Fake firmware update email designed to steal crypto assets
Blockstream, a leading Bitcoin infrastructure and hardware wallet provider, has issued an urgent warning about a new phishing campaign impersonating its Jade hardware wallet firmware update. The scam, delivered via email, attempts to lure users into clicking a malicious link disguised as a legitimate firmware download.
In its statement, Blockstream stressed that it never distributes firmware files via email and confirmed that no customer data has been compromised. The company urged users to remain vigilant, reminding them that firmware updates should only be downloaded directly from official sources.
Phishing campaigns are designed to steal sensitive information by mimicking legitimate communications. In this case, the fraudulent email contained a simple message urging users to install the “latest Jade firmware” — a link that led to a malicious site.
Phishing scams on the rise in 2025
The warning comes as phishing attacks surge across the crypto sector. According to Scam Sniffer, phishing scams cost users over $12 million in August alone, impacting more than 15,000 victims — a 67% increase from July.
Blockchain security firm Hacken reported that crypto users lost over $3.1 billion to scams and hacks in the first half of 2025, marking a sharp rise compared to 2024. Experts note that phishing remains one of the most common and effective attack methods used by bad actors.
How to stay safe against phishing
Security specialists emphasize that phishing campaigns often use emails mimicking customer support or urgent security alerts, tricking users into revealing private keys, passwords, or seed phrases.
To stay safe, users should:
- Double-check website URLs for subtle errors, such as replacing letters with numbers.
- Bookmark official websites instead of relying on search engines or ads.
- Avoid clicking unknown links in emails or messages.
- Use a VPN to enhance privacy and security.
- Inspect emails for spelling or grammatical mistakes, a common red flag in phishing attempts.
As phishing schemes grow increasingly sophisticated, Blockstream’s warning highlights the importance of constant vigilance and strict online security practices for anyone holding digital assets.
Disclaimer
This content is for informational purposes only and does not constitute financial, investment, or legal advice. Cryptocurrency trading involves risk and may result in financial loss.

