Peter's Switck = Switch from Matrix. It was a tell. 🚩🚩🚩 The core of the #Coldcard vulnerability was a silent switch in the source of randomness. The intended path used the device’s hardware true random number generator. A defective preprocessor check in the `libngu` library instead allowed (and in practice forced) a fallback to a weak software PRNG (Yasmarang) whose output was far more predictable. Seeds created under the affected firmware therefore contained dramatically less entropy than expected—enough that offline brute-force became feasible years later. The switch was not loud; it was a quiet change in the code path that left the rest of the system appearing to function normally while the foundational randomness was compromised. In The Matrix, Switch was designed as a character who could rewrite residual self-image—appearing one way in the real world and another inside the simulation. The name itself encoded the act of changing identity and presentation at will. Even after the dual-gender concept was removed, the androgynous figure in white remained a symbol of someone who understood that the system’s rules about what is “real” could be altered by those who controlled the underlying code. Under the handle switck, the same developer who publicly maintained Coldcard’s cryptographic stack as DocHex introduced the library that quietly switched the entropy source. Where hardware randomness was supposed to flow, the defective guard selected the weak software path instead. The rest of the firmware continued as if nothing had changed, just as the Matrix continued to present a coherent world while its deeper rules had been rewritten. Years later the reduced entropy space was exploited, and the wallets whose seeds had been generated under that switched implementation were emptied. image
Laser's avatar Laser
Switck appears to be a reference to the androgenous/trans character Switch in the Matrix. The switck GitHub and Twitter profiles use the identical profile pic. The Twitter profile contains the pronouns "She/he/his/hers." in the bio. Coinkite CTO Peter D. Gray's GPG key signed a large number of commits under the switck GitHub account in the libngu repository (the library that introduced the critical RNG preprocessor bug). This includes the key January 2021 commit (f19de05) that contained the defective #ifndef guard. Multiple independent checks (terminal verification scripts shared publicly) confirmed the signatures match Peter’s known key used for Coldcard/firmware work under the doc-hex identity. View quoted note →
View quoted note →

Replies (3)

Nate's avatar
Nate / yesterday
NVK recently published an essay on security architecture of HWWs where he explained security flaws of competitor HWWs and how to design against these flaws. You can see this on his nostr page. The first thing it taught me was how to compromise a seedsigner. This shows he has the competence and mindset to develop a hidden exploit in cc. $130M in stolen btc is the motive. With everything else you're pointing out about Peter Gray, this looks straight up like an inside job by those two folks. They are either criminally negligent incompetents, or thieves.
The only thing that makes me doubt malice is how weird the timing is. Or did Peter and/or NVK put this in to be able to rug pull in the future, but were to greedy to execute, wanting more. And then AI found the vulnerability and some other person(s) performed this attack? Or maybe their idea was to steal a little every now and then for years. A few people here and there have reported their wallets swept. The occasional wallet sweep could be explained by just wallet collisions, though. How many of these wallet sweep reports have there been? Have there been any reports of people finding bitcoin in their wallet just after setting it up? There is a lot that points towards malice, but I will not rule out incompetence completely yet. However, they could just be incompetent at being malicious...
Chiefwhite's avatar
Chiefwhite yesterday
the serial numbers were on the bags. the serial/uid played onto seed. they knew who had what when where