The $116M Coldcard hack exposed a five-year-old firmware bug in seed generation. With hardware wallet security under renewed scrutiny, this comparison examines Blockstream's Jade lineup, Jade and Plus, against the BitBox02, and explains why multi-vendor multi-sig might be the only sane approach to self-custody in 2026.

Jade vs Plus: A Hardware Wallet Comparison After the $116M Coldcard Hack

Quick Take

  • JadeAffiliate link. You support sovgrid at no extra cost to you. See /support. is the entry point at €59.
  • Jade CoreAffiliate link. You support sovgrid at no extra cost to you. See /support. at €74 adds Genuine Check to the same Blind Oracle security model.
  • Jade PlusAffiliate link. You support sovgrid at no extra cost to you. See /support. at €126 adds a QR camera, SD card slot, color display, and metal build, features that matter for air-gapped workflows.
  • The BitBox02Affiliate link. You support sovgrid at no extra cost to you. See /support. sits between JadeAffiliate link. You support sovgrid at no extra cost to you. See /support. and Plus in price and is the device I personally use.
  • After the $116M Coldcard hack, the lesson is clear: single-vendor single-sig is an unhedged bet. Multi-vendor multi-sig is the only approach that survives a vendor-level failure.

I’ve been using a Blockstream Jade (the original version) for several years. I also experimented with the Blockstream app for Lightning and Liquid, Bitcoin’s second layer. Liquid is used by exchanges and trading desks for bulk movements where speed and privacy matter; Lightning handles consumer-facing use cases like retail payments or zaps in Nostr. They’re complementary, institutions often use both depending on the scenario. But I kept the Jade standalone, not in multi-sig. This article is the comparison I wish I’d had before committing to any device.

The Coldcard Hack: Why One Bug Cost $116 Million

The story starts on July 30, 2026, when Coinkite, the maker of the COLDCARD hardware wallet, published a security advisory that sent shockwaves through the self-custody community. A critical flaw in COLDCARD firmware had been producing recovery phrases with significantly reduced entropy since March 2021. See the Coinkite security advisory for full technical details.

COLDCARD firmware version 4.0.0 shipped with a build setting that was supposed to disable the device’s dedicated hardware randomness chip. A supporting library checked whether the setting existed. It did not check whether the setting was switched on. The result: key generation fell through to a software substitute seeded from the chip’s serial number and its clock registers.

For Mk2 and Mk3 devices running firmware 4.0.1 through 4.1.9, effective randomness dropped from 128 bits to about 40 bits. For Mk4, Mk5, and Q devices, the impact was less severe but still serious, approximately 72 bits instead of the expected 128 bits.

Forty bits sounds like a lot. It is not. A search space of 40 bits is roughly one trillion possibilities. On ordinary hardware, that runs in a weekend of rented computing power. Seventy-two bits is larger, but still within reach of well-resourced attackers. One hundred twenty-eight bits is not, it is a number with 39 digits. Nothing that exists, or will exist, can search through that.

The consequences were catastrophic. Since July 30, an attacker moved approximately 1,816 bitcoin, roughly $116 million, out of more than 5,200 addresses generated on affected COLDCARD devices. Galaxy Research counted the largest single sweep at 1,082 bitcoin from 1,196 wallets, broadcast inside 41 minutes. A fourth wave emptied another 709 addresses.

Nobody was phished. No device was stolen. The funds were drained because the seed phrases were not as random as they should have been, and attackers could enumerate the possibilities.

Coinkite CEO Rodolfo Novak (known online as NVK) published an apology and a follow-up letter calling the previous three days “some of the hardest in this company’s history.” He then suggested that AI might be finding such bugs at speed that outpaces human review. Security specialists pushed back: a build flag that disables a hardware random number generator is a human engineering failure, and conventional code review should have caught it years before any model read the repository. See Coinkite’s technical deep dive and community reactions on Reddit for the broader discussion. See the Coinkite security advisory for full technical details.

The key takeaway: a seed generated on affected firmware stays weak even after you update to fixed firmware. Updating does not repair an existing seed. If your seed was created on an affected device and you did not supplement it with at least 50 independent, private dice rolls, your funds are at risk. Coinkite’s advice: migrate immediately.

Coinkite’s Open-Source to Closed-Source Switch: A Community Failure

The Coldcard firmware was open-source for years, allowing the community to audit it and catch bugs. Then Coinkite switched to closed-source firmware, removing that oversight. Security researchers like Andrew Poelstra (co-author of libsecp256k1 and core Bitcoin developer) have publicly stated that security-critical firmware should always be open-source. See Poelstra’s statement on GitHub and Coinkite’s blog post on the closed-source switch for context.

