Currencies38392
Market Cap$ 2.27T+0.38%
24h Spot Volume$ 22.68B-1.07%
DominanceBTC56.69%+0.21%ETH9.95%-0.12%
ETH Gas0.10 Gwei
Cryptorank
/

Coinkite CTO Accused of Ignoring Prior Warning on Coldcard Code Flaw


Coinkite CTO Accused of Ignoring Prior Warning on Coldcard Code Flaw

Share:

AI Overview

Reports allege Coinkite CTO Peter Gray may have ignored a May warning about a critical RNG flaw in the LibNgU library used by Coldcard hardware wallets, a vulnerability tied to the theft of more than 1,800 BTC and complicated by GPG-signed commits linking Gray to the anonymous developer 'switck'. The timeline and code-signing evidence raise serious crypto security and responsible-disclosure concerns for hardware wallets, increasing risk to user funds and underscoring the need for independent audits and faster vendor responses to protect adoption and market confidence.

Bearish

Predictions Markets

See what traders are focused on

View analytics →
Prediction Banner

BitcoinWorld

Coinkite CTO Accused of Ignoring Prior Warning on Coldcard Code Flaw

New questions are emerging about whether Coinkite co-founder and CTO Peter Gray overlooked a direct warning about a critical flaw in the Coldcard hardware wallet, a vulnerability that has been linked to the loss of more than 1,800 Bitcoin. Reports from Bitcoin News indicate that the flaw resides in LibNgU, a library previously attributed to an anonymous developer known as ‘switck.’ However, Gray’s GPG key was used to sign dozens of commits under the switck account, raising the possibility that Gray and switck are the same person.

Timeline of the Warning

According to Bitcoin developer James O’Beirne, he contacted Coinkite in May of last year to express concerns about the LibNgU code, specifically the random number generator implementation, which he deemed questionable. O’Beirne claims that the company responded that if a real issue existed, it would likely have been discovered by now. This response, if accurate, suggests that the author of code tied to the theft of over 1,800 BTC had received a direct warning more than a year before the vulnerability was publicly disclosed, yet took no corrective action.

Implications for the Crypto Community

This incident underscores the critical importance of transparency and responsiveness in hardware wallet security. For users who rely on Coldcard devices to secure their digital assets, the timeline raises concerns about how seriously initial security reports are taken. The fact that the alleged author of the flawed code may have been the same person who received the warning adds another layer of accountability. The crypto community is now left to question whether more could have been done to prevent the loss of such a significant amount of Bitcoin.

What This Means for Users

For Coldcard users, this situation serves as a reminder to stay informed about security updates and to consider the broader implications of how manufacturers handle vulnerability reports. It also highlights the need for independent security audits and community vigilance. While Coinkite has not yet publicly responded to these new allegations, the story is developing, and further details may emerge.

Conclusion

The allegations against Peter Gray and Coinkite highlight a potential failure in the responsible disclosure process. If the claims are true, a warning that could have prevented the loss of over 1,800 BTC was ignored, leading to a significant breach of user trust. As the investigation continues, the crypto community will be watching closely to see how Coinkite addresses these serious concerns and what steps they will take to restore confidence in their products.

FAQs

Q1: What is LibNgU and why is it important?
LibNgU is a library used in Coldcard hardware wallets, responsible for certain cryptographic functions, including random number generation. A flaw in this library could compromise the security of private keys, leading to potential theft of funds.

Q2: Who is James O’Beirne and what did he claim?
James O’Beirne is a Bitcoin developer who claims he warned Coinkite in May of last year about the questionable random number generator implementation in LibNgU. He says the company dismissed his concerns, stating that any real issue would have been found already.

Q3: How much Bitcoin was lost due to this vulnerability?
According to reports, losses are estimated at more than 1,800 BTC, which at current market prices represents a substantial financial impact on affected users.

This post Coinkite CTO Accused of Ignoring Prior Warning on Coldcard Code Flaw first appeared on BitcoinWorld.

Read the article at Bitcoin World

In This News

Coins

$ 64.15K

+0.51%

Predictions Markets

See what traders are focused on

View analytics →
Prediction Banner

Share:

In This News

Coins

$ 64.15K

+0.51%

Predictions Markets

See what traders are focused on

View analytics →
Prediction Banner

Share:

Read More

Alex Thorn Warns of Fourth Apparent BTC Theft Wave Targeting Coldcard Users

Alex Thorn Warns of Fourth Apparent BTC Theft Wave Targeting Coldcard Users

BitcoinWorld Alex Thorn Warns of Fourth Apparent BTC Theft Wave Targeting Coldcard U...
Coldcard Thefts Escalate: Onchain Lens Reports 1,816 BTC Lost in Ongoing Attack

Coldcard Thefts Escalate: Onchain Lens Reports 1,816 BTC Lost in Ongoing Attack

BitcoinWorld Coldcard Thefts Escalate: Onchain Lens Reports 1,816 BTC Lost in Ongoin...