Tracing the Source of a Hardware Wallet Crisis: The Mystery of the Anonymous Coder
Investigations into the COLDCARD entropy failure incident have taken a significant turn. Emerging evidence suggests the real-world identity behind the pivotal LibNgU code library may have been uncovered.
The Smoking Gun: GPG Keys Link to CTO
Researchers within the Bitcoin community have identified a critical connection. The anonymous account “switck,” responsible for submitting the LibNgU code, used a specific GPG key to sign dozens of its commits. Analysis shows this key belongs to Peter Gray, co-founder and Chief Technology Officer of hardware wallet firm Coinkite.
Beyond the cryptographic signature, investigators point to additional technical identifiers that appear to tie the “switck” online persona to Gray’s professional identity. If confirmed, this would mean the engineer who authored the flawed code was a senior insider at the company responsible for the product's security.
Warnings Unheeded: Early Red Flags on RNG Risk
Perhaps more consequential than the authorship is the timeline of warnings. Bitcoin Core developer James O’Beirne has stated that he contacted Coinkite directly in May 2025, flagging that the Random Number Generator implementation in LibNgU “looked suspicious” and advising its removal.
The reported response was that any issues would likely have been caught by the community already, indicating the warning may not have triggered urgent action.
Digging further back, public forum discussions reveal that as early as April 2021, technical users were questioning the necessity and potential risks of the LibNgU rewrite. These early signals also appear to have gone unaddressed.
Implications and Unanswered Questions
If the findings hold, they paint a troubling chronology: the engineer who introduced the defective code held a senior position, and direct, expert technical warnings about its critical RNG component were reportedly received over a year before the vulnerability was exploited, leading to a loss exceeding 1800 BTC.
The connections raise profound questions beyond a single bug, touching on accountability in open-source projects, transparency in hardware wallet supply chains, and the efficacy of security warning protocols. Formal responses to the latest allegations regarding identity links are still pending.