Articles on: Bitcoin Wallets
This article is also available in:

Verify Jade Plus and avoid wallet scams

A genuine hardware wallet cannot protect you if you install a fake companion app, approve a substituted address, or disclose the recovery phrase to an impostor. Verify the device, software source, firmware path, and every transaction independently.


No legitimate support agent needs your wallet secret. Never share or enter a recovery phrase or passphrase in a phone, computer, website, coordinator, cloud form, chat, support ticket, remote-access session, or “verification” tool. Enter it only directly on trusted hardware during a documented setup or recovery flow.


Buy and inspect carefully


Prefer Blockstream or a seller you trust. On arrival:


  • inspect the parcel, packaging, and device for unexpected damage or modification;
  • compare the product with images reached from Blockstream's official site;
  • do not use a recovery phrase supplied in the box or by a seller;
  • initialize the wallet yourself in private;
  • stop if the device asks you to expose recovery words to the companion computer.


Packaging is not proof of authenticity. Run Jade's documented Genuine Check during setup. If it fails, stop using the device and reach Blockstream support by navigating from the official Blockstream website, not through a link in an unsolicited message or advertisement.


Blockstream App Genuine Check result for Jade Plus


Official reference: Perform a Genuine Check with Jade.


Obtain software and firmware from official sources


Reach downloads from a bookmarked or manually checked Blockstream domain. Treat sponsored search results, lookalike domains, browser pop-ups, QR stickers, direct messages, and email attachments as untrusted. A fake app may display a plausible balance while stealing a phrase or changing a destination.


Update firmware only through Blockstream's documented app, firmware page, or air-gapped JadeLink process. Review release notes. Blockstream also publishes a manual firmware verification procedure for users who need to check a downloaded binary independently.


Do not accept “urgent security updates” delivered through social media, chat, a phone call, or a file attachment. Legitimate incident guidance will not require recovery words.


Recognize common wallet scams


Stop when anyone:


  • asks for recovery words, a passphrase, private key, SeedQR, or device PIN;
  • sends a form to “validate,” “synchronize,” or “upgrade” a wallet;
  • asks you to install remote-control software;
  • claims funds must be moved immediately to a “safe address” they provide;
  • offers to recover a wallet through a website or coordinator seed-entry form;
  • asks for a photo, partial phrase, first or last words, or checksum test;
  • impersonates Bitcoin Well, Blockstream, an exchange, law enforcement, or a family member and creates urgency.


Partial secrets are still secrets. Support can diagnose public error messages, firmware versions, transaction IDs, and account issues without recovery words.


Verify addresses and transactions on Jade


A compromised phone or computer can replace an address shown on its own screen. When receiving, ask Jade to display the address and compare the complete value. Checking only the first and last characters is not sufficient.


Before signing a send, inspect the network, complete destination, amount, fee, and displayed change information on Jade. Reject the transaction if anything differs. QR transport or an air gap does not remove this requirement; malicious transaction data can still travel by QR.


For multisig, register or review the complete policy on supported devices and verify receive addresses independently on more than one signer. Stop if a signer cannot recognize the policy or change output.


Respond to suspected or confirmed compromise


If only the phone or computer is suspected, stop using it and preserve non-secret evidence. From a known-clean companion, verify the wallet fingerprint, a known complete address and, where applicable, the multisig policy on trusted hardware. Do not assume keys are protected merely because no unauthorized transaction is visible.


If one recovery factor or one multisig signer may have been observed, copied, or lost, treat that layer as untrusted and prepare a wallet with fresh independent keys. Urgency depends on what additional material an attacker would need: for example, a recovery phrase may still require a separate BIP39 passphrase, and one 2-of-3 signer cannot spend alone.


If enough material to authorize a spend is confirmed exposed, move urgently to a new hardware-verified wallet. Examples include a singlesig recovery phrase plus its required passphrase, a singlesig private key, or enough multisig signer credentials to meet the threshold. Do not delay solely for a small test when delay materially increases theft risk. Changing a device PIN does not make exposed signing material secret again.


If an unauthorized Bitcoin transaction is already broadcast, it normally cannot be reversed. Preserve non-secret evidence such as the transaction ID and scam messages. Contact Bitcoin Well for account-related issues and Blockstream for device-related issues through independently verified channels without sharing wallet secrets.


Complete Secure Jade Plus before funding and test recovery before increasing the wallet balance.



Updated on: 04/08/2026

Was this article helpful?

Share your feedback

Cancel

Thank you!