\n\r\n<h2 class=\"nm-block-heading wp-block-heading\">What happens to your seed during an update<\/h2>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\"><strong>During a normal update, your seed and your addresses should not change.<\/strong> Firmware updates the system software running on the device; it does not move or recreate your wallet on the blockchain. Once the update finishes normally, you continue using the same keys, addresses, and balances.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">But an update can fail. If power is lost, the connection drops, or something crashes mid-process, some devices may wipe their internal state and require recovery. <strong>Your coins do not disappear: they remain on the blockchain, and access can be restored from the correct seed phrase.<\/strong> The real problem begins when the backup is missing, incomplete, or written down incorrectly.<\/p>\r\n\r\n\r\n<p>[vc_message color=&#8221;warning&#8221; message_box_style=&#8221;classic&#8221; message_box_color=&#8221;alert-warning&#8221; style=&#8221;rounded&#8221;]<\/p>\r\n<p>Before updating, physically check that your seed backup exists, is readable, and actually belongs to this wallet. Do not rely on \u201cI\u2019m pretty sure it\u2019s somewhere.\u201d Take it out and verify it.<\/p>\r\n<p>[\/vc_message]<\/p>\r\n\r\n\r\n<h2 class=\"nm-block-heading wp-block-heading\">Why updates matter: security fixes from 2025\u20132026<\/h2>\r\n\r\n\r\n<div class=\"wp-block-image wp-block-image size-large is-style-default blog-img\">\r\n<figure class=\"aligncenter\"><img decoding=\"async\" width=\"1024\" height=\"573\" src=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-firmware-update-for-hardware-wallet-24-09-2026-content-pic3-1024x573.jpg\" alt=\"Hardware wallet firmware security fixes in 2025\u20132026\" class=\"wp-image-73183\" title=\"\" srcset=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-firmware-update-for-hardware-wallet-24-09-2026-content-pic3-1024x573.jpg 1024w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-firmware-update-for-hardware-wallet-24-09-2026-content-pic3-300x168.jpg 300w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-firmware-update-for-hardware-wallet-24-09-2026-content-pic3-766x429.jpg 766w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-firmware-update-for-hardware-wallet-24-09-2026-content-pic3-1536x860.jpg 1536w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-firmware-update-for-hardware-wallet-24-09-2026-content-pic3-349x195.jpg 349w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-firmware-update-for-hardware-wallet-24-09-2026-content-pic3-679x380.jpg 679w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-firmware-update-for-hardware-wallet-24-09-2026-content-pic3.jpg 1631w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\r\n<\/div>\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Security research usually follows responsible disclosure: a researcher reports a vulnerability privately, gives the vendor time to fix it, and technical details are published later\u2014either after the patch ships or after an agreed disclosure window. <strong>That means an old firmware release can eventually go from \u201cbattle-tested\u201d to a documented target with known attack conditions.<\/strong><\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\"><strong>Blockstream Jade, November 2025.<\/strong> Security researchers at DARKNAVY found a buffer overflow in the <code>register_descriptor<\/code> RPC command, which had been introduced in firmware 1.0.24. On versions 1.0.24\u20131.0.35, malware running on a connected computer or phone could crash a Jade and, under certain conditions, achieve limited code execution. For 1.0.36, Blockstream confirmed the crash condition but did not claim a known code-execution path. QR-only use without that interface was not affected. Blockstream confirmed the issue within 24 hours of receiving the full report, released 1.0.37 with the fix, and then 1.0.38 with anti-rollback. The company said it found no evidence of real-world exploitation.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\"><strong>Trezor Safe 3, March 2025.<\/strong> Ledger Donjon publicly demonstrated a voltage-glitching attack against the TRZ32F429 microcontroller. With physical access to a device before it reaches the user, the technique could bypass parts of the supply-chain protections and modify code on the main microcontroller while preserving the appearance of an authentic device. Trezor Safe 5 was not affected by this specific issue because it uses the newer STM32U5, which is more resilient to this class of attack. The key point is that this was an advanced physical attack scenario, not a remote internet exploit against every Safe 3.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\"><strong>Trezor Safe 7, June 2026.<\/strong> Ledger Donjon used a laser fault-injection attack against TROPIC01 in a lab and was able to bypass part of the chip\u2019s firmware-signature verification under carefully controlled conditions. Tropic Square later described additional defense-in-depth measures and prepared a new silicon revision. But there is an equally important second half to the story: Trezor said the attack <strong>does not give an attacker the PIN, wallet backup, or access to funds<\/strong>, and Safe 7 owners were not asked to take urgent action. It is a good example of why security disclosures need to be read in full rather than reduced to a headline about a \u201csignature verification bypass.