Skip to main content
Sign in

Audit log

Every state-changing event for Blockstream Jade — Fake Firmware Phishing Campaign (August 2026): moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.

  1. #1publishby system:backfill
    2026-08-11 23:07:06Z
    Score: ?? (no score change)
    anchorpending
    chain
    hash
    AFwyxrz948gp…yVXgVY2asha256 → base58
    verifying row…
    canonical bytes (23180 B) ▸
    {"actor":"system:backfill","investigation_id":"ebfb4383-754a-4e4e-b2ae-1dbf8c1fccd0","kind":"publish","page_slug":"blockstream-jade-fake-firmware-phishing-campaign-august-2026","published_at":"2026-08-11T23:07:06.273Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Blockstream Jade — Fake Firmware Phishing Campaign (August 2026)","sections":[{"content":"The Blockstream Jade fake firmware phishing campaign is a targeted email fraud operation that impersonates Blockstream — the company behind the Jade Bitcoin hardware wallet — to trick users into downloading malicious software disguised as a legitimate firmware update. Blockstream publicly disclosed the campaign on September 12, 2025, via an official post on X (formerly Twitter), stating: 'This was not sent from Blockstream. Blockstream will never email you firmware files. No data has been compromised.' Bitcoin developer Jimmy Song is reported to have first alerted Blockstream to the existence of the fraudulent emails, according to multiple crypto news outlets. A second wave of Jade-targeted phishing was documented in August 2026, coinciding with widespread attacker activity following the Coldcard hardware wallet exploit that began July 30, 2026.","heading":"Campaign Overview","severity":"high","sources":[{"credibility":1,"name":"Blockstream official X alert — @Blockstream/status/1966586521827368990","type":"official","url":"https://x.com/Blockstream/status/1966586521827368990"},{"credibility":2,"name":"CoinTelegraph: Blockstream sounds the alarm on new email phishing campaign","type":"news_article","url":"https://cointelegraph.com/news/blockstream-sounds-alarm-email-phishing-campaign"},{"credibility":2,"name":"Cryptopolitan: Blockstream warns Jade wallet users of new phishing scam","type":"news_article","url":"https://www.cryptopolitan.com/blockstream-warns-of-jade-scam/"},{"credibility":2,"name":"Decrypt: Hardware Wallet Firms Warn of Phishing Surge as Coldcard Losses Near $130M","type":"news_article","url":"https://decrypt.co/374891/hardware-wallet-firms-warn-of-phishing-surge-as-coldcard-losses-near-130m"}]},{"content":"The phishing campaign operates primarily through email. Fraudulent messages impersonate Blockstream and instruct recipients to download what is presented as a new version of the Jade wallet firmware. The emails cite firmware version numbers, though community members noted that the version numbers in the phishing emails were internally inconsistent and did not match any legitimate Blockstream release. At least one documented example showed the email purportedly sent from the 'General Manager of Adelphia Restaurant,' with download links pointing to the domain getbento.com — a domain wholly unaffiliated with Blockstream. This mismatch between claimed sender identity and actual sending domain is a strong indicator of a compromised or spoofed email infrastructure being used to distribute the campaign. The emails are crafted using urgency language typical of social engineering attacks. If a recipient were to download and install the malicious payload, security analysts assess it would likely expose private keys or redirect funds to attacker-controlled addresses, though no forensic technical details of the specific payload have been publicly disclosed. A separate, earlier phishing incident documented in October 2023 used physical mail rather than email, directing recipients to a fake emergency firmware update. In the broader August 2026 hardware wallet phishing environment triggered by the Coldcard exploit, attackers employed cloned websites, GitHub-hosted batch files, and remote-access tools (specifically ScreenConnect) — though those specific payloads have been attributed to Coldcard-targeted campaigns, not confirmed Jade-specific incidents.","heading":"Attack Vector and Tactics","severity":"high","sources":[{"credibility":2,"name":"CoinCentral: Blockstream Alerts Users of Fake Email Phishing Campaign Targeting Wallets","type":"news_article","url":"https://coincentral.com/blockstream-alerts-users-of-fake-email-phishing-campaign-targeting-wallets/"},{"credibility":2,"name":"BTCC: Blockstream Sounds Alarm on Sophisticated Phishing Campaign","type":"news_article","url":"https://www.btcc.com/en-US/square/Cryptonews/947704"},{"credibility":2,"name":"Cryptonews.net: Blockstream Jade Firmware