Here’s some timeline fillers for what @Laser didn’t have. Still working on more
2010
Peter D. Gray and Rodolfo Novak (NVK) begin working together at Ripe Apps, an iPhone/iPad app development studio in Toronto. Predates their Bitcoin involvement by a year.
2011
Gray discovers the Bitcoin whitepaper and shares it with Novak, his existing business partner.
2012
The pair builds btclook.com, a visual blockchain explorer, as a Ripe Apps side project. Later that year they build PCI-certified Bitcoin payment terminals and begin international deployment, ahead of incorporating.
2012–2013
Peter D. Gray and Rodolfo Novak (NVK) co-found Coinkite in Toronto. Gray becomes CTO, Novak becomes CEO. Debuts a working terminal at the Bitcoin Conference. Raises a $120K seed round, the company’s only funding round to date. Remains a team of around five.
November 7, 2013
Peter D. Gray creates his GPG key (uid “Peter D. Gray peter@coinkite.com”). This key later signs dozens of commits under the switck identity, including the critical libngu changes.
Early 2016
Coinkite shuts down its web wallet/exchange service, citing legal complications and DDoS attacks, and pivots fully to hardware — the turn that leads to Opendime and eventually Coldcard.
December 2017
Coinkite announces the Coldcard hardware wallet. Pre-orders open for 2018 shipping.
July 25, 2018
First Coldcard Mk1 units ship.
August 2019
Peter creates the anonymous identity “switch,” named after the Matrix character Switch, using a still of that character as the profile picture. First posts note DEF CON is a good time to start a new identity. Later commits under this name are often single-word or extremely terse.
2019–2020 onward
Bitcoin educators and influencers, including BTC Sessions, begin promoting Coldcard as one of the most secure Bitcoin hardware wallets.
July 2020
Foundation Devices announces the Passport, built in part on Coldcard’s then-GPLv3 firmware.
Early 2020s
Ten31 becomes Coinkite’s sole external investor, confirmed on record by NVK in podcast disclosures.
January 8, 2021
Coldcard firmware 3.2.1 announces the license change from GPL to MIT + Commons Clause.
January 5, 2021
Domain switck.com is registered via a privacy service. The switck account posts the single word “got” the same day.
January 28, 2021
Under switck, the vulnerable preprocessor guard (#ifndef MICROPY_HW_ENABLE_RNG) is committed to libngu. This fails to force the hardware TRNG when the macro is set to zero. The library is co-maintained with scgbckbone.
March 1, 2021
Under doc-hex, the commit “First pass w/ libNgU” (b18723dd) replaces remaining Trezor-derived GPL crypto and BIP-39 code with libngu. Seed generation switches from hardware path to ngu.random.bytes(). This is the point real hardware entropy is replaced by the weak software PRNG. Coinkite release notes later thank @switck for the library.
March 17, 2021
Firmware v4.0.0 released, stating all crypto and BIP39 code had been replaced and the last remaining GPL code removed.
March 29, 2021
Firmware 4.0.1 ships. Seeds generated under this and later affected versions fall back to the software PRNG, yielding roughly 40 bits of effective entropy on Mk2/Mk3 (roughly 72 bits on later models with limited secure-element mixing).
Around April 2021
Public users begin questioning the libngu rewrite and the replacement of the prior crypto stack.
2022
As DocHex, Gray publicly states that as CTO he encourages Coinkite developers to operate under nyms and stay low-profile about their employer, and notes he may appear to author his own GitHub commits under a different identity. In a podcast appearance the same year, Novak refers to Gray directly as “Doc Hex, my co-founder.”
May 2025
James O’Beirne audits the firmware, identifies the low-star, pseudonymously maintained libngu library as the RNG source. In his own words, posted on X: he wanted to figure out conclusively where the Coldcard RNG was sourced from, and traced it to a shady library. He contacts Coinkite. Reported response: if something were wrong, they’d likely already know about it by now. The warning is not acted on.
July 30, 2026
Attackers begin draining wallets. Initial wave: roughly 594 BTC (~$38M) from about 500 addresses in ~25 minutes. Coinkite publishes a security advisory the same day acknowledging the 2021 entropy failure.
