COLDCARD RNG incident the public record, collected and explained
Informational only, and this site never asks for your seed words. details

Informational only. This is an open source collection of what others have published about the incident, together with an explanation of it. It is not financial, security or legal advice, and not a substitute for professional advice about your own situation. It is not affiliated with, endorsed by, or speaking for Coinkite. Material is attributed and quoted as published; where sources disagree their scenarios are kept separate with their assumptions rather than reconciled into one answer. Everything is meant to be checked against the linked evidence rather than taken on trust. Act on your own judgement about a particular situation. Editorial standards and corrections.

Do not disclose recovery material to a website, form, message or support account. This site never asks for it, and contributions containing recovery words or private keys are not accepted.

r/Bitcoin: claims about the switck identity and COLDCARD code review

reddit-switck-identity-claims

https://www.reddit.com/r/Bitcoin/comments/1vgto2m/the_weirdest_part_of_the_coldcard_mess_was_peter/

Latest reviewed change

source content difference between and

New comment from jarsgars: "Straight to jail".

seen +8 -0 full history below
 edited: false
 body:
 Everyday, there are five to ten new posts with vital fresh information, all adding another layer. I've said this in other posts but we will be talking about this for decades, perhaps even centuries. 
+
+comment: p27w8eh
+parent: t3_1vgto2m
+author: jarsgars
+created_utc: 1786086344

First lines only. The complete diff is in the timeline below.

Organisation
reddit
Evidence role
Community discussion
Published
not established
Source changes
4
Detected differences
4
Unreviewed
0
Copies held
5

Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .

  1. source content difference between and Current source content +8 -0

    New comment from jarsgars: "Straight to jail".

    seen · Captured here 19,281 chars
    What changed from the previous capture 8 lines
     edited: false
     body:
     Everyday, there are five to ten new posts with vital fresh information, all adding another layer. I've said this in other posts but we will be talking about this for decades, perhaps even centuries. 
    +
    +comment: p27w8eh
    +parent: t3_1vgto2m
    +author: jarsgars
    +created_utc: 1786086344
    +edited: false
    +body:
    +Straight to jail
    
    Extracted text as captured
    post: 1vgto2m
    author: inner_engineering08
    created_utc: 1785989265
    title: The weirdest part of the Coldcard mess: was Peter D. Gray talking to himself through “switck”?
    body:
    I’m not going to re-explain the RNG bug. That part has already been documented. What I want to know is who exactly was behind `switck`, and why this identity existed in the first place.
    
    Someone checked the actual Git signatures in the `switck/libngu` repository. They found **58 commits authored as “Switck” signed with Peter D. Gray’s personal GPG key**. The same key also signed commits under Peter’s real name, with both identities being used during overlapping periods. Unless Peter shared or lost control of his private signing key, the obvious conclusion is that GitHub `switck` was Peter Gray operating under another name.
    
    Now look at the social-media side.
    
    In 2019, switck posted: “#defcon seems like a good time to start a new identity. Follow me!”
    
    https://preview.redd.it/w5rmzok8sohh1.png?width=588&format=png&auto=webp&s=ebe00de9eacaac13e2bdb4aea73ec5eb7401d621
    
    That tweet is real and still online.
    
    Later, the account promoted `switck/libngu`, thanked DocHex for a merge and said the library might someday be useful on Coldcard.
    
    So the account that announced it was starting a “new identity” was apparently Peter’s alias, publicly speaking to Peter’s main identity as though they were two different developers. 
    
    https://preview.redd.it/x33a7a85sohh1.png?width=609&format=png&auto=webp&s=461d44b0b6c4ffe05191c03a2d0dde29d9a47159
    
    The same thing appears on GitHub. `doc-hex` opened issues in the `switck/libngu` repository. In one pull request, `doc-hex` added four commits, then `switck` merged them. GitHub lists **no reviews**.
    
    And this wasn’t some unrelated side project. `switck/libngu` became part of Coldcard. The `switck` account introduced a critical piece of the vulnerable RNG path, and `doc-hex` later integrated libNgU into the Coldcard firmware. Coinkite itself confirms that this migration moved wallet-seed generation onto the wrong RNG implementation.
    
    None of this proves Peter intentionally created the vulnerability, knew it could be exploited or had anything to do with the thefts.
    
    But it is still extremely fucking weird.
    
    Why was a security-critical Coldcard library hosted under a pseudonymous personal account instead of Coinkite or Coldcard?
    
    Did Coinkite know that `switck` and `doc-hex` were apparently the same person?
    
