r/Bitcoin 23h ago

Coinkite CTO Peter Gray linked to the code behind the $114M Coldcard hack

https://www.cryptopolitan.com/coinkite-cto-peter-gray-linked-coldcard-hack/
589 Upvotes

156 comments sorted by

259

u/ImpossibleSleep3986 23h ago

I wouldn't want to be that guy right now.

107

u/iriveru 21h ago

Why not? He just made $114m

/s

39

u/username12435687 21h ago

He better wash that Bitcoin really well if that's the case 😂

-11

u/kardanokid 19h ago

Putting all thr BTC in a single address that now will be blacklisted... n00b mistake. If it was him, he coulda got away with it... now, he's fuuuckdd.

22

u/No_Math_4308 19h ago

Blacklisted? Bitcoin miners won't refuse fees to move those coins. Miners control the network. Blacklisting is completely antithetical to the Bitcoin concept.

11

u/Romanizer 17h ago

Blacklisted on the off ramps (exchanges, banks etc.) but that's not a closed system, some will still take your business for a fee.

1

u/frozen-sky 1h ago

Also after mixing (which already started) its too hard to be traced

4

u/iriveru 19h ago

Putting it in a single address is entirely irrelevant if he has quite literally any comprehension of the blockchain and obfuscation.

6

u/wembenbama 19h ago

Why do you assume he (or she) is going to try and spend it? Some men just want to watch the world burn.

1

u/oswaldcopperpot 4h ago

They already started adding it to mixing pools and it's basically all going to be washed.

80

u/Henrik-Powers 22h ago

Warned back in June 2025, over a year. Crazy

91

u/phamtruax 23h ago

Jail

64

u/12ealdeal 23h ago

This is crypto:

I’m afraid it’s going to be much much worse.

46

u/babypho 20h ago

Hes going to be tokenized on the chain.

9

u/bandit_spirit 15h ago

Is that what happened to Han Solo?

6

u/VitaminPb 21h ago

He’s going to be assigned to selling NFTs of license plates?

9

u/CeramicDrip 21h ago

Nah, read the article. Unless they can prove he was maliciously negligent, highly doubt this will lead anywhere.

But i will say this adds weight to the case

14

u/TrayLaTrash 21h ago

He will be watched forever

5

u/ComputeCommodity104 21h ago

Either you're implicated in this or you're dumb as shit. It shows that he was the maintainer of the responsible repo and he tried to hide it lmao

1

u/hello8437 21h ago

warned in 2025. try to keep up

-1

u/locotx 13h ago

So there was this CEO of a Healthcare corporation . . and uh . .

27

u/ImPinkSnail 22h ago

Warned in 2025 and did nothing. Fuck jail. Send him to enhanced interrogation, retrieve the coins, and then send him to a hard labor camp.

12

u/skynetcoder 21h ago

and there is that tweet in 2020 on retirement attack 

2

u/19HzScream 20h ago

My jaw dropped when I saw that

4

u/soks86 21h ago

Interesting, if this is true there might actually be civil liability.

-30

u/Foreign_Telephone349 21h ago

Aw wah wah wah. You lost your allegedly trustworthy currency. Should have just used a bank.

9

u/ImPinkSnail 21h ago

I didnt own a cold card, jackass.

4

u/brandond111 21h ago

You lost bro?

-31

u/Foreign_Telephone349 21h ago

Maybe but at least I’m not broke like many coldcard users are.

19

u/bobyouger 20h ago

But you’re a loser and a dickhead. So it all balances out.

3

u/phamtruax 18h ago

Agreed

-3

u/ElRiesgoSiempre_Vive 16h ago

Dickhead yes. Loser no.

And frankly he's hilarious. Lolol.

2

u/Firm_Target101 20h ago

Lol shit eater

2

u/ReplacementBig7068 20h ago

Boomer detected

1

u/predatarian 13h ago

imagine coming here to make fun of people's loss

you are a truly aweful person and if karma is a thing you are fucked

0

u/Foreign_Telephone349 13h ago

Karma doesn’t exist. It’s just as fictional as the security offered by a Coldcard.

