Blockstream has stated that its Jade hardware wallet is not affected by the Coldcard random number generator vulnerability, and has released firmware 1.41 after receiving a large volume of AI-assisted security reviews.
The Jade team said the device has undergone dozens of automated AI scans and multiple manual reviews, with a focus on sensitive areas such as random number generation and transaction signing. The new firmware strengthens stack protection, updates dependencies, audits sensitive memory cleanup processes, and upgrades the Jade runtime environment.
Blockstream also detailed Jade's random number generation mechanism: it uses multiple entropy sources — hardware chip noise, timing data, sensor data, and camera noise — mixed via SHA-512, so that a single entropy source failure cannot affect seed generation.
The team added that other lower-severity findings are still being addressed, and firmware 1.42 is expected in a shorter development cycle.