\u201d<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\"><strong>COLDCARD, July 2026.<\/strong> This case had real-world consequences. Because of a firmware integration bug, affected versions could use a weak software PRNG\u2014a pseudorandom number generator\u2014during new seed generation instead of the intended hardware source of randomness. Attackers were able to recover weakened private keys offline and steal real funds. Coinkite released fixed firmware, but emphasized one critical point: <strong>updating the firmware does not repair a seed that was already created with insufficient entropy<\/strong>. If a seed falls into the affected category, the funds need to be migrated to a completely new, safely generated seed. We cover the incident in detail in our separate article on <a href=\"https:\/\/lwallet.com.ua\/en\/how-coldcard-was-hacked\/\">how COLDCARD was compromised and why affected seeds need to be migrated<\/a>.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">This is an important limit to the rule \u201cinstall the patch and the problem is solved.\u201d Sometimes the update only fixes how the device behaves from that point forward, while <strong>something created by the old version remains unsafe<\/strong>. After a serious security advisory, do not stop at the new version number. Read the vendor\u2019s instructions and check whether you also need to replace a seed, key, PIN, or another secret that already exists.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">There is also a classic historical example. In 2018, researcher Saleem Rashid demonstrated a firmware-substitution attack against the Ledger Nano S, and Ledger addressed the issue in firmware 1.4.1. <strong>Vulnerabilities can be discovered years after a device launches, and firmware updates remain the main way to deliver software fixes to hardware that is already in users\u2019 hands.<\/strong><\/p>\r\n\r\n\r\n\r\n<h2 class=\"nm-block-heading wp-block-heading\">Why you should not install every release on day one<\/h2>\r\n\r\n\r\n<div class=\"wp-block-image wp-block-image size-large is-style-default blog-img\">\r\n<figure class=\"aligncenter\"><img decoding=\"async\" width=\"1024\" height=\"573\" src=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-firmware-update-for-hardware-wallet-24-09-2026-content-pic4-1024x573.jpg\" alt=\"Why you may want to wait before installing a feature firmware release\" class=\"wp-image-73186\" title=\"\" srcset=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-firmware-update-for-hardware-wallet-24-09-2026-content-pic4-1024x573.jpg 1024w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-firmware-update-for-hardware-wallet-24-09-2026-content-pic4-300x168.jpg 300w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-firmware-update-for-hardware-wallet-24-09-2026-content-pic4-1536x860.jpg 1536w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-firmware-update-for-hardware-wallet-24-09-2026-content-pic4-766x429.jpg 766w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-firmware-update-for-hardware-wallet-24-09-2026-content-pic4-349x195.jpg 349w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-firmware-update-for-hardware-wallet-24-09-2026-content-pic4-679x380.jpg 679w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-firmware-update-for-hardware-wallet-24-09-2026-content-pic4.jpg 1631w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\r\n<\/div>\r\n\r\n\r\n<p class=\"wp-block-paragraph\">There is a valid argument on the other side too: <strong>not every update is a security fix<\/strong>. A new release may add features, redesign the interface, or change part of the device\u2019s internal logic. Sometimes those changes matter more than a routine changelog suggests.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">The best-known example is <strong>Ledger Recover<\/strong>. In May 2023, Ledger announced the upcoming recovery service and added the required support in Ledger OS 2.2.1 for the Nano X. After a strong community reaction, the company delayed the launch, published additional technical material, and ultimately launched Ledger Recover in October 2023. The service remained optional: users have to sign up for it separately and approve the process on the device.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">When enabled, the Secure Element encrypts the material used to recover the Secret Recovery Phrase, splits it into three encrypted fragments, and sends them through protected channels to three providers\u2014Ledger, Coincover, and EscrowTech. Recovery is tied to identity verification. <strong>Simply installing the firmware does not automatically send your seed anywhere<\/strong>, but Recover made one trust boundary much more visible to many users: vendor-signed firmware can implement new operations involving secret material inside the Secure Element after the user authorizes them.