Coinkite CTO reportedly brushed off RNG flaw warning a year before COLDCARD entropy exploit

AI Market Summary
Allegations that Coinkite's CTO ignored prior warnings about faulty RNG code tied to the COLDCARD entropy failure revive scrutiny of hardware-wallet security and vendor governance. The report underscores operational and reputational risks in self-custody infrastructure, potentially weakening near-term confidence in certain custody solutions and increasing sensitivity to security-related headlines across the Bitcoin ecosystem after a theft exceeding 1,800 BTC.
Impact level
● Medium
Affected assets
BTC/USDT+0.67%
AI Insight · BTC/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
New evidence indicates the pseudonymous "switck" account that authored LibNgU—the code at the center of the COLDCARD entropy failure—may have been Coinkite cofounder and CTO Peter Gray. Researchers say Gray's GPG key signed dozens of commits attributed to "switck," and cite additional identifiers they believe connect the two identities. Bitcoin developer James O'Beirne (@jamesob) says he alerted Coinkite in May 2025 that LibNgU's RNG implementation appeared suspicious and advised removing it, but claims he was told any problem would have already been detected. Screenshots also show users questioning the LibNgU rewrite as early as April 2021. If confirmed, the findings would suggest that the engineer who introduced code later linked to the theft of more than 1,800 BTC also received a direct warning about the RNG implementation more than a year before the vulnerability was publicly disclosed.