CTO Ignored Warning: 1,800 BTC Lost to Coldcard Flaw

Key Takeaways

Allegations indicate Coinkite CTO Peter Gray dismissed a May 2023 warning regarding a LibNgU vulnerability linked to 1,800 BTC losses. Evidence suggests Gray may be the anonymous developer 'switck' who authored the flawed code.

Woofun AI reports that Coinkite CTO Peter Gray faces accusations of disregarding a critical security alert concerning the Coldcard hardware wallet, with the LibNgU library and anonymous developer 'switck' central to the controversy.

James O’Beirne contacted the firm in May of last year to flag a questionable random number generator implementation within the code, . This specific technical concern was raised well before the vulnerability became public knowledge, establishing a clear timeline for the alleged negligence.

The financial impact of the flaw is severe, linked to the loss of 1,800 Bitcoin, or 1,800 BTC. Forensic evidence complicates the narrative, as Gray’s GPG key signed dozens of commits under the switck account, implying he may be the author of the vulnerable code.

Per Woofun AI, the company’s alleged response was that if a real issue existed, it would likely have been discovered by now, resulting in no corrective action being publicly disclosed. This dismissal suggests a failure to address the warning despite the potential for significant asset compromise.

The incident underscores the necessity for transparency, responsiveness, and independent security audits within the hardware wallet sector. While Coinkite has not yet publicly responded, community vigilance remains high regarding these unresolved accountability questions.

Comments

Me
Replying to @User
0/800

No comments yet.

Notifications

Sign in to view messages
View all messagesManage subscriptions