Reddit’s r/Coinkite criticized the closed-source decision, with users noting that the firmware’s open-source history was one of its key selling points. The Coinkite CEO NVK acknowledged the community’s frustration, but the decision stood. The Coldcard hack, combined with the closed-source switch, is a cautionary tale about the dangers of removing transparency from security software.

Why This Matters for Everyone, Not Just Coldcard Users

The Coldcard bug is specific to Coinkite’s firmware. It never touched your BitBox02, your Trezor, your Ledger, or your Blockstream Jade. Other manufacturers have confirmed they are unaffected.

But the broader lesson applies to everyone in self-custody: single-signature wallets have one thing that must never fail. If that one thing fails (a vendor bug, a lost device, a compromised passphrase), you lose everything. Multisig closes that gap. In a 2-of-3 setup, you hold three keys and any two of them can spend, so one weak seed, one stolen device, or one house fire is not enough.

The key insight: use different devices from different manufacturers, stored separately, so one vendor’s bug cannot take two of your three. That is the point where single-sig starts looking less like simplicity and more like an unhedged bet.

I have never used a Coldcard myself. My experience with hardware wallets starts with the BitBox02. Later I added a Jade as a second independent device for experimentation. The BitBox was my first step out of exchange custody and it served me well. The Jade was an alternative path. But the Coldcard hack made me think seriously about multi-sig, and that is what this article is about.

Blockstream Jade: Three Models, One Security Philosophy

Blockstream has three Jade models in their store, and the differences between them are not just marketing. Here is the breakdown.

Jade (€59)

The entry point. Plastic body, 21g, color display (1.9”), USB-C and Bluetooth. No Genuine Check. You cannot verify the device was manufactured by Blockstream. For anyone buying from third-party sellers, this is a risk.

What it does well: it is the cheapest entry point into self-custody. It supports air-gapped transactions via QR codes displayed on screen (you scan them with your phone camera). It is compatible with Sparrow, Electrum, Nunchuk, BlueWallet, and the Blockstream app.

What it does not do: No Genuine Check means you cannot verify authenticity. No QR camera means you cannot use the fully air-gapped workflow where the device itself scans QR codes from your screen, you need your phone as an intermediary.

I have used the Jade (the original version) for several years. It has been reliable. It does the job for basic self-custody. But compared to the Plus, it lacks the QR camera and feels like a device from a different era.

Jade Core (€74)

The Core adds Genuine Check to the standard Jade. Plastic body, 20g, USB-C and Bluetooth. Genuine Check ensures the device you received was manufactured by Blockstream and is not a malicious third-party clone. For anyone buying from third-party sellers, this is not optional.

What it does well: same as Jade, but with the peace of mind that your device is authentic. The Blind Oracle security model is as strong as any physical Secure Element, and the open-source oracle lets you remove the trust assumption entirely by hosting it yourself.

What it does not do: Same limitations as Jade. No QR camera, no SD card slot. The €15 premium over the standard Jade buys you authenticity verification only.

I have used the Jade Core for several years. It has been reliable. It does the job for basic self-custody. But compared to the Plus, it lacks the QR camera and feels like a device from a different era.

Jade Plus (€126-€143)

The Plus is the flagship. Metal body (or plastic for the €126 Black variant), color display, QR camera, SD card slot, 280 mAh battery, 25-30g depending on material. The navigation buttons are responsive and the display is easy on the eyes.

The QR camera changes the air-gapped workflow fundamentally. Instead of displaying QR codes on screen for your phone to scan, the Jade PlusAffiliate link. You support sovgrid at no extra cost to you. See /support. camera reads QR codes directly from your computer screen. This means you can sign transactions without the device ever connecting to a networked machine, not via USB, not via Bluetooth, not via anything. The camera is the only interface, and it only reads. It cannot transmit data out.

The SD card slot enables additional workflows: storing backups, importing recovery phrases, and potentially future air-gapped firmware updates. It is a feature that signals Blockstream’s commitment to keeping the device secure without compromising on flexibility.

Is the €53 premium over the standard Jade worth it? If you do air-gapped workflows regularly, yes. If you primarily use USB or Bluetooth, the standard Jade is sufficient. The Plus is for power users who want the highest level of air-gap security and the best user experience.

