# Firmware Upgrade


**Draft, not yet verified on hardware.**

Install firmware v1.4.3 on a SeedHammer II from a Windows or Linux computer or an Android phone by copying one file. No flashing tool is needed.

**Note:** An upgrade never asks for seed words, and the machine stores nothing an upgrade could lose ([What the machine keeps](/doc/manual/security-faq#storage)). Seed words are typed on the machine only and never pass through a phone, a computer or a chat assistant.

## What you need {#requirements}

- A Windows or Linux computer, or an Android phone. A Mac connected directly shows no USB drive ([workaround](#troubleshooting)).
- A USB cable to the machine's USB-C port. The computer or phone powers the machine during the upgrade.
- The machine's USB-C PD supply, to read the version only ([Choose the power supply](/doc/manual/power-and-first-start#power)).
- The file `seedhammerii-v1.4.3.uf2` ([Download the firmware](#download)).

## Check the installed version {#version}

- Connect the PD supply and wait for the start screen "Backup Wallet".
- Read the two lines at the bottom right, for example "Firmware: v1.4.3" and "Hardware: v1.5".

![Start screen with the version lines at the bottom right](/static/img/firmware-upgrade-01.webp)
<!-- capture: II screen, start screen "Backup Wallet", bottom right "Firmware: v1.4.3" over "Hardware: v1.5" (device-screen-map 4.2 row 1, version string "Firmware: v1.4.3\nHardware: v1.5") -->

| On screen | Meaning |
| --- | --- |
| v2.x, for example "v2.0.4-beta" | An older beta. Releases restarted at v1. |
| v1.4.1 (April 2026) or v1.4.2 (June 2026) | A descriptor's QR code leaves out the master fingerprints and the origin paths before each key. |
| v1.4.3 (July 2026) | Latest release; the QR code keeps them. Update a new machine before its first plate. |
| " (UNLOCKED)" after the hardware version | Secure boot is off, or the SeedHammer key is not the only valid boot key ([Read the lock mark](/doc/manual/security-faq#unlocked)). |

## Download the firmware {#download}

- Open the <a href="https://github.com/seedhammer/seedhammer/releases" target="_blank">firmware releases</a>. v1.4.1, v1.4.2 and v1.4.3 are the signed, open-source SeedHammer II releases. Older `.img` releases are for the original SeedHammer.
- Under v1.4.3, open **Assets** and download `seedhammerii-v1.4.3.uf2`.
- Optional: compare the file's SHA-256 with `07bdb759041a08307cf151f94fb77d2c21444418ccc0bf04b432015cbbcb3794`. Windows: `certutil -hashfile seedhammerii-v1.4.3.uf2 SHA256`. Linux: `sha256sum seedhammerii-v1.4.3.uf2`. Mac: `shasum -a 256 seedhammerii-v1.4.3.uf2`.

**Note:** From here on the computer or phone can stay offline. To rebuild a release or sign your own builds, see [Rebuild a release](/doc/manual/security-faq#reproduce) and [Use your own signing key](/doc/manual/security-faq#own-key).

## Put the machine into upgrade mode {#connect}

In upgrade mode the screen shows no picture (dark, or backlight only) and the machine appears as a USB drive named `SHII` or the chip's default name (unverified). Start with the PD supply unplugged and the screen dark.

### Without the button (v1.4.2 and v1.4.3) {#no-button}

From v1.4.2 on, the firmware restarts into upgrade mode by itself on a port that cannot offer 20 V to 28 V at 3 A or more (unverified). Most computer and phone ports cannot.

- Connect the machine's USB-C port to the computer or phone. The USB drive appears.

### With the firmware button {#button}

Use the button on firmware older than v1.4.2, when the start screen appears instead of a drive, or when the machine does not start. The chip's boot ROM reads it, so it works whatever firmware is installed. The firmware button (RP2350 BOOTSEL) sits on the underside near the hammerhead and carries the label "Hold button while connecting the USB cable to update firmware"; the other button, "RESET", only restarts the board (labels and position unverified). Find it by its label, not by a button number in a photo.

