Skip to main content
AVOID.NET

Blockstream Jade — Fake Firmware Phishing Campaign (August 2026)

avoid.net/blockstream-jade-fake-firmware-phishing-campaign-august-2026→0/100·78% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·3c1R88…F5tx

Summary

A recurring phishing campaign has targeted owners of Blockstream Jade Bitcoin hardware wallets by sending fraudulent emails that impersonate Blockstream and claim to offer firmware updates. Blockstream first issued an official alert on September 12, 2025, confirming it never distributes firmware via email and that no Jade devices were confirmed compromised. The threat resurged in August 2026 in the wake of the high-profile Coldcard hardware wallet exploit, as opportunistic attackers broadened impersonation campaigns across the hardware wallet sector.

Connected Entities

6 entities · 60 linked investigations
Organizations
□Blockstream
Protocols
⌂Blockstream Jade — Fake Firmware Phishing Campaign (August 2026)
Tokens
♦Coinkite♦Bitcoin62♦Coinkite / Coldcard♦Cointelegraph62
Relationships
  • Coinkite→mentioned with→Bitcoin(70%)
  • Coinkite / Coldcard→mentioned with→Coinkite(70%)
  • Coinkite / Coldcard→mentioned with→Bitcoin(80%)
  • Blockstream Jade — Fake Firmware Phishing Campaign (August 2026)→mentioned with→Coinkite / Coldcard(80%)
  • Blockstream→mentioned with→Blockstream Jade — Fake Firmware Phishing Campaign (August 2026)(80%)
  • Blockstream Jade — Fake Firmware Phishing Campaign (August 2026)→mentioned with→Coinkite(65%)
  • Blockstream Jade — Fake Firmware Phishing Campaign (August 2026)→mentioned with→Bitcoin(65%)
  • Blockstream Jade — Fake Firmware Phishing Campaign (August 2026)→mentioned with→Blockstream(70%)
  • Blockstream→mentioned with→Bitcoin(80%)
  • Blockstream Jade — Fake Firmware Phishing Campaign (August 2026)→mentioned with→Cointelegraph(60%)

Connected Through

6 shared actors · 552 investigations

Distinct actors this investigation shares with others — holders, traders, and named parties. Shared infrastructure (exchanges, pools) is excluded.

Have evidence about Blockstream Jade — Fake Firmware Phishing Campaign (August 2026)?

Timeline(6 events)

21 October 2023

Earliest documented Blockstream Jade phishing incident: users received fraudulent emails claiming an emergency firmware update was required. Blockstream investigated and attributed possible data exposure to a third-party shipping provider breach or leak.

U.Today: Phishing Alert — Blockstream Customers Targeted by Mail Scam

12 September 2025

Blockstream posted an official phishing alert on X, warning users of fake emails claiming a 'Jade firmware update.' The alert confirmed no data was compromised and reiterated the company never sends firmware via email. Bitcoin developer Jimmy Song is reported to have first alerted Blockstream to the campaign.

Blockstream official X — @Blockstream/status/1966586521827368990

13 September 2025

Multiple crypto news outlets including CoinTelegraph, Cryptopolitan, CoinCentral, and others published coverage of the Blockstream phishing alert. Reports documented fraudulent emails originating from the domain getbento.com and purportedly sent by 'General Manager of Adelphia Restaurant.'

CoinCentral: Blockstream Alerts Users of Fake Email Phishing Campaign Targeting Wallets

30 July 2026

Coinkite disclosed a firmware vulnerability in Coldcard Mk3 hardware wallets, stemming from a March 2021 build error that weakened seed randomness. Attackers began draining BTC from affected addresses — ultimately totaling approximately 1,816 BTC (~$116 million) across four theft waves from over 5,200 addresses.

TRM Labs: The Largest Hardware Wallet Exploit of 2026

31 July 2026

Blockstream published a blog post confirming that Jade Classic, Jade Core, and Jade Plus are unaffected by the Coldcard RNG vulnerability, and warned users: 'Any email carrying a firmware update is hostile, whoever the sender appears to be.' Proactive guidance for Coldcard users to migrate to Jade was included.

Blockstream Blog: Jade Is Unaffected by the Recent Coldcard Vulnerability

August 2026

Hardware wallet phishing campaigns surged sector-wide as attackers exploited user confusion following the Coldcard exploit. Documented tactics included spoofed 'hardware audit' emails, cloned vendor websites, and GitHub-hosted batch files installing ScreenConnect remote-access software. Multiple hardware wallet companies warned of impersonation attempts.

Decrypt: Hardware Wallet Firms Warn of Phishing Surge as Coldcard Losses Near $130M
Provenance & Audit Trail

Decision Log

This investigation is cryptographically anchored to the Solana blockchain (3 events). 18 of 19 cited source URLs have an Internet Archive snapshot.

model: claude-sonnet-4-6

generated: 8/11/2026, 11:06:48 PM

last updated: 8/25/2026, 6:02:55 PM

6 views

avoid.net — verified advice for a post-truth world