The hidden risk of updatable firmware  

24 April 2025

Cointelegraph by Igor Zemtsov

  ​

The hidden risk of updatable firmware

Opinion by: Igor Zemtsov, chief technology officer at TBCC

Crypto security is a ticking time bomb. Updatable firmware might just be the match that lights the fuse.

Hardware wallets have become the holy grail of self-custody, the ultimate safeguard against hackers, scammers and even government overreach. There’s an inconvenient truth, however, that most people ignore: Firmware updates aren’t just security patches. 

They’re potential backdoors, waiting for someone — whether a hacker, a rogue developer or a shady third party — to kick them wide open.

Every time a hardware wallet manufacturer pushes an update, users are forced to make a choice. Hit that update button and hope for the best, or refuse to update and risk using outdated software with unknown vulnerabilities. Either way, it’s a gamble. 

In crypto, a bad gamble can mean waking up to an empty wallet.

Firmware updates aren’t always your friend

Updating firmware sounds like common sense. More security! Fewer bugs! Better user experience!

Here’s the thing: Every update is also an opportunity not just for the wallet provider but for anyone with the power, or motivation, to tamper with the process.

Hackers dream of firmware vulnerabilities. A rushed or poorly audited update can introduce tiny, almost imperceptible flaws — ones that sit in the background, waiting for the right moment to drain funds. And the best part? Users will never know what hit them.

Then there’s the more unsettling possibility: deliberate backdoors.

Recent: Hardware wallet Ledger helps competitor Trezor resolve security vulnerability

Tech companies have been forced to include government-mandated surveillance tools before. What makes anyone think hardware wallet makers are exempt? If a regulatory agency — or worse, a criminal organization — wants access to private keys, firmware updates are the perfect attack vector. One hidden function. One disguised line of code. 

That’s all it takes. Still think firmware updates are harmless? 

Firmware vulnerabilities are already being exploited

This isn’t some far-fetched, doomsday scenario. It has already happened.

Ledger, one of the biggest names in crypto security, had a major security crisis in 2018 when security researcher Saleem Rashid exposed a vulnerability that allowed attackers to replace Ledger Nano S firmware and hijack private keys. Nearly 1 million devices were at risk before a fix was rolled out. The scary part? There was no way for users to know if their devices had already been compromised.

In 2023, OneKey suffered a similar nightmare. White hat hackers demonstrated that its firmware could be cracked in mere seconds. No crypto was lost — this time. But what if real attackers had found the flaw first?

Then came the “Dark Skippy” exploit, taking firmware-based attacks to an entirely new level. With just two signed transactions, hackers could extract a user’s entire seed phrase — without setting off a single alarm. If firmware updates can be manipulated this easily, how can anyone be sure their assets are safe?

The hidden price of updatable firmware

To be fair, not all firmware updates are security disasters. Ledger uses a proprietary operating system and secure element chips for added protection now. Trezor takes an open-source approach, allowing the community to scrutinize its firmware. Coldcard and BitBox02 give users manual control over updates, reducing — but not eliminating — risk.

Here’s the real question: Can users ever be 100% sure that an update won’t introduce a fatal flaw?

Some wallets have decided to eliminate the risk altogether. Tangem ships with fixed, non-updatable firmware, meaning that its code can never be altered once the device leaves the factory. No updates. No patches. 

Of course, this approach has its trade-offs. If a vulnerability is discovered, there’s no way to fix it. But in security, predictability matters. 

Real crypto security means taking back control

The crypto market was worth $2.79 trillion as of March 2025. With that much money on the table, cybercriminals, rogue insiders and overreaching governments are always looking for weak points. Hardware wallet makers should be laser-focused on security.

Choosing a hardware wallet shouldn’t feel like gambling with private keys. It shouldn’t involve blind trust in a corporation’s ability to push updates responsibly. Users deserve more than vague reassurances. They deserve security models that put control where it belongs — with them.

Security isn’t about convenience. It’s about control. Any system that requires trusting unknown developers, opaque update processes or firmware that can be changed at will? That’s not control. That’s a liability.

The only real way to keep a hardware wallet safe? Remove the guesswork. Strip away the blind trust. Always research the developers’ backgrounds, check their track record for security incidents, and see how they’ve handled past vulnerabilities. Stick to verifiable facts — security should never be based on assumptions.

Opinion by: Igor Zemtsov, chief technology officer at TBCC.

This article is for general information purposes and is not intended to be and should not be taken as legal or investment advice. The views, thoughts, and opinions expressed here are the author’s alone and do not necessarily reflect or represent the views and opinions of Cointelegraph.

 

You might also like

Arizona governor signs law for state to keep unclaimed crypto  
Arizona governor signs law for state to keep unclaimed crypto  

Arizona Governor Katie Hobbs has signed a bill into law allowing the US state to keep unclaimed crypto and establish a “Bitcoin Reserve Fund” that won’t use any taxpayer money or state funds.Hobbs signed House Bill 2749 into law on May 7, which allows Arizona to claim ownership of abandoned digital assets if the owner fails to respond to communications within three years.The state’s custodians can stake the crypto to earn rewards or receive airdrops, which can then be deposited into what Arizona has called a Bitcoin and Digital Asset Reserve Fund.“This law ensures Arizona doesn’t leave value sitting on the table and puts us in a position to lead the country in how we secure, manage, and ultimately benefit from abandoned digital currency,” the bill’s sponsor, Jeff Weninger, said in a May 7 statement.Arizona House Representative Jeff Weninger’s statement on the signing of HB 2749 into law. Source: Jeff Weninger“We’ve built a structure that protects property rights, respects ownership, and gives the state tools to account for a new category of value in the economy,” Weninger added.On May 3, Hobbs vetoed a similar Bitcoin (BTC) reserve bill, Senate Bill 1025, which would have allowed the state to invest seized funds into Bitcoin, citing concerns over using public funds for “untested assets.”Hobbs’ move gives hope for future crypto billsBitcoin Laws founder Julian Fahrer said on X that Hobbs’ signing of HB 2749 offers more hope that she may also sign Senate Bill 1373, which is currently on her desk.Related: Bitcoin bros at ‘the club’ may stop US gov’t from buying BTC — Arthur HayesSB 1373 would authorize Arizona’s treasurer, currently Kimberly Yee, to allocate up to 10% of Arizona’s Budget Stabilization Fund into Bitcoin. The bill’s passage in Arizona follows New Hampshire Governor Kelly Ayotte on May 6 signing House Bill 302 into law, allowing her state’s treasury to use funds to invest in cryptocurrencies with a market capitalization of more than $500 billion.Bitcoin is currently the only cryptocurrency that meets that threshold.Magazine: Crypto wanted to overthrow banks, and now it’s becoming them in stablecoin fight

