Blockstream said Jade is not affected by the Coldcard random number generator vulnerability and released firmware version 1.0.41 after extensive AI-assisted security reviews. According to Odaily, the firmware update adds stack protection, updates dependencies, audits sensitive memory-clearing processes, and upgrades the Jade runtime environment.
Jade said it underwent dozens of automated AI scans and multiple manual reviews, with attention focused on sensitive areas including random number generation and transaction signing. Blockstream said Jade’s random number generation uses multiple entropy sources, including hardware chip noise, timing data, sensor data, and camera noise, which are mixed with SHA-512 to reduce the risk of a single entropy source failure affecting seed generation.
The team said other lower-severity findings are still being addressed, and firmware 1.0.42 is expected to be released on a shorter development cycle.