Morning Edition · Wednesday, August 26, 2026Published at 1:49 AM EDT · New York
Jade firmware 1.0.41 tightens stack protection and memory clearing after dozens of automated code scans, while the entropy defect that drained Coldcard wallets cannot be undone by any update.

The Jade firmware team at Blockstream published its response to the Coldcard failure on Tuesday, describing what it changed in firmware 1.0.41 and how it tested its own key generation. The release upgrades the device runtime, increases stack protection, updates dependencies and audits the clearing of sensitive memory regions. The team says it has received dozens of automated scans of the Jade codebase generated by artificial-intelligence tools, plus additional human reviews, and that analysis of deep scans by the open-weight model Kimi K3 found the Jade entropy design unaffected by the defect that hit its competitor.
The underlying incident remains one of the largest self-custody failures of the year. Coinkite, the maker of Coldcard, warned on July 30 that recovery phrases created on a Coldcard Mk3 running firmware 4.0.1 or later could be at risk. The root cause was not a smart-contract bug or a phishing campaign. The firmware did not draw from the device's hardware random number generator during seed creation and fell back to a weaker software source, so some devices produced recovery phrases with far less randomness than the standard requires. An attacker who can enumerate that reduced space can reconstruct private keys directly and sign valid transactions.
Loss estimates have grown as researchers traced more addresses. Galaxy Research tallied more than $115 million in confirmed Coldcard-linked losses using data through August 13, verifying 1,596 bitcoin taken from roughly 7,300 addresses across three waves and identifying a suspected fourth wave. Rekt News, which catalogues on-chain thefts, lists the incident alongside the year's protocol exploits. No funds have been recovered and no attacker has been publicly identified. Patched firmware protects only seeds generated after the update, so affected users must create a new seed and move their coins.
The wider point the Jade team makes is about method rather than product. Cheap automated code review now points at the same open-source firmware repositories that wallet vendors, node operators and signing devices share, and defects that sat undiscovered for five years are being surfaced by whoever runs the scan first. Vendors and attackers are now working with the same tooling to find these flaws, and whoever finds one first determines whether it becomes a patch or an exploit.
Part of a tracked trend
Hardware-Wallet Trust Erodes
Recurring firmware and entropy defects in self-custody hardware, now surfaced faster by AI-assisted code analysis, will keep pushing risk-averse holders toward custodial and ETF products rather than personal key management.
Start a discussion in Townsquare.
More from this edition
Blockstream, which sells the competing Jade device, gains market share from publishing a hardening account while a rival's failure is still unresolved, and custodians and exchange-traded product issuers gain from holders who conclude self-custody is unmanageable.
The Coldcard entropy defect is independently documented, but the loss total is an estimate that moved from about $70 million on July 30 to $88.6 million across 4,585 addresses to a wider range reaching 2,055 bitcoin depending on which address clusters a researcher attributes to the flaw, and Blockstream's assessment that Jade's own entropy design is unaffected is a vendor self-assessment, not an independent audit.
An open-source-intelligence read of how likely this story is true with its real nuance, not a judgment of any outlet. It assesses the claim, weighing independent and adversarial reporting. How we label confidence.
What this means
Entropy failures break the core assumption of self-custody, which is that a certified device generates a key no one else can reproduce, and no insurance or freeze mechanism exists to reverse the loss. Holders who conclude that auditing their own hardware is impractical move funds toward exchange custody and exchange-traded products, which shifts fee income to custodians and issuers and increases the share of supply sitting behind a small number of institutional keys. Vendors that publish reproducible entropy tests gain share within self-custody, and those that do not lose it.
What to watch
Observations to monitor, not financial advice.
Synthesized from: Blockstream Blog · Rekt News
Comments
0No comments yet.