Phishing May Target Bitcoin Users With Malicious Update Links","type":"news_article","url":"https://cryptonews.net/news/security/31612243/"},{"credibility":2,"name":"Decrypt: Hardware Wallet Firms Warn of Phishing Surge as Coldcard Losses Near $130M","type":"news_article","url":"https://decrypt.co/374891/hardware-wallet-firms-warn-of-phishing-surge-as-coldcard-losses-near-130m"}]},{"content":"How attackers obtained email addresses of Jade hardware wallet owners has not been definitively established. Blockstream's own investigation, published after the October 2023 phishing incident, concluded that 'customer data may have been exposed by either a breach or a leak from a third-party shipping provider.' Data allegedly included email addresses, telephone numbers, and shipping addresses. Blockstream stated that no private keys or wallet addresses were exposed. Some community members speculated that attackers harvested email contacts from prior data breaches affecting cryptocurrency exchanges and services, then conducted mass campaigns against the full crypto-user population. A community observer noted on the Blockstream X post that the scam email address 'was only shared with Blockstream,' suggesting at least some targeting was specific to the Blockstream customer base rather than a mass blast. No independent forensic confirmation of the data source has been published.","heading":"Suspected Source of Victim Email Addresses","severity":"medium","sources":[{"credibility":2,"name":"U.Today: Blockstream Publishes Phishing Investigation Results","type":"news_article","url":"https://u.today/blockstream-publishes-phishing-investigation-results"},{"credibility":2,"name":"U.Today: Phishing Alert — Blockstream Customers Targeted by Mail Scam","type":"news_article","url":"https://u.today/phishing-alert-blockstream-customers-targeted-by-mail-scam"},{"credibility":1,"name":"Blockstream official X alert — @Blockstream/status/1966586521827368990","type":"official","url":"https://x.com/Blockstream/status/1966586521827368990"}]},{"content":"Blockstream confirmed that no Jade devices were compromised through the campaign's fraudulent update channels, and that no user credentials or private keys were exposed through any breach of Blockstream's own systems. No confirmed financial losses attributable specifically to the fake Jade firmware campaign have been publicly documented in available sources. Blockstream stated that 'zero exploits through genuine update channels' occurred and that all confirmed incidents of user loss traced to user-initiated installations from unverified sources. The broader hardware wallet phishing environment in 2025–2026 is severe: phishing attacks cost crypto users over $12 million in August 2025 alone, affecting more than 15,000 victims — a 67 percent increase month-over-month. H1 2025 crypto crime losses exceeded $3.1 billion in total, with phishing accounting for $410 million across 132 separate attacks, according to figures cited in multiple reporting sources. These figures are sector-wide and not specific to the Jade campaign.","heading":"Confirmed Impact and Losses","severity":"medium","sources":[{"credibility":2,"name":"Cryptopolitan: Blockstream warns Jade wallet users of new phishing scam","type":"news_article","url":"https://www.cryptopolitan.com/blockstream-warns-of-jade-scam/"},{"credibility":2,"name":"BTCC: Blockstream Exposes Sophisticated Jade Wallet Fake Firmware Scam","type":"news_article","url":"https://www.btcc.com/en-US/square/Cryptopolitan/947404"},{"credibility":2,"name":"CoinCentral: Blockstream Alerts Users of Fake Email Phishing Campaign Targeting Wallets","type":"news_article","url":"https://coincentral.com/blockstream-alerts-users-of-fake-email-phishing-campaign-targeting-wallets/"}]},{"content":"The August 2026 iteration of Jade-targeted phishing is best understood in the context of the Coldcard hardware wallet exploit that began July 30, 2026. A five-year-old firmware flaw in Coinkite's Coldcard Mk3 caused seed generation to rely on a weak software random number generator rather than a hardware entropy source, effectively reducing private key strength to as few as 40 bits. Attackers exploited this to drain approximately 1,816 BTC — worth roughly $116 million — from over 5,200 addresses across four theft waves, making it the largest hardware wallet exploit on record as of that date. The exploit created fertile conditions for secondary phishing campaigns across the entire hardware wallet sector. As Coldcard users searched for firmware updates and migration instructions, attackers launched impersonation campaigns using cloned websites, 'coordinated hardware audit' email themes, and GitHub-hosted batch files that installed ScreenConnect