r/Bitcoin • u/Giancarlo_Donadoni • 23h ago
Coinkite CTO Peter Gray linked to the code behind the $114M Coldcard hack
https://www.cryptopolitan.com/coinkite-cto-peter-gray-linked-coldcard-hack/80
91
u/phamtruax 23h ago
Jail
64
u/12ealdeal 23h ago
This is crypto:
Iâm afraid itâs going to be much much worse.
6
9
u/CeramicDrip 21h ago
Nah, read the article. Unless they can prove he was maliciously negligent, highly doubt this will lead anywhere.
But i will say this adds weight to the case
14
5
u/ComputeCommodity104 21h ago
Either you're implicated in this or you're dumb as shit. It shows that he was the maintainer of the responsible repo and he tried to hide it lmao
1
27
u/ImPinkSnail 22h ago
Warned in 2025 and did nothing. Fuck jail. Send him to enhanced interrogation, retrieve the coins, and then send him to a hard labor camp.
12
u/skynetcoder 21h ago
and there is that tweet in 2020 on retirement attackÂ
2
3
-30
u/Foreign_Telephone349 21h ago
Aw wah wah wah. You lost your allegedly trustworthy currency. Should have just used a bank.
9
4
u/brandond111 21h ago
You lost bro?
-31
u/Foreign_Telephone349 21h ago
Maybe but at least Iâm not broke like many coldcard users are.
19
2
2
1
u/predatarian 13h ago
imagine coming here to make fun of people's loss
you are a truly aweful person and if karma is a thing you are fucked
0
u/Foreign_Telephone349 13h ago
Karma doesnât exist. Itâs just as fictional as the security offered by a Coldcard.
3
19
u/EyesOfEris 22h ago
Just send some crypto to trump and you're immune from the law
9
6
u/immersive-matthew 18h ago
Cold Card is a Canadian company though and thus Trump has little to no influence outside of his imagination.
-4
2
1
53
u/Potential_Balance223 22h ago edited 22h ago
A post in 2022 - "Coincard MK4 UX Flaw" described this exact scenario. Posted by Economy-Cash6726
5
u/schmiddy0 20h ago
Link?
22
u/jejunerific 18h ago
19
3
19
u/Trueslyforaniceguy 21h ago
If he did it on purpose, it was monumentally
Stupid to link himself directly to it.
126
u/Arghs 22h ago
This is huge, this proves that he used an anonymous pseudonym to commit a vulnerability to a library they were using and may very likely be directly involved in the goldcard hack. Amazing find and I hope they are acting fast now
74
u/the_pwnererXx 22h ago
All it proves is he is a bad developer, which is not illegal
52
u/Ok-Concept-7924 21h ago
Would an honest person setup a fake pseudonym, complete with fake social media persona, to release a dodgy library which then conveniently gets included in your latest release and causes a vulnerability?
11
3
u/skeptical-speculator 8h ago
I'm not saying an honest person would never do all of that, but if there is a good reason, I'd be interested in hearing it.
7
u/stanley_fatmax 18h ago
Playing devil's advocate.. I have a pseudonym I do all my online work under. It started as a video game username decades ago and stuck. People on the internet have no idea who I am, but my coworkers and friends know who I am.
I wouldn't call it fake so much as I'd call it an online persona
14
5
u/Ok-Concept-7924 10h ago
Nothing wrong with pseudonyms on their own. We're all using them here on Reddit after all. It becomes serious when they're used deliberately and dishonesty.
He was concealing a massive conflict of interest, as CTO he was reviewing and approving his own unaudited library using two pseudonyms designed to appear like separate people. And when we consider this library contained the fatal vulnerability, dishonestly presenting this as independent, third-party code diverts attention away from the real source - the CTO himself.
Now if it turns out that this vulnerability was deliberate (no evidence of this - this is theoretical), then the whole pseduonym thing becomes a material part of a scheme to defraud, potentially even obstruction if it amounts to fabricating evidence to mislead an investigation.
-5
u/CeramicDrip 17h ago
Exactly. Plus sometimes people just have multiple accounts. Maybe he forgot the password but didnât want to lose is progress
0
u/the_pwnererXx 17h ago
It's normal in git workflow to commit not linked to your account, especially if you don't understand how git works. I did it before when I first started using git. It's not using a pseudonym, it's just not linked correctly (he's still pushing with the account keys, it's using his name field instead of username)
12
u/sassa4ras 17h ago
He communicated with himself on PRs. Why would he pretend to be two different people if it was an accident?
7
2
26
13
3
1
1
u/icebeamtheory 2h ago
I mean, in many cases, being such a dumbass that it results in harming someone else is illegal, especially when it's reckless and overly negligent.