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">That was the core of the controversy. Earlier Ledger communication had often been understood to mean that the seed could never leave the Secure Element in principle. During the Recover debate, the company clarified that the firmware users trust had always been part of that security model. <strong>The broader lesson goes beyond one brand: a major feature release can change the trust model of a device even when it does not fix a vulnerability.<\/strong><\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">That is why waiting a week or two after a major feature release can make sense. It gives early bug reports, GitHub discussions, and vendor explanations time to appear. If the release notes do not contain a critical security fix and your device is working normally, waiting a few days usually costs you nothing. <strong>Security releases and feature releases should not be treated the same way.<\/strong><\/p>\r\n\r\n\r\n\r\n<h2 class=\"nm-block-heading wp-block-heading\">Fake updates: why the source matters more than the version number<\/h2>\r\n\r\n\r\n<div class=\"wp-block-image wp-block-image size-large is-style-default blog-img\">\r\n<figure class=\"aligncenter\"><img decoding=\"async\" width=\"1024\" height=\"573\" src=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-firmware-update-for-hardware-wallet-24-09-2026-content-pic5-1024x573.jpg\" alt=\"Fake firmware update and phishing download warning\" class=\"wp-image-73189\" title=\"\" srcset=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-firmware-update-for-hardware-wallet-24-09-2026-content-pic5-1024x573.jpg 1024w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-firmware-update-for-hardware-wallet-24-09-2026-content-pic5-766x429.jpg 766w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-firmware-update-for-hardware-wallet-24-09-2026-content-pic5-300x168.jpg 300w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-firmware-update-for-hardware-wallet-24-09-2026-content-pic5-1536x860.jpg 1536w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-firmware-update-for-hardware-wallet-24-09-2026-content-pic5-349x195.jpg 349w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-firmware-update-for-hardware-wallet-24-09-2026-content-pic5-679x380.jpg 679w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-firmware-update-for-hardware-wallet-24-09-2026-content-pic5.jpg 1631w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\r\n<\/div>\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Even the best secure boot implementation cannot help if a user is tricked into <strong>installing a fake companion app and typing the seed phrase into it<\/strong>. That is why phishing \u201cupdates\u201d remain one of the most practical ways to attack hardware-wallet owners. A scammer does not need to break a Secure Element if the victim hands over the recovery secret voluntarily. We explain this attack pattern in more detail in our article on <a href=\"https:\/\/lwallet.com.ua\/en\/crypto-phishing\/\">crypto phishing and fake emails that look legitimate<\/a>.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\"><strong>September 2025, Blockstream Jade.<\/strong> Jade owners began receiving emails pretending to come from Blockstream and claiming that an urgent firmware update was required. The messages looked convincing and included version numbers and branded design. After public warnings, Blockstream confirmed that it does not email users firmware files or update links and does not ask for a recovery phrase. The company did not report confirmed Jade compromises from that campaign.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\"><strong>November 2023, fake Ledger Live in the Microsoft Store.<\/strong> A fraudulent app called Ledger Live Web3 appeared in Microsoft\u2019s store, imitated the real interface, and asked users to enter 24 words \u201cto restore access.\u201d Microsoft removed it after ZachXBT raised the alarm on November 5, but by then addresses associated with the scam had received at least about $768,000 in stolen crypto.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\"><strong>April 2026, fake Ledger app in the Mac App Store.<\/strong> A malicious app passed Apple\u2019s review process and, between April 7 and April 13, was linked to roughly $9.5 million in stolen assets from more than 50 victims. The mechanism was the same: during \u201csetup,\u201d users were asked to enter their 24-word recovery phrase. No Ledger device had to be hacked. The attackers only needed the seed.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">The practical rules are simple:<\/p>\r\n\r\n\r\n\r\n<ul class=\"nm-block-list wp-block-list\">\r\n<li><strong>Do not install firmware from an email attachment, a messenger message, or a random download link.<\/strong> If you receive a release notification, open the vendor\u2019s official app or website yourself.<\/li>\r\n\r\n\r\n\r\n<li><strong>Download the companion app through the vendor\u2019s official website.<\/strong> If the manufacturer uses the App Store or Google Play for a mobile version, follow the link from the official site instead of searching for the app name and trusting the first result.