matrixx (OP)
Newbie

Activity: 51
Merit: 0
|
 |
September 29, 2026, 07:16:11 AM |
|
Every time a new firmware update drops for a hardware wallet, I find myself second-guessing whether to install it or just leave the device alone.
On one hand, keeping an air-gapped device on an older, stable version that already does basic PSBT signing feels like the safest route. There is no risk of a bad release bricking the device, unexpected code changes, or unwanted features being introduced. If the device has never touched the internet and only signs raw transactions offline, it feels like "if it isn't broken, don't touch it."
On the other hand, security advisories and bug disclosures pop up occasionally, and ignoring patches could theoretically leave known vulnerabilities open to physical side-channel attacks or parsing bugs.
For those of you holding long term in cold storage, what is your actual routine here? Do you flash updates as soon as they roll out, wait a few weeks or months to see if other users report issues, or simply keep your signing device on its factory firmware until a transaction literally fails to build?
|
|
|
|
|
_act_
Legendary

Activity: 1764
Merit: 2003
|
 |
September 29, 2026, 07:25:16 AM |
|
Updating the firmware can be very important, that is the reason it is good to be following the recent updates. Some can be because of vulnerability and which should be updated as fast as possible.
But if the update is not because of any vulnerability, you can wait for sometime. If no one report bug or vulnerability, you can update it. It is good to use the latest firmware.
I also prefer wallets that are on airgapped devices than hardware wallet. I do not update wallet on an airgapped device fast until it is no more working, but which is very rare.
|
|
|
|
Darker45
Legendary

Activity: 3444
Merit: 2141
Spinly.io - Next-gen Crypto iGaming Platform
|
 |
September 29, 2026, 07:37:32 AM |
|
My hardware wallet funds are for long-term hodling, so I seldom plug my device to the computer. But when I do and there are updates waiting I'd install it.
I generally believe updates are necessary, but if you're worried about bad releases, and there's no urgent call to install the latest updates, I think it doesn't hurt to wait for a while to hear feedbacks from experts first.
As a crypto layman, I'd rather wait for advanced users to test updates first and locate bugs. Unless it's a critical emergency security patch like the one released by Coinkite in the middle of the Coldcard theft, I'd sit on it for a while.
|
░▄████████████▀▄ ▀▀▀▀▀▀▀▀▀▀▀▀▀▄██ ████████████░█▀ ████░▄▄▄███████▄ ████▄▄▄▄▄▄▄▄░▄██ ▀▀▀▀▀▀▀▀████░███ ████████████░███ ████████████░█▀ | ░▄████████████▀▄ ▀▀▀▀▀▀▀▀▀▀▀▀▀▄██ ████████████░███ ████████████░███ ████████████░███ ████▄▄▄▄████░██▀ ████▀▀▀▀▀▀▀▀░▀ ████░█▀ | ░▄████████████▀▄ ▀▀▀▀▀▀▀▀▀▀▀▀▀▄██ ████████████░█▀ █████████░▄▄▄ █████████░███ ░▄░██████░██▀██▄ ▀▀░██████░▀██▄██ ████████████░█▀ | ░▄███████▀░▄██▀▄ ▀▀▀▀▀▀▀▀██▀▀▀▄██ ████████████░███ ████████████░███ ██░▄░███████░███ ██░█░███████░███ ████████████░███ ████████████░█▀ | ░▄██████▀▄ ▀▀▀▀▀▀▀▄██ ██████░███ ██████░███ ██████░███ ██████░███████▀▄ ██████░▀▀▀▀▀▀▄██ ████████████░█▀ | ░▄████▀██▄█████▀▄ ▀▀▀▀▀███▀▀▀▀▀▀▄██ █████████████░███ █████░█░█████░███ █████░▀░█████░███ █████████████░█▀ ██████████░▄▄▄ ██████████░█▀ | ..... Next−Gen Crypto iGaming ..... | | | | | | | Play now |
|
|
|
5W-KILO
Full Member
 

Activity: 412
Merit: 196
Spinly.io - Next-gen Crypto iGaming Platform
|
 |
September 29, 2026, 07:40:13 AM |
|
Sometimes, that stable version can have a vulnerability, this can be detected very late and if you aren't following the hardware wallet social media account you won't know when a fix is available for that vulnerability.
I don't rush to update firmware, because this is also not very safe, I take my time with the latest firmware update, like days or a week later knowing fully well that some people will rush to update.
Because in the past there was a time where a crypto wallet released a update and it was bad, buggy or something like that, almost make the wallet unusable, someone should test them first before I update mine.
|
|
|
|
AHOYBRAUSE
Legendary

Activity: 1456
Merit: 2049
よろしく
|
 |
September 29, 2026, 07:43:20 AM |
|
My hardware wallet funds are for long-term hodling, so I seldom plug my device to the computer. But when I do and there are updates waiting I'd install it.
I generally believe updates are necessary, but if you're worried about bad releases, and there's no urgent call to install the latest updates, I think it doesn't hurt to wait for a while to hear feedbacks from experts first.
As a crypto layman, I'd rather wait for advanced users to test updates first and locate bugs. Unless it's a critical emergency security patch like the one released by Coinkite in the middle of the Coldcard theft, I'd sit on it for a while.
Same here, if it's not broken, why fix it? Sure, updates always also provide some "security update" but if everything went well the whole time then often enough I don't see the necessity to update, it just brings some risk coming with it in my opinion. As long as i have no issues and the wallet works perfectly fine (and I don't need to touch it) I just keep it where it is, often that's the best thing to do in my experience.
|
| | Sportsbet.io | │ |
| │ |
| │ | ████████████████████████ ██ ██████
██ ████████████████
MORE THAN A BET!
██ ████████████████
██ █████████████████████ ██ ████████ |
|
|
|
aoluain
Legendary

Activity: 3122
Merit: 1774
|
 |
September 29, 2026, 07:54:27 AM |
|
For those of you holding long term in cold storage, what is your actual routine here? Do you flash updates as soon as they roll out, wait a few weeks or months to see if other users report issues, or simply keep your signing device on its factory firmware until a transaction literally fails to build?
While I dont access my wallet every day or even every week I always install updates, but not immediately. I wait a few weeks to see if there are any issues reported with those updates. I go to the Hardware wallet section of the forum to keep a lookout on the board to see if there are any reports of issues, but I eventually bring my wallet up to date. I would imagine with an air-gapped wallet not updating the wallet would not be an issue, my thinking is that its a closed environment and if there were no issues at the time of install then none would arise because all other systems wouldnt develop issues , everything is in a state of limbo so to speak
|
| DΞX.fo | | | | | | ▄▄██████ █████████ ██████████ ██████████ ██████████ █████████ ▀▀██████
▄███████ ▄██████████ ████████████ █████████████ █████████████ | | | | ▄▄█ ▄████▀ ▄███▀█▄ ▄██▀█▄██ █████▀▀█ ████████ ████████ ▀██▄████ ▄████▄▄█ ▄█████▀███ ▄█████▀████▀ █████▀███████ ▀██▀█████████ | | | | | BTC XMR DAI LTC Fees 0.8% |
|
|
|
m2017
Legendary

