Bitcoin Forum
September 30, 2026, 02:06:33 AM *
News: Latest Bitcoin Core release: 31.1 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Do you update hardware wallet firmware regularly or leave it untouched?  (Read 153 times)
matrixx (OP)
Newbie
*
Offline

Activity: 50
Merit: 0


View Profile
September 29, 2026, 07:16:11 AM
 #1

Every time a new firmware update drops for a hardware wallet, I find myself second-guessing whether to install it or just leave the device alone.

On one hand, keeping an air-gapped device on an older, stable version that already does basic PSBT signing feels like the safest route. There is no risk of a bad release bricking the device, unexpected code changes, or unwanted features being introduced. If the device has never touched the internet and only signs raw transactions offline, it feels like "if it isn't broken, don't touch it."

On the other hand, security advisories and bug disclosures pop up occasionally, and ignoring patches could theoretically leave known vulnerabilities open to physical side-channel attacks or parsing bugs.

For those of you holding long term in cold storage, what is your actual routine here? Do you flash updates as soon as they roll out, wait a few weeks or months to see if other users report issues, or simply keep your signing device on its factory firmware until a transaction literally fails to build?
_act_
Legendary
*
Offline

Activity: 1750
Merit: 2002



View Profile
September 29, 2026, 07:25:16 AM
Merited by The Sceptical Chymist (4)
 #2

Updating the firmware can be very important, that is the reason it is good to be following the recent updates. Some can be because of vulnerability and which should be updated as fast as possible.

But if the update is not because of any vulnerability, you can wait for sometime. If no one report bug or vulnerability, you can update it. It is good to use the latest firmware.

I also prefer wallets that are on airgapped devices than hardware wallet. I do not update wallet on an airgapped device fast until it is no more working, but which is very rare.

Darker45
Legendary
*
Offline

Activity: 3444
Merit: 2139


Spinly.io - Next-gen Crypto iGaming Platform


View Profile
September 29, 2026, 07:37:32 AM
 #3

My hardware wallet funds are for long-term hodling, so I seldom plug my device to the computer. But when I do and there are updates waiting I'd install it.

I generally believe updates are necessary, but if you're worried about bad releases, and there's no urgent call to install the latest updates, I think it doesn't hurt to wait for a while to hear feedbacks from experts first.

As a crypto layman, I'd rather wait for advanced users to test updates first and locate bugs. Unless it's a critical emergency security patch like the one released by Coinkite in the middle of the Coldcard theft, I'd sit on it for a while.


░▄████████████▀▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▄██
████████████░█▀
████░▄▄▄███████▄
████▄▄▄▄▄▄▄▄░▄██
▀▀▀▀▀▀▀▀████░███
████████████░███
████████████░█▀

░▄████████████▀▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▄██
████████████░███
████████████░███
████████████░███
████▄▄▄▄████░██▀
████▀▀▀▀▀▀▀▀░▀
████░█▀

░▄████████████▀▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▄██
████████████░█▀
█████████░▄▄▄
█████████░███
░▄░██████░██▀██▄
▀▀░██████░▀██▄██
████████████░█▀

░▄███████▀░▄██▀▄
▀▀▀▀▀▀▀▀██▀▀▀▄██
████████████░███
████████████░███
██░▄░███████░███
██░█░███████░███
████████████░███
████████████░█▀

░▄██████▀▄
▀▀▀▀▀▀▀▄██
██████░███
██████░███
██████░███
██████░███████▀▄
██████░▀▀▀▀▀▀▄██
████████████░█▀

░▄████▀██▄█████▀▄
▀▀▀▀▀███▀▀▀▀▀▀▄██
█████████████░███
█████░█░█████░███
█████░▀░█████░███
█████████████░█▀
██████████░▄▄▄
██████████░█▀
 
.....  Next−Gen Crypto iGaming  .....
| 
     Play now      
5W-KILO
Full Member
***
Offline

Activity: 407
Merit: 195


Spinly.io - Next-gen Crypto iGaming Platform


View Profile
September 29, 2026, 07:40:13 AM
 #4

Sometimes, that stable version can have a vulnerability, this can be detected very late and if you aren't following the hardware wallet social media account you won't know when a fix is available for that vulnerability.

I don't rush to update firmware, because this is also not very safe, I take my time with the latest firmware update, like days or a week later knowing fully well that some people will rush to update.

Because in the past there was a time where a crypto wallet released a update and it was bad, buggy or something like that, almost make the wallet unusable, someone should test them first before I update mine.

AHOYBRAUSE
Legendary
*
Online Online

Activity: 1456
Merit: 2049


よろしく


View Profile WWW
September 29, 2026, 07:43:20 AM
 #5

My hardware wallet funds are for long-term hodling, so I seldom plug my device to the computer. But when I do and there are updates waiting I'd install it.

I generally believe updates are necessary, but if you're worried about bad releases, and there's no urgent call to install the latest updates, I think it doesn't hurt to wait for a while to hear feedbacks from experts first.

As a crypto layman, I'd rather wait for advanced users to test updates first and locate bugs. Unless it's a critical emergency security patch like the one released by Coinkite in the middle of the Coldcard theft, I'd sit on it for a while.

Same here, if it's not broken, why fix it? Sure, updates always also provide some "security update" but if everything went well the whole time then often enough I don't see the necessity to update, it just brings some risk coming with it in my opinion.

As long as i have no issues and the wallet works perfectly fine (and I don't need to touch it) I just keep it where it is, often that's the best thing to do in my experience.


aoluain
Legendary
*
Offline

Activity: 3122
Merit: 1770



View Profile WWW
September 29, 2026, 07:54:27 AM
 #6


For those of you holding long term in cold storage, what is your actual routine here? Do you flash updates as soon as they roll out, wait a few weeks or months to see if other users report issues, or simply keep your signing device on its factory firmware until a transaction literally fails to build?

While I dont access my wallet every day or even every week I always install updates, but not
immediately. I wait a few weeks to see if there are any issues reported with those updates.
I go to the Hardware wallet section of the forum to keep a lookout on the board to see if there
are any reports of issues, but I eventually bring my wallet up to date.

I would imagine with an air-gapped wallet not updating the wallet would not be an issue,
my thinking is that its a closed environment and if there were no issues at the time of install
then none would arise because all other systems wouldnt develop issues , everything is in
a state of limbo so to speak

▄▄████████████████████▄▄
▄███████▀▀██████▀▀███████▄
█████▀██████████████▀█████
████████▄▄██████▄▄████▀███

██████████████████████████
██▄▄██████████████▄▄██████
██▀▀██████████████████▄▄██
██████▀▀██████████████▀▀██
██████████████████████████
███▄████▀▀██████▀▀████████
█████▄██████████████▄█████
▀███████▄▄██████▄▄███████▀
▀▀████████████████████▀▀
 
 DΞX.fo 
▄▄██████
█████████
██████████
██████████
██████████
█████████
▀▀██████

▄███████
▄██████████
████████████
█████████████
█████████████
|
▄▄█
▄████▀
▄███▀█▄
▄██▀█▄██
█████▀▀█
████████
████████
▀██▄████
▄████▄▄█
▄█████▀███
▄█████▀████▀
█████▀███████
▀██▀█████████
|  BTC     XMR  
  DAI     LTC  
   Fees  0.8%    
m2017
Legendary
*
Offline

Activity: 2618
Merit: 1737


keep walking, Johnnie


View Profile
September 29, 2026, 08:10:55 AM
 #7

Every time a new firmware update drops for a hardware wallet, I find myself second-guessing whether to install it or just leave the device alone.
Which hardware wallet do you have?

If the firmware doesn't contain fixes for critical errors, then I suppose installing the new firmware can be postponed (for a while).

On one hand, keeping an air-gapped device on an older, stable version that already does basic PSBT signing feels like the safest route.
The Coldcard incident demonstrated that not all older firmware versions are secure (they may contain legacy vulnerabilities).

There is no risk of a bad release bricking the device, unexpected code changes, or unwanted features being introduced.
It seems you’ve described all the paranoid fears that owners of hardware wallets have regarding the new firmware. Smiley

If the device has never touched the internet and only signs raw transactions offline, it feels like "if it isn't broken, don't touch it."
Let’s revisit the Coldcard story. The devices from which funds were stolen could also have gone years without connecting to the internet (the vulnerability stemmed from overly simple generation of the seed phrase). So, this is (don't touch HW) far from a 100% guarantee of security.

On the other hand, security advisories and bug disclosures pop up occasionally, and ignoring patches could theoretically leave known vulnerabilities open to physical side-channel attacks or parsing bugs.
Therefore, I believe one should install updates rather than ignore them - much like anti-vaxxers refuse vaccinations (only to subsequently fall ill).

For those of you holding long term in cold storage, what is your actual routine here? Do you flash updates as soon as they roll out, wait a few weeks or months to see if other users report issues, or simply keep your signing device on its factory firmware until a transaction literally fails to build?
Well, relying solely on the factory firmware doesn't seem entirely sensible to me (for the latest update version may differ significantly from the factory version, especially if the hardware wallet model is no longer new). Besides, updated firmware often includes new features. That’s why I prefer to update the HW device, though I do so with a bit of a delay. I don't stick to a strict schedule for updates - usually, it’s a matter of days or weeks (though the delay can be longer if I haven't used the HW device for a while). If there isn't a lot of "noise" about issues following the update's release, I go ahead and install it.