<\/li>\r\n\r\n\r\n\r\n<li><strong>A normal firmware update does not require you to type your seed phrase into a computer or phone.<\/strong> If software asks for 12 or 24 words, stop and do not enter them.<\/li>\r\n<\/ul>\r\n\r\n\r\n<p>[vc_message color=&#8221;warning&#8221; message_box_style=&#8221;classic&#8221; message_box_color=&#8221;alert-warning&#8221; style=&#8221;rounded&#8221;]<\/p>\r\n<p>A personalized email is not proof that it is genuine. After Ledger\u2019s 2020 customer-data breach, names, email addresses, and other contact details from many buyers were used for targeted phishing for years afterward.<\/p>\r\n<p>[\/vc_message]<\/p>\r\n\r\n\r\n<h2 class=\"nm-block-heading wp-block-heading\">Dark Skippy: what malicious firmware can do<\/h2>\r\n\r\n\r\n<div class=\"wp-block-image wp-block-image size-large is-style-default blog-img\">\r\n<figure class=\"aligncenter\"><img decoding=\"async\" width=\"1024\" height=\"573\" src=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-firmware-update-for-hardware-wallet-24-09-2026-content-pic6-1024x573.jpg\" alt=\"Dark Skippy \u2014 the risk of malicious hardware wallet firmware\" class=\"wp-image-73192\" title=\"\" srcset=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-firmware-update-for-hardware-wallet-24-09-2026-content-pic6-1024x573.jpg 1024w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-firmware-update-for-hardware-wallet-24-09-2026-content-pic6-1536x860.jpg 1536w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-firmware-update-for-hardware-wallet-24-09-2026-content-pic6-766x429.jpg 766w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-firmware-update-for-hardware-wallet-24-09-2026-content-pic6-300x168.jpg 300w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-firmware-update-for-hardware-wallet-24-09-2026-content-pic6-349x195.jpg 349w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-firmware-update-for-hardware-wallet-24-09-2026-content-pic6-679x380.jpg 679w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-firmware-update-for-hardware-wallet-24-09-2026-content-pic6.jpg 1631w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\r\n<\/div>\r\n\r\n\r\n<p class=\"wp-block-paragraph\">A good illustration of how dangerous malicious firmware can be is <strong>Dark Skippy<\/strong>, a proof of concept published in August 2024 by Lloyd Fournier, Nick Farrow, and Robin Linus.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">When a Bitcoin transaction is signed, the signer uses a one-time value called a nonce. In Dark Skippy, malicious firmware constructs that nonce in a way that covertly encodes fragments of secret entropy associated with a <a href=\"https:\/\/lwallet.com.ua\/en\/seed-phrase\/\">12-word seed phrase<\/a> inside the signatures. Those signatures are public, so an attacker can observe them on-chain, apply a specialized algorithm to recover the weak nonces, and reconstruct the secret. <strong>In the basic demonstration, two signatures are enough.<\/strong><\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">The disturbing part is that the transactions look normal, and the seed does not have to have been generated on the compromised device. Importing the seed and signing the required transactions with malicious firmware can be enough. There are no public reports of Dark Skippy being used against real users, but the technique demonstrates why <strong>firmware authenticity matters just as much as protecting the private key in storage<\/strong>. We also cover device checks, official software, and first-time setup in our <a href=\"https:\/\/lwallet.com.ua\/en\/the-first-30-minutes-with-a-hardware-wallet-checklist\/\">first 30 minutes with a hardware wallet checklist<\/a>.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">One way to reduce this class of risk is through anti-exfil protocols. BitBox02 uses a mechanism called anti-klepto: the nonce is created with input from both the hardware wallet and the companion app, so the signer cannot unilaterally choose a value and quietly encode a secret into it. Jade also supports anti-exfil in certain signing flows, although that is not a universal guarantee for every possible signing path.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">The practical takeaway is straightforward: <strong>an unofficial firmware file does not become safe just because it claims to be the latest version.<\/strong> If you cannot verify the release through the vendor\u2019s official channel, do not install it.