Jade doesn’t use a physical secure element. We just published a full post on how the Virtual Secure Element works: https://blog.blockstream.com/jade-virtual-secure-element/ Your recovery phrase sits encrypted on the device. Unlocking it needs the PIN you type on Jade and a key share from a blind oracle. Neither is enough by itself. The oracle never sees the real PIN or any wallet data. It only gets a scrambled version that includes a secret unique to that particular Jade. Three wrong PINs and both sides wipe. Device and oracle. After that the encrypted data is permanently unusable without the recovery phrase. A locked Jade holds nothing an attacker can use alone. Everything is open source, firmware, hardware, and the oracle. You can run the oracle yourself, or skip it completely and use SeedQR or type the recovery phrase.