    Why create the public appearance of two developers interacting, submitting code and merging each other’s work?
    
    Who independently reviewed the library and the Coldcard integration if the library author and the person integrating it were apparently using the same private signing key?
    
    And why has Coinkite explained the technical bug without addressing who controlled the `switck` identity?

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  2. source content difference between and source content +67 -0

    Several new comments, including nullc saying they had assumed switck was Peter Gray's other account and discussing the missed chance to put the question to Coinkite, plus more tripwire-theory discussion and a white-rabbit-tattoo tweet observation.

    seen · Captured here 19,166 chars
    What changed from the previous capture 67 lines
     edited: false
     body:
     The only question is where he is on the incompetence/malice spectrum. 
    +
    +comment: p23e1a2
    +parent: t3_1vgto2m
    +author: IndependenceTop6501
    +created_utc: 1786035300
    +edited: false
    +body:
    +I've heard from some devs, that things like this aren't unheard of.  Sometimes teams do it to make it look like they are bigger, and therefore less vulnerable.  That's on the repo side, idk how his twitter posts play into it.
    +
    +That said his 2nd twitter post (non-post) is: "Thinking of getting one of these [White rabbit tattoo]... too obvious? " 
    +
    +https://x.com/switck/status/1173275546186334211?s=20
    +
    +It's very sus in light of recent events.
    +
    +Another thing is that the libNgU commit is the only thing he did at all.  He's only got a few other projects on GitHub and he didn't do anything with them.  
    +
    +So basically Switck was created, then got libNgU commited into the Coldcard code, and then disappeared shortly there after. 
    +
    +comment: p23njeg
    +parent: t1_p2131z2
    +author: circuit_breaker
    +created_utc: 1786037614
    +edited: false
    +body:
    +The more I learn, the more questions I have
    +
    +comment: p23qc14
    +parent: t1_p208fiw
    +author: CipherNonce
    +created_utc: 1786038298
    +edited: false
    +body:
    +The tripwire theory makes sense to me and explains why the “bug” has gone unnoticed for years because they need Coldcard users to keep generating bad entropy seeds and accumulate sats.
    +
    +comment: p245efb
    +parent: t1_p20lemc
    +author: nullc
    +created_utc: 1786042051
    +edited: false
    +body:
    +Seems reasonable-- before these intrigue posts I had just assumed switck was another account for Peter Gray, and (checking backscroll) even refereed to his commits as "by peter" in discussions of the initial hack.   I just assumed he used another account for that repo to isolate notices / perhaps decrease kidnapping risks.
    +
    +So the thing that was surprising to me wasn't the commit signing, but the "will you accept our PRs" theatrics.  In any case, at no point has coldcard tried pointing the blame at this repo as distinct from themselves.
    +
    +It's kind of unfortunate that it played out this way:  after realizing that the identity appeared more or less provable it would have been good to put the question to coldcard to see if they'd try to lie about it.  Unfortunately no one did that, and since it's now public they're obviously not going to lie about it.
    +
    +
    +
    +
    +comment: p248ul0
    +parent: t1_p209g88
    +author: nullc
    +created_utc: 1786042930
    +edited: false
    +body:
    +People looked at it, just not very hard.
    +
    +There were many bad smells in coldcard so many people considered it for their own use just ran into one of those and considered no deeper.
    +
    +comment: p26xe6g
    +parent: t1_p201k2o
    +author: dj_destroyer
    +created_utc: 1786071671
    +edited: false
    +body:
    +Everyday, there are five to ten new posts with vital fresh information, all adding another layer. I've said this in other posts but we will be talking about this for decades, perhaps even centuries. 
    
    Extracted text as captured
    post: 1vgto2m
    author: inner_engineering08
    created_utc: 1785989265
    title: The weirdest part of the Coldcard mess: was Peter D. Gray talking to himself through “switck”?
    body:
    I’m not going to re-explain the RNG bug. That part has already been documented. What I want to know is who exactly was behind `switck`, and why this identity existed in the first place.
    
    Someone checked the actual Git signatures in the `switck/libngu` repository. They found **58 commits authored as “Switck” signed with Peter D. Gray’s personal GPG key**. The same key also signed commits under Peter’s real name, with both identities being used during overlapping periods. Unless Peter shared or lost control of his private signing key, the obvious conclusion is that GitHub `switck` was Peter Gray operating under another name.
    
    Now look at the social-media side.
    