Activity: 2618
Merit: 1737
keep walking, Johnnie
|
 |
September 29, 2026, 08:10:55 AM |
|
Every time a new firmware update drops for a hardware wallet, I find myself second-guessing whether to install it or just leave the device alone.
Which hardware wallet do you have? If the firmware doesn't contain fixes for critical errors, then I suppose installing the new firmware can be postponed (for a while). On one hand, keeping an air-gapped device on an older, stable version that already does basic PSBT signing feels like the safest route.
The Coldcard incident demonstrated that not all older firmware versions are secure (they may contain legacy vulnerabilities). There is no risk of a bad release bricking the device, unexpected code changes, or unwanted features being introduced.
It seems you’ve described all the paranoid fears that owners of hardware wallets have regarding the new firmware.  If the device has never touched the internet and only signs raw transactions offline, it feels like "if it isn't broken, don't touch it."
Let’s revisit the Coldcard story. The devices from which funds were stolen could also have gone years without connecting to the internet (the vulnerability stemmed from overly simple generation of the seed phrase). So, this is (don't touch HW) far from a 100% guarantee of security. On the other hand, security advisories and bug disclosures pop up occasionally, and ignoring patches could theoretically leave known vulnerabilities open to physical side-channel attacks or parsing bugs.
Therefore, I believe one should install updates rather than ignore them - much like anti-vaxxers refuse vaccinations (only to subsequently fall ill). For those of you holding long term in cold storage, what is your actual routine here? Do you flash updates as soon as they roll out, wait a few weeks or months to see if other users report issues, or simply keep your signing device on its factory firmware until a transaction literally fails to build?
Well, relying solely on the factory firmware doesn't seem entirely sensible to me (for the latest update version may differ significantly from the factory version, especially if the hardware wallet model is no longer new). Besides, updated firmware often includes new features. That’s why I prefer to update the HW device, though I do so with a bit of a delay. I don't stick to a strict schedule for updates - usually, it’s a matter of days or weeks (though the delay can be longer if I haven't used the HW device for a while). If there isn't a lot of "noise" about issues following the update's release, I go ahead and install it. I think the "Hardware wallets" section would be more suitable for this topic.
|
|
|
|
eternalgloom
Legendary

Activity: 1988
Merit: 1413
|
 |
September 29, 2026, 08:27:27 AM |
|
Hello, Chatbot, I never install update on Day One. At the same time I don't wait around until fund transaction actually fails.  For me its very simple. I do not make unnecessary change to firmware unless any major security vulnerability or advisory arises. And if I absolutely have to update, I wait at least a month for code to mature in open source release. Then I verify PGP signature to ensure everything is in order and proceed to update without worry.
|
|
|
|
matrixx (OP)
Newbie

Activity: 51
Merit: 0
|
 |
September 29, 2026, 08:32:15 AM |
|
Which hardware wallet do you have? I've been using a Coldcard alongside a Blockstream Jade. Your approach of holding off for a few weeks to see if the community reports any bricked devices or regressions before flashing is probably the most sensible middle ground. It protects against day-one release bugs while avoiding leaving known security holes open forever. You make a very fair point about the Coldcard seed generation issue. If the initial firmware had flawed entropy or derivation logic right out of the box, keeping the unit strictly offline doesn't save you since the keys were already weak from day zero. Taking five minutes to actually read the changelog to see whether an update patches critical cryptographic logic versus just adding altcoin support or cosmetic menu changes is probably the best filter for whether to flash it immediately. Also, good call on the section—I didn't realize Hardware Wallets was the better fit. I'll hit the Move Topic link at the bottom left and shift the thread over.
|
|
|
|
|
|
Livingleged
|
 |
September 29, 2026, 08:33:02 AM Last edit: September 29, 2026, 08:44:14 AM by Livingleged |
|
Every time a new firmware update drops for a hardware wallet, I find myself second-guessing whether to install it or just leave the device alone.
Yes is can be somehow discouraging to keep updating to newer firmware for a hardware wallet, most especially if you’re very much comfortable and never encountered any security compromised challenge, but for any company to bring a newer version of its hardware firmware, there should be definitely be a loop and of course it should be necessary to do that if you take your security seriously. Let’s look back at what happened with the coldcard hardware wallet firmware, the recent attack never affected those that updated to the Mk4/5. but what to also take note is that you’re updating to the right firmware, and also from the right source not any malicious software.
|
|
|
|
matrixx (OP)
Newbie

Activity: 51
Merit: 0
|
 |
September 29, 2026, 08:41:44 AM |
|
Hello, Chatbot, I never install update on Day One. Ouch, "chatbot" hurts haha. Just trying to write clean English without butchering the grammar! Verifying the PGP signature against developer keys is definitely the step most people skip when they rush to update. Waiting a month makes a lot of sense too—gives plenty of time for any bad commits or regressions to get flagged on GitHub before you flash it to hardware.
|
|
|
|
|
Cointxz
Copper Member
Legendary

