Default
- How it works
- Seed stored on the device; PIN unlock completed through Blockstream's server.
- Good fit
- Most people. The server assists with unlocking but cannot spend your coins.
Jade protects your PIN differently from every other device on this site, and that choice shapes your backup plan. Understand it first, then set the thing up.
Jade is open source down to the hardware, inexpensive, and capable of fully air-gapped signing over QR codes. It is one of the easiest recommendations on this site. It also does one thing so differently from every other device here that setting it up without understanding it first is how people end up surprised later.
That thing is the PIN. On most hardware wallets a dedicated secure element chip stores your key and counts failed attempts. Jade takes a different route, and the consequence is a design decision you make during setup rather than a detail you can ignore.
A Blockstream Jade Plus held up with its camera facing a laptop screen displaying a QR code, mid-scan.
Image to come
Inspect the packaging for cuts, re-glued seams, or a second seal laid over the first, and the case for scratches around the seam. Then run the genuine check offered by the companion app, which asks the device to prove cryptographically that it is real Blockstream hardware.
Jade has no dedicated secure element chip. Instead it uses what Blockstream calls a virtual secure element: your seed is stored encrypted on the device, and the key needed to decrypt it is not held entirely on the device either. Part of it lives on a server — Blockstream's, by default.
When you enter your PIN, the device talks to that server to complete the unlock. The server is what enforces the limit on wrong attempts, doing the job a secure element chip does elsewhere.
Two things follow, and neither is hidden or sinister — but both are yours to plan around:
It removes the closed, unauditable chip that other devices depend on, which is exactly what lets Jade be open source all the way down. In exchange, ordinary unlocking involves a service. Whether that is a good trade depends on what you are optimising for — auditability or independence — and the next section covers what to do if you want both.
Decide this now, because it determines what your backup has to cover.
The third mode changes the shape of your risk entirely. A Jade holding no seed is just electronics — losing it costs you the hardware and nothing else. The cost is that every signing session starts with entering your words, which is slower and puts them in front of you far more often. That is a real trade-off in both directions, and it only works if your backup is somewhere you can reach routinely.
Choose to create a new wallet rather than restoring one. The device generates the words and shows them on its own screen.
Jade Plus has a camera and a screen large enough to display QR codes back. That means the whole signing loop can happen without the device ever being connected to anything: your wallet software shows an unsigned transaction as a QR code, Jade reads it, you approve on the device, and Jade displays the signature as a QR code for the computer to read back.
No cable, no Bluetooth, no shared bus. Whatever is wrong with your computer stays on your computer.
Jade offers Bluetooth and USB alongside the camera. If you have set up QR signing, you do not need the radio, and a capability you never use should not be switched on.
This is not a claim that Bluetooth on this device is broken. It is the ordinary principle that a signer's job is to be boring, and every enabled interface is one more thing that has to be correct.
Because Jade's unlock design is unusual, it is worth being explicit about what your recovery words do and do not depend on.
Run the drill in test your recovery. It matters on every device and slightly more here, because Jade offers several ways to operate and you want to have proven the one you actually chose.
Modes, menu wording, and hardware revisions change between releases. Confirm the current setup flow and the details of the PIN design against Blockstream's own documentation before following any step here that does not match what your device shows.