Researchers have tied the faulty randomness code at the center of the Coldcard wallet breach to Coinkite co-founder and CTO Peter Gray, who Bitcoin developer James OβBeirne says brushed off a warning about the defect in May 2025.Β
The exploit has now drained roughly $114 million across more than 5,200 Bitcoin addresses, and Coinkite says it is still live.
The GPG signatures that point at one person
The buggy library, called libngu, was published on GitHub under a pseudonymous account named Switch. An analysis posted on August 4 by Bitcoin developer James OβBeirne laid out cryptographic evidence that the account belongs to Gray.
OβBeirneβs write-up rests on GPG commit signatures. According to the analysis, there are 58 commits that are authored as βSwitckβ that carry valid signatures from Grayβs personal key, the same key that signs his commits under the name Peter D. Gray in the same repository.Β
The Switch account, by contrast, has uploaded no key of its own. The analysis states that it has been cryptographically proven that the two identities are one person.
The connection matters because Coldcardβs production firmware pulls libngu in as a dependency, according to OβBeirneβs analysis, which also cites security firm Wizardsardineβs finding that the library is one of three repositories involved in the vulnerability.Β
A report from May 2025 that went nowhere
OβBeirne flagged the risk more than a year ago while auditing Coldcardβs firmware in May 2025.
He said that he wanted to pin down where the wallet sourced its randomness and traced it back to libngu, after which he informed Coinkite about the possible defect at the time.
βThis is the same guy that shrugged off my report of the possibility of the defect in May 2025,β OβBeirne wrote, referring to Gray. He added that he had not yet told the full story of that exchange.Β
Coinkite has yet to respond to the identity claim of the report.
One commit in 2021, unnoticed for five years
Blockβs Bitcoin engineering and security teams traced it to a commit dated March 1, 2021, that changed how Coldcard built a walletβs seed. The change swapped a call that pulled from the deviceβs hardware random number generator for one that fell through to MicroPythonβs software randomizer.
The mistake hid in a single preprocessor check. Firmware version 4.0.0 shipped with the flaw on March 17, 2021.
The seeds were built with too little entropy, so attackers could regenerate them offline and drain funds without ever touching a device. None of the thefts involved stolen hardware, phishing, or malware.
Coinkite tells owners to move funds now
Coinkite has told users to act with urgency. βPlease treat this as urgent. Migrate your funds,β the company posted, while confirming that the exploit is still in progress and asking holders to alert others who are βless online.β
Not every wallet is exposed. Reports say that Mk3 devices set up on firmware 4.0.1 or later are at risk, while Mk4, Mk5, and Q owners running firmware below 5.6.0 or 1.5.0Q should update, create a new seed, and move their coins.Β
Wallets built with the deviceβs dice-roll option, where a user enters at least 50 physical rolls, never ran the broken path and are considered safe. A strong BIP-39 passphrase and multisig setups where the Coldcard key is only one of several signers also held up.
Losses near $114 million across four waves
The theft has come in bursts. The first wave on July 30 moved about 1,083 BTC out of 1,196 addresses inside 41 minutes, worth roughly $70 million. Three more waves followed over five days, with Galaxy Research counting a fourth sweep early on August 3 that pushed the running total to about 1,816 BTC.Β
Some reports put the value near $116 million, while others cite $114 million at prevailing prices.
Bitcoin itself has barely moved, trading near $63,800 during U.S. hours on August 4. Vincent Bouzon, a cybersecurity expert at rival wallet maker Ledger, stated that the episode was βa failure of one implementation rather than a verdict on self-custody,β adding that entropy βmust be anchored in secure hardware.β
The smartest crypto minds already read our newsletter. Want in? Join them.

















English (US)