Trezor firmware controls asset support through Universal and Bitcoin-only builds
Trezor firmware runs your hardware wallet's functions, and its Universal and Bitcoin-only builds support different assets and authentication features. Universal handles Bitcoin and other supported cryptocurrencies. Bitcoin-only restricts wallet functions to BTC and excludes FIDO2 and U2F authentication. The choice also affects updates and recovery preparation: changing firmware types can erase device storage. Match the installed build to the functions you need, with a checked wallet backup ready before any installation.
Key takeaway: Switching firmware types can erase device storage, so a checked wallet backup matters even when your assets remain on their blockchains.
Removing non-Bitcoin functions changes device capabilities
Bitcoin-only firmware omits non-Bitcoin wallet functions, so connecting another application won't make those functions available on the device. Universal includes support for Bitcoin and other supported cryptocurrencies. The word Universal doesn't promise compatibility with every asset, network, or token. Support still has to match the particular hardware model and wallet application. Some supported assets need a compatible third-party interface because Suite doesn't manage them directly.
Authentication also matters because FIDO2 and U2F let compatible devices act as security keys for signing in to supported services. These functions require Universal firmware on models that implement them, so choosing Bitcoin-only affects more than the coins shown in your wallet app. If a service requires your Trezor login key, have another accepted sign-in method available before removing its authentication function. Bitcoin-only's narrower scope removes functionality you may not need without eliminating every possible security problem.
Suite, device software, and startup checks
Firmware runs on the hardware wallet, while Trezor Suite runs on the computer or supported mobile device. Suite supplies the interface for accounts and firmware installation. Firmware updates work in desktop and web Suite and on Android, but aren't supported in the iOS app. The bootloader is a separate program on the Trezor, responsible for installing firmware and checking its integrity and signatures before startup. An unofficial firmware warning means the device hasn't accepted the image as a normal trusted release.
Updating Suite changes the application; updating firmware changes software on the device. One update doesn't automatically stand in for the other. In Suite's Device settings, the firmware entry shows the installed version and type. A type describes the supported function set, while a version identifies a particular release within it. Matching numbers don't make different builds interchangeable.
A firmware image belongs to a specific hardware model, so a manually chosen file for a different Trezor model is incompatible even when version numbers match.
Does switching firmware erase the wallet?
Changing firmware types can erase the wallet stored on your device, making a valid backup necessary before you authorize installation. On Trezor Safe-family devices, plan to recover the wallet after switching between Universal and Bitcoin-only firmware. A routine update within the same type is a different operation. Previous updates preserving your wallet don't establish what a type switch will do.
Check backup, also called dry-run recovery, confirms whether your saved backup matches the wallet secret already on the Trezor. A wallet passphrase, if used, remains a separate requirement for reopening the same hidden wallet after recovery. The PIN unlocks the device and can't replace the backup or passphrase. Recovery preparation therefore needs the actual wallet secrets, even when you can still access the device normally.
Installing Bitcoin-only firmware doesn't erase non-Bitcoin balances from their blockchains. Those accounts become unavailable through the restricted firmware, including their signing functions. Restoring Universal can make supported accounts accessible again, provided the original wallet secrets are present or recovered. Switching software doesn't automatically transfer or convert coins. Erasing device storage changes access to the keys, so missing recovery information can still cause permanent loss of access.
A Bitcoin-only switch with a checked backup
In this hypothetical example, a Trezor manages existing Bitcoin accounts using Universal firmware, and its owner wants Bitcoin-only firmware. Suite warns the switch will erase storage, and the saved backup passes its check. The owner uses the standard wallet, so no additional passphrase is needed.
The owner reviews the requested Bitcoin-only type in Suite and the firmware version shown on the device. Installation remains unconfirmed during that review. When the details match the intended change, the owner authorizes installation and waits for it to finish. After the planned wipe, recovery loads the original backup instead of creating a new wallet. Suite can then discover the original Bitcoin accounts under Bitcoin-only firmware.
If the backup check instead fails, the owner stops before authorizing installation, leaving the existing firmware in place while the recovery problem remains unresolved.
After installation begins, cancellation isn't a way to retrieve an erased wallet secret. Losing the connection while new firmware is loading wipes the device, requiring reinstallation and wallet recovery. The original backup remains necessary in that case: it restores wallet access once compatible firmware works again. Without it, reinstalling Universal would restore software without reconstructing the original wallet.
When should I update the installed firmware?
Install a firmware update when its release addresses a relevant security issue, fixes a problem affecting your device, or enables a needed supported function. Releases can also update transaction handling as supported networks change. Suite displays the available release for the connected device, so another model's version isn't an upgrade target. Bitcoin-only can have fewer routine updates because it excludes other-coin functionality, though security fixes affecting its remaining code still matter. Have a checked backup ready before starting, and keep the connection stable during loading. A release notice doesn't eliminate the possibility of a device wipe.
Interrupted updates and empty account views
An interrupted firmware update can leave the device needing reinstallation and, if storage was erased, wallet recovery. A connection problem can also prevent Suite from recognizing the device during an update. For a USB connection, cable and port faults can interrupt communication. A bootloader screen shows firmware update mode; entering that mode doesn't confirm installation has started or that funds moved on-chain.
An empty account view after a completed update can follow Bitcoin-only firmware disabling non-Bitcoin accounts. A wiped device needs the original backup, and a newly generated wallet produces different accounts. For a passphrase wallet, a changed character selects a different wallet even after successful backup recovery. A missing account alone doesn't establish that funds moved on-chain.
A working installation can't compensate for missing recovery secrets, and repeated flashing introduces further interruption risk without solving that access problem.
Useful questions about Trezor firmware
-
Why is the Switch to Universal button missing on a Bitcoin-only Trezor?
- Trezor Suite doesn't show the Switch to Universal button on hardware sold as a Bitcoin-only edition. That interface restriction doesn't make Universal firmware impossible to install. Trezor Safe 3, Safe 5, and Safe 7 support installation through Suite's Install custom firmware option using the matching signed image. Check your backup and choose the correct file for the device before proceeding; custom installation can erase storage or leave the device unusable.
-
Does disabling other coins in Suite remove their firmware code?
- Disabling coins in Suite changes which accounts the application displays, while installing Bitcoin-only firmware changes the functions available on the device. Leaving Universal installed with only Bitcoin accounts enabled therefore retains its other supported capabilities. The firmware type shown in Device settings identifies the installed build; the visible account list alone doesn't establish it.
-
Can downgrading Trezor firmware preserve my wallet?
- Some supported firmware downgrades preserve wallet storage, while others erase it. The outcome depends on the device model and the installed and target versions. Some model and version combinations don't permit a downgrade at all. Older firmware can also lack later security fixes. Manual installation also carries a risk of leaving the device unusable.
-
Will a routine firmware update require my backup words on a website?
- A routine firmware installation asks you to confirm your backup is available without submitting its words to a website. If installation wipes the device, recovering the wallet is a separate process. Recovery entry differs by model and must follow the recovery instructions your Trezor confirms. An unsolicited web form requesting words to authorize an update isn't part of firmware installation.
-
Why does a Trezor Model One sometimes request two update confirmations?
- A Trezor Model One running firmware 1.11.2 or earlier can need separate confirmations for bootloader and firmware installation. The update involves both components, and the required prompts depend on the device's state.