    In 2019, switck posted: “#defcon seems like a good time to start a new identity. Follow me!”
    
    https://preview.redd.it/w5rmzok8sohh1.png?width=588&format=png&auto=webp&s=ebe00de9eacaac13e2bdb4aea73ec5eb7401d621
    
    That tweet is real and still online.
    
    Later, the account promoted `switck/libngu`, thanked DocHex for a merge and said the library might someday be useful on Coldcard.
    
    So the account that announced it was starting a “new identity” was apparently Peter’s alias, publicly speaking to Peter’s main identity as though they were two different developers. 
    
    https://preview.redd.it/x33a7a85sohh1.png?width=609&format=png&auto=webp&s=461d44b0b6c4ffe05191c03a2d0dde29d9a47159
    
    The same thing appears on GitHub. `doc-hex` opened issues in the `switck/libngu` repository. In one pull request, `doc-hex` added four commits, then `switck` merged them. GitHub lists **no reviews**.
    
    And this wasn’t some unrelated side project. `switck/libngu` became part of Coldcard. The `switck` account introduced a critical piece of the vulnerable RNG path, and `doc-hex` later integrated libNgU into the Coldcard firmware. Coinkite itself confirms that this migration moved wallet-seed generation onto the wrong RNG implementation.
    
    None of this proves Peter intentionally created the vulnerability, knew it could be exploited or had anything to do with the thefts.
    
    But it is still extremely fucking weird.
    
    Why was a security-critical Coldcard library hosted under a pseudonymous personal account instead of Coinkite or Coldcard?
    
    Did Coinkite know that `switck` and `doc-hex` were apparently the same person?
    
    Why create the public appearance of two developers interacting, submitting code and merging each other’s work?
    
    Who independently reviewed the library and the Coldcard integration if the library author and the person integrating it were apparently using the same private signing key?
    
    And why has Coinkite explained the technical bug without addressing who controlled the `switck` identity?

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  3. source content difference between and source content +26 -2

    The post body was edited to drop the "u/" prefixes before switck and DocHex, and three new comments appeared (Sociapaths remark, Rollo Tomassi, incompetence/malice spectrum).

    seen · Captured here 16,356 chars
    What changed from the previous capture 28 lines
     
     Now look at the social-media side.
     
    -In 2019, u/switck posted: “#defcon seems like a good time to start a new identity. Follow me!”
    +In 2019, switck posted: “#defcon seems like a good time to start a new identity. Follow me!”
     
     https://preview.redd.it/w5rmzok8sohh1.png?width=588&format=png&auto=webp&s=ebe00de9eacaac13e2bdb4aea73ec5eb7401d621
     
     That tweet is real and still online.
     
    -Later, the account promoted `switck/libngu`, thanked u/DocHex for a merge and said the library might someday be useful on Coldcard.
    +Later, the account promoted `switck/libngu`, thanked DocHex for a merge and said the library might someday be useful on Coldcard.
     
     So the account that announced it was starting a “new identity” was apparently Peter’s alias, publicly speaking to Peter’s main identity as though they were two different developers. 
     
     edited: false
     body:
     Coldcard ceo played by a black lesbian. I'd pay to see it. 
    +
    +comment: p2171lr
    +parent: t3_1vgto2m
    +author: Complete-MessUP
    +created_utc: 1786012276
    +edited: false
    +body:
    +Sociapaths has no remorse.
    +
    +comment: p21lml7
    +parent: t1_p201k2o
    +author: SACRED-GEOMETRY
    +created_utc: 1786017880
    +edited: false
    +body:
    +Rollo Tomassi
    +
    +comment: p21smv5
    +parent: t1_p201u2d
    +author: MiceAreTiny
    +created_utc: 1786020128
    +edited: false
    +body:
    +The only question is where he is on the incompetence/malice spectrum. 
    
    Extracted text as captured
    post: 1vgto2m
    author: inner_engineering08
    created_utc: 1785989265
    title: The weirdest part of the Coldcard mess: was Peter D. Gray talking to himself through “switck”?
    body:
    I’m not going to re-explain the RNG bug. That part has already been documented. What I want to know is who exactly was behind `switck`, and why this identity existed in the first place.
    
    Someone checked the actual Git signatures in the `switck/libngu` repository. They found **58 commits authored as “Switck” signed with Peter D. Gray’s personal GPG key**. The same key also signed commits under Peter’s real name, with both identities being used during overlapping periods. Unless Peter shared or lost control of his private signing key, the obvious conclusion is that GitHub `switck` was Peter Gray operating under another name.
    
    Now look at the social-media side.
    