July 31, 2026
Coinkite releases fixed firmware (4.2.0 Mk3, 5.6.0 Mk4/Mk5, 1.5.0Q). Existing weak seeds remain compromised and must be migrated. Independent verification beyond Coinkite’s own account: Bitcoin Core developer instagibbs reproduces the vulnerability on a fresh Mk3 device. Kevin Loaec of Wizardsardine is among the first to publicly sound the alarm. Peter Todd flags a specific multisig risk for 2-of-3 setups using compromised Coldcards. Multiple reports note NVK deleting older tweets related to the 2020–2021 license change and open-source decisions.
View quoted note →
Contra
reformedsaint@zaps.lol
npub14hq5...jjzu
The unexamined premise is the only tyranny that asks for your consent. Reformed Christian, Nostr class of 23, I think
I make music, bitcoin music 👇🏻
https://wavlake.com/contra
The armor doesn’t dent. It gets pierced by the gap they left open on purpose.


I’ve watched a lot of groups claim resilience. Bitcoiners are the only ones I’ve seen actually live it. We unite. Nobody has to ask twice.
I have a sneaky suspicion more people will be involved in this CC farce than we know right now.
Part 1: Who Peter Gray Is..
Peter D. Gray. CTO and co-founder of Coinkite. Goes by “doc-hex” online. Bachelor of Mathematics from Waterloo. Programmer since before there was a commercial web, by his own bio. Still codes every day, still an active CTO, not just a name on the letterhead.
He’s Irish based now. Founded four companies total, angel invests in a handful more, mostly UK and Ireland fintech. But Coinkite is the one that matters here. He’s the guy who actually wrote the firmware.
Part 2: How He and NVK Got Here
2011. Gray reads the Bitcoin whitepaper, gets hooked, brings it to his business partner. That partner is Rodolfo Novak. Not a chance meeting. They already ran a company together, Ripe Apps, before Bitcoin was even on the radar.
They build btclook.com, a blockchain explorer, just to scratch the itch. Can’t find a wallet they actually like. So in 2013 they build their own and call it Coinkite. Started as a bitcoin banking and payment terminal play before it pivoted hard into hardware.
Part 3: The Part We’re Still Verifying
There’s a claim circulating that the specific commit tied to the broken RNG path, the libngu integration, traces back to Gray’s authorship on GitHub.
I’m not saying I can prove intent (yet). I’m saying the pattern doesn’t look like an accident anymore. Trust doesn’t survive a coincidence this convenient.
May the Nostr investo commence…
NVK is deleting his 2020 posts right now. Trying to clean up the Coldcard history before people connect the dots on the entropy bug.
Someone already has the receipts. They’d do well to keep them.
I’m awake and ready to be a problem.
Good Morning. ☀️ ☕️
I'm a big fan of the GPS Theory when you miss a turn, your GPS doesn't judge you, it recalculates. No matter how many detours you take, it finds another way forward.
Life works like that too. You'll make mistakes, but your destination doesn't vanish.
The route just changes.
Yeah, it sucked. Coins vanished that shouldn’t have. A lot are pissed and some are scared. Good. Channel it.
The people who treat this like a funeral will shrink. The ones who treat it like training will own the next decade.
Self custody just got more expensive in attention and more valuable in practice. That’s not a reason to quit. It’s a reason to get better at it.
My takeaway from this coldcard situation is that self custody doesn’t remove the need for responsibility.
It multiplies it.
The future of healthcare wont be built in labs.
It will be built in kitchens, backyards, walking trails.
It will be built by people who grow their own food, lift heavy things, breathe deeply, and remember that community is medicine.
Weve outsourced healing for too long..it's time to bring it home.
Open source only works if skilled eyes are actually looking. Reproducible builds only protect you from a company shipping different binaries. They don’t protect you from a subtle logic error that was in the source the whole time.
We need more people who actually read the entropy paths. Not just more people who repost “don’t trust, verify.”
Lessons…
Breaking from social media is a must. But you also can lose track real quick if you’re not plugged in.
What did I miss on Thursday? Readers digest version please…
Late start. Gm to my favorite Bitcoin Maxis
Lords day people. May you go to worship the King of Kings.


When lies bring people together, the truth will eventually tear them apart.
Stay true to yourself…integrity always wins in the end.
Enjoy this Saturday. And stack accordingly. Gm
I’ve said this before and I stand by it…People who introduce you to new ways of thinking and new ways of seeing life are so important.
#HealthStr