BitBox02 Reference (€~134)

For context, the BitBox02 Bitcoin-only edition (the variant I use) sits between the Jade and Jade Plus in price. Swiss-made, open-source firmware and hardware, microSD backups instead of seed phrases, USB-C connection. It does not have Bluetooth or a QR camera. The BitBoxApp provides a clean interface and native LND integration through PSBT import/sign/export flows.

The BitBox02’s differentiation is in the multisig and recovery workflows. Setting up a 2-of-3 across BitBox02, Coldcard, and a Sparrow-managed software signer takes about ten minutes. The recovery card system (stored on microSD) is more durable than paper for most users. But the BitBox02 is a different product category, it does not compete directly with the Jade line on connectivity or air-gap features. For more on the BitBox02 setup, see Setup: BitBox Hardware Wallet.

Comparison Table

FeatureJadeJade CoreJade PlusBitBox02Coldcard Mk5
Price€59€74€126€134€~150
MaterialPlasticPlasticMetal / PlasticPolycarbonateClear plastic
Weight21g20g25-30g33g55g
DisplayColor 1.9”N/AColor 1.9”ColorMonochrome
ConnectivityUSB-C + BluetoothUSB-C + BluetoothUSB-C + Bluetooth + QR Camera + SDUSB-CUSB-C + microSD
Battery240 mAhN/A280 mAhN/AN/A
Genuine Check✅ (via app)✅ (NFC)
Air-Gap (QR)Phone scans devicePhone scans deviceDevice scans screenPSBT via USBmicroSD cards
Multisig✅ (2-of-2, 2-of-3)
Dice Roll Entropy
Anti-Exfil
Blind Oracle (Virtual SE)❌ (physical SE)❌ (physical SE)
Open-Source Firmware❌ (closed since 2024)

Two Security Features That Matter: Blind Oracle and Anti-Exfil

Most hardware wallet comparisons stop at connectivity and price. They should not. Two cryptographic features on the Jade distinguish it from nearly every other device on the market: the Blind Oracle security model and Anti-Exfil protection. Neither is marketing. Both are implemented in open-source code that anyone can audit.

Blind Oracle: The Virtual Secure Element

Most hardware wallets (Ledger, Trezor, Coldcard) use a physical Secure Element (SE) chip, a dedicated piece of silicon designed to store secrets and perform cryptographic operations in isolation.

Blockstream’s approach is different. Instead of a physical SE, Jade uses what they call a “Blind Oracle”, a virtual secure element implemented in software. Here is how it works: your seed is encrypted with AES-256. The encryption key is co-created with a rate-limited oracle service that lives on a remote server. To unlock the encrypted seed, you need both the PIN (entered on the device) and a response from the oracle. The oracle wipes after three wrong PIN attempts, making brute-force attacks impractical.

The advantage: the encrypted seed on the device is useless without the oracle response. Even if someone steals your Jade and cracks the PIN, they cannot extract your keys. The attack becomes interactive and remote, they need to interact with the oracle, which rate-limits and monitors for abuse.

The disadvantage: you trust a remote server. Blockstream mitigates this by making the oracle code fully open-source (GitHub: blind_pin_server) and by allowing users to run their own oracle. You can host the Blind Oracle on your own server, eliminating the trust assumption entirely.

This is fundamentally different from Coldcard’s approach: a physical SE that can theoretically be compromised through side-channel attacks (like the laser fault injection attacks demonstrated against Ledger’s SE2 by Donjon in 2023). The Blind Oracle trades physical tamper-resistance for software transparency. Both approaches have tradeoffs. Neither is objectively “better.” But the Blind Oracle model is genuinely innovative and worth understanding.

Anti-Exfil: Stopping Key Leakage Through Signatures

Anti-Exfil is a feature written by Andrew Poelstra (co-author of libsecp256k1, core Bitcoin developer) that addresses a subtle but real threat: a compromised hardware wallet can slowly leak your private keys through the nonces in its signatures, even if the keys themselves were generated securely.

Here is the problem in plain terms. When you sign a Bitcoin transaction, the device generates a random number called a nonce. The nonce is combined with your private key to produce the signature. In theory, the nonce should be impossible to predict. In practice, if the device’s random number generator is compromised (or backdoored), an attacker can observe enough signatures to reconstruct the private key. This is not theoretical, it has happened with Android’s RSA implementation and with Bitcoin wallets that used weak entropy sources.

Anti-Exfil stops this by using “sign-to-contract.” Before signing, Jade cryptographically commits its nonce to random data from your host computer. This fully re-randomizes the nonce, so no key material can be smuggled out through the signature. Even if the device is compromised, the signatures it produces are useless for key recovery.