Activity: 3654
Merit: 1343
Leading Crypto Sports Betting & Casino Platform
|
 |
September 29, 2026, 08:43:45 AM |
|
I only update my hardware wallet whenever I open it once a month to check my funds and wallet functionality since I have trezor 1st gen wallet that got screen burn just by sitting on my drawer for a long time without opening it.
I never open my hardware wallet just to update the software since I can always do this anytime and it will make me tempted to break my long term holding on my tokens.
IIRC some wallet developers announced if the update is crucial for device security and that’s the only time I open my device just for updating purposes.
|
| ..Stake.com.. | | | ▄████████████████████████████████████▄ ██ ▄▄▄▄▄▄▄▄▄▄ ▄▄▄▄▄▄▄▄▄▄ ██ ▄████▄ ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██ ██████ ██ ██████████ ██ ██ ██████████ ██ ▀██▀ ██ ██ ██ ██████ ██ ██ ██ ██ ██ ██ ██████ ██ █████ ███ ██████ ██ ████▄ ██ ██ █████ ███ ████ ████ █████ ███ ████████ ██ ████ ████ ██████████ ████ ████ ████▀ ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██ ██ ▀▀▀▀▀▀▀▀▀▀ ██ ▀█████████▀ ▄████████████▄ ▀█████████▀ ▄▄▄▄▄▄▄▄▄▄▄▄███ ██ ██ ███▄▄▄▄▄▄▄▄▄▄▄▄ ██████████████████████████████████████████ | | | | | | ▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄ █ ▄▀▄ █▀▀█▀▄▄ █ █▀█ █ ▐ ▐▌ █ ▄██▄ █ ▌ █ █ ▄██████▄ █ ▌ ▐▌ █ ██████████ █ ▐ █ █ ▐██████████▌ █ ▐ ▐▌ █ ▀▀██████▀▀ █ ▌ █ █ ▄▄▄██▄▄▄ █ ▌▐▌ █ █▐ █ █ █▐▐▌ █ █▐█ ▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█ | | | | | | ▄▄█████████▄▄ ▄██▀▀▀▀█████▀▀▀▀██▄ ▄█▀ ▐█▌ ▀█▄ ██ ▐█▌ ██ ████▄ ▄█████▄ ▄████ ████████▄███████████▄████████ ███▀ █████████████ ▀███ ██ ███████████ ██ ▀█▄ █████████ ▄█▀ ▀█▄ ▄██▀▀▀▀▀▀▀██▄ ▄▄▄█▀ ▀███████ ███████▀ ▀█████▄ ▄█████▀ ▀▀▀███▄▄▄███▀▀▀ | | | ..PLAY NOW.. |
|
|
|
promise444c5
Legendary

Activity: 1148
Merit: 1211
All things are numbers
|
 |
September 29, 2026, 10:17:13 AM |
|
Verifying the PGP signature against developer keys is definitely the step most people skip when they rush to update. Waiting a month makes a lot of sense too—gives plenty of time for any bad commits or regressions to get flagged on GitHub before you flash it to hardware.
It’s good that you are aware of the verification aspect. Waiting period shouldn’t be attached to a x period though, a month isn’t really that bad but just stay up-to-date with discussions, you may need to update early.. and don’t be behind too much. Yes, but for any company to bring a newer version of its hardware firmware, there should be definitely be a loop and of course it should be necessary to do that if you take your security seriously.
While in most cases it done to fix something, there could be some which are only adding new features, replacing/removing improving the existing in some cases(can still fall under “fix”).
|
|
|
|
Zaguru12
Legendary