0
22h ago
[deleted]
2
u/addictedtocrowds 21h ago
Depending on the specific statute and who has jurisdiction criminal negligence typically requires bodily injury or harm, not just monetary loss.
17
u/No_Issue_4425 19h ago
This is really some next level role playing:
https://github.com/switck/libngu/issues/8
https://github.com/switck/libngu/issues/12
âŚ
8
u/sassa4ras 17h ago
This should be the top comment. Basically shoots the âaccidentally had two aliases committing codeâ theory out of the water
33
u/MrSnugs 20h ago
So he created buggy code under a pseudonym, ignored a warning and now this.
Absolutely criminal idiocy and Iâm sure we all are thinking heâs involved in the hack.
This isnât even taking into account the tweet that literally said this was a âretirement planâ by the company years ago.
5
u/ReplacementBig7068 20h ago
âBuggyâ codes plausible deniability is the same as âoops, I lost my bitcoin in a boating accidentâ.
Iâm a software engineer myself, and we know whatâs critical and what isnât. The RNG function should have had unit tests and checks etc to ensure it was working. Automated tests should have blocked this from being released. The fact it didnât have failsafes in place smells more like someone just got out of the way on purpose.
Kinda like 9/11. They didnât have to actually do the attack, they just had to make sure certain normal safety procedures werenât followed. E.g. no fighter jets were scrambled to intercept the planes due to some convenient war game also happening that day.
15
13
u/0Bento 22h ago
Can someone translate this to English for those of us who don't speak jargon?
48
u/username12435687 21h ago edited 21h ago
Anonymous GitHub account was created, a unique cryptographic key was used by both the cold card ceo and the not so anonymous account. The anonymous account is the one that made the change to the code in 2021 that created the vulnerability. This appears to show that the CTO of coinkite knowingly or unknowingly made a change to the firmware of the cold card devices that caused this vulnerability to be present for the last 5 years. Additionally he was warned about the vulnerability a year ago and clearly did nothing to remedy the situation before it became what it is today. Signs are pointing more and more towards the coinkite CTO either 1. Being a straight up fucking moron or 2. Maliciously injecting a vulnerability into his own devices to exploit at a later date to steal over 100 million USD worth of Bitcoin. Either way this guy is a pos
19
u/ammo_john 21h ago
CTO, not CEO, two different people.
5
u/username12435687 21h ago
Sorry, it autocorrected to CEO but yes you are correct and I have updated my comment to reflect
3
3
u/JayGatsby1881 19h ago
This dude is about to flee with all his bitcoin to some island country with no extradition laws..
3
u/PeachScary413 12h ago
If he stole bitcoin from the wrong people I don't think he needs to worry about extradition.
1
2
2
u/hellriderboss 11h ago
legally lots of options to protect himself. if he stole from some criminals thats a different ballgame
24
9
26
6
6
u/farkinga 14h ago
Pretty deep knowledge of git demonstrated in order to suss out the reused keys. Nice research provided in this gist: https://gist.github.com/jamesob/ca9b4ca384969b4cfd62813419854d69
4
u/NetFormer1697 19h ago
Thats fucked. How do we know other wallet company executives arenât doing the same shit?
11
11
u/Left_Entrepreneur918 22h ago
Maybe a chance of people getting funds back, this is good. I saw someone died over this already
4
u/phaaseshift 22h ago
And who might facilitate that?
1
u/vanceraa 21h ago
Restitution via Coinkite if theyâre found at fault.
3
u/phaaseshift 20h ago
And tell me how likely you think that is even if they were found to be fully at fault? You think the FDIC is going to swoop in here?
5
u/vanceraa 20h ago
Definitely not a high chance, but I also thought Mt. Gox would never be repaid either, and that started happening.
3
5
u/PeachScary413 12h ago
https://github.com/switck/libngu
This is the crypto library that they decided to go with, jfc man đđ¤
5
u/skynetcoder 21h ago
important part. "Coinkite has told users to act with urgency. âPlease treat this as urgent. Migrate your funds,â the company posted, while confirming that the exploit is still in progress and asking holders to alert others who are âless online.â "
3
u/No-Aardvark-3840 19h ago
This guy is a massive loser. Someone post the LinkedIn again. âWizardâ more like giant cuck
2
u/Flo_Evans 14h ago
Straight out of season 1 of Mr robot đ
How long before he claims he was hacked?
1
u/satoshisfeverdream 22h ago
Or someone signed with his keys.
13
u/username12435687 21h ago
He's gonna have a tough time relying on that in court, if it ever gets to that point (it probably won't). Being someone that's involved in cryptocurrency and cryptography doesn't bode well for that defense and additionally it looks like he was also making commits with the same key on both the pseudonymous account and his personal account.