<\/p>\r\n\r\n\r\n\r\n<h2 class=\"nm-block-heading wp-block-heading\">The right firmware update process, step by step<\/h2>\r\n\r\n\r\n<div class=\"wp-block-image wp-block-image size-large is-style-default blog-img\">\r\n<figure class=\"aligncenter\"><img decoding=\"async\" width=\"1024\" height=\"573\" src=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-firmware-update-for-hardware-wallet-24-09-2026-content-pic7-1024x573.jpg\" alt=\"Safe hardware wallet firmware update process step by step\" class=\"wp-image-73196\" title=\"\" srcset=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-firmware-update-for-hardware-wallet-24-09-2026-content-pic7-1024x573.jpg 1024w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-firmware-update-for-hardware-wallet-24-09-2026-content-pic7-300x168.jpg 300w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-firmware-update-for-hardware-wallet-24-09-2026-content-pic7-1536x860.jpg 1536w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-firmware-update-for-hardware-wallet-24-09-2026-content-pic7-766x429.jpg 766w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-firmware-update-for-hardware-wallet-24-09-2026-content-pic7-679x380.jpg 679w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-firmware-update-for-hardware-wallet-24-09-2026-content-pic7-349x195.jpg 349w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-firmware-update-for-hardware-wallet-24-09-2026-content-pic7.jpg 1631w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\r\n<\/div>\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Regardless of the brand, a safe update process looks broadly similar.<\/p>\r\n\r\n\r\n\r\n<ol class=\"nm-block-list wp-block-list\">\r\n<li><strong>Verify your seed backup.<\/strong> Physically take it out and make sure it exists, is readable, and is complete. Do not photograph the words or type them into a computer. If the device offers an official backup-check feature that does not require a full recovery\u2014for example, Check wallet backup in Trezor\u2014use it.<\/li>\r\n\r\n\r\n\r\n<li><strong>Update the companion app from an official source.<\/strong> Install the current version of Ledger Wallet, Trezor Suite, or your vendor\u2019s official app first, then update the firmware. Do not get the software through a search ad or a random app-store listing.<\/li>\r\n\r\n\r\n\r\n<li><strong>Compare the version with the official release.<\/strong> Before installing, check the vendor\u2019s changelog or firmware page. For air-gapped devices, use only the official firmware file. If the vendor publishes a SHA-256 hash or another checksum, compare it.<\/li>\r\n\r\n\r\n\r\n<li><strong>Start the update and do not interrupt it.<\/strong> Do not unplug the cable, close the app, or let your laptop go to sleep. The device may reboot several times during the process; that can be normal.<\/li>\r\n\r\n\r\n\r\n<li><strong>Check the result.<\/strong> When the update is finished, confirm the firmware version on the device or in the official app. Addresses derived from the same seed and the same derivation path should not suddenly change after a normal firmware update.<\/li>\r\n\r\n\r\n\r\n<li><strong>If the device stops booting, do not type your seed into random software.<\/strong> Start with the vendor\u2019s official bootloader or recovery-mode instructions. If the device cannot be recovered, you can restore access on another compatible wallet using a verified backup.<\/li>\r\n<\/ol>\r\n\r\n\r\n<p>[vc_message color=&#8221;warning&#8221; message_box_style=&#8221;classic&#8221; message_box_color=&#8221;alert-warning&#8221; style=&#8221;rounded&#8221;]<\/p>\r\n<p>If anything during an \u201cupdate\u201d asks you to enter your seed phrase on a computer or smartphone, stop. A legitimate firmware update does not need those words.<\/p>\r\n<p>[\/vc_message]<\/p>\r\n\r\n\r\n<h2 class=\"nm-block-heading wp-block-heading\">When to update, when to wait, and when to leave the device alone<\/h2>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Here is a quick reference for the most common situations:<\/p>\r\n\r\n\r\n\r\n<figure class=\"wp-block-table\"><table><thead><tr><th>Situation<\/th><th>What to do<\/th><th>Why<\/th><\/tr><\/thead><tbody><tr><td>The release notes include a security fix, or the vendor explicitly tells users to update<\/td><td><strong>Verify the official release and update without unnecessary delay<\/strong><\/td><td>The vulnerability conditions may already be public, while the old release remains unpatched<\/td><\/tr><tr><td>The vendor warns that an existing seed, key, or another secret may already be compromised<\/td><td><strong>Do not stop at the firmware update\u2014follow the migration guide<\/strong><\/td><td>A patch can fix future device behavior without making an already compromised secret safe again<\/td><\/tr><tr><td>A major feature release adds new networks, a redesign, a major new function, or a new major version<\/td><td><strong>If there is no security urgency, wait 1\u20132 weeks<\/strong><\/td><td>Early bug reports, vendor clarifications, and real user experience will start to appear<\/td><\/tr><tr><td>The wallet is used only for long-term storage and is connected a few times per year<\/td><td><strong>Check for updates well before planned use<\/strong><\/td><td>An offline device has no constant remote attack surface, but you still want to know about current security advisories before signing a transaction<\/td><\/tr><tr><td>The update app came from a search ad, a random search result, or an unknown publisher in an app store<\/td><td><strong>Stop and open the vendor\u2019s official website manually<\/strong><\/td><td>Fake companion apps have repeatedly passed store review and stolen seed phrases<\/td><\/tr><tr><td>An email or messenger message contains a firmware file or pushes you to install an \u201curgent patch\u201d through a link<\/td><td><strong>Do