Can This Chinese Chip Steal Your Bitcoin?

https://m.primal.net/QUus.mp4

Reply to this note

Please Login to reply.

Discussion

Blockstream has claimed the Jade is not vulnerable, but would 1) want to see an independent 3rd party verify that claim and 2) if someone is using a Jade probably best to switch to the firmware that disables Bluetooth for now.

Update: seems Blockstream is most likely correct they are not vulnerable because they don’t rely on the ESP32 to do the crypto

Great video anyone using a Jade should watch. Urgency is a red flag so take your time, take a deep breath, don’t panic, and carefully consider, but personally I would not keep using a Jade without switching to the No-Radio firmware.

nostr:nevent1qqswqv0zw3jgv3hq3lyer574rrljmc2rywjcp7r0nk63dqzta2lq64gpzemhxw309ucnjv3wxymrst338qhrww3hxumnwzh3mh9

this is Chinese vendor's response claims...

https://www.espressif.com/en/news/response_esp32_bluetooth

I highly approve of your example low-entropy private key.