
Out-of-date firmware is the most common self-inflicted security hole in hardware wallet ownership. This page shows the current stable firmware for every major bitcoin hardware wallet plus a running log of security incidents that actually matter. Bookmark it — a monthly glance is all you need.
Security incident log
July 31, 2026 — CRITICAL — Coldcard RNG firmware vulnerability — funds actively stolen
A firmware bug caused Coldcard devices to silently bypass their hardware random number generator, producing weak keys that attackers brute-forced remotely. Roughly 594 BTC (~$38M) was reportedly drained from about 500 wallets in under half an hour. No physical access and no user error was required. Action: update to Mk4 5.6.0 / Q 1.5.0Q immediately. If your wallet was set up on affected firmware, treat the seed as compromised: create a fresh wallet on patched firmware (or another device) and move funds to it. Other brands (Trezor, Ledger, Jade, BitBox, Foundation) report they are not affected. Sources: TechTimes, Securities.io.
June 2026 — LOW (lab-only) — Trezor Safe 7 secure-element flaw found by Ledger researchers
Ledger’s Donjon security team demonstrated a laser fault-injection attack against the TROPIC01 chip in the Safe 7. It requires physical possession of your device plus laboratory equipment, defeats only one of several security layers, and cannot be fixed in firmware. No real-world exploitation is known. Action: use a passphrase — it independently protects your funds even if a stolen device is fully cracked. Sources: CoinDesk, Decrypt.
December 2023 — RESOLVED — Ledger ConnectKit supply-chain attack
A compromised JavaScript library used by many web3 sites briefly served wallet-draining code. Devices themselves were never affected; the fix shipped within hours. Lasting lesson: be suspicious of every “connect wallet” prompt.
July 2020 — ONGOING PHISHING — Ledger customer data breach
Ledger’s marketing database (emails, addresses, phone numbers) was leaked. Devices and funds were never at risk, but the leaked list still fuels phishing emails, fake “security updates,” and even physical threats years later. If you get an urgent message about your wallet: it is fake. No wallet maker will ever ask for your 12 or 24 words.
How to use this page
Check your device’s version against the table (your wallet’s official app shows it under Settings → Device). If you’re behind, update through the official app only — never from a link in an email. New here? Start with our setup guide or the full comparison table.
Maintained by BTC Wallets editors. Incident reports summarize third-party reporting, linked above — always verify with the manufacturer’s official channels. Last full review: August 1, 2026.