not use the file or the link from the message<\/strong><\/td><td>Even if the security advisory itself is real, open the update through the official app or website<\/td><\/tr><tr><td>You have an important high-value transaction coming up<\/td><td><strong>Do not schedule an optional feature update for the same day<\/strong><\/td><td>Separating the update from the critical transaction reduces the chance that a failed update creates a last-minute problem<\/td><\/tr><\/tbody><\/table><\/figure>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">There is also a different model: <strong>Tangem uses immutable firmware<\/strong>. The code is written to the chip during manufacturing and cannot be updated after the card is produced. That removes the post-sale firmware-update channel entirely, along with some of the risks that come with future firmware delivery. The trade-off is equally clear: if a serious flaw is discovered in code that is already on the card, it cannot be fixed with a normal patch on that existing card. This is not automatically \u201cbetter\u201d or \u201cworse\u201d; it is a different security trade-off.<\/p>\r\n\r\n\r\n\r\n<h2 class=\"nm-block-heading wp-block-heading\">Conclusion<\/h2>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">After the security incidents of 2025\u20132026, the simple advice \u201calways update immediately\u201d or \u201cnever touch stable firmware\u201d is no longer good enough. <strong>Jade showed why security fixes should not be ignored; COLDCARD showed that a firmware bug can lead to real losses and that a patch does not always repair a seed that was already generated; fake Ledger apps showed that the correct version number means nothing if the software came from the wrong source.<\/strong><\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">So the rule for a hardware wallet firmware update is straightforward. If the release fixes a vulnerability, verify it through an official channel and <strong>update without unnecessary delay<\/strong>. If the vendor says an old seed or key may already be compromised, follow the full migration process rather than installing the firmware and stopping there. If it is a major feature release with no urgent security fix, waiting a week or two gives you time to see real bug reports and clarifications.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">For a wallet that spends most of its time offline, it is better to update well before planned use rather than five minutes before an important transfer. <strong>Before every update, verify your backup, and open the release only through the vendor\u2019s official app or website.<\/strong><\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">One rule has not changed at all: <strong>never type your seed phrase into a computer or smartphone \u201cto update the firmware.\u201d<\/strong> A legitimate firmware update does not need it. If software asks for 12 or 24 words, the problem is no longer the firmware version\u2014you are dealing with phishing or malicious software.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">We follow the same routine ourselves: we do not delay security releases without a reason, we give major feature releases a few days for early feedback, and we verify the backup before updating even when we are \u201csure everything is fine.\u201d In this area, the best outcome is for the process to remain boring maintenance rather than turn into a recovery story.<\/p>\r\n","protected":false},"excerpt":{"rendered":"<p>A hardware wallet is supposed to sit in a drawer and stay out of your way. Most of the time, that is exactly what it does\u2014until its companion app tells you that a hardware wallet firmware update is available. That is where people tend to make opposite mistakes: some stay on firmware with documented vulnerabilities &hellip;<\/p>\n","protected":false},"author":10,"featured_media":73178,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[633],"tags":[],"class_list":["post-73204","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-hardware-wallets"],"_links":{"self":[{"href":"https:\/\/lwallet.com.ua\/en\/wp-json\/wp\/v2\/posts\/73204","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lwallet.com.ua\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lwallet.com.ua\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lwallet.com.ua\/en\/wp-json\/wp\/v2\/users\/10"}],"replies":[{"embeddable":true,"href":"https:\/\/lwallet.com.ua\/en\/wp-json\/wp\/v2\/comments?post=73204"}],"version-history":[{"count":2,"href":"https:\/\/lwallet.com.ua\/en\/wp-json\/wp\/v2\/posts\/73204\/revisions"}],"predecessor-version":[{"id":73206,"href":"https:\/\/lwallet.com.ua\/en\/wp-json\/wp\/v2\/posts\/73204\/revisions\/73206"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/lwallet.com.ua\/en\/wp-json\/wp\/v2\/media\/73178"}],"wp:attachment":[{"href":"https:\/\/lwallet.com.ua\/en\/wp-json\/wp\/v2\/media?parent=73204"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lwallet.com.ua\/en\/wp-json\/wp\/v2\/categories?post=73204"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lwallet.com.ua\/en\/wp-json\/wp\/v2\/tags?post=73204"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}