Top

Coinkite CTO accused of ignoring prior warning on Coldcard code flaw

August 04, 2026, 3:32 PM
Questions have emerged over whether Coinkite co-founder and CTO Peter Gray wrote the LibNgU code blamed for a Coldcard hardware wallet vulnerability tied to losses estimated at more than 1,800 BTC, Bitcoin News reported. LibNgU was known to have been written by an anonymous developer using the handle "switck," according to the report. However, Gray’s GPG key was found to have signed dozens of code commits under the switck account, raising the possibility that the two are the same person. Bitcoin developer James O’Beirne claimed he urged Coinkite in May last year to remove the LibNgU code, saying its random number generator implementation looked questionable. The company was said to have replied at the time that any issue would likely already have been discovered if one existed. If accurate, the account suggests the author of code linked to the theft of more than 1,800 BTC had received a direct warning more than a year before the vulnerability was disclosed that the random number generation method could be flawed, but did not act on it.

Leave the first comment

You need to log in to leave a comment.
Log In
Loading