Why smart home gadgets stop receiving security updates
The first sign is always tactile. You pick up the camera, the hub, the smart lock—whatever it is—and run your thumb over the power button. The plastic feels the same, the weight is familiar, but the connection to the company that made it has grown cold.

I experienced this recently with a smart plug I'd used for three years. The companion app, once reliably updated with new scheduling features, hadn't changed its icon in over 18 months. The firmware version number in the settings menu was a fossil. The device still toggled my lamp on and off, but it had become a digital ghost, haunting my network with potential vulnerabilities it would never be patched against. It wasn't broken; it was abandoned. This is the quiet crisis of the smart home: your devices aren't built to last forever, and the companies that sold them to you have already decided when they'll die.
The promise of the connected home is perpetual convenience, but the reality is governed by cold, hard economics and the brutal lifecycle of silicon. Understanding why a device loses its security updates isn't about deciphering marketing spin; it's about reading the autopsy report of a product that's been written off. It's a story of cost-benefit analyses, chipset obsolescence, and regulatory gaps that leave your most personal devices exposed. And if you've ever wondered how to check whether your smart home gadgets have crossed that invisible line into unsupported territory, the answer requires more than a cursory glance at a product page.
The Ledger Sheet: How Your $40 Camera Becomes a Liability
Let's start with the math. That smart plug I mentioned? It probably cost $15 to make, sold for $39, and carries with it a perpetual hidden cost: the cloud. Every time you check its status or toggle it via an app, a request pings a server somewhere. That server has to be maintained, secured, and updated. The TLS certificates that encrypt your commands need rotating. The mobile app needs updates to comply with the latest iOS or Android security sandbox requirements. The customer support tickets from people who can't connect their device still need answering.
For a company selling millions of units, this operational overhead is a rounding error. For a vendor with a niche product or an aging device, it's a hemorrhage. The moment the cost of maintaining that server and software stack for your old device exceeds the projected profit from selling you a new device, the old one is on death row. The switch is flipped internally, and the public-facing support page starts its slow march from "Active" to "Legacy."
This is accelerated by acquisitions and corporate reshuffling. When a company is bought, the first spreadsheet opened is the product portfolio. Does this old hub align with our new roadmap? No? Sunset it. We've seen this with Google's Nest absorbing and then abandoning the Revolv hub, and Amazon doing something similar with early Ring and Eero hardware. The inherited product is a stranded asset, and the new owner's only incentive is to migrate you to their current, supported ecosystem.
The legislative landscape is only beginning to address this. The EU's Cyber Resilience Act, proposed by the European Commission in 2022 and formally adopted in 2024, envisions a minimum five-year support window for many connected consumer devices. But its obligations won't fully apply to manufacturers until 2027—meaning the law is still in the implementation phase, not yet enforceable. Until these rules have real teeth, the decision to pull the plug remains an internal, financial one.
The cloud isn't a feature; it's a subscription your hardware company pays for on your behalf. When they stop paying, your device dies.
The Heartbeat Inside: Why Your Chipset Has an Expiry Date
Forget the marketing on the box. The true lifecycle of your gadget is etched into the silicon at its core. A smart bulb or camera is built around a System-on-a-Chip (SoC)—a tiny computer from manufacturers like Espressif, Realtek, or MediaTek. This SoC runs on a software development kit (SDK) and a network stack provided by the chipmaker.
When the chipmaker stops updating that SDK, the device manufacturer is left with a grim choice: spend significant engineering resources maintaining their own private fork of the networking code (a costly, ongoing security commitment) or simply accept that the device's foundational software is now frozen in time. Almost all consumer brands choose the latter. Maintaining a private fork means paying embedded engineers indefinitely to backport security patches into code they didn't write, targeting hardware that will never generate another dollar of revenue. The economics simply don't pencil out.
This is why the last firmware update date is such a telling signal. I've opened devices from 2023 that were running a build of OpenSSL older than the Heartbleed vulnerability. The cryptographic library was a pre-compiled binary blob from the SoC vendor, dropped into the device's operating system and never touched again. The OEM never budgeted to maintain it. The moment a critical CVE hits that aging library, your device becomes an open door for attackers, and the manufacturer has no plan to close it.
