Coinkite CTO Peter Gray linked to the code behind the $114M Coldcard hack

- Researchers traced the faulty randomness code behind the $114 million Coldcard wallet breach to Coinkite co-founder Peter Gray.
- Developer James O’Beirne says he warned Coinkite about the defect in May 2025.
- The exploit has hit over 5,200 addresses across four waves since July 30.
Researchers have tied the faulty randomness code at the center of the Coldcard wallet breach to Coinkite co-founder and CTO Peter Gray, who Bitcoin developer James O’Beirne says brushed off a warning about the defect in May 2025.
The exploit has now drained roughly $114 million across more than 5,200 Bitcoin addresses, and Coinkite says it is still live.
The GPG signatures that point at one person
The buggy library, called libngu, was published on GitHub under a pseudonymous account named Switch. An analysis posted on August 4 by Bitcoin developer James O’Beirne laid out cryptographic evidence that the account belongs to Gray.
O’Beirne’s write-up rests on GPG commit signatures. According to the analysis, there are 58 commits that are authored as “Switck” that carry valid signatures from Gray’s personal key, the same key that signs his commits under the name Peter D. Gray in the same repository.
The Switch account, by contrast, has uploaded no key of its own. The analysis states that it has been cryptographically proven that the two identities are one person.
The connection matters because Coldcard’s production firmware pulls libngu in as a dependency, according to O’Beirne’s analysis, which also cites security firm Wizardsardine’s finding that the library is one of three repositories involved in the vulnerability.
A report from May 2025 that went nowhere
O’Beirne flagged the risk more than a year ago while auditing Coldcard’s firmware in May 2025.
He said that he wanted to pin down where the wallet sourced its randomness and traced it back to libngu, after which he informed Coinkite about the possible defect at the time.
“This is the same guy that shrugged off my report of the possibility of the defect in May 2025,” O’Beirne wrote, referring to Gray. He added that he had not yet told the full story of that exchange.
Coinkite has yet to respond to the identity claim of the report.
One commit in 2021, unnoticed for five years
Block’s Bitcoin engineering and security teams traced it to a commit dated March 1, 2021, that changed how Coldcard built a wallet’s seed. The change swapped a call that pulled from the device’s hardware random number generator for one that fell through to MicroPython’s software randomizer.
The mistake hid in a single preprocessor check. Firmware version 4.0.0 shipped with the flaw on March 17, 2021.
The seeds were built with too little entropy, so attackers could regenerate them offline and drain funds without ever touching a device. None of the thefts involved stolen hardware, phishing, or malware.
Coinkite tells owners to move funds now
Coinkite has told users to act with urgency. “Please treat this as urgent. Migrate your funds,” the company posted, while confirming that the exploit is still in progress and asking holders to alert others who are “less online.”
Not every wallet is exposed. Reports say that Mk3 devices set up on firmware 4.0.1 or later are at risk, while Mk4, Mk5, and Q owners running firmware below 5.6.0 or 1.5.0Q should update, create a new seed, and move their coins.
Wallets built with the device’s dice-roll option, where a user enters at least 50 physical rolls, never ran the broken path and are considered safe. A strong BIP-39 passphrase and multisig setups where the Coldcard key is only one of several signers also held up.
Losses near $114 million across four waves
The theft has come in bursts. The first wave on July 30 moved about 1,083 BTC out of 1,196 addresses inside 41 minutes, worth roughly $70 million. Three more waves followed over five days, with Galaxy Research counting a fourth sweep early on August 3 that pushed the running total to about 1,816 BTC.
Some reports put the value near $116 million, while others cite $114 million at prevailing prices.
Bitcoin itself has barely moved, trading near $63,800 during U.S. hours on August 4. Vincent Bouzon, a cybersecurity expert at rival wallet maker Ledger, stated that the episode was “a failure of one implementation rather than a verdict on self-custody,” adding that entropy “must be anchored in secure hardware.”
The smartest crypto minds already read our newsletter. Want in? Join them.
FAQs
Who wrote the code behind the Coldcard exploit?
An analysis by Bitcoin developer James O'Beirne argues that the pseudonymous `switck` account, author of the libngu library that generated weak seeds, is Coinkite CTO Peter Gray, based on GPG signatures from Gray's personal key on commits made under both names.
How much Bitcoin has been stolen in the Coldcard hack?
Galaxy Research counts roughly 1,816 BTC drained from more than 5,200 addresses across four waves since July 30, worth between $114 million and $116 million.
Which Coldcard wallets are safe from the exploit?
Wallets created using the device's dice-roll option with at least 50 rolls, those protected by a strong BIP-39 passphrase, and multisig setups where the Coldcard key is only one signer were not affected.
Disclaimer. The information provided is not trading advice. Cryptopolitan.com holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decisions.

Hannah Collymore
Hannah is a writer and editor with nearly a decade of blog writing and event reporting experience in the crypto space. At Cryptopolitan, Hannah contributes to the news page, reporting and analyzing the latest developments in DeFi, RWA, crypto regulation, AI and frontier tech industries. She graduated from Arcadia university with a degree in Business Administration.
