remote-access software. Blockstream responded proactively: on July 31, 2026, it published an official blog post confirming that Jade Classic, Jade Core, and Jade Plus are unaffected by the Coldcard RNG vulnerability, and explicitly warned: 'Any email carrying a firmware update is hostile, whoever the sender appears to be.' Opportunistic phishing campaigns alleged to be impersonating Blockstream were reported in this window, consistent with the documented pattern of the September 2025 campaign. The Jade device itself uses Secure Boot v2, which verifies firmware cryptographic signatures before execution, and anti-rollback protection was added in firmware version 1.0.38, preventing attackers from tricking users into downgrading to vulnerable versions.","heading":"Broader Context: Coldcard Exploit and August 2026 Phishing Surge","severity":"high","sources":[{"credibility":1,"name":"Blockstream Blog: Jade Is Unaffected by the Recent Coldcard Vulnerability","type":"official","url":"https://blog.blockstream.com/jade-unaffected-coldcard-vulnerability/"},{"credibility":2,"name":"TRM Labs: The Largest Hardware Wallet Exploit of 2026 — Inside the USD 116 Million Coldcard Hack","type":"research","url":"https://www.trmlabs.com/resources/blog/the-largest-hardware-wallet-exploit-of-2026-inside-the-usd-116-million-coldcard-hack"},{"credibility":1,"name":"CoinDesk: Coldcard exploit reignites Bitcoin self-custody debate after $38 million theft","type":"news_article","url":"https://www.coindesk.com/business/2026/07/31/coldcard-s-usd38-million-so-far-exploit-shakes-faith-in-self-custody-may-push-investors-to-etfs"},{"credibility":2,"name":"Decrypt: Hardware Wallet Firms Warn of Phishing Surge as Coldcard Losses Near $130M","type":"news_article","url":"https://decrypt.co/374891/hardware-wallet-firms-warn-of-phishing-surge-as-coldcard-losses-near-130m"},{"credibility":2,"name":"Cryptonews.net: Blockstream Jade Wallets Unaffected by Recent RNG Vulnerability","type":"news_article","url":"https://cryptonews.net/news/security/33228747/"}]},{"content":"Blockstream has consistently stated that it distributes firmware exclusively through its official website and its GitHub repository. Firmware is cryptographically signed and verified via Secure Boot v2 before it will execute on any Jade device, meaning unsigned or tampered firmware binaries will be rejected by the hardware. Firmware 1.0.38 added anti-rollback protection to prevent downgrade attacks via phishing or fake firmware portals. A prior security disclosure addressed a potential vulnerability in older firmware versions when paired with malicious third-party applications; this was responsibly disclosed by security research group DARKNAVY and was resolved in firmware 1.0.38 with no confirmed user exploitation. Users who may have clicked a phishing link are advised by Blockstream to: disconnect the device from the internet immediately, not enter seed phrases or passwords into any site, use a clean device to check for unauthorized transactions, and contact security@blockstream.com to report the incident. Blockstream's official update channels are https://blockstream.com and https://github.com/Blockstream. The company reiterates it will never request recovery phrases, never send firmware via email, and will never ask users to perform actions through unofficial channels.","heading":"Blockstream's Security Architecture and Official Guidance","severity":"low","sources":[{"credibility":1,"name":"Blockstream Blog: Important Jade Security Update (DARKNAVY disclosure)","type":"official","url":"https://blog.blockstream.com/important-jade-security-update/"},{"credibility":1,"name":"Blockstream Help Center: Manually verify firmware binary","type":"official","url":"https://help.blockstream.com/blockstream-jade/add-more-security-functionality/manually-verify-firmware-binary"},{"credibility":1,"name":"Blockstream Blog: Jade Is Unaffected by the Recent Coldcard Vulnerability","type":"official","url":"https://blog.blockstream.com/jade-unaffected-coldcard-vulnerability/"},{"credibility":2,"name":"CoinCentral: Blockstream Alerts Users of Fake Email Phishing Campaign Targeting Wallets","type":"news_article","url":"https://coincentral.com/blockstream-alerts-users-of-fake-email-phishing-campaign-targeting-wallets/"}]},{"content":"The following indicators have been documented or reported in association with the campaign. Any email claiming to offer a Blockstream Jade firmware update should be treated as hostile regardless of apparent sender identity. Documented red flags include: emails originating from domains unrelated to Blockstream, including the sender domain getbento.com and alleged senders identified as third-party businesses (e.g., 'General Manager of Adelphia