Blockstream Jade — Fake Firmware Phishing Campaign (August 2026)
Summary
A recurring phishing campaign has targeted owners of Blockstream Jade Bitcoin hardware wallets by sending fraudulent emails that impersonate Blockstream and claim to offer firmware updates. Blockstream first issued an official alert on September 12, 2025, confirming it never distributes firmware via email and that no Jade devices were confirmed compromised. The threat resurged in August 2026 in the wake of the high-profile Coldcard hardware wallet exploit, as opportunistic attackers broadened impersonation campaigns across the hardware wallet sector.
Connected Entities
1 entitiesTimeline(6 events)
2023-10-21
Earliest documented Blockstream Jade phishing incident: users received fraudulent emails claiming an emergency firmware update was required. Blockstream investigated and attributed possible data exposure to a third-party shipping provider breach or leak.
U.Today: Phishing Alert — Blockstream Customers Targeted by Mail Scam2025-09-12
Blockstream posted an official phishing alert on X, warning users of fake emails claiming a 'Jade firmware update.' The alert confirmed no data was compromised and reiterated the company never sends firmware via email. Bitcoin developer Jimmy Song is reported to have first alerted Blockstream to the campaign.
Blockstream official X — @Blockstream/status/19665865218273689902025-09-13
Multiple crypto news outlets including CoinTelegraph, Cryptopolitan, CoinCentral, and others published coverage of the Blockstream phishing alert. Reports documented fraudulent emails originating from the domain getbento.com and purportedly sent by 'General Manager of Adelphia Restaurant.'
CoinCentral: Blockstream Alerts Users of Fake Email Phishing Campaign Targeting Wallets2026-07-30
Coinkite disclosed a firmware vulnerability in Coldcard Mk3 hardware wallets, stemming from a March 2021 build error that weakened seed randomness. Attackers began draining BTC from affected addresses — ultimately totaling approximately 1,816 BTC (~$116 million) across four theft waves from over 5,200 addresses.
TRM Labs: The Largest Hardware Wallet Exploit of 20262026-07-31
Blockstream published a blog post confirming that Jade Classic, Jade Core, and Jade Plus are unaffected by the Coldcard RNG vulnerability, and warned users: 'Any email carrying a firmware update is hostile, whoever the sender appears to be.' Proactive guidance for Coldcard users to migrate to Jade was included.
Blockstream Blog: Jade Is Unaffected by the Recent Coldcard Vulnerability2026-08-01
Hardware wallet phishing campaigns surged sector-wide as attackers exploited user confusion following the Coldcard exploit. Documented tactics included spoofed 'hardware audit' emails, cloned vendor websites, and GitHub-hosted batch files installing ScreenConnect remote-access software. Multiple hardware wallet companies warned of impersonation attempts.
Decrypt: Hardware Wallet Firms Warn of Phishing Surge as Coldcard Losses Near $130MDecision Log
- #1publish⛓ pending8/11/2026, 11:07:06 PMhash: AFwyxrz948gpPPqt5WZD2HrL8Xr97RfS9zyLyVXgVY2a
18 of 19 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 8/11/2026, 11:06:48 PM
last updated: 8/12/2026, 5:55:28 AM
avoid.net — verified advice for a post-truth world