August 04, 15:18
Coinkite CTO Allegedly Linked to Code in 1,800 BTC Theft
Over 1,800 BTC Stolen, Coinkite CTO Allegedly Ignored RNG Code Warnings a Year in Advance

Odaily
Key Point
New evidence suggests Coinkite co-founder and CTO Peter Gray may be the anonymous account switck, who wrote the LibNgU code at the center of the COLDCARD entropy failure incident. Researchers claim Gray's GPG key signed dozens of commits by switck. Bitcoin developer James O'Beirne stated that he warned Coinkite in May 2025 that the LibNgU RNG implementation looked suspicious. O'Beirne stated that he recommended removing the implementation. Screenshots show that users raised questions about the LibNgU rewrite as early as April 2021.
Why it matters: Weak entropy may turn private-key generation into a direct custody risk and could reduce trust in hardware-wallet supply chains.
Market Sentiment
Cautiously Bearish, Stress-on, Event-driven, Fear.
Reason: The alleged LibNgU entropy failure tied to over 1,800 stolen BTC points to custody risk, which can weaken confidence in self-custody tools.
Similar Past Cases
In 2023, CVE-2023-39910 in Libbitcoin Explorer exposed weak entropy in wallet generation, and NVD said attackers exploited it in June and July 2023 to recover wallet private keys and steal funds. (NVD) The difference is that the current case centers on alleged identity links and prior warnings around LibNgU, so accountability risk is more central than in a generic vulnerability disclosure.
Ripple Effect
A wallet entropy failure could spread through custody confidence because users may question whether generated keys are truly random. If Coinkite or researchers publish stronger confirmation, then scrutiny could move from one code path to broader hardware-wallet review processes.
Opportunities & Risks
Opportunities: If Coinkite publishes a technical explanation or remediation plan, then verified fixes can become a confidence-repair signal for affected self-custody workflows.
Risks: If additional evidence links the same RNG implementation to more theft reports, then reducing reliance on affected wallet setups limits custody downside.
This content is an AI-generated summary/analysis for informational purposes only and does not constitute investment advice.