Binance founder CZ asked Trump to pardon money laundering conviction  
Binance founder CZ asked Trump to pardon money laundering conviction  

Binance founder and convicted felon Changpeng Zhao says that he applied for a pardon from US President Donald Trump shortly after denying reports that he was seeking one.Zhao, also known as CZ, said on a Farokh Radio podcast episode aired May 6 that he “wouldn’t mind” a pardon and that his lawyers have already filed the paperwork on his behalf“I got lawyers applying,” Zhao said, adding that he submitted the request after Bloomberg and The Wall Street Journal reported in March that he was seeking a pardon from Trump amid discussions of a business deal between the Trump family and Binance.US.Zhao denied the reports at the time, but said on the podcast that he thought “if they’re writing this article, I may as well just officially apply.”He added that Trump’s pardon of three BitMEX founders, including Arthur Hayes, also motivated him to submit an application.Zhao said the application was submitted about two weeks ago.Changpeng Zhao (right) speaking with Farokh Sarmad (left). Source: Farokh RadioZhao said at the time of the Bloomberg and Wall Street Journal reports that “no felon would mind a pardon,” and claimed he is the only person in US history to serve prison time for a Bank Secrecy Act charge.Zhao pleaded guilty to a money laundering charge in November 2023 as part of a deal Binance reached with US authorities, which saw it pay a $4.3 billion fine, to which Zhao contributed $50 million. He was also forced to step down as CEO.Zhao was later sentenced to four months in prison and was prohibited from working at Binance as part of his plea deal.Related: VanEck files for BNB ETF, first in USAccording to the US Department of Justice, a pardon would not erase Zhao’s money laundering conviction; however, it could potentially allow him to assume a management or operational role at Binance.US.Zhao has no plans to return as Binance CEOWhile Zhao remains a Binance shareholder, he said in November at Binance Blockchain Week that he has “no plans to return to the CEO position.” “I feel the team is doing well and doesn’t need me back,” Zhao said.Since leaving prison, Zhao has commenced advisory roles in Pakistan and Kyrgyzstan, assisting on matters related to crypto regulation and implementing blockchain solutions.Magazine: Bitcoiner Adam Back on Blockstream conspiracy theories and Satoshi question

Ex-SafeMoon CEO claims innocence, blames founder as trial begins  
Ex-SafeMoon CEO claims innocence, blames founder as trial begins  

Braden John Karony, the former CEO of crypto firm SafeMoon, made an out-of-court statement claiming innocence as his criminal trial began in New York.In a May 6 X post after court proceedings had likely ended for the day, Karony said he was innocent and “did not commit fraud” in response to media coverage of his trial. The former CEO, as well as SafeMoon creator Kyle Nagy and former chief technology officer Thomas Smith, were charged in 2023 for having allegedly “diverted and misappropriated millions of dollars’ worth” of the platform’s SFM token.According to reporting from the US District Court for the Eastern District of New York (EDNY) on May 6, Karony implied that Nagy, who reportedly fled to Russia after authorities filed charges, was responsible for some of the alleged fraud at SafeMoon. On the first day of the trial, after jury selection, Smith reportedly appeared as a witness for the prosecution with a SafeMoon victim.The trial, expected to run until May 26, has arguably received less media attention and scrutiny than other crypto cases, such as the 2023 trial of former FTX CEO Sam Bankman-Fried and the sentencing of former Binance CEO Changpeng Zhao. Karony pleaded not guilty to charges of securities fraud conspiracy, wire fraud conspiracy and money laundering conspiracy, and has been free on a $3 million bond since February 2024.Related: What do crypto users want to happen to Alex Mashinsky?Many high-profile individuals from the crypto industry who faced criminal charges did not publicly comment on social media until the conclusion of their cases, likely on the advice of counsel. Such statements may be used at trial.Trump’s interim appointee moves in without Senate confirmationKarony’s case, first filed in November 2023, came as Donald Trump appointee Joseph Nocella assumed the role of interim US Attorney for the court district. EDNY’s courts have previously handled cases involving allegations of crypto fraud, but it’s unclear whether politics will play a role moving forward, given Trump’s alignment with the crypto industry.In the neighboring US District Court for the Southern District of New York, Alex Mashinsky is scheduled to be sentenced on May 8. The former Celsius CEO pleaded guilty to two felony charges in December 2024. Prosecutors have asked a judge to impose a 20-year sentence.Magazine: Bitcoiner Adam Back on Blockstream conspiracy theories and Satoshi question

Open chat
1
BlockFo Chat
Hello 👋, How can we help you?
📱 When you've pressed the BlockFo button, we automatically transfer to WhatsApp 🔝🔐
🖥️ Or, if you use a PC or Mac, then we'll open a new window to load your desktop app.
BlockFo
BlockFo