![The two buttons on the controller board](/static/img/firmware-upgrade-02.webp)
<!-- capture: photo, SH II controller board of a v1.4.3 unit, machine unplugged, both buttons in frame with their printed labels legible ("Hold button while connecting the USB cable to update firmware", "RESET"), firmware button marked -->

- Connect the cable to the computer or phone, not yet to the machine.
- Press and hold the firmware button.
- While holding it, connect the cable to the machine.
- Release the button when the USB drive appears.

## Copy the firmware {#upload}

- Copy `seedhammerii-v1.4.3.uf2` onto the USB drive (drag it, or use a file manager on Android).
- Wait until the drive disappears. The installation is complete.
- Connect the PD supply in place of the cable.

![Copying the firmware file onto the USB drive](/static/img/firmware-upgrade-03.webp)
<!-- capture: Windows 11 File Explorer, SH II in upgrade mode, drive window open with its files listed, seedhammerii-v1.4.3.uf2 dragged onto it -->

## What the machine shows {#machine}

- During and after the copy: a dark screen, or backlight only. Normal on USB power.
- On a computer or phone port the drive may appear again, because the new firmware restarts into upgrade mode (unverified). The upgrade has worked.
- On the PD supply: "Backup Wallet" with "Firmware: v1.4.3" at the bottom right. A dark screen here: [Power faults](/doc/manual/power-and-first-start#troubleshooting).

## If it does not work {#troubleshooting}

| Symptom | Cause | Fix |
| --- | --- | --- |
| No USB drive on a Mac | Apple USB controllers do not work with the RP2350 boot mode. This cannot be fixed on SH II boards. | A USB-C to USB-A adapter on the Mac, then a USB-A to USB-C cable. Or use Windows, Linux or Android. |
| No USB drive on Windows, Linux or Android | Without the button, only v1.4.2 or later enters upgrade mode. | Use [the firmware button](#button). A computer works more reliably than a phone. |
| The start screen appears instead of a drive | The port offered enough power, so the firmware started normally. | Use [the firmware button](#button). |
| The USB drive appears on the PD supply | The supply does not offer 20 V to 28 V at 3 A or more. | Use one that offers 20 V or 28 V at 5 A ([Choose the power supply](/doc/manual/power-and-first-start#power)). |
| No start after an upgrade, even on a suitable PD supply | | Enter upgrade mode with [the firmware button](#button) and copy the release file again. |
| Garbled display after an upgrade | The screen's flat cable is loose. | [Screen and touch](/doc/manual/troubleshooting#screen). |
| A descriptor that fitted on v1.4.2 shows "Too Large" on v1.4.3 | v1.4.3 keeps the master fingerprints and origin paths, so the QR code is larger. | Option: engrave it on v1.4.2. Secure boot may refuse the downgrade (unverified). That QR code restores with extra steps: [Plates from older firmware](/doc/manual/recovery-from-plates#old-plates). |