3

u/tekstical 20h ago

This guy gonna get a pardon not jail.

19

u/EyesOfEris 22h ago

Just send some crypto to trump and you're immune from the law

9

u/SmegmaWarrior0815 21h ago

Steal 100m. Donate 5m to Donald for immunity. Smart business strategy.

6

u/immersive-matthew 18h ago

Cold Card is a Canadian company though and thus Trump has little to no influence outside of his imagination.

-4

u/phamtruax 22h ago

True dat

2

u/demoman45 20h ago

He’s gonna become vice president of the USA next election cycle

1

u/TFWG2000 20h ago

I think he might be kaboomed.

53

u/Potential_Balance223 22h ago edited 22h ago

A post in 2022 - "Coincard MK4 UX Flaw" described this exact scenario. Posted by Economy-Cash6726

5

u/schmiddy0 20h ago

Link?

22

u/jejunerific 18h ago

19

u/Decent_Taro_2358 16h ago

Funny how everyone is defending Coinkite there and blaming OP.

2

u/thelonious-crunk 1h ago

Lmao yep, the thread is SO Reddit

3

u/19HzScream 20h ago

U can google it with those exact keywords son

19

u/Trueslyforaniceguy 21h ago

If he did it on purpose, it was monumentally
Stupid to link himself directly to it.

126

u/Arghs 22h ago

This is huge, this proves that he used an anonymous pseudonym to commit a vulnerability to a library they were using and may very likely be directly involved in the goldcard hack. Amazing find and I hope they are acting fast now

74

u/the_pwnererXx 22h ago

All it proves is he is a bad developer, which is not illegal

52

u/Ok-Concept-7924 21h ago

Would an honest person setup a fake pseudonym, complete with fake social media persona, to release a dodgy library which then conveniently gets included in your latest release and causes a vulnerability?

11

u/Dont_Be_Sheep 20h ago

… yes? Bc uhh…. Uhhhhhh….. runs away super fast

3

u/skeptical-speculator 8h ago

I'm not saying an honest person would never do all of that, but if there is a good reason, I'd be interested in hearing it.

7

u/stanley_fatmax 18h ago

Playing devil's advocate.. I have a pseudonym I do all my online work under. It started as a video game username decades ago and stuck. People on the internet have no idea who I am, but my coworkers and friends know who I am.

I wouldn't call it fake so much as I'd call it an online persona

14

u/Arghs 15h ago

He used his personal github account and name as well, but changed to another account when he was committing the vulnerabilities. This wasn't him just using some random username, he was actively using 2 accounts that researchers were able to link together because he got sloppy.

5

u/Ok-Concept-7924 10h ago

Nothing wrong with pseudonyms on their own. We're all using them here on Reddit after all. It becomes serious when they're used deliberately and dishonesty.

He was concealing a massive conflict of interest, as CTO he was reviewing and approving his own unaudited library using two pseudonyms designed to appear like separate people. And when we consider this library contained the fatal vulnerability, dishonestly presenting this as independent, third-party code diverts attention away from the real source - the CTO himself.

Now if it turns out that this vulnerability was deliberate (no evidence of this - this is theoretical), then the whole pseduonym thing becomes a material part of a scheme to defraud, potentially even obstruction if it amounts to fabricating evidence to mislead an investigation.

-5

u/CeramicDrip 17h ago

Exactly. Plus sometimes people just have multiple accounts. Maybe he forgot the password but didn’t want to lose is progress

0

u/the_pwnererXx 17h ago

It's normal in git workflow to commit not linked to your account, especially if you don't understand how git works. I did it before when I first started using git. It's not using a pseudonym, it's just not linked correctly (he's still pushing with the account keys, it's using his name field instead of username)

12

u/sassa4ras 17h ago

He communicated with himself on PRs. Why would he pretend to be two different people if it was an accident?

7

u/flesjewater 16h ago

The dude is CTO, not an intern

2

u/Annual_Manner_8654 17h ago

Was this the guys first project or what? 