The clock started ticking when the chip was designed, not when you bought the device. If your camera uses a three-generation-old Realtek Wi-Fi SoC that the vendor has stopped actively supporting, your camera's security has an expiration date, regardless of what the product page says.
The Seven Signs Your Device Is Being Abandoned
Vendors rarely send a termination notice. The abandonment is signaled through neglect. Here's what to look for, in order of severity.
1. The Companion App Stagnates. This is the canary in the coal mine. If the app you use to control the device hasn't had an update in six to nine months, especially after a major mobile OS release, the software team has moved on. The app is the first thing to break, and if they're not fixing it, they're not planning for the future.
2. The Firmware Changelog Goes Silent. If you can find a public firmware version history (some brands like Wyze or Ubiquiti offer these), and the last entry for your specific model is over a year old, that product is in a maintenance freeze.
3. The Support Page Language Softens. Keep a bookmark to your device's official support page. Watch for the shift from "Get the latest features" to "Troubleshooting" to "Legacy Product Information." Use the Wayback Machine to track changes. This wording shift is often the first public admission.
4. The App Disappears from Stores. If the companion app is suddenly delisted from the Apple App Store or Google Play Store, your device is functionally bricked for most users. This was a quiet kill switch used by Insteon before its servers went dark.
5. The Product Vanishes from the Storefront. When the "Buy" button on the manufacturer's own website is replaced with "Out of Stock" or "Discontinued," and no successor is announced, the installed base has become an orphaned liability.
6. A Public EOL List Appears. Some diligent companies (Sonos, Lutron, Logitech) maintain public End-of-Life lists with explicit dates. If your device appears on one, you have a deadline.
7. The Company Is Acquired. As mentioned, acquisition is a death knell for many product lines. The new owner's roadmap rarely includes supporting yesterday's acquisitions.
| Signal of Abandonment | Where to Verify | Typical Time Left |
|---|---|---|
| App update drought | App Store / Play Store changelogs | 6–12 months to functional failure |
| Firmware gone silent | Vendor support/community forums | 3–6 months to critical vulnerability |
| Support page wording | Official site & Wayback Machine | 2–6 months to formal EOL |
| App delisted | App Store / Play Store | 0–3 months (often the final act) |
| Acquisition news | Tech press, SEC filings | 6–18 months to product line purge |
| Appearance on EOL list | Vendor documentation | Hard deadline |
The quietest way to kill a product isn't a press release—it's simply to stop updating the app.
The Verification Playbook: Don't Assume, Verify
When you suspect a device is nearing its end, you need a definitive answer. Guessing isn't a security strategy. Work through this methodically.
First, hunt for the official EOL statement. Go directly to the manufacturer's support site and search for "end of life," "legacy products," or "support lifecycle" for your specific model. Brands like Sonos and Lutron are relatively transparent here. Others bury this information in developer portals or legal pages nobody reads. If you can't find any statement at all, that's not reassuring—it's a red flag that the company doesn't even have a formal lifecycle management process.
Second, check the firmware. Open your device's app, go to settings, and note the exact firmware version number. A quick web search for "[Product Name] firmware [version number]" will often pull up release notes and a date. If it's old, that's your first hard data point. Cross-reference this against community forums where users often catalog update histories far more meticulously than the manufacturers themselves.
Third, consult the vulnerability databases. The CISA Known Exploited Vulnerabilities (KEV) catalog is a public list of vulnerabilities actively being used in attacks. Search for your device manufacturer and model. If a CVE affecting your device is listed here, and no patch exists, you have your answer: it's compromised, and the vendor has left you exposed. The National Vulnerability Database (NVD) and vendor-specific security advisories are worth checking too, but the KEV catalog tells you what's actually being exploited right now in the wild.
Fourth, gauge the community. Dive into Reddit's r/homeautomation or r/smarthome, the Home Assistant community forums, or niche Discord servers. Real users report bricked devices, delisted apps, and server shutdowns months before any official communication. Their collective experience is the most reliable early-warning system you have. Pay particular attention to threads where multiple users report the same connectivity failures after an OS update—this often means the developer has stopped adapting the app to platform changes.
Fifth, know your silicon. If you're technically inclined, a quick teardown (or a search of the FCC internal photos database for your device's FCC ID) can reveal the exact SoC. A 2018-era Realtek chip is a much riskier proposition in 2025 than a current-generation ESP32 variant. Understanding what's inside tells you how long the chipmaker's support window realistically extends—and whether you're already past it.
