Tuesday, August 4, 2026
28.7 C
New York

Coinkite CTO Peter Gray linked to the code behind the $114M Coldcard hack



Researchers have tied the faulty randomness code at the center of the Coldcard wallet breach to Coinkite co-founder and CTO Peter Gray, who Bitcoin developer James O’Beirne says brushed off a warning about the defect in May 2025. 

The exploit has now drained roughly $114 million across more than 5,200 Bitcoin addresses, and Coinkite says it is still live.

The GPG signatures that point at one person

The buggy library, called libngu, was published on GitHub under a pseudonymous account named Switch. An analysis posted on August 4 by Bitcoin developer James O’Beirne laid out cryptographic evidence that the account belongs to Gray.

O’Beirne’s write-up rests on GPG commit signatures. According to the analysis, there are 58 commits that are authored as “Switck” that carry valid signatures from Gray’s personal key, the same key that signs his commits under the name Peter D. Gray in the same repository. 

The Switch account, by contrast, has uploaded no key of its own. The analysis states that it has been cryptographically proven that the two identities are one person.

The connection matters because Coldcard’s production firmware pulls libngu in as a dependency, according to O’Beirne’s analysis, which also cites security firm Wizardsardine’s finding that the library is one of three repositories involved in the vulnerability. 

A report from May 2025 that went nowhere

O’Beirne flagged the risk more than a year ago while auditing Coldcard’s firmware in May 2025.

He said that he wanted to pin down where the wallet sourced its randomness and traced it back to libngu, after which he informed Coinkite about the possible defect at the time.

“This is the same guy that shrugged off my report of the possibility of the defect in May 2025,” O’Beirne wrote, referring to Gray. He added that he had not yet told the full story of that exchange. 

Coinkite has yet to respond to the identity claim of the report.

One commit in 2021, unnoticed for five years

Block’s Bitcoin engineering and security teams traced it to a commit dated March 1, 2021, that changed how Coldcard built a wallet’s seed. The change swapped a call that pulled from the device’s hardware random number generator for one that fell through to MicroPython’s software randomizer.

The mistake hid in a single preprocessor check. Firmware version 4.0.0 shipped with the flaw on March 17, 2021.

The seeds were built with too little entropy, so attackers could regenerate them offline and drain funds without ever touching a device. None of the thefts involved stolen hardware, phishing, or malware.

Coinkite tells owners to move funds now

Coinkite has told users to act with urgency. “Please treat this as urgent. Migrate your funds,” the company posted, while confirming that the exploit is still in progress and asking holders to alert others who are “less online.”

Not every wallet is exposed. Reports say that Mk3 devices set up on firmware 4.0.1 or later are at risk, while Mk4, Mk5, and Q owners running firmware below 5.6.0 or 1.5.0Q should update, create a new seed, and move their coins. 

Wallets built with the device’s dice-roll option, where a user enters at least 50 physical rolls, never ran the broken path and are considered safe. A strong BIP-39 passphrase and multisig setups where the Coldcard key is only one of several signers also held up.

Losses near $114 million across four waves

The theft has come in bursts. The first wave on July 30 moved about 1,083 BTC out of 1,196 addresses inside 41 minutes, worth roughly $70 million. Three more waves followed over five days, with Galaxy Research counting a fourth sweep early on August 3 that pushed the running total to about 1,816 BTC. 

Some reports put the value near $116 million, while others cite $114 million at prevailing prices.

Bitcoin itself has barely moved, trading near $63,800 during U.S. hours on August 4. Vincent Bouzon, a cybersecurity expert at rival wallet maker Ledger, stated that the episode was “a failure of one implementation rather than a verdict on self-custody,” adding that entropy “must be anchored in secure hardware.”



Source link

Hot this week

U.S. International Trade in Goods and Services, June 2026

The U.S. Census Bureau and the U.S. Bureau...

Lucid Group (LCID) earnings Q2 2026

The Lucid Gravity is displayed during the 2023...

3D Systems Corporation 2026 Q2 – Results – Earnings Call Presentation (NYSE:DDD) 2026-08-04

This article was written byFollowSeeking Alpha's transcripts team...

Why voting belongs on every Realtor’s job description

Communities are strongest when the people who understand...

Latest Post

Lucid Group (LCID) earnings Q2 2026

The Lucid Gravity is displayed during the 2023...

Why voting belongs on every Realtor’s job description

Communities are strongest when the people who understand...

U.S. International Trade in Goods and Services, June 2026

The U.S. Census Bureau and the U.S. Bureau...

3D Systems Corporation 2026 Q2 – Results – Earnings Call Presentation (NYSE:DDD) 2026-08-04

This article was written byFollowSeeking Alpha's transcripts team...
Demo

Related Articles

Popular Categories

Demo