From James Obeirne on x “I haven't told the full story yet, but I came to the same conclusion back in May 2025 when I started doing an audit of `coldcard/firmware`.
I wanted to figure out conclusively where the CC RNG was getting sourced from, and found that it backed up to some shady library called libngu (github.com/switck/libngu) that had literally 6 stars on github and was maintained solely by a pseudoanon tranny.
I knew from past experience that linking to libsecp256k1 from Python was pretty easy, which seemed to be the stated purpose of the library use, and so I was confused about why it was there.
I sent a report to the CC team that I had doubts about whether the true RNG was actually in use, and pointed out that the hardcoded yasmarang constants in libngu were sloppy. I advised they rip the whole thing out and link against libsecp256k1 directly.
I was told that if something was wrong "we'd already know about it by now" and that everything was properly configured for the real boards.
I didn't follow up rigorously, which was a horrible mistake on my part.”
Login to reply
Replies (4)
👀 what?
View quoted note →
DEImocracy in action, don't you just love this jewmerican meritocracy?
A movie script at this point.
View quoted note →
Wow