tradingkey.logo
tradingkey.logo
Search

Blame lands on Coinkite CTO as BTC exploit loss nears $120M

CryptopolitanAug 4, 2026 7:24 PM
facebooktwitterlinkedin
View all comments(0)

Researchers have tied the faulty randomness code at the center of the Coldcard wallet breach to Coinkite co-founder and CTO Peter Gray, who Bitcoin developer James O’Beirne says brushed off a warning about the defect in May 2025. 

The exploit has now drained roughly $114 million across more than 5,200 Bitcoin addresses, and Coinkite says it is still live.

The GPG signatures that point at one person

The buggy library, called libngu, was published on GitHub under a pseudonymous account named Switch. An analysis posted on August 4 by Bitcoin developer James O’Beirne laid out cryptographic evidence that the account belongs to Gray.

O’Beirne’s write-up rests on GPG commit signatures. According to the analysis, there are 58 commits that are authored as “Switck” that carry valid signatures from Gray’s personal key, the same key that signs his commits under the name Peter D. Gray in the same repository. 

The Switch account, by contrast, has uploaded no key of its own. The analysis states that it has been cryptographically proven that the two identities are one person.

The connection matters because Coldcard’s production firmware pulls libngu in as a dependency, according to O’Beirne’s analysis, which also cites security firm Wizardsardine’s finding that the library is one of three repositories involved in the vulnerability. 

A report from May 2025 that went nowhere

O’Beirne flagged the risk more than a year ago while auditing Coldcard’s firmware in May 2025.

He said that he wanted to pin down where the wallet sourced its randomness and traced it back to libngu, after which he informed Coinkite about the possible defect at the time.

“This is the same guy that shrugged off my report of the possibility of the defect in May 2025,” O’Beirne wrote, referring to Gray. He added that he had not yet told the full story of that exchange. 

Coinkite has yet to respond to the identity claim of the report.

One commit in 2021, unnoticed for five years

Block’s Bitcoin engineering and security teams traced it to a commit dated March 1, 2021, that changed how Coldcard built a wallet’s seed. The change swapped a call that pulled from the device’s hardware random number generator for one that fell through to MicroPython’s software randomizer.

The mistake hid in a single preprocessor check. Firmware version 4.0.0 shipped with the flaw on March 17, 2021.

The seeds were built with too little entropy, so attackers could regenerate them offline and drain funds without ever touching a device. None of the thefts involved stolen hardware, phishing, or malware.

Coinkite tells owners to move funds now

Coinkite has told users to act with urgency. “Please treat this as urgent. Migrate your funds,” the company posted, while confirming that the exploit is still in progress and asking holders to alert others who are “less online.”

Not every wallet is exposed. Reports say that Mk3 devices set up on firmware 4.0.1 or later are at risk, while Mk4, Mk5, and Q owners running firmware below 5.6.0 or 1.5.0Q should update, create a new seed, and move their coins. 

Wallets built with the device’s dice-roll option, where a user enters at least 50 physical rolls, never ran the broken path and are considered safe. A strong BIP-39 passphrase and multisig setups where the Coldcard key is only one of several signers also held up.

Losses near $114 million across four waves

The theft has come in bursts. The first wave on July 30 moved about 1,083 BTC out of 1,196 addresses inside 41 minutes, worth roughly $70 million. Three more waves followed over five days, with Galaxy Research counting a fourth sweep early on August 3 that pushed the running total to about 1,816 BTC. 

Some reports put the value near $116 million, while others cite $114 million at prevailing prices.

Bitcoin itself has barely moved, trading near $63,800 during U.S. hours on August 4. Vincent Bouzon, a cybersecurity expert at rival wallet maker Ledger, stated that the episode was “a failure of one implementation rather than a verdict on self-custody,” adding that entropy “must be anchored in secure hardware.”

The smartest crypto minds already read our newsletter. Want in? Join them.

Disclaimer: The information provided on this website is for educational and informational purposes only and should not be considered financial or investment advice.

Comments (0)

Click the $ button, enter the symbol, and select to link a stock, ETF, or other ticker.

0/500
Commenting Guidelines
Loading...

Recommended Articles

tradingkey.logo
Risk Warning: Our Website and Mobile App provides only general information on certain investment products. Finsights does not provide, and the provision of such information must not be construed as Finsights providing, financial advice or recommendation for any investment product.
Investment products are subject to significant investment risks, including the possible loss of the principal amount invested and may not be suitable for everyone. Past performance of investment products is not indicative of their future performance.
Finsights may allow third party advertisers or affiliates to place or deliver advertisements on our Website or Mobile App or any part thereof and may be compensated by them based on your interaction with the advertisements.
© Copyright: FINSIGHTS MEDIA PTE. LTD. All Rights Reserved.