Security updates

hi

a few things:

  1. since 2.3.5 i find it very hard to believe that no security updates have been necessary since this release. its been years how is this possible?

  2. i really want to support this company but when you deprecate a device in favour of a new shiny model with no security updates in years i find that really annoying.

  3. i believe you should put an expiry on a product or charge an annual fee once that period is over to support security updates but you cant just ignore it while you focus on a new model. how are we ever supposed to keep up

Hi,

On the first point, there have been several firmware releases since 2.3.5. That version shipped in October 2024, and it was followed by 2.3.6 through to 2.3.11, the most recent of which was December 2025. There is also a 2.4.0 in development right now. So the gap is not as long as it looks, and development has not stopped.

A firmware release is not the same thing as a security patch, and the absence of security patches is not the same thing as neglect. If no vulnerability has been found that affects the device, there is nothing to fix, and shipping updates purely to look busy would be the wrong instinct in a product like this. Every firmware change to a hardware wallet carries its own risk, so we would rather release when there is a reason to.

What we do instead is keep reviewing. This past week we have been through the entire entropy and seed generation path in Passport Core again, line by line, prompted by the Coldcard disclosure, alongside a considerable number of independent researchers doing the same thing in public. That work happens whether or not it results in a release.

On deprecation, we genuinely have not deprecated anything. Passport Founder’s Edition, our first device from 2021, is still supported. Passport Core is still supported. Both still work with modern wallet software and coordinators. We have never dropped support for a device we have sold, and we do not intend to start.

On your third suggestion, I would push back gently. We do not think anyone should have to pay a subscription to keep a hardware wallet secure, or face an expiry date on a device they own. You bought the hardware, and keeping it safe to use is our job rather than a service we rent back to you. Our firmware is also open source and reproducibly built, so even in a hypothetical where we stopped caring, the code is public and verifiable rather than locked away.

my apologies on this. your numbering system leaves somewhat to be desired lol. i assumed 2.3.5 is higher than 2.3.11 ie it should be 2.3.05 lol. i was looking everywhere 2.3.6