<!--
bench-checks:
  - [ ] Enter upgrade mode on v1.4.3 with no button (Windows, Linux and Android port) and with the firmware button; record the screen (dark or backlight only); page marks the no-button restart "unverified"
  - [ ] Photograph the controller board: position and silkscreen label of both buttons ("Hold button while connecting the USB cable to update firmware" by SW1 on net ~{USB_BOOT}, "RESET" by SW2 in the repo design); confirm the firmware button sits on the underside near the hammerhead (company manual); confirm on a shipped board and keep in step with hardware-and-spares; page marks labels and position "unverified"
  - [ ] Flash from macOS through a USB-C to A to C chain; try picotool on macOS (not on the page until it works)
  - [ ] Flash from Windows (File Explorer), Linux and Android (name the file manager and its version)
  - [ ] Screen state after the UF2 copy with and without the PD supply; does the drive reappear on a computer port after the copy on a v1.4.3 board (page: "unverified")
  - [ ] Downgrade from v1.4.3 to v1.4.2: does the drive accept the file, does secure boot refuse it, does v1.4.2 start (the company suggests v1.4.2 for descriptors that no longer fit; page: "Option: engrave it on v1.4.2", "Secure boot may refuse the downgrade (unverified)")
  - [ ] USB drive name and files on a shipped unit: "SHII" with the company's white-label data, or the RP2350 default (page: "unverified")
  - [ ] Shipped units: no " (UNLOCKED)" after the hardware version (definition now in security-faq#unlocked words, harmonized 2026-10-10)
  - [ ] A v1.4.1 and a v2 beta machine connected to a computer port without the button: start screen, dark screen, or drive? (moved from the "start screen instead of a drive" row)
  - [ ] No drive on Windows, Linux or Android with the button: is releasing the button before the drive appears a cause? (removed from the page: no source)
  - [ ] A PD supply offering 20 V below 3 A (45 W class): drive appears instead of the start screen, as the code predicts
  - [ ] SHA-256 of the downloaded file matches the page; certutil, sha256sum and shasum output as shown
  - [ ] Garbled display fix (connector locks): owner is troubleshooting#screen, this page links there
provenance removed from the body (edit pass 2026-10-10): Mac row cause and workaround are the company's statement; own-key section folded into the download note and the releases bullet ("signed, open-source", no inbound links); "a computer works more reliably than a phone" is from owner reports (harvest, see sources); v1.4.2 for descriptors that no longer fit is the company's suggestion; button position from the company manual, button labels from the board design files.
sources: manuals/REVIEW-wave1.md sections 2 to 4 (harmonized: power gate and buying advice linked to power-and-first-start#power, UNLOCKED wording from security-faq#unlocked, own key and reproducible builds linked to security-faq, old-QR wording; the v1.4.2 downgrade suggestion stays on this page only; see manuals/HARMONIZE-wave1.md); research/device-screen-map.md (1.1, 1.2, 2 "Hardware", 5 items 4 and 5, bench checks 3, 4, 8), research/BRIEF.md (power and upgrade-mode correction), upstream ea4b65b README.md "Installation" (lines 12-14) and "Reproducible builds" (lines 25-33), cmd/controller/platform_sh2.go :159-161 minVoltage/maxVoltage, :413-426 rebootIntoBOOTSEL, :428-439 monitorPowerSupply (comment "help the user in case they didn't hold the BOOTSEL button while connecting"), :510-519 LockBoot and :666-694 writeOTPValues (the only durable writes; no machine.Flash, EraseBlocks or WriteAt in non-test code, grep of lab/check/upstream 2026-10-10), :712-739 isSecureBootEnabled, driver/ap33772s/ap33772s.go:100-139 (3 A minimum), gui/gui.go 2370-2373, GitHub release notes read 2026-10-10: v1.4.1 "First open source and reproducible release of the SeedHammer II firmware." (2026-04-23), v1.4.2 "Reboot into USB drive mode if an insufficient power supply is connected. Blocks users from operating the machine in vain, and helps users upgrade firmware without holding the programming button while connecting." (2026-06-14), v1.4.3 (2026-07-14) and its asset digest sha256:07bdb759041a08307cf151f94fb77d2c21444418ccc0bf04b432015cbbcb3794, releases list (SH I v0.9.0 to v1.3.1 on the same page), github.com/seedhammer/hardware mainboard/pcb/mainboard.kicad_pcb (F.SilkS gr_text line 61428, SW2 Label "RESET" line 50842, SW1 on net /~{USB_BOOT}), https://seedhammer.com/doc/manual/firmware-upgrade (company's button location, read 2026-10-10), harvest Q02 Q05 Q06 Q07 Q08 Q10, SYNTHESIS section C (2025-06-20, 2025-09-10, 2026-04-23, 2026-05-22, 2026-07-14, 2026-07-26, 2026-08-03, 2026-09-15, 2026-09-18), section D (Mac drive, drive vanishes, backlight only, garbled display, 3-of-5 Too Large, stripped QR rows), section F rows 8 and 10 and the downgrade note. Internal links: power-and-first-start#power #troubleshooting, security-faq#storage #unlocked #own-key #reproduce, troubleshooting#screen, recovery-from-plates#old-plates (all drafted in manuals/).
-->
