# Blockstream's Jade team details firmware hardening as Coldcard losses pass $115 million

Jade firmware 1.0.41 tightens stack protection and memory clearing after dozens of automated code scans, while the entropy defect that drained Coldcard wallets cannot be undone by any update.

- Published: 2026-08-26T05:49:32.350Z
- Canonical: https://polylog.news/crypto/2026-08-26/blockstream-s-jade-team-details-firmware-hardening-as-coldca
- Publisher: Polylog (Crypto desk)
- Section: crypto
- Sources: [Blockstream Blog](https://blog.blockstream.com/reflections-on-the-coldcard-fallout/), [Rekt News](https://www.rekt.news/)

The Jade firmware team at Blockstream [published its response to the Coldcard failure](https://blog.blockstream.com/reflections-on-the-coldcard-fallout/) on Tuesday, describing what it changed in firmware 1.0.41 and how it tested its own key generation. The release upgrades the device runtime, increases stack protection, updates dependencies and audits the clearing of sensitive memory regions. The team says it has received dozens of automated scans of the Jade codebase generated by artificial-intelligence tools, plus additional human reviews, and that analysis of deep scans by the open-weight model Kimi K3 found the Jade entropy design unaffected by the defect that hit its competitor.

The underlying incident remains one of the largest self-custody failures of the year. Coinkite, the maker of Coldcard, [warned on July 30](https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/) that recovery phrases created on a Coldcard Mk3 running firmware 4.0.1 or later could be at risk. The root cause was not a smart-contract bug or a phishing campaign. The firmware did not draw from the device's hardware random number generator during seed creation and fell back to a weaker software source, so some devices produced recovery phrases with far less randomness than the standard requires. An attacker who can enumerate that reduced space can reconstruct private keys directly and sign valid transactions.

Loss estimates have grown as researchers traced more addresses. Galaxy Research [tallied more than $115 million in confirmed Coldcard-linked losses](https://thehackernews.com/2026/08/coldcard-hardware-wallet-flaw-linked-to.html) using data through August 13, verifying 1,596 bitcoin taken from roughly 7,300 addresses across three waves and identifying a suspected fourth wave. Rekt News, which catalogues on-chain thefts, [lists the incident](https://www.rekt.news/) alongside the year's protocol exploits. No funds have been recovered and no attacker has been publicly identified. Patched firmware protects only seeds generated after the update, so affected users must create a new seed and move their coins.

The wider point the Jade team makes is about method rather than product. Cheap automated code review now points at the same open-source firmware repositories that wallet vendors, node operators and signing devices share, and defects that sat undiscovered for five years are being surfaced by whoever runs the scan first. Vendors and attackers are now working with the same tooling to find these flaws, and whoever finds one first determines whether it becomes a patch or an exploit.

## What this means

Entropy failures break the core assumption of self-custody, which is that a certified device generates a key no one else can reproduce, and no insurance or freeze mechanism exists to reverse the loss. Holders who conclude that auditing their own hardware is impractical move funds toward exchange custody and exchange-traded products, which shifts fee income to custodians and issuers and increases the share of supply sitting behind a small number of institutional keys. Vendors that publish reproducible entropy tests gain share within self-custody, and those that do not lose it.

## What to watch

- Whether other hardware wallet makers publish independent entropy verification of shipped firmware, because silence now reads as an untested design rather than a safe one.
- Whether the Coldcard-linked address total rises further as researchers extend tracing, which would show the vulnerable seed population is larger than the initial waves suggested.
- Whether custodial and exchange-traded product holdings grow faster than self-custody balances in the coming months, the clearest measure of whether the incident changed holder behavior.
