Connect with us

Published

on

The hidden risk of updatable firmware

Opinion by: Igor Zemtsov, chief technology officer at TBCC

Crypto security is a ticking time bomb. Updatable firmware might just be the match that lights the fuse.

Hardware wallets have become the holy grail of self-custody, the ultimate safeguard against hackers, scammers and even government overreach. There’s an inconvenient truth, however, that most people ignore: Firmware updates aren’t just security patches. 

They’re potential backdoors, waiting for someone — whether a hacker, a rogue developer or a shady third party — to kick them wide open.

Every time a hardware wallet manufacturer pushes an update, users are forced to make a choice. Hit that update button and hope for the best, or refuse to update and risk using outdated software with unknown vulnerabilities. Either way, it’s a gamble. 

In crypto, a bad gamble can mean waking up to an empty wallet.

Firmware updates aren’t always your friend

Updating firmware sounds like common sense. More security! Fewer bugs! Better user experience!

Here’s the thing: Every update is also an opportunity not just for the wallet provider but for anyone with the power, or motivation, to tamper with the process.

Hackers dream of firmware vulnerabilities. A rushed or poorly audited update can introduce tiny, almost imperceptible flaws — ones that sit in the background, waiting for the right moment to drain funds. And the best part? Users will never know what hit them.

Then there’s the more unsettling possibility: deliberate backdoors.

Recent: Hardware wallet Ledger helps competitor Trezor resolve security vulnerability

Tech companies have been forced to include government-mandated surveillance tools before. What makes anyone think hardware wallet makers are exempt? If a regulatory agency — or worse, a criminal organization — wants access to private keys, firmware updates are the perfect attack vector. One hidden function. One disguised line of code. 

That’s all it takes. Still think firmware updates are harmless? 

Firmware vulnerabilities are already being exploited

This isn’t some far-fetched, doomsday scenario. It has already happened.

Ledger, one of the biggest names in crypto security, had a major security crisis in 2018 when security researcher Saleem Rashid exposed a vulnerability that allowed attackers to replace Ledger Nano S firmware and hijack private keys. Nearly 1 million devices were at risk before a fix was rolled out. The scary part? There was no way for users to know if their devices had already been compromised.

In 2023, OneKey suffered a similar nightmare. White hat hackers demonstrated that its firmware could be cracked in mere seconds. No crypto was lost — this time. But what if real attackers had found the flaw first?

Then came the “Dark Skippy” exploit, taking firmware-based attacks to an entirely new level. With just two signed transactions, hackers could extract a user’s entire seed phrase — without setting off a single alarm. If firmware updates can be manipulated this easily, how can anyone be sure their assets are safe?

The hidden price of updatable firmware

To be fair, not all firmware updates are security disasters. Ledger uses a proprietary operating system and secure element chips for added protection now. Trezor takes an open-source approach, allowing the community to scrutinize its firmware. Coldcard and BitBox02 give users manual control over updates, reducing — but not eliminating — risk.

Here’s the real question: Can users ever be 100% sure that an update won’t introduce a fatal flaw?

Some wallets have decided to eliminate the risk altogether. Tangem ships with fixed, non-updatable firmware, meaning that its code can never be altered once the device leaves the factory. No updates. No patches. 

Of course, this approach has its trade-offs. If a vulnerability is discovered, there’s no way to fix it. But in security, predictability matters. 

Real crypto security means taking back control

The crypto market was worth $2.79 trillion as of March 2025. With that much money on the table, cybercriminals, rogue insiders and overreaching governments are always looking for weak points. Hardware wallet makers should be laser-focused on security.

Choosing a hardware wallet shouldn’t feel like gambling with private keys. It shouldn’t involve blind trust in a corporation’s ability to push updates responsibly. Users deserve more than vague reassurances. They deserve security models that put control where it belongs — with them.

Security isn’t about convenience. It’s about control. Any system that requires trusting unknown developers, opaque update processes or firmware that can be changed at will? That’s not control. That’s a liability.

The only real way to keep a hardware wallet safe? Remove the guesswork. Strip away the blind trust. Always research the developers’ backgrounds, check their track record for security incidents, and see how they’ve handled past vulnerabilities. Stick to verifiable facts — security should never be based on assumptions.

Opinion by: Igor Zemtsov, chief technology officer at TBCC.

This article is for general information purposes and is not intended to be and should not be taken as legal or investment advice. The views, thoughts, and opinions expressed here are the author’s alone and do not necessarily reflect or represent the views and opinions of Cointelegraph.

Continue Reading

Politics

Corbyn and Sultana have ‘patched things up’ – but what really happened?

Published

on

By

Corbyn and Sultana have 'patched things up' - but what really happened?

For decades he was the dissident backbencher, then unlikely Labour leader. She was a firebrand left-wing Labour MP with a huge online presence. To the left – on paper – it looked like the perfect combination.

