★★★★☆ 4.0 / 5

Blockstream Jade Plus: Fully Open, With a Security Model to Understand

A cheap, fully open-source signer with an excellent QR camera — built on a general-purpose ESP32 and a blind-oracle design you should understand before you trust it.

Verdict. The Jade Plus is one of the best-value fully open-source hardware wallets: great QR scanning, multiple connectivity options, and firmware and hardware you can fully inspect. The trade-off is that it uses a general-purpose ESP32 MCU instead of a dedicated secure element, leaning on a 'blind oracle' for physical-attack resistance — a clever model, but one with real caveats and a documented history of ESP32-class attacks.

What’s good

  • Fully open-source hardware and firmware — you can even build a compatible device from off-the-shelf parts
  • Excellent built-in camera for fast, air-gap-friendly QR signing
  • Flexible connectivity: USB, Bluetooth, camera QR, and microSD
  • Inexpensive — the Plus is around $149 and the base Jade Core is even cheaper
  • Blind-oracle model can be self-hosted (e.g. on Umbrel) or run statelessly, so you're not forced to trust Blockstream's server
  • Larger, sharper screen and better build than the original Jade

What’s not

  • No dedicated secure element — it runs on a general-purpose ESP32-S3, a chip class with a documented fault-injection/glitching history
  • Physical-attack resistance depends on the blind oracle; run it fully stateless and you give up some of that protection
  • The blind oracle introduces an availability and privacy consideration you must reason about (self-hosting mitigates it)
  • Security researchers (esp32.fail / Ledger Donjon) have published evil-maid firmware-extraction and glitch findings on Jade-class hardware
  • At least one firmware-level bug (a CBOR 'register_descriptor' issue) was disclosed and patched — keep firmware updated
  • Bluetooth is convenient but adds attack surface some users prefer to avoid
Buy it ifValue-focused and open-source-first users who will take the time to understand the blind-oracle model and keep firmware current.
Skip it ifBuyers who specifically want a dedicated secure element and the simplest possible 'set it and forget it' physical-security story.

The Jade Plus makes a strong opening argument: it is fully open source, top to bottom. Blockstream publishes the hardware and firmware, and famously you can assemble a compatible Jade from off-the-shelf parts. For people who believe verifiability is the foundation of trust, that openness is the headline feature, and it is not marketing fluff — it is a genuine, auditable commitment that most competitors only partially match.

In daily use it is pleasant and capable. The built-in camera is one of the better QR scanners on the market, which makes air-gapped signing fast rather than fiddly. You also get USB, Bluetooth and microSD, so it slots into almost any wallet workflow. The Plus adds a bigger, nicer screen and a more premium feel than the original. At roughly $149 — with the base Jade Core cheaper still — the value proposition is excellent on paper.

The part that demands honesty is the security architecture. Unlike Coldcard or Passport, the Jade does not use a dedicated secure element. It runs on a general-purpose ESP32-S3 microcontroller. To compensate, Blockstream designed the 'blind oracle': your wallet encryption is split between your PIN, the device, and a remote oracle server that never learns your PIN, keys or addresses. It functions as a virtual secure element, and critically you can run your own oracle (for example on Umbrel) or operate the device in a stateless mode with no oracle at all.

That design is genuinely clever, and it is the reason Jade can stay fully open — secure-element silicon is proprietary, so avoiding it is what buys the openness. But the trade-offs are real and worth stating plainly. Lean on the blind oracle and you introduce an availability and privacy consideration (mitigated, though not eliminated, by self-hosting). Run fully stateless and you shed some of the physical-attack resistance the oracle provides. There is no free lunch; there is a choice you should make deliberately.

The ESP32 lineage also carries baggage. General-purpose MCUs of this class have a documented history of voltage-glitching and fault-injection attacks going back to Black Hat research, and security researchers have published evil-maid firmware-extraction work specifically against Jade-class hardware. Separately, a firmware-level vulnerability in the CBOR 'register_descriptor' path was responsibly disclosed and patched. None of this means Jade is broken — Blockstream has responded with updates — but it does mean physical security here is a moving target that depends on you keeping firmware current.

We land at 4.0. The Jade Plus is a legitimately great open-source wallet at a great price, and for a threat model centered on remote attackers and everyday use it is more than sufficient. It loses points only against the strictest physical-security bar, where a dedicated secure element and a simpler trust story win. Buy it if openness and value are your priorities and you are willing to understand the oracle model; look elsewhere if you want a secure element and zero homework.

Bottom line. A superb-value, fully open-source signer whose novel blind-oracle security model is a strength and a homework assignment in equal measure.
Blockstream Jade Plus

$149 · pay with Bitcoin, Lightning or x402

See it in the shop →

Sources (12)

  1. Blockstream Jade Plus — Official Product Page — Blockstream
  2. Blockstream Jade Plus — Store — Blockstream Store
  3. Introducing the All-New Blockstream Jade Plus — Blockstream Blog
  4. Jade Security Model FAQs — Blockstream Help Center
  5. Why Doesn't Jade Have a Secure Element? — Blockstream Help Center
  6. Blind Oracle — Glossary — Blockstream
  7. Set Up a Personal Blind Oracle with Umbrel — Blockstream Help Center
  8. jade.fail / esp32.fail — Vulnerabilities & Mishaps of Blockstream Jade — esp32.fail
  9. Firmware Extraction: Evil-Maid Attacks on Blockstream Jade — Ledger Donjon
  10. Jade Security Disclosure — Blockstream Blog
  11. Less Complexity, Same Security: Blockstream Introduces Jade Core — Blockstream Press
  12. Blockstream Jade Review (2025): Open-Source Security — WalletPilot