Skip to main content
Sign in

Blockstream Jade — Fake Firmware Phishing Campaign (August 2026)

avoid.net/blockstream-jade-fake-firmware-phishing-campaign-august-20260/100·78% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·3c1R88…F5tx

Summary

A recurring phishing campaign has targeted owners of Blockstream Jade Bitcoin hardware wallets by sending fraudulent emails that impersonate Blockstream and claim to offer firmware updates. Blockstream first issued an official alert on September 12, 2025, confirming it never distributes firmware via email and that no Jade devices were confirmed compromised. The threat resurged in August 2026 in the wake of the high-profile Coldcard hardware wallet exploit, as opportunistic attackers broadened impersonation campaigns across the hardware wallet sector.

Connected Entities

1 entities
Protocols
Blockstream Jade — Fake Firmware Phishing Campaign (August 2026)
Relationships
    Have evidence about Blockstream Jade — Fake Firmware Phishing Campaign (August 2026)?

    Timeline(6 events)

    21 October 2023

    Earliest documented Blockstream Jade phishing incident: users received fraudulent emails claiming an emergency firmware update was required. Blockstream investigated and attributed possible data exposure to a third-party shipping provider breach or leak.

    U.Today: Phishing Alert — Blockstream Customers Targeted by Mail Scam

    12 September 2025

    Blockstream posted an official phishing alert on X, warning users of fake emails claiming a 'Jade firmware update.' The alert confirmed no data was compromised and reiterated the company never sends firmware via email. Bitcoin developer Jimmy Song is reported to have first alerted Blockstream to the campaign.

    Blockstream official X — @Blockstream/status/1966586521827368990

    13 September 2025

    Multiple crypto news outlets including CoinTelegraph, Cryptopolitan, CoinCentral, and others published coverage of the Blockstream phishing alert. Reports documented fraudulent emails originating from the domain getbento.com and purportedly sent by 'General Manager of Adelphia Restaurant.'

    CoinCentral: Blockstream Alerts Users of Fake Email Phishing Campaign Targeting Wallets

    30 July 2026

    Coinkite disclosed a firmware vulnerability in Coldcard Mk3 hardware wallets, stemming from a March 2021 build error that weakened seed randomness. Attackers began draining BTC from affected addresses — ultimately totaling approximately 1,816 BTC (~$116 million) across four theft waves from over 5,200 addresses.

    TRM Labs: The Largest Hardware Wallet Exploit of 2026

    31 July 2026

    Blockstream published a blog post confirming that Jade Classic, Jade Core, and Jade Plus are unaffected by the Coldcard RNG vulnerability, and warned users: 'Any email carrying a firmware update is hostile, whoever the sender appears to be.' Proactive guidance for Coldcard users to migrate to Jade was included.

    Blockstream Blog: Jade Is Unaffected by the Recent Coldcard Vulnerability

    August 2026

    Hardware wallet phishing campaigns surged sector-wide as attackers exploited user confusion following the Coldcard exploit. Documented tactics included spoofed 'hardware audit' emails, cloned vendor websites, and GitHub-hosted batch files installing ScreenConnect remote-access software. Multiple hardware wallet companies warned of impersonation attempts.

    Decrypt: Hardware Wallet Firms Warn of Phishing Surge as Coldcard Losses Near $130M
    Provenance & Audit Trail

    Decision Log

    This investigation is cryptographically anchored to the Solana blockchain (3 events). 18 of 19 cited source URLs have an Internet Archive snapshot.

    model: claude-sonnet-4-6

    generated: 8/11/2026, 11:06:48 PM

    last updated: 8/25/2026, 6:02:55 PM

    4 views

    avoid.net — verified advice for a post-truth world