I think the "Hardware wallets" section would be more suitable for this topic.

eternalgloom
Legendary
*
Offline

Activity: 1988
Merit: 1412



View Profile
September 29, 2026, 08:27:27 AM
 #8

Hello, Chatbot, I never install update on Day One. At the same time I don't wait around until fund transaction actually fails. Tongue

For me its very simple. I do not make unnecessary change to firmware unless any major security vulnerability or advisory arises.
And if I absolutely have to update, I wait at least a month for code to mature in open source release.
Then I verify PGP signature to ensure everything is in order and proceed to update without worry.

.◼.◼.Vega.bet.◼.◼.██
██
██
██
██
██
██
██
██
██
██
██
██

...100 FS + 750% BONUS..MAX.WIN.$5,000...

███...FAST PAYOUTS  |  NO KYC  |  10% LOSSBACK...███
██
██
██
██
██
██
██
██
██
██
██
██
██

...Play Now...
matrixx (OP)
Newbie
*
Offline

Activity: 50
Merit: 0


View Profile
September 29, 2026, 08:32:15 AM
 #9

Quote from: m2017
Which hardware wallet do you have?
I've been using a Coldcard alongside a Blockstream Jade. Your approach of holding off for a few weeks to see if the community reports any bricked devices or regressions before flashing is probably the most sensible middle ground. It protects against day-one release bugs while avoiding leaving known security holes open forever.

You make a very fair point about the Coldcard seed generation issue. If the initial firmware had flawed entropy or derivation logic right out of the box, keeping the unit strictly offline doesn't save you since the keys were already weak from day zero. Taking five minutes to actually read the changelog to see whether an update patches critical cryptographic logic versus just adding altcoin support or cosmetic menu changes is probably the best filter for whether to flash it immediately.

Also, good call on the section—I didn't realize Hardware Wallets was the better fit. I'll hit the Move Topic link at the bottom left and shift the thread over.
Livingleged
Full Member
***
Offline

Activity: 322
Merit: 206



View Profile
September 29, 2026, 08:33:02 AM
Last edit: September 29, 2026, 08:44:14 AM by Livingleged
 #10

Every time a new firmware update drops for a hardware wallet, I find myself second-guessing whether to install it or just leave the device alone.

Yes is can be somehow discouraging to keep updating to newer firmware for a hardware wallet, most especially if you’re very much comfortable and never encountered any security compromised challenge, but for any company to bring a newer version of its hardware firmware, there should be definitely be a loop and of course it should be necessary to do that if you take your security seriously.

Let’s look back at what happened with the coldcard hardware wallet firmware, the recent attack never affected those that updated to the Mk4/5. but what to also take note is that you’re updating to the right firmware, and also from the right source not any malicious software.

matrixx (OP)
Newbie
*
Offline

Activity: 50
Merit: 0


View Profile
September 29, 2026, 08:41:44 AM
 #11

Quote from: eternalgloom
Hello, Chatbot, I never install update on Day One.
Ouch, "chatbot" hurts haha. Just trying to write clean English without butchering the grammar!

Verifying the PGP signature against developer keys is definitely the step most people skip when they rush to update. Waiting a month makes a lot of sense too—gives plenty of time for any bad commits or regressions to get flagged on GitHub before you flash it to hardware.
Cointxz
Copper Member
Legendary
*
Offline

Activity: 3640
Merit: 1342


Leading Crypto Sports Betting & Casino Platform


View Profile WWW
September 29, 2026, 08:43:45 AM
 #12

I only update my hardware wallet whenever I open it once a month to check my funds and wallet functionality since I have trezor 1st gen wallet that got screen burn just by sitting on my drawer for a long time without opening it.

I never open my hardware wallet just to update the software since I can always do this anytime and it will make me tempted to break my long term holding on my tokens.

IIRC some wallet developers announced if the update is crucial for device security and that’s the only time I open my device just for updating purposes.

..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
promise444c5
Legendary
*
Offline

Activity: 1148
Merit: 1207


All things are numbers


View Profile WWW
September 29, 2026, 10:17:13 AM
 #13

Verifying the PGP signature against developer keys is definitely the step most people skip when they rush to update. Waiting a month makes a lot of sense too—gives plenty of time for any bad commits or regressions to get flagged on GitHub before you flash it to hardware.
It’s good that you are aware of the verification aspect. Waiting period shouldn’t be attached to a x period though, a month isn’t really that bad but just stay up-to-date with discussions, you may need to update early.. and don’t be behind too much.