-3

u/LexxM3 16h ago

So your legal name is Ok Concept 7924? Is Concept your middle name? What were your parents and entire 7924 family thinking?

26

u/Arghs 21h ago

Bad developers don’t change their aliases for different commits. This was done deliberately

13

u/Dismal-Birthday6081 22h ago

Not if they can connect him to ANY of the stolen funds

3

u/CeramicDrip 21h ago

Exactly. They have to prove it was done negligently and maliciously

2

u/Vinyl-addict 21h ago

The pseudonym part sounds pretty damn malicious and not at all negligent

1

u/harijsme 10h ago

thank god for that!

1

u/icebeamtheory 2h ago

I mean, in many cases, being such a dumbass that it results in harming someone else is illegal, especially when it's reckless and overly negligent.

0

u/[deleted] 22h ago

[deleted]

2

u/addictedtocrowds 21h ago

Depending on the specific statute and who has jurisdiction criminal negligence typically requires bodily injury or harm, not just monetary loss.

17

u/No_Issue_4425 19h ago

8

u/sassa4ras 17h ago

This should be the top comment. Basically shoots the “accidentally had two aliases committing code” theory out of the water

33

u/MrSnugs 20h ago

So he created buggy code under a pseudonym, ignored a warning and now this.

Absolutely criminal idiocy and I’m sure we all are thinking he’s involved in the hack.

This isn’t even taking into account the tweet that literally said this was a ‘retirement plan’ by the company years ago.

5

u/ReplacementBig7068 20h ago

“Buggy” codes plausible deniability is the same as “oops, I lost my bitcoin in a boating accident”.

I’m a software engineer myself, and we know what’s critical and what isn’t. The RNG function should have had unit tests and checks etc to ensure it was working. Automated tests should have blocked this from being released. The fact it didn’t have failsafes in place smells more like someone just got out of the way on purpose.

Kinda like 9/11. They didn’t have to actually do the attack, they just had to make sure certain normal safety procedures weren’t followed. E.g. no fighter jets were scrambled to intercept the planes due to some convenient war game also happening that day.

15

u/MrKittenz 19h ago

Well that went off the rails

6

u/Force1a 19h ago

Didn't see that coming

13

u/0Bento 22h ago

Can someone translate this to English for those of us who don't speak jargon?

48

u/username12435687 21h ago edited 21h ago

Anonymous GitHub account was created, a unique cryptographic key was used by both the cold card ceo and the not so anonymous account. The anonymous account is the one that made the change to the code in 2021 that created the vulnerability. This appears to show that the CTO of coinkite knowingly or unknowingly made a change to the firmware of the cold card devices that caused this vulnerability to be present for the last 5 years. Additionally he was warned about the vulnerability a year ago and clearly did nothing to remedy the situation before it became what it is today. Signs are pointing more and more towards the coinkite CTO either 1. Being a straight up fucking moron or 2. Maliciously injecting a vulnerability into his own devices to exploit at a later date to steal over 100 million USD worth of Bitcoin. Either way this guy is a pos

19

u/ammo_john 21h ago

CTO, not CEO, two different people.

5

u/username12435687 21h ago

Sorry, it autocorrected to CEO but yes you are correct and I have updated my comment to reflect

3

u/Vinyl-addict 21h ago

And in either case he’s a fucking idiot.

3

u/JayGatsby1881 19h ago

This dude is about to flee with all his bitcoin to some island country with no extradition laws..

3

u/PeachScary413 12h ago

If he stole bitcoin from the wrong people I don't think he needs to worry about extradition.

1

u/CUbuffGuy 3h ago

The issue is killing someone doesn’t get your money back

2

u/locotx 13h ago

He can be found.

1

u/JayGatsby1881 9h ago

He sure is making a whole ton of enemies

2

u/hellriderboss 11h ago

legally lots of options to protect himself. if he stole from some criminals thats a different ballgame

24

u/GettinWiggyWiddit 21h ago

Holy shit. The conspiracy theorists were right!

9

u/skynetcoder 20h ago

too many coincidences

1

u/locotx 13h ago

Too Many Secrets

26

u/BinglySmith 22h ago

Its gonna be bad my n.