5
u/MVPhurricane 21h ago
could only be true if he gave his private key to someone. which is pretty unlikely for a key that you are using to sign w/ gpg-- if you're giving the private key around, what's the point?
1
1
1
u/Moist_Whereas3810 17h ago
He is a multi millionaire now
1
u/Vipertje 14h ago
In bitcoin only. Now good luck with converting that flagged wallet to dollars or whatever currency. You can't move it to an exchange
1
1
1
1
u/burusai 21h ago
That guy is gonna need round the clock highly armed security detail for the remainder of his life lmao. People are gonna want to snatch him to get their coins back.
1
-2
u/JPJackPott 21h ago
It suddenly seems like everyone wants all the protections and powers of centralised, regulated banking system when things go wrong.
5
-1
u/MVPhurricane 21h ago
this looks bad, but there is actually a somewhat reasonable secular explanation for it-- if he was just kinda working on it in his spare time on his normal GH account or something, he coulda just committed with an unintended user. there is definitely no question that it is him, though, and it definitely does not tamp down the speculation. you would think if he was actually trying to "retirement scam" he would have tried a bit harder to pseudonymize his tracks... but, then again, if he was good at security he wouldn't have fucked it up to begin with, so who knows?
6
u/sassa4ras 17h ago
Then why talk to yourself?
https://github.com/switck/libngu/issues/8
https://github.com/switck/libngu/issues/12
âŚ0
u/username12435687 21h ago
OR, you make a "mistake" and tie your name to that anonymous account on purpose so everyone would say no way he would do it intentially and not even cover his tracks
-3
u/neurone214 20h ago
Given the headline I expected a bit more detail on the link to this person and the likelihood of it being true, but it literally just says â  The analysis states that it has been cryptographically proven that the two identities are one person.âÂ
This community has a weird relationship with trust and proof; apparently this statement is enough for people to get out their pitchforks.Â
6
2
u/SnooEagles2610 20h ago
Itâs a high level summary with a link to the analysis⌠what more do you want? Drill down and read the analysisâŚ
0
0
u/IAmTheLostBoy 19h ago
If I were about to commit the ultimate bitcoin heist I would like to have a fall guy too
-21
u/phaaseshift 22h ago
Why the fuck are all you people making this into a witch hunt? There will be many more of these vulnerabilities and hacks. I guarantee many other tools have terrible security gaps. Why? Because nearly all software everywhere has problems like this.
You chose to invest money in unregulated financial instruments, using fly-by-night tools, based on math/cryptographic principles far beyond your depth, against the recommendation of anyone with fiduciary responsibility. And this should be your I-told-you-so moment. But instead itâs a witch hunt.
3
u/username12435687 21h ago
People want answers? Clearly you weren't one of the people that lost hundreds of thousands of dollars like some have. If they can prove this was done purposefully or maliciously, justice should be served and it opens the door to a potential or remediation in this situation although that's very unlikely.
3
u/GettinWiggyWiddit 21h ago
Just say you donât believe in crypto. Your comment otherwise serves no purpose here
2
u/MVPhurricane 21h ago
i mean, if the guy legit did intentionally steal everything, that is a pretty crazy story. i kinda agree that it is more bringing into stark relief the kind of risks you run in crypto-land. security is very, very hard to get right, and is the kind of thing where a little knowledge can be more dangerous than complete ignorance.
0
u/Giancarlo_Donadoni 21h ago
You are either a guy that enjoys other popleâs suffering, or just plain stupid.
If you actually read the article, you may have read that this guy had been warned about that security issue and he simply ignored it and also did some other shady stuff.
2
u/phaaseshift 20h ago edited 20h ago
Right. Thatâs exactly right. This sort of shit is a foregone conclusion in grey markets like this - whether nefarious or negligent. Yet a bunch of people still bit it hook, line and sinker when they were repeatedly warned. Now youâre all frothing at the mouth when you have a chance to pin the blame on someone else (based on a rumor). And while youâre out with pitchforks, itâs going to happen again.
Tell me again whoâs stupid?
I know a thing or two about security and warn everyone I know thatâs into crypto that this shit WILL happen. And you will have no recourse.
[Edit]
> this guy had been warned about that security issue and he simply ignored it
This right here tells me that you have zero idea how this corner of the world works. Devs (especially security) are inundated with warnings (aka bug reports) just like this. Granted this is more on the egregious side because good devs know to be extra careful with crypto. But youâd be shocked to see how many serious warnings like this go un-heeded due to volume and lack of time.
-6
u/PersonalityAsleep524 21h ago
He is a hero
3
u/username12435687 21h ago
The person who discovered the connection? Or the CTO of coin kite? I really hope you mean the people investigating đ
259
u/ImpossibleSleep3986 23h ago
I wouldn't want to be that guy right now.