    In 2019, switck posted: “#defcon seems like a good time to start a new identity. Follow me!”
    
    https://preview.redd.it/w5rmzok8sohh1.png?width=588&format=png&auto=webp&s=ebe00de9eacaac13e2bdb4aea73ec5eb7401d621
    
    That tweet is real and still online.
    
    Later, the account promoted `switck/libngu`, thanked DocHex for a merge and said the library might someday be useful on Coldcard.
    
    So the account that announced it was starting a “new identity” was apparently Peter’s alias, publicly speaking to Peter’s main identity as though they were two different developers. 
    
    https://preview.redd.it/x33a7a85sohh1.png?width=609&format=png&auto=webp&s=461d44b0b6c4ffe05191c03a2d0dde29d9a47159
    
    The same thing appears on GitHub. `doc-hex` opened issues in the `switck/libngu` repository. In one pull request, `doc-hex` added four commits, then `switck` merged them. GitHub lists **no reviews**.
    
    And this wasn’t some unrelated side project. `switck/libngu` became part of Coldcard. The `switck` account introduced a critical piece of the vulnerable RNG path, and `doc-hex` later integrated libNgU into the Coldcard firmware. Coinkite itself confirms that this migration moved wallet-seed generation onto the wrong RNG implementation.
    
    None of this proves Peter intentionally created the vulnerability, knew it could be exploited or had anything to do with the thefts.
    
    But it is still extremely fucking weird.
    
    Why was a security-critical Coldcard library hosted under a pseudonymous personal account instead of Coinkite or Coldcard?
    
    Did Coinkite know that `switck` and `doc-hex` were apparently the same person?
    
    Why create the public appearance of two developers interacting, submitting code and merging each other’s work?
    
    Who independently reviewed the library and the Coldcard integration if the library author and the person integrating it were apparently using the same private signing key?
    
    And why has Coinkite explained the technical bug without addressing who controlled the `switck` identity?

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  4. source content difference between and source content +256 -0

    Large batch of new comments, including achow101's detailed git-forensics analysis arguing the libngu commit's author, committer and GPG-signer timestamps suggest Switck and Peter Gray are the same person, plus tripwire and intelligence-agency speculation.