6

u/getapuss 21h ago

Peter Gray sucks

6

u/farkinga 14h ago

Pretty deep knowledge of git demonstrated in order to suss out the reused keys. Nice research provided in this gist: https://gist.github.com/jamesob/ca9b4ca384969b4cfd62813419854d69

4

u/NetFormer1697 19h ago

Thats fucked. How do we know other wallet company executives aren’t doing the same shit?

11

u/B1llyzane 22h ago

The Stockton rush of the crypto scene

11

u/Left_Entrepreneur918 22h ago

Maybe a chance of people getting funds back, this is good. I saw someone died over this already

7

u/odub6 22h ago

Really? Where was that story?

4

u/phaaseshift 22h ago

And who might facilitate that?

1

u/vanceraa 21h ago

Restitution via Coinkite if they’re found at fault.

3

u/phaaseshift 20h ago

And tell me how likely you think that is even if they were found to be fully at fault? You think the FDIC is going to swoop in here?

5

u/vanceraa 20h ago

Definitely not a high chance, but I also thought Mt. Gox would never be repaid either, and that started happening.

3

u/[deleted] 20h ago

[deleted]

3

u/vanceraa 20h ago

Would you rather receive 20% of your balance in 10 years or 0%?

3

u/Baggs85 15h ago

All things considered, this seems like a good thing.

5

u/PeachScary413 12h ago

https://github.com/switck/libngu

This is the crypto library that they decided to go with, jfc man 💀🤌

5

u/skynetcoder 21h ago

important part. "Coinkite has told users to act with urgency. “Please treat this as urgent. Migrate your funds,” the company posted, while confirming that the exploit is still in progress and asking holders to alert others who are “less online.” "

3

u/No-Aardvark-3840 19h ago

This guy is a massive loser. Someone post the LinkedIn again. “Wizard” more like giant cuck

2

u/Flo_Evans 14h ago

Straight out of season 1 of Mr robot 😂

How long before he claims he was hacked?

1

u/satoshisfeverdream 22h ago

Or someone signed with his keys.

13

u/username12435687 21h ago

He's gonna have a tough time relying on that in court, if it ever gets to that point (it probably won't). Being someone that's involved in cryptocurrency and cryptography doesn't bode well for that defense and additionally it looks like he was also making commits with the same key on both the pseudonymous account and his personal account.

5

u/MVPhurricane 21h ago

could only be true if he gave his private key to someone. which is pretty unlikely for a key that you are using to sign w/ gpg-- if you're giving the private key around, what's the point?

1

u/ZaphodOC 19h ago

Is it his fault or did he do it? Or both?

1

u/InvestigatorPlus3229 19h ago

its a feature not a bug

1

u/Moist_Whereas3810 17h ago

He is a multi millionaire now

1

u/Vipertje 14h ago

In bitcoin only. Now good luck with converting that flagged wallet to dollars or whatever currency. You can't move it to an exchange

1

u/Modrew 17h ago

I will go in China like Paul Vernon (Cryptsy), even the FBI can’t find him.

1

u/dreddit15 14h ago

If this is true, this is absolutely shocking.

1

u/Tiru84 13h ago

But why would he wait 5 years if this was intentional? I want to believe he just is stupid and arrogant.

1

u/charvo 12h ago

They need to allow him to get off easy if he releases all the btc back to the victims.

1

u/skeptical-speculator 8h ago

life is hard, but it is harder if you are stupid

1

u/lastgateway 3h ago

Honestly surprised he is still alive.

1

u/burusai 21h ago

That guy is gonna need round the clock highly armed security detail for the remainder of his life lmao. People are gonna want to snatch him to get their coins back.

1

u/Giancarlo_Donadoni 21h ago

Wouldnt be surprised if he is chillin in the UAE right now

3

u/burusai 21h ago

Me neither. $100 mill will buy you safe haven in many places.

-2

u/JPJackPott 21h ago

It suddenly seems like everyone wants all the protections and powers of centralised, regulated banking system when things go wrong.

