A hardware-wallet firmware update can add support, fix bugs, or address security issues. Before installing one, verify that the update is intended for your exact device and comes through an authentic path. There is no single hash command or verification routine that applies to every wallet: some manufacturers verify a signed firmware package on the device, some provide a desktop authenticity check, and some also publish hashes or signatures for advanced manual verification.
This checklist helps you establish what you actually verified. A green status in a companion app, a valid package signature, and a device’s bootloader accepting firmware are related safeguards, but they are not interchangeable guarantees. As of September 30, 2026, follow the current instructions for your model and firmware release rather than copying steps from another wallet.
Quick checklist
| Before proceeding | Pass condition | Stop if |
| Identify device and current version | Model, hardware revision, and installed version match the manufacturer’s update guidance. | The release is for a different model, channel, or revision. |
| Open the official update path | You reached the vendor’s genuine desktop app or typed the manufacturer’s official domain yourself. | A message, ad, QR code, search result, or unsolicited support agent supplied the installer. |
| Check release details | Version, release notes, and any required intermediate version agree with the official page. | The version is missing, the details conflict, or the prompt is unexpected. |
| Verify authenticity using the vendor’s method | The app, device bootloader, signature checker, or published checksum reports the expected result. | Any signature, hash, genuine-device, or firmware-integrity warning appears. |
| Read and confirm on the device | The physical device displays the expected update and asks for your explicit approval. | The prompt asks for a recovery phrase, PIN on a computer, or unrelated transaction approval. |
| Check after restart | The wallet reports the intended version and the manufacturer’s integrity/authenticity check passes. | The device shows a warning, unexpected reset, or different firmware version. |
1. Confirm the update applies to your exact wallet
Start with the model name printed on the device or shown in its settings, then check the installed firmware version. A manufacturer may publish separate builds for different generations, secure-element variants, regional editions, or release channels. Do not infer compatibility from a similar product name or from another owner’s screenshot. Check the official release notes for the exact model and whether an intermediate update is required.
Read what changed and whether the release is stable, beta, or developer firmware. A new version number alone is not proof that an update is urgent or authentic. If an update notice arrives by email, social media, a pop-up, or a direct message, do not use its link. Open the manufacturer’s official app independently and compare the notice with the vendor’s support or release page.
2. Secure the companion app and download path
The desktop or mobile app is part of the verification chain. Download it only from the manufacturer’s official website or its explicitly linked app-store listing. Confirm the domain carefully, especially before installing a desktop app. Avoid sponsored search results, third-party download sites, browser extensions, and links sent by people claiming to be support.
For desktop software, use the vendor’s published signature-verification instructions when available. Trezor, for example, provides a guide to downloading and verifying Trezor Suite. Verifying the companion app helps establish that the software presenting an update is authentic; it does not by itself prove that every firmware binary or device is safe. Keep the operating system and security tools current, and do not disable protections simply because a download is blocked.
3. Understand what firmware verification means for your model
Many hardware wallets use a bootloader or secure hardware to check a manufacturer signature before the new firmware runs. The wallet’s screen may ask you to approve an update, and the bootloader may reject an unsigned or altered image. That on-device check is valuable because it can protect against a modified file even if the file passed through a compromised computer. The exact design and warning behavior vary by device.
Some companion applications perform additional checks. Trezor documents separate firmware revision and hash checks in its firmware hash-check explanation, and describes its firmware update flow in the official update guide. Ledger’s support documentation describes the device’s authenticity check and firmware-update process; start from its Ledger OS update guide and the genuine-device check.
For some wallets, the manufacturer publishes a firmware file, cryptographic signature, checksum, or reproducible-build procedure for manual verification. COLDCARD’s firmware upgrade documentation includes file verification steps and installation guidance. Do not substitute a checksum copied from a forum or calculate a hash and assume it proves authenticity: a hash is useful only when compared against a value obtained through an authenticated, independent channel. A signature is meaningful only when verified with the correct trusted public key and prescribed tool.
4. Protect your recovery access before updating
Know where your recovery backup is and confirm that you can access it if the device needs to be restored. Never type a seed phrase or recovery phrase into a computer, phone, website, chat, or “verification” form to prepare for a firmware update. A legitimate update should not require you to disclose those words to the companion app or a support agent. If the official procedure for a particular device involves a reset or restore, read that model-specific guidance first and make sure you understand the consequences before beginning.
Check the wallet’s own instructions for app removal, account availability, passphrase handling, or multisignature setup. Firmware updates can change device behavior or compatibility even when the seed remains the same. For a multisignature wallet, confirm that you have the required signer backups and configuration details before changing any signer’s firmware.
5. Install only after checking the physical device prompt
Use a stable connection and follow the official app’s model-specific steps. When the device itself displays an update prompt, read the screen before approving. Confirm that it describes a firmware installation and corresponds to the update you initiated. Do not approve an unrelated transaction or a prompt that appears when you are not updating. Never enter the recovery phrase on your computer, even if a page says it is required to “unlock,” “sync,” or “verify” the update.
During installation, keep the device connected and follow the manufacturer’s instructions about whether it may be unplugged or restarted. Do not interrupt power simply because progress pauses briefly. If the process fails, capture the exact error text without including private recovery information, then consult the vendor’s official troubleshooting guidance. Avoid repeatedly retrying an unexplained warning or installing a file offered by a forum user.
6. Verify the result after restart
After the device restarts, check the firmware version on the hardware wallet or in its official companion app. Run the manufacturer’s authenticity or integrity check if offered. A successful transfer bar is not enough: the device should boot normally, show the expected version, and present no signature, counterfeit, tampering, or firmware-integrity warning. Confirm that the companion app reconnects to the correct device and that your accounts appear as expected.
If a warning remains, stop using the wallet for signing until you have followed the manufacturer’s official resolution steps. Do not disable security checks to clear the message. Contact support through the vendor’s official website, and share only non-secret diagnostic details. No authentic verification routine can prove that a vendor, its signing infrastructure, or every element of the device supply chain is risk-free; these checks reduce specific risks rather than eliminating them.
When manual verification is appropriate
Manual signature or reproducible-build checks are useful for technically experienced users when the manufacturer documents the exact commands, key fingerprints, and release artifacts. Follow the directions for the exact firmware and device revision. Verify public-key fingerprints through a second official channel where the vendor provides one. If the vendor does not publish an independent signature or checksum procedure for your model, do not invent one or treat a community script as an official verification method. Use the documented update path and the device’s built-in checks instead.
Final go/no-go checklist
- I identified the exact wallet model, hardware revision, and installed firmware.
- I reached the official companion app and release information independently.
- The target version and release channel match my model and the vendor’s instructions.
- I understand which checks are performed by the app, the device, or a manual signature tool.
- I have access to my recovery backup, and I will not enter it into a computer or share it.
- The physical device shows the expected firmware prompt, with no authenticity or integrity warning.
- After restart, the installed version matches the intended release and the device passes its available checks.
If any item fails, pause the update and verify the instructions through the manufacturer’s official support site. Keeping firmware current can matter, but installing a release you cannot authenticate defeats the purpose of using a hardware wallet.