Activity: 1554
Merit: 1302
|
 |
September 29, 2026, 01:58:22 PM |
|
Let’s look back at what happened with the coldcard hardware wallet firmware, the recent attack never affected those that updated to the Mk4/5. but what to also take note is that you’re updating to the right firmware, and also from the right source not any malicious software.
There sometimes new firmware that usually has bugs maybe mistakenly from the developers end or an attacker. That’s why most of the time it’s best not to update new firmware very early and just to wait a while. Although off topic but there is a problem with that coldcard example, even if a user had actually upgraded to a new coldcard firmware (Mk4 or Mk5) they won’t still be automatically safe from that attack because they had generated their seed phrase from the old model which had the entropy that was affected. So if the they hadn’t moved out to the new seed phrase generated by the new model (which is still Low) they would have been affected. While in most cases it done to fix something, there could be some which are only adding new features, replacing/removing improving the existing in some cases(can still fall under “fix”).
This is now mostly common with Software wallets because they basically add new functional features to make navigation easy
|
|
|
|
|
Meuserna
|
 |
September 29, 2026, 05:51:17 PM |
|
I let other people test firmware updates. Unless the update fixes something critical, I wait.
I'm a long term holder though, so I don't actually use my hardware wallet that much. I use Bitcoin Core and Sparrow a lot though. I keep those up to date... but even then, I wait a little so other people can test updates first.
|
|
|
|
dkbit98
Legendary

Activity: 3094
Merit: 8888
|
 |
September 29, 2026, 09:38:21 PM |
|
Do you flash updates as soon as they roll out, wait a few weeks or months to see if other users report issues, or simply keep your signing device on its factory firmware until a transaction literally fails to build?
You don't need to perform quick firmware update as soon as they got released, except in case if that is emergency security update that fixes some serious bug. I would always read the latest update release, and if there is nothing urgent I would wait for few days before making my update. Just don't allow months or years to pass with updating your devices.
|
▄▄██████▄░░░▄██████▄▄ ██▀▀░░░░▀░░░░░▀░░░░▀▀██ ▄▄██████▄░▄██████▄▄ ▄████▀▀▀▀█████▀▀▀▀████▄ ▄███░░░▄▄░░░█░░░▄▄░░░███▄ ▄▄▄███░░░░██░░░░░░░██░░░░███▄▄▄ ████████░░░░██░░░░░░░██░░░░████████ ██████████░░░▀▀░░░█░░░▀▀░░░██████████ ████▀▀██████▄▄▄▄█████▄▄▄▄██████▀▀████ ▀███▄░░▀▀███████████████████▀▀░░▄███▀ ▀████▄▄░░░░▀▀▀▀▀▀▀▀▀▀▀▀▀░░░░▄▄████▀ ▀███████▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄███████▀ ▀▀█████████████████████▀▀ | | OrangeFren | | ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ | | | | ▄▄█████▄▄ ▄████▀▀▀████▄ ███▀░░░░░░░▀███ ███▀░░░▄█░░░░▀███ ███░░░░░█░░░░░███ ███▄░░░▄█▄░░░▄███ ███▄░░░░░░░▄███ ▀████▄▄▄████▀ █████████ ▐█████████▌ █████░█████ ▐████▌░▐████▌ ▀▀░▀█░░░█▀░▀▀ | | |
|
|
|
Mia Chloe
Legendary

