⚡️💬 TESTOMINIAL - COINKITE CTO ALLEGEDLY DISMISSED WARNING ABOUT FAULTY RNG CODE A YEAR BEFORE EXPLOIT
New evidence suggests the pseudonymous switck account that wrote the LibNgU code at the center of the COLDCARD entropy failure was actually Coinkite co-founder and CTO Peter Gray.
Researchers say Gray’s GPG key signed dozens of switck commits, with additional identifiers appearing to link the two identities.
Bitcoin developer James O’Beirne says he warned Coinkite in May 2025 that LibNgU’s RNG implementation looked suspicious and recommended removing it, but says he was told any issue would already have been discovered.
Screenshots also show users questioning the LibNgU rewrite as early as April 2021.
If these findings are accurate, it would mean the engineer who introduced the code later tied to the theft of more than 1,800 BTC also received a direct warning about the RNG implementation more than a year before the vulnerability was publicly disclosed.
🗣 "I haven't told the full story yet, but I came to the same conclusion back in May 2025 when I started doing an audit of `coldcard/firmware`.
I wanted to figure out conclusively where the CC RNG was getting sourced from, and found that it backed up to some shady library called libngu (https://github.com/switck/libngu) that had literally 6 stars on github and was maintained solely by a pseudoanon tranny.
I knew from past experience that linking to libsecp256k1 from Python was pretty easy, which seemed to be the stated purpose of the library use, and so I was confused about why it was there.
I sent a report to the CC team that I had doubts about whether the true RNG was actually in use, and pointed out that the hardcoded yasmarang constants in libngu were sloppy. I advised they rip the whole thing out and link against libsecp256k1 directly.
I was told that if something was wrong "we'd already know about it by now" and that everything was properly configured for the real boards.
I didn't follow up rigorously, which was a horrible mistake on my part." 


