There is not 1 single compelling evidence that this was a backdoor.
CoinKite fucked in a major way, and there are MANY red flags, but all are explained by sloppy practices and incompetence.
People who were not sucking off nvk are not surprise by the low standards.
I get that people are angry and want an explanation, and the backdoor explanation will make you feel better as coinkite conspired against you, but this is an emotional way to think.
The reality is you listened and trusted people who are clueless and don't have even a basic understanding of how Bitcoin works.
All the trust was strictly based on social dynamics and 0 verification.
It is easier to claim backdoor than to admit you are a bad judge of character, as that would mean you COULD have somehow avoided this somehow.
Backdoor makes it feel unavoidable, which sorry to say it was not.
1) there is no way to make a backdoor like this an get away with it. this adds permanent damage, and when it gets out you are done, reputation burned for life.
2) don't say they did this for money because the cost vs. benefit makes no sense, too much risk for not that much reward.
business was very successful, they had too much to lose.
3) if you do this for money when bug gets out others will also attack it so you are competing with other hackers
4) look at the fucking code, it a typical mistake that happens in this type of things. the lack of review and using social status to push away scrutiny from project is why it was not caught
You did absolutely NOTHING wrong in using single sig and not rolling dice.
The understanding between coinkite and user is that they provide secure key generation, which is industry standard and works if you have the right internal practices and correct way of doing business.
Login to reply
Replies (6)
Why would Peter Gray create the “switck” profile and introduce the corrupt code? Here’s evidence
what could possibly be the reason?

Gist
switck == doc-hex
switck == doc-hex. GitHub Gist: instantly share code, notes, and snippets.
YES, I have saw both of @jamesob posts with the strange github stuff
which indeed looks VERY, I mean VERY sus, but still NOT pointing to backdoor.
And his 2nd post is direct evidence they they did not take suggestions about their security being bad serious.
In times of crisis and emotions, the most important thing is to push emotions away(and I get that is hard), but if you don't you just make a VERY bad situation worst.

Gist
switck == doc-hex
switck == doc-hex. GitHub Gist: instantly share code, notes, and snippets.

X (formerly Twitter)
James O'Beirne (@jamesob) on X
I haven't told the full story yet, but I came to the same conclusion back in May 2025 when I started doing an audit of `coldcard/firmware`...
Agreed on keeping emotions away. But there is strong evidence of gross negligence at best, criminal behavior at worst, and the clock is running. If it was criminal we are running out of time to him to address the “VERY, I mean VERY sus” information that has come out. That is not emotional, but urgency
Everyone debating this is retarded. Bad RNG is a backdoor, period. Stop lying.
Why were they so dismissive of early reports of swept wallets when they clearly were aware (or at the very least should of been aware) of the gaping exploit?
Backdoors are hard to prove; it's hard to prove intent.