Blame lands on Coinkite CTO as BTC exploit loss nears $120M

NewsTue, 04 Aug 2026 19:24:58 UTC1 hour ago
Blame lands on Coinkite CTO as BTC exploit loss nears $120M

Researchers have tied the faulty randomness code at the center of the Coldcard wallet breach to Coinkite co-founder and CTO Peter Gray, who Bitcoin developer James O’Beirne says brushed off a warning about the defect in May 2025. 

The exploit has now drained roughly $114 million across more than 5,200 Bitcoin addresses, and Coinkite says it is still live.

The GPG signatures that point at one person

The buggy library, called libngu, was published on GitHub under a pseudonymous account named Switch. An analysis posted on August 4 by Bitcoin developer James O’Beirne laid out cryptographic evidence that the account belongs to Gray.

O’Beirne’s write-up rests on GPG commit signatures. According to the analysis, there are 58 commits that are authored as “Switck” that carry valid signatures from Gray’s personal key, the same key that signs his commits under the name Peter D. Gray in the same repository. 

The Switch account, by contrast, has uploaded no key of its own. The analysis states that it has been cryptographically proven that the two identities are one person.

… Continue reading the full article at the original source below.

Read from Source · cryptopolitan.com ↗
This content is automatically aggregated. Full credit goes to the original publisher (cryptopolitan.com).

Related