Restaurant'); firmware version numbers cited in the email that do not match any Blockstream release, or are internally inconsistent within the email itself; urgency-framing language instructing immediate download or installation; download links pointing to any domain other than blockstream.com or github.com/Blockstream. In the August 2026 broader phishing environment, additional red flags include: emails referencing a 'coordinated hardware audit' or inviting users to verify their device; any website featuring a 'Start Hardware Audit' button; prompts to install remote desktop or remote access software; and requests to enter seed phrases or recovery words into any web form, regardless of how official the site appears.","heading":"Indicators of Compromise and Red Flags","severity":"critical","sources":[{"credibility":2,"name":"CoinCentral: Blockstream Alerts Users of Fake Email Phishing Campaign Targeting Wallets","type":"news_article","url":"https://coincentral.com/blockstream-alerts-users-of-fake-email-phishing-campaign-targeting-wallets/"},{"credibility":1,"name":"Blockstream official X alert — @Blockstream/status/1966586521827368990","type":"official","url":"https://x.com/Blockstream/status/1966586521827368990"},{"credibility":2,"name":"Decrypt: Hardware Wallet Firms Warn of Phishing Surge as Coldcard Losses Near $130M","type":"news_article","url":"https://decrypt.co/374891/hardware-wallet-firms-warn-of-phishing-surge-as-coldcard-losses-near-130m"},{"credibility":2,"name":"Crypto Economy: Hardware Wallet Providers Flag Dangerous Phishing Campaign","type":"news_article","url":"https://crypto-economy.com/hardware-wallet-phishing-campaign-warning/"}]}],"sources_used":[{"credibility":1,"name":"Blockstream official X phishing alert","type":"official","url":"https://x.com/Blockstream/status/1966586521827368990"},{"credibility":1,"name":"Blockstream Blog: Jade Is Unaffected by the Recent Coldcard Vulnerability","type":"official","url":"https://blog.blockstream.com/jade-unaffected-coldcard-vulnerability/"},{"credibility":1,"name":"Blockstream Blog: Important Jade Security Update (DARKNAVY disclosure)","type":"official","url":"https://blog.blockstream.com/important-jade-security-update/"},{"credibility":1,"name":"Blockstream Help Center: Manually verify firmware binary","type":"official","url":"https://help.blockstream.com/blockstream-jade/add-more-security-functionality/manually-verify-firmware-binary"},{"credibility":1,"name":"CoinDesk: Coldcard exploit reignites Bitcoin self-custody debate","type":"news_article","url":"https://www.coindesk.com/business/2026/07/31/coldcard-s-usd38-million-so-far-exploit-shakes-faith-in-self-custody-may-push-investors-to-etfs"},{"credibility":2,"name":"TRM Labs: The Largest Hardware Wallet Exploit of 2026","type":"research","url":"https://www.trmlabs.com/resources/blog/the-largest-hardware-wallet-exploit-of-2026-inside-the-usd-116-million-coldcard-hack"},{"credibility":2,"name":"Decrypt: Hardware Wallet Firms Warn of Phishing Surge as Coldcard Losses Near $130M","type":"news_article","url":"https://decrypt.co/374891/hardware-wallet-firms-warn-of-phishing-surge-as-coldcard-losses-near-130m"},{"credibility":2,"name":"CoinTelegraph: Blockstream sounds the alarm on new email phishing campaign","type":"news_article","url":"https://cointelegraph.com/news/blockstream-sounds-alarm-email-phishing-campaign"},{"credibility":2,"name":"Cryptopolitan: Blockstream warns Jade wallet users of new phishing scam","type":"news_article","url":"https://www.cryptopolitan.com/blockstream-warns-of-jade-scam/"},{"credibility":2,"name":"CoinCentral: Blockstream Alerts Users of Fake Email Phishing Campaign Targeting Wallets","type":"news_article","url":"https://coincentral.com/blockstream-alerts-users-of-fake-email-phishing-campaign-targeting-wallets/"},{"credibility":2,"name":"BTCC: Blockstream Exposes Sophisticated Jade Wallet Fake Firmware Scam","type":"news_article","url":"https://www.btcc.com/en-US/square/Cryptopolitan/947404"},{"credibility":2,"name":"BTCC: Blockstream Sounds Alarm on Sophisticated Phishing Campaign","type":"news_article","url":"https://www.btcc.com/en-US/square/Cryptonews/947704"},{"credibility":2,"name":"Cryptonews.net: Blockstream Jade Firmware Phishing May Target Bitcoin Users With Malicious Update Links","type":"news_article","url":"https://cryptonews.net/news/security/31612243/"},{"credibility":2,"name":"Cryptonews.net: Blockstream Jade Wallets Unaffected by Recent RNG Vulnerability","type":"news_article","url":"https://cryptonews.net/news/security/33228747/"},{"credibility":2,"name":"U.Today: Blockstream Publishes Phishing Investigation Results","type":"news_article","url":"https://u.today/blockstream-publishes-phishing-investigation-results"},{"credibility":2,"name":"U.Today: