TL;DR
Yes, update, but calmly: through the maker’s own app, not right before a big transaction, and check afterwards that Sparrow still shows the same fingerprint and addresses. An update doesn’t change your seed.
Update, but not on day one
Updates fix bugs, including security bugs, and keep your device working with new versions of Sparrow and the makers’ apps. Old firmware also gets less attention from the maker over time.
New firmware occasionally has problems of its own. In a multisig, nothing forces you to update all devices on day one. Updating one device at a time, a few days after release, is a sensible habit.
How
- Check you have the seed backup for this device and know where it is.
- Connect the device to your signing computer and open its official app: Trezor Suite, BitBoxApp or Ledger Wallet.
- Install the update and confirm on the device when asked. The device checks that the firmware is signed by the maker.
- Unlock the device as usual (with the passphrase, if you use one).
- In Sparrow, check the master fingerprint is unchanged and show a receive address. On the BitBox02 or Ledger it should still verify against the registered multisig. On the Trezor it’s only an extra check, because the Trezor trusts what Sparrow sends.
Warning signs
- An update offered by email, a pop-up on a website or anything other than the official app. That’s a scam.
- A device that asks for your seed words after an update without you starting a recovery. Stop and contact the maker through their website.
- A different fingerprint afterwards. Usually a passphrase typo; otherwise, stop and investigate before using the device.
Related: Bitcoin-only firmware · yearly check-up