Yes, but for any company to bring a newer version of its hardware firmware, there should be definitely be a loop and of course it should be necessary to do that if you take your security seriously.
While in most cases it done  to fix something, there could be some  which are only adding new  features, replacing/removing improving the existing in some cases(can still fall under “fix”).

Zaguru12
Legendary
*
Offline

Activity: 1554
Merit: 1299



View Profile WWW
September 29, 2026, 01:58:22 PM
 #14


Let’s look back at what happened with the coldcard hardware wallet firmware, the recent attack never affected those that updated to the Mk4/5. but what to also take note is that you’re updating to the right firmware, and also from the right source not any malicious software.

There sometimes new firmware that usually has bugs maybe mistakenly from the developers end or an attacker. That’s why most of the time it’s best not to update new firmware very early and just to wait a while.

Although off topic but there is a problem with that coldcard example, even if a user had actually upgraded to a new coldcard firmware (Mk4 or Mk5) they won’t still be automatically safe from that attack because they had generated their seed phrase from the old model which had the entropy that was affected. So if the they hadn’t moved out to the new seed phrase generated by the new model (which is still Low) they would have been affected.

While in most cases it done  to fix something, there could be some  which are only adding new  features, replacing/removing improving the existing in some cases(can still fall under “fix”).

This is now mostly common with Software wallets because they basically add new functional features to make navigation easy

.◼.◼.Vega.bet.◼.◼.██
██
██
██
██
██
██
██
██
██
██
██
██

...100 FS + 750% BONUS..MAX.WIN.$5,000...

███...FAST PAYOUTS  |  NO KYC  |  10% LOSSBACK...███
██
██
██
██
██
██
██
██
██
██
██
██
██

...Play Now...
Meuserna
Sr. Member
****
Offline

Activity: 379
Merit: 691


View Profile WWW
September 29, 2026, 05:51:17 PM
 #15

I let other people test firmware updates. Unless the update fixes something critical, I wait.

I'm a long term holder though, so I don't actually use my hardware wallet that much. I use Bitcoin Core and Sparrow a lot though. I keep those up to date... but even then, I wait a little so other people can test updates first.

dkbit98
Legendary
*
Offline

Activity: 3094
Merit: 8888



View Profile WWW
September 29, 2026, 09:38:21 PM
 #16

Do you flash updates as soon as they roll out, wait a few weeks or months to see if other users report issues, or simply keep your signing device on its factory firmware until a transaction literally fails to build?
You don't need to perform quick firmware update as soon as they got released, except in case if that is emergency security update that fixes some serious bug.
I would always read the latest update release, and if there is nothing urgent I would wait for few days before making my update.
Just don't allow months or years to pass with updating your devices.

▄▄██████▄░░░▄██████▄▄
██▀▀░░░░▀░░░░░▀░░░░▀▀██
▄▄██████▄░▄██████▄▄
▄████▀▀▀▀█████▀▀▀▀████▄
▄███░░░▄▄░░░█░░░▄▄░░░███▄
▄▄▄███░░░░██░░░░░░░██░░░░███▄▄▄
████████░░░░██░░░░░░░██░░░░████████
██████████░░░▀▀░░░█░░░▀▀░░░██████████
████▀▀██████▄▄▄▄█████▄▄▄▄██████▀▀████
▀███▄░░▀▀███████████████████▀▀░░▄███▀
▀████▄▄░░░░▀▀▀▀▀▀▀▀▀▀▀▀▀░░░░▄▄████▀
▀███████▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄███████▀
▀▀█████████████████████▀▀
  
OrangeFren
  
██
██
██
██
██
██
██
██
██
██
██
  
▄▄█████▄▄
▄████▀▀▀████▄
███▀░░░░░░░▀███
███▀░░░▄█░░░░▀███
███░░░░░█░░░░░███
███▄░░░▄█▄░░░▄███
███▄░░░░░░░▄███
▀████▄▄▄████▀
█████████
▐█████████▌
█████░█████
▐████▌░▐████▌
▀▀░▀█░░░█▀░▀▀
 
Mia Chloe
Legendary
*
Offline

Activity: 1204
Merit: 2304


Contact me for you designs...


View Profile
September 29, 2026, 09:40:09 PM
 #17

It’s good that you are aware of the verification aspect. Waiting period shouldn’t be attached to a x period though, a month isn’t really that bad but just stay up-to-date with discussions, you may need to update early.. and don’t be behind too much.
They're nothing wrong cruising an old software or firmware so long you are sure that particular version is not having any major risk issues or exploitable bugs as the case may be. Sometimes people compromise their totally Safe devices in the process of trying to update it.

Generally even for wallets too it's best you let new versions "marinate" into the space and internet in general before you eventually hop on. The point is to reduce your exposure to big bugs.

Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!