Coupled with the support of four other independent MPs, it held the blueprints of a credible party. But ever since the launch of Your Party (working title) the left-wing movement has faced mockery and exasperation over its inability to look organised.

First, we learned Jeremy Corbyn’s team had been unaware of the exact timing of Zarah Sultana’s announcement that she would quit the Labour Party. Then a much bigger row emerged when she launched a membership drive linking people to sign up to the party without the full consent of the team.

It laid bare the holes in the structure of the party and pulled focus away from its core values of trying to be a party to counter Labour and Reform UK, while also drawing out some pretty robust language from their only woman MP calling the grouping a “sexist boys club”. It gave the impression that she was being sidelined by the four other male MPs behind the scenes.

This week, they tried to come together for the first time at a rally I attended in Liverpool and then, in quick succession, another event at The World Transformed conference the day after. But not everyone I spoke to who turned up to see the two heroes of the left found them all that convincing.

Jeremy Corbyn admitted to me that “there were some errors made about announcements and that caused a problem”. He said he was disappointed but that “we’re past that”.

Jeremy Corbyn and Zarah Sultana take part in a discussion on Your Party at The World Transformed conference in Manchester. Pic: PA
Image:
Jeremy Corbyn and Zarah Sultana take part in a discussion on Your Party at The World Transformed conference in Manchester. Pic: PA

Zarah Sultana said they were like Liam and Noel, who managed to “patch things up and have a very successful tour – we are doing the same”.

The problem is, it didn’t really explain what happened, or how they resolved things behind the scenes, and for some, it might have done too much damage already.

Layla signed up as a member when she first saw the link. It was the moment she had been waiting for after becoming frustrated with Labour. But she told me she found the ordeal “very unprofessional, very dishonest and messy”, and said she doesn’t want to be in a disorganised party and has lost trust in where her money will end up. She’s now thinking about the Greens. She said their leader, Zack Polanski “seemed like such a strong politician” with “a lot of charisma”.

Please use Chrome browser for a more accessible video player

Jeremy Corbyn’s back – with Zarah Sultana and a new party. But is it a real threat to Labour, or just political theatre?

Since Polanski’s rise to power as leader, the Green Party has surged in popularity. According to a recent poll, they went up four points in just one week (following their conference). Voters, particularly on the left, seem to like his brand of “eco populism”.

While he has politely declined formally working in conjunction with Your Party publicly, he has said the “door is always open” to collaboration especially as he sees common goals between the two parties. Zarah Sultana said this weekend though that the Greens don’t describe themselves as socialists and that they support NATO which she has dubbed an “imperialist war machine”.

While newer coalitions may not be the problem for now, internal fissures might come sooner than they expect. Voters at the rally this weekend came with pretty clear concerns about some of the other independent MPs involved in Your Party.

The two heroes of the left fell out over a row over their party's paid membership system
Image:
The two heroes of the left fell out over a row over their party’s paid membership system

Read more on Sky News:
AI ‘distorting women online’
Pros and cons of digital IDs
Impact of new online safety rules

I asked Ayoub Khan if he considered himself left-wing. A question that would solicit a simple answer in a crowd like this. But he said his view was very simple, that he is interested in fighting for equality, fairness and justice: ‘We all know that different wards, different constituencies have different priorities and MPs should be allowed to represent the views of the communities they serve.” To him, that can sometimes mean voting against the private school tax and against decriminalising abortion.

The Your Party rally on Thursday night was packed, but the tone was subdued. People came full of optimism but they also wanted to make up their mind about the credibility of the new offering and to see the renewed reconciliation up close.

The organisers closed the evening off with John Lennon’s song, Imagine. That was apt, because until the party can get their act together, that’s all they’ll be doing.

Continue Reading

Politics

DeFi booming as $11B Bitcoin whale stirs ‘Uptober’ hopes: Finance Redefined

Published

on

By

DeFi booming as B Bitcoin whale stirs ‘Uptober’ hopes: Finance Redefined

DeFi booming as B Bitcoin whale stirs ‘Uptober’ hopes: Finance Redefined

An $11 billion Bitcoin whale returned to crypto markets this week, likely seeking trading opportunities tied to October’s historic crypto rallies and uncertainty in the US.

Continue Reading

Politics

SEC’s ‘future-proofing’ push to shape how much freedom crypto enjoys after Trump

Published

on

By

SEC’s ‘future-proofing’ push to shape how much freedom crypto enjoys after Trump

SEC’s ‘future-proofing’ push to shape how much freedom crypto enjoys after Trump

Could a future US presidential administration undo all of Paul Atkins’ work in a matter of days? Cointelegraph spoke to legal and regulatory experts to find out.

Continue Reading

Trending