The caveat: Anti-Exfil requires cooperation from the host software. Not all wallet applications support it yet. Sparrow Wallet does. Electrum has experimental support. The Blockstream app does not (yet). It is a feature that will become more valuable as more software adopts it.

Multi-Sig: Why One Wallet Is Not Enough

The Coldcard hack proved a simple point: single-signature wallets have a single point of failure. No matter how secure the device, no matter how careful you are, one vendor-level bug can compromise everything.

The solution is multi-signature. In a 2-of-3 setup, you hold three keys on three different devices. To spend, any two of the three must sign. This means one weak seed, one stolen device, or one vendor bug cannot drain your funds. You need two out of three.

A Concrete Example: BitBox02 + Jade + Jade Plus

Here is what a practical 2-of-3 setup might look like:

All three devices are from two different manufacturers (Shift Crypto and Blockstream). This is important: if Blockstream had a vendor-level bug similar to Coldcard’s, the BitBox02 would still protect half your funds. If Shift Crypto had a similar issue, the two Jade devices would still protect half. Using two manufacturers instead of three is a trade-off. It reduces complexity and price, while still surviving a single vendor failure.

The setup happens in Sparrow Wallet, which has excellent multisig support. You connect each device, verify the extended public keys (xpubs) on-screen, and create the multisig descriptor. The whole process takes about ten minutes. Sparrow then manages the multisig wallet, allowing you to create, sign, and broadcast transactions using any combination of two devices.

Why Different Manufacturers Matter

The Coldcard hack is the most recent example, but it is not the first. Ledger lost 270,000 customer records in 2020. Trezor has had hardware vulnerabilities discovered in their Secure Elements. Every hardware wallet vendor is a potential single point of failure.

Using three devices from two different manufacturers is the only approach that survives a vendor-level failure. In practice, this means:

If you cannot afford three devices, start with two from different manufacturers. Two is better than one. The goal is to ensure that no single vendor’s bug can compromise all your keys.

Recovery Testing: The Discipline Nobody Talks About

Hardware wallet recovery cards are physical artifacts with a specific failure mode: they fade, get coffee-stained, or get filed in a drawer no one remembers. Store two recovery cards in geographically-separate locations, test recovery quarterly, and set a calendar reminder. Most loss-of-funds incidents are not technical failures, they are human failures of the recovery procedure.

I run a quarterly recovery drill on a second machine with a small amount to verify the entire chain works end-to-end. The cost is one hardware-wallet’s worth of attention twice a year. The benefit is knowing the recovery actually works rather than assuming it.

What to Buy

If you are new to self-custody and want the simplest path from exchange to cold storage: Jade at €59. It is the cheapest entry point, but has no Genuine Check.

If you want Genuine Check and the Blind Oracle security model: Jade Core at €74. The Genuine Check is worth the small premium. The Blind Oracle security model is as strong as any physical Secure Element, and the open-source oracle lets you remove the trust assumption entirely by hosting it yourself.

If you do air-gapped workflows regularly: Jade PlusAffiliate link. You support sovgrid at no extra cost to you. See /support. at €126. The QR camera changes the air-gap game. The color display is genuinely nicer. The metal build feels premium. The SD card slot signals long-term thinking.

If you want the Swiss-made alternative with microSD backups: BitBox02Affiliate link. You support sovgrid at no extra cost to you. See /support. at €134. It is the device I use. It integrates well with my Lightning node setup. The multisig workflow is smooth. But it does not have Bluetooth, a QR camera, or the Blind Oracle model.

The real answer to “which hardware wallet should I buy” is “buy three from different manufacturers and set up 2-of-3.” The Coldcard hack proved that single-vendor single-sig is an unhedged bet. The cost of three devices (€250-€350) is negligible compared to the amount of Bitcoin you are protecting. If you cannot afford three devices right now, start with one. But plan for multi-sig. The setup is not complicated, Sparrow Wallet makes it straightforward. The real cost is attention, not money. And that is a cost worth paying.

Where to Buy

All three JadeAffiliate link. You support sovgrid at no extra cost to you. See /support. models are available directly from Blockstream’s store with the SOVGRID referral code, which gives you a 10% discount on top, supports this blog at no extra cost to you.

Was this worth it? Zap the article.

Value for value, no signup. Sats go straight to the writer.

sats zapped
zaps
Today 7d 30d All-time
Unique readers
Page views
All Article Insights →