Blockstream: Jade is not affected by the Coldcard random number vulnerability, firmware 1.41 released
Blockstream stated that Jade is not affected by the Coldcard random number generator vulnerability and has released firmware 1.41 after receiving extensive AI-assisted security reviews. Jade indicated that it has undergone dozens of automated AI scans and multiple manual reviews, focusing on sensitive areas such as random number generation and transaction signing.
The new firmware enhances stack protection, updates dependencies, audits sensitive memory cleanup processes, and upgrades the Jade runtime environment. Blockstream claims that Jade's random number generation mechanism uses multiple entropy sources, including hardware chip noise, timing data, sensor data, and camera noise, and mixes them using SHA-512 to prevent a single entropy source failure from affecting seed generation. The team stated that other lower-severity findings are still being addressed, and firmware 1.42 is expected to be released in a shorter development cycle.






