1. Peter (as switck) wrote the broken #ifndef guard in libngu (Jan 2021).
2. Peter (as doc-hex) integrated libngu into #Coldcard firmware and changed seed generation to use it (March 2021).
3. The combination caused ngu.random.bytes() → MicroPython Yasmarang software PRNG (seeded from UID + timers) instead of the hardware TRNG.
Result: seeds with ~40 bits effective entropy on Mk2/Mk3 (and ~72 bits on later models that mixed in some secure-element data), which "attackers" later brute-forced.
#Bitcoin


Peter D. Gray, Coinkite's CTO, must be investigated as a primary suspect in the Coincard heist.
View quoted note →