Phishing Alert — Blockstream Customers Targeted by Mail Scam","type":"news_article","url":"https://u.today/phishing-alert-blockstream-customers-targeted-by-mail-scam"},{"credibility":2,"name":"Crypto Economy: Hardware Wallet Providers Flag Dangerous Phishing Campaign","type":"news_article","url":"https://crypto-economy.com/hardware-wallet-phishing-campaign-warning/"},{"credibility":2,"name":"Bitget News: Blockstream Jade Firmware Phishing May Target Bitcoin Users With Malicious Update Links","type":"news_article","url":"https://www.bitget.com/news/detail/12560604964333"},{"credibility":2,"name":"CryptoRank: Blockstream alerts Jade Wallet users to fake firmware update scam","type":"news_article","url":"https://cryptorank.io/news/feed/48d0c-blockstream-warns-of-jade-scam"}],"summary":"A recurring phishing campaign has targeted owners of Blockstream Jade Bitcoin hardware wallets by sending fraudulent emails that impersonate Blockstream and claim to offer firmware updates. Blockstream first issued an official alert on September 12, 2025, confirming it never distributes firmware via email and that no Jade devices were confirmed compromised. The threat resurged in August 2026 in the wake of the high-profile Coldcard hardware wallet exploit, as opportunistic attackers broadened impersonation campaigns across the hardware wallet sector.","timeline":[{"date":"2023-10-21","event":"Earliest documented Blockstream Jade phishing incident: users received fraudulent emails claiming an emergency firmware update was required. Blockstream investigated and attributed possible data exposure to a third-party shipping provider breach or leak.","source":"U.Today: Phishing Alert — Blockstream Customers Targeted by Mail Scam","source_url":"https://u.today/phishing-alert-blockstream-customers-targeted-by-mail-scam"},{"date":"2025-09-12","event":"Blockstream posted an official phishing alert on X, warning users of fake emails claiming a 'Jade firmware update.' The alert confirmed no data was compromised and reiterated the company never sends firmware via email. Bitcoin developer Jimmy Song is reported to have first alerted Blockstream to the campaign.","source":"Blockstream official X — @Blockstream/status/1966586521827368990","source_url":"https://x.com/Blockstream/status/1966586521827368990"},{"date":"2025-09-13","event":"Multiple crypto news outlets including CoinTelegraph, Cryptopolitan, CoinCentral, and others published coverage of the Blockstream phishing alert. Reports documented fraudulent emails originating from the domain getbento.com and purportedly sent by 'General Manager of Adelphia Restaurant.'","source":"CoinCentral: Blockstream Alerts Users of Fake Email Phishing Campaign Targeting Wallets","source_url":"https://coincentral.com/blockstream-alerts-users-of-fake-email-phishing-campaign-targeting-wallets/"},{"date":"2026-07-30","event":"Coinkite disclosed a firmware vulnerability in Coldcard Mk3 hardware wallets, stemming from a March 2021 build error that weakened seed randomness. Attackers began draining BTC from affected addresses — ultimately totaling approximately 1,816 BTC (~$116 million) across four theft waves from over 5,200 addresses.","source":"TRM Labs: The Largest Hardware Wallet Exploit of 2026","source_url":"https://www.trmlabs.com/resources/blog/the-largest-hardware-wallet-exploit-of-2026-inside-the-usd-116-million-coldcard-hack"},{"date":"2026-07-31","event":"Blockstream published a blog post confirming that Jade Classic, Jade Core, and Jade Plus are unaffected by the Coldcard RNG vulnerability, and warned users: 'Any email carrying a firmware update is hostile, whoever the sender appears to be.' Proactive guidance for Coldcard users to migrate to Jade was included.","source":"Blockstream Blog: Jade Is Unaffected by the Recent Coldcard Vulnerability","source_url":"https://blog.blockstream.com/jade-unaffected-coldcard-vulnerability/"},{"date":"2026-08-01","event":"Hardware wallet phishing campaigns surged sector-wide as attackers exploited user confusion following the Coldcard exploit. Documented tactics included spoofed 'hardware audit' emails, cloned vendor websites, and GitHub-hosted batch files installing ScreenConnect remote-access software. Multiple hardware wallet companies warned of impersonation attempts.","source":"Decrypt: Hardware Wallet Firms Warn of Phishing Surge as Coldcard Losses Near $130M","source_url":"https://decrypt.co/374891/hardware-wallet-firms-warn-of-phishing-surge-as-coldcard-losses-near-130m"}]},"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision 47055cb1-90ab-4076-b65f-b092e49a0374
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine — python -m src.verify_decision <event_id>.