Activity: 1218
Merit: 2304
Contact me for you designs...
|
 |
September 29, 2026, 09:40:09 PM |
|
It’s good that you are aware of the verification aspect. Waiting period shouldn’t be attached to a x period though, a month isn’t really that bad but just stay up-to-date with discussions, you may need to update early.. and don’t be behind too much.
They're nothing wrong cruising an old software or firmware so long you are sure that particular version is not having any major risk issues or exploitable bugs as the case may be. Sometimes people compromise their totally Safe devices in the process of trying to update it. Generally even for wallets too it's best you let new versions "marinate" into the space and internet in general before you eventually hop on. The point is to reduce your exposure to big bugs.
|
|
|
|
|
X-ray
|
 |
September 30, 2026, 03:35:26 AM |
|
I updated regularly but before I update I will read the changelog and find out if the update is urgent, if not then there's no point being in hurry, i'll just wait few days.
Been doing this for quite sometime, I find it to be the best way to deal with these hardware wallet updates.
I can be paranoid and always wait for few days or weeks before updating to latest version but sometime there's a security patch that better be installed on your device as fast as you can.
Just go to their github and read their changelog, won't even take you 2 minutes.
General rule of thumb for me if the most recent changelog have security section, I'll update it faster than usual.
|
| ..Stake.com.. | | | ▄████████████████████████████████████▄ ██ ▄▄▄▄▄▄▄▄▄▄ ▄▄▄▄▄▄▄▄▄▄ ██ ▄████▄ ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██ ██████ ██ ██████████ ██ ██ ██████████ ██ ▀██▀ ██ ██ ██ ██████ ██ ██ ██ ██ ██ ██ ██████ ██ █████ ███ ██████ ██ ████▄ ██ ██ █████ ███ ████ ████ █████ ███ ████████ ██ ████ ████ ██████████ ████ ████ ████▀ ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██ ██ ▀▀▀▀▀▀▀▀▀▀ ██ ▀█████████▀ ▄████████████▄ ▀█████████▀ ▄▄▄▄▄▄▄▄▄▄▄▄███ ██ ██ ███▄▄▄▄▄▄▄▄▄▄▄▄ ██████████████████████████████████████████ | | | | | | ▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄ █ ▄▀▄ █▀▀█▀▄▄ █ █▀█ █ ▐ ▐▌ █ ▄██▄ █ ▌ █ █ ▄██████▄ █ ▌ ▐▌ █ ██████████ █ ▐ █ █ ▐██████████▌ █ ▐ ▐▌ █ ▀▀██████▀▀ █ ▌ █ █ ▄▄▄██▄▄▄ █ ▌▐▌ █ █▐ █ █ █▐▐▌ █ █▐█ ▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█ | | | | | | ▄▄█████████▄▄ ▄██▀▀▀▀█████▀▀▀▀██▄ ▄█▀ ▐█▌ ▀█▄ ██ ▐█▌ ██ ████▄ ▄█████▄ ▄████ ████████▄███████████▄████████ ███▀ █████████████ ▀███ ██ ███████████ ██ ▀█▄ █████████ ▄█▀ ▀█▄ ▄██▀▀▀▀▀▀▀██▄ ▄▄▄█▀ ▀███████ ███████▀ ▀█████▄ ▄█████▀ ▀▀▀███▄▄▄███▀▀▀ | | | ..PLAY NOW.. |
|
|
|
The Sceptical Chymist
Legendary

Activity: 4200
Merit: 7388
♻️ Automatic Exchange
|
 |
September 30, 2026, 03:38:39 AM |
|
Once upon a time I'd have thought nothing of updating any kind of software for any device or what have you.....and then came Ledger and their fucking knife in the backs of so many of their customers who trusted them, i.e., the Recover debacle. True, everyone was alerted to their choice brand of shenanigans ahead of time, but that whole thing still left a gnarly taste in my mouth as far as what's contained in all of the updates you have to do if you own [insert HW wallet name here].
A good non-crypto example of update nonsense is Microsoft and all of the spyware they pump your poor ol' PC full of until it's so bloated it can hardly compute 2+2.
By the way, screw them and anything AI-related. They're two different things and I'm not painting them with the same brush, but I just wanted to curse them both because because because.
|
░░░░▄▄████████████▄ ░▄████████████████▀ ▄████████████████▀▄█▄ ▄███████▀▀░░▄███▀▄████▄ ▄██████▀░░░▄███▀░▀██████▄ ██████▀░░▄████▄░░░▀██████ ██████░░▀▀▀▀░▄▄▄▄░░██████ ██████▄░░░▀████▀░░▄██████ ▀██████▄░▄███▀░░░▄██████▀ ▀████▀▄████░░▄▄███████▀ ▀█▀▄████████████████▀ ▄████████████████▀░ ▀████████████▀▀░░░░ | | CCECASH | | | | ANN THREAD TUTORIAL |
|
|
|
Pmalek
Legendary

Activity: 3626
Merit: 9591
|
 |
September 30, 2026, 08:05:22 AM |
|
There are usually release notes posted with every firmware update. Read those and see what was changed. They will mention if the firmware update contains fixes for known vulnerabilities. If those vulnerabilities are critical and in some way connected to the way you use the hardware wallet, I would update my firmware quicker than I usually do it. But if the new release isn't that important, I will wait for a few weeks. I see no reason to be among the first group who updates a piece of software and then needs to report bugs and issues. I would rather wait. It's not uncommon to see a software update and in a few days a newer version gets released that fixes problems created by the previous release.
|
|
|
|
|
|