Coldcard’s $114M Hack May Trace Back to Its Own CTO
- A Bitcoin developer says GPG signatures tie the flawed randomness code to Coinkite CTO Peter Gray.
- Developer James O’Beirne says he flagged the same bug to Coinkite in May 2025 and was brushed off.
- The exploit has now drained roughly 1,816 BTC, worth about $114 million, from more than 5,200 addresses since July 30.
The company that built one of Bitcoin’s most trusted hardware wallets may have shipped the flaw that broke it, and even more interesting is that the person who wrote the code may be the same person who now runs the company’s engineering.
The Pseudonym That Wasn’t
For years, a GitHub contributor going by “Switck” maintained libngu, the cryptographic library later found to generate predictable seed phrases on Coldcard devices. Bitcoin developer James O’Beirne published an analysis Monday arguing that Switck’s real identity is Peter Gray, Coinkite’s co-founder and chief technology officer.
His case rests on GPG signatures: 58 commits made under the Switck name carry valid signatures from Gray’s personal key, the same key that signs Gray’s commits under his own name in the same repository. Switck’s account never published a key of its own.
That detail matters because Coldcard’s production firmware pulls libngu in as a direct dependency. If the identification holds, the person responsible for catching this kind of bug may also be the person who wrote it.
O’Beirne adds a second layer to the story. He says he emailed Coinkite in May 2025 about the random-number implementation in libngu, specifically calling it out as questionable. According to O’Beirne, the company’s response was that a real issue would likely have surfaced by now. It didn’t surface until an attacker found it first.
What Happens Now
Coinkite has not addressed the identification claim directly. Its public response has focused on the technical fix and user migration, not on who wrote the original code. The company’s advisory, updated as the investigation continues, still tells affected users their only real fix is generating a new seed on updated firmware and moving funds over, since a firmware patch cannot repair a key that was already compromised.
For the wider market, this shifts the story from a technical failure to a governance question. A firmware bug is one kind of risk. A company allegedly dismissing an outside warning about that exact bug, from the same person who wrote it, is a different kind of risk, and one that due-diligence conversations around hardware wallet vendors are likely to raise for a long time after this specific incident is closed.
Source: