Flipper Zero firmware goes into maintenance mode as company hands the wheel to volunteers

The pocket-sized hacking gadget's maker is shrinking its firmware team and letting the community vote on what gets built next.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 4 min read
A small orange handheld electronic gadget with a monochrome screen and a directional pad sitting on a cluttered workbench, surrounded by tangled wires, a solder
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • Flipper Devices announced on 10 July 2025 that full-time feature development on the Flipper Zero firmware is over.
  • The company says more than one million people now own a Flipper Zero, more messages than its small team can handle.
  • Firmware version 1.4.3, available since December 2025, is the current stable release and will keep getting security and stability fixes.
  • All future feature requests will be filed and voted on through GitHub, the public code-sharing site owned by Microsoft.
  • The team says it will scrutinise contributions written with the help of AI, especially code that touches sensitive low-level parts of the device.

The Flipper Zero is a small orange gadget that looks like a Tamagotchi and lets its owner poke at wireless signals and access cards. It became a viral hit, a favourite of security researchers, and a headache for governments that tried to ban it.

Now its maker, Flipper Devices, is stepping back from building new features for it.

The company said this week that the firmware, the built-in software that makes the device work, has reached what it considers a finished state. Version 1.0 shipped in September 2024 after three years of work, and 1.4.3 is the last one the internal team plans to actively expand.

From here, the community writes the code.

What does this actually mean for people who own one?

Your Flipper Zero keeps working and still gets updates, mostly from volunteers. The official firmware isn't being abandoned. Flipper Devices says it will still review changes and publish releases. It's just no longer paying a full-time team to dream up new features.

That's a significant shift. Owners who expected steady new capabilities from the manufacturer will now depend on what unpaid contributors feel like building and what other users vote up.

The company, first reported by BleepingComputer as scaling back, framed the change as a response to scale. With over a million users, the small team says it can no longer keep up with direct messages on social media. Those channels are being closed. Everything moves to GitHub Discussions, where users file requests and vote on which ones get worked on next.

Why is the company doing this now?

Flipper Devices wants to build new hardware. The company is putting resources into the Flipper One, a bigger device running Linux, the open-source operating system that powers most of the internet's servers, and the Busy Bar, a desk gadget aimed at people with ADHD, which goes on sale in the US, UK and Canada on 14 July 2025.

Moving Flipper Zero into community-driven maintenance frees up engineers for those projects. It's a common pattern in hardware: ship the thing, declare it done, move on. The failure mode is when "community-maintained" quietly becomes "nobody maintains it" and security fixes stop landing.

Flipper Devices has set some rules to avoid that. Every firmware change must pass integration and regression tests, the automated checks that confirm a new tweak doesn't break something old. The team says it will pay special attention to AI-generated code, particularly anything touching the low-level guts of the device, where a subtle bug can brick hardware or open a security hole.

That's the right instinct. A lot of code being submitted to open-source projects right now comes from AI assistants, and reviewers are learning the hard way that plausible-looking code isn't the same as correct code. We covered a related problem on 3 July 2026 when runZero found seven bugs in FatFs, the filesystem library hiding inside cameras, drones and hardware wallets, precisely because low-level code gets audited slowly and patched even more slowly.

Should you worry?

If this arrangement goes wrong, the postmortem will note the obvious: the moment a vendor stops paying people to fix its firmware, the clock starts on how fast volunteers catch the next serious bug. Nobody outside the company knows how strict that review bar will actually be in practice, and "stricter review" is easy to say in a blog post.

Keep your Flipper Zero updated and treat the official GitHub as the front door now. That's the whole playbook.

© 2026 Threat Vectr