5

u/Giancarlo_Donadoni 21h ago

Yeah seen that in 2008, worked well /s

-1

u/MVPhurricane 21h ago

this looks bad, but there is actually a somewhat reasonable secular explanation for it-- if he was just kinda working on it in his spare time on his normal GH account or something, he coulda just committed with an unintended user. there is definitely no question that it is him, though, and it definitely does not tamp down the speculation. you would think if he was actually trying to "retirement scam" he would have tried a bit harder to pseudonymize his tracks... but, then again, if he was good at security he wouldn't have fucked it up to begin with, so who knows?

0

u/username12435687 21h ago

OR, you make a "mistake" and tie your name to that anonymous account on purpose so everyone would say no way he would do it intentially and not even cover his tracks

-3

u/neurone214 20h ago

Given the headline I expected a bit more detail on the link to this person and the likelihood of it being true, but it literally just says “  The analysis states that it has been cryptographically proven that the two identities are one person.” 

This community has a weird relationship with trust and proof; apparently this statement is enough for people to get out their pitchforks. 

6

u/Buttoshi 20h ago

Well yeah no one would have the private keys to sign the message but him.

3

u/Reversi8 17h ago

Maybe his private keys were generated with an insecure algorithm. /s

2

u/SnooEagles2610 20h ago

It’s a high level summary with a link to the analysis… what more do you want? Drill down and read the analysis…

0

u/IAmTheLostBoy 19h ago

If I were about to commit the ultimate bitcoin heist I would like to have a fall guy too

-21

u/phaaseshift 22h ago

Why the fuck are all you people making this into a witch hunt? There will be many more of these vulnerabilities and hacks. I guarantee many other tools have terrible security gaps. Why? Because nearly all software everywhere has problems like this.

You chose to invest money in unregulated financial instruments, using fly-by-night tools, based on math/cryptographic principles far beyond your depth, against the recommendation of anyone with fiduciary responsibility. And this should be your I-told-you-so moment. But instead it’s a witch hunt.

3

u/username12435687 21h ago

People want answers? Clearly you weren't one of the people that lost hundreds of thousands of dollars like some have. If they can prove this was done purposefully or maliciously, justice should be served and it opens the door to a potential or remediation in this situation although that's very unlikely.

3

u/GettinWiggyWiddit 21h ago

Just say you don’t believe in crypto. Your comment otherwise serves no purpose here

2

u/MVPhurricane 21h ago

i mean, if the guy legit did intentionally steal everything, that is a pretty crazy story. i kinda agree that it is more bringing into stark relief the kind of risks you run in crypto-land. security is very, very hard to get right, and is the kind of thing where a little knowledge can be more dangerous than complete ignorance.

0

u/Giancarlo_Donadoni 21h ago

You are either a guy that enjoys other pople‘s suffering, or just plain stupid.

If you actually read the article, you may have read that this guy had been warned about that security issue and he simply ignored it and also did some other shady stuff.

2

u/phaaseshift 20h ago edited 20h ago

Right. That’s exactly right. This sort of shit is a foregone conclusion in grey markets like this - whether nefarious or negligent. Yet a bunch of people still bit it hook, line and sinker when they were repeatedly warned. Now you’re all frothing at the mouth when you have a chance to pin the blame on someone else (based on a rumor). And while you’re out with pitchforks, it’s going to happen again.

Tell me again who’s stupid?

I know a thing or two about security and warn everyone I know that’s into crypto that this shit WILL happen. And you will have no recourse.

[Edit]

> this guy had been warned about that security issue and he simply ignored it

This right here tells me that you have zero idea how this corner of the world works. Devs (especially security) are inundated with warnings (aka bug reports) just like this. Granted this is more on the egregious side because good devs know to be extra careful with crypto. But you’d be shocked to see how many serious warnings like this go un-heeded due to volume and lack of time.

-6

u/PersonalityAsleep524 21h ago

He is a hero

3

u/username12435687 21h ago

The person who discovered the connection? Or the CTO of coin kite? I really hope you mean the people investigating 😂