Auditing Your Smart Home: A Practical Security Walkthrough
Most people have between ten and thirty connected devices scattered across their network, and they've never checked the support status of a single one. This is understandable—it's tedious work—but it's also how critical vulnerabilities accumulate unnoticed. A practical audit of your smart home security posture doesn't require a cybersecurity degree; it requires a systematic approach.
Start by making a simple inventory. Walk room by room and note every internet-connected device: smart speakers, thermostats, light bulbs, plugs, cameras, locks, garage door openers, robot vacuums, even that Wi-Fi-enabled air purifier you forgot about. For each device, record the manufacturer, model, firmware version, and date you last remember it receiving an update. This spreadsheet—your network census—is the foundation of everything else.
Next, categorize each device by its attack surface. A smart bulb that runs on a Zigbee mesh and connects only to a local hub presents a relatively small risk surface. A security camera with cloud recording, two-way audio, and direct internet connectivity? That's a fortress wall with a known crack in it. Devices with microphones, cameras, or physical access control (locks, garage doors) deserve the most scrutiny and the shortest leash.
Check each device against the verification steps in the previous section. Flag anything that hasn't received a firmware update in over a year, whose app hasn't been refreshed since the last major OS cycle, or whose manufacturer has been acquired, pivoted business models, or gone silent. Then look at your network architecture itself. Many consumer routers now offer an "IoT network" or "guest network" feature. Use it. Segregating your smart home devices from your primary computers and phones limits the blast radius if a compromised device tries to pivot laterally across your network.
This audit isn't a one-time exercise. Set a reminder every six months—tie it to daylight saving time changes, tax season, whatever mnemonic works. The smart home landscape moves fast, and a device that was actively supported last spring might be a liability by winter.
The Verdict: Isolate or Evict
So, you've confirmed it. Your device is abandoned. It's receiving no updates, it runs on obsolete software, and it's a sitting duck on your network. You have two choices, and neither is ideal.
The First Choice: Isolation. If the device is non-critical—a smart bulb, a simple plug—and you can't live without its specific function, you can try to quarantine it. Place it on a separate IoT VLAN with strict firewall rules that block it from accessing the internet entirely and limit its ability to communicate with other devices on your network. This mitigates the risk of it being recruited into a botnet or used as a pivot point for an attack. You keep the functionality; you wall off the risk. On consumer-grade routers, this might mean putting it on a guest network. On more capable hardware, configure dedicated VLANs with inter-VLAN blocking. The goal is simple: the device can talk to your phone locally, but it cannot phone home to a cloud server that may no longer exist—or worse, may have been compromised.
The Second Choice: Eviction. This is the correct, if more painful, option for anything with a camera, a microphone, or a lock. A security camera that isn't patched is a privacy nightmare—a live feed that an attacker can tap with known, unpatched exploits. A smart lock with unfixed vulnerabilities is a physical security risk, no different from leaving a spare key under the doormat. The responsible action is to unplug it, wipe it, and either recycle it or donate it (with a clear warning to the recipient about its security status). Replace it with a device from a vendor with a proven track record of long-term support and, ideally, one that complies with the emerging security mandate philosophies that regulations like the EU's Cyber Resilience Act are beginning to codify.
What to Look for in a Replacement
When shopping for a successor device, don't just read the spec sheet. Read the company's track record. How long did they support their previous-generation products? Do they publish firmware changelogs? Do they have an explicit EOL policy? Do they support open standards like Matter or Thread that reduce dependence on a single vendor's cloud? A $60 camera from a company that patches for five years is infinitely cheaper than a $30 camera from a company that abandons it in eighteen months. The real cost of a smart home device is measured not at checkout, but over its full lifecycle on your network.
The smart home industry sells you a future of seamless integration. What it often delivers is a collection of devices with a hidden expiration date, supported only until the next quarterly earnings call. Your only defense is informed skepticism. Verify the support lifecycle, read the silicon, and don't be sentimental about hardware that the company that made it has already forgotten. Your security is too important to be left in the hands of a spreadsheet.
The best smart home device isn't the one with the most features. It's the one whose manufacturer respects you enough to keep it safe long after the unboxing high has faded.