    seen · Captured here 15,937 chars
    What changed from the previous capture 256 lines
     edited: false
     body:
     Yes but reality and a a claim are two different things. Me and you could get together and say you typed this even though it's a reply from my device in my style of writing, unless their is video footage all i see an account logged in under that user id. Not the person who created the account logged in. Code is law but once it hit code all law is gone. 
    +
    +comment: p20668x
    +parent: t3_1vgto2m
    +author: junglehypothesis
    +created_utc: 1785994523
    +edited: false
    +body:
    +Important questions and the fact we must even ask them at all points to culpability, there’s just not reason for anyone to do this. Plus this may go much deeper than the immediate team, I wouldn’t rule out intelligence agency interference, possible goal to track users.
    +
    +comment: p206w6z
    +parent: t1_p204mm5
    +author: jwhendy
    +created_utc: 1785994857
    +edited: false
    +body:
    +I don't think this is analogous. They would have to have shared the same computer with access to the same private key file. It's not about imitating wording style, it's about signing using a digital signature that is, indeed, used to unfakeably say "this is exactly who I am."
    +
    +At the least, if they are not actually the same person, there has been some instance of theft, leak, collusion, and/or deception.
    +
    +It's more like two police records with different names but the same fingerprint on file.
    +
    +comment: p206yme
    +parent: t3_1vgto2m
    +author: circuit_breaker
    +created_utc: 1785994887
    +edited: false
    +body:
    +This is all so crazy
    +
    +comment: p2071c2
    +parent: t1_p201u2d
    +author: circuit_breaker
    +created_utc: 1785994922
    +edited: false
    +body:
    +But why let this bug sit in the open for years? Surely you could have believed someone else would discover it in that time
    +
    +So much about this doesn't add up
    +
    +comment: p208fiw
    +parent: t1_p2071c2
    +author: eckstuhc
    +created_utc: 1785995576
    +edited: false
    +body:
    +The initial hack had batched transactions and was sent in 4-5 continuous blocks, which indicates preparation - as opposed to iterating one by one and slowly plucking seed phrases. 
    +
    +We don’t know how long they were prepared for. The attacker (Peter Gray) could have batched, signed them, and was ready to transmit them at a moments notice - LITERALLY WHAT COLD CARD DOES. 
    +
    +These could have been identified years ago, and ready to “dump all” as soon as the command is sent. The command could be a deadman’s switch (if I don’t check in every week), or it could be a tripwire (if X amount of these wallets start to get swept, someone else has found the bug - dump all that you’ve prepared). 
    +
    +For plausible deniability, I bet it’s a tripwire. We’re going to see that “someone” found the bug just a couple days before, then Peter Gray drained everything he was sitting on - the initial guy will take the fall and be blamed for “not handing over the funds”. 
    +
    +This dude went through the steps of making an alias to plant a bug, he definitely has a “plan” for where to point the finger. 
    +
    +comment: p2097gj
    +parent: t1_p2071c2
    +author: inner_engineering08
    +created_utc: 1785995939
    +edited: false
    +body:
    +The longer it sitss there, the less suspicious it looks and the easier it can be to write off as a massive mistake.That doesn’t prove anything, but waiting years wouldn’t rule anything out either.
    +
    +comment: p209g88
    +parent: t1_p2097gj
    +author: circuit_breaker
    +created_utc: 1785996054
    +edited: false
    +body:
    +I'm sorry but something as basic as this? I've been fucking around with software online since the '90s, I don't believe we can truly audit everything because of the many eyes meaning bugs are shallow but I do honestly expect people to pick up on this kind of fault. It's egregious. 
    +
    +What this means is that literally nobody looked at this. Literally nobody that knew what they were doing. For years. 
    +
    +I wouldn't be able to sleep if I made a mechanism to rob people en masse and left it for the world to see for years. 
    +
    +comment: p20ah3c
    +parent: t3_1vgto2m
    +author: extraepicc
    +created_utc: 1785996529
    +edited: false
    +body:
    +This guy is going to get some love 
    +
    +comment: p20b2ed
    +parent: t1_p209g88
    +author: inner_engineering08
    +created_utc: 1785996801
    +edited: false
    +body:
    +Yeah, that’s the part I find suspicious. The output looked random, the wallets and addresses looked completely normal, and the weakness was buried in the full RNG path. I’m not saying that proves intent, but it’s a very convenient kind of failure.
    +
    +comment: p20bihx
    +parent: t1_p201u2d
    +author: Todo_es
    +created_utc: 1785997006
    +edited: false
    +body:
    +> Peter Gray thought he was smart enough to get away with fraud
    +
    +Theft, you mean theft.
    +
    +comment: p20d99r
    +parent: t1_p203ers
    +author: luenix
    +created_utc: 1785997814
    +edited: false
    +body:
    +There are only a few possible scenarios in which a pk *ever* leaves the host it was generated on.  Seeing as how this wasn't a service account, it takes all of 0 seconds to conclude confidently that for all intents and purposes the two identities should be assumed to share the same host.
    +
    +"Private key means nothing" is a not a serious-enough take to prevent someone from taking measures (legal, surely) against the assumed core identity.
    +
    +  
    +Put another way, if someone reports a hit-and-run and video surveillance happens to cover the encounter well enough for a (plausibly unique) vehicle fingerprint, the owner of the offending vehicle is going to be sought after by law enforcement.
    +
    +comment: p20f6f1
    +parent: t1_p208fiw
    +author: fuckswithboats
    +created_utc: 1785998728
    +edited: false
    +body:
    +I’m just some dude but I like your hypothesis about the tripwire. I wonder if the other older blips we’ve seen of wallets being drained was him testing it out, random collisions (monkeys blah blah Shakespeare), or one-off lucky guesses that weren’t aware of the bug to exploit it further 
    +
    +comment: p20gn1n
    +parent: t1_p209g88
    +author: Ok-Source-4748
    +created_utc: 1785999422
    +edited: false
    +body:
    +It was early tech still he could have been the first vibe one coding Projects with Alexa or something like that 
    +
    +comment: p20j9bh
    +parent: t3_1vgto2m
    +author: terfez
    +created_utc: 1786000681
    +edited: false
    +body:
    +I think it was Interpol
    +
    +comment: p20lemc
    +parent: t3_1vgto2m
    +author: achow101
    +created_utc: 1786001736
    +edited: false
    +body:
    +As someone who has become far too familiar with git's internals that I ever wanted to be, I would not say that it's actually unusual to see a commit signed by someone who did not author it. It's possible to have a workflow where commits are rebased, cherry picked, squashed, etc. where the original author's authorship is preserved, but the maintainer is essentially creating a new commit. If the maintainer has configured their git to sign new commits, then we would see a commit with an Author of one person, and a GPG signature from someone else.
    +
    +We can actually see this behavior in the BIPs repo, for example this commit that has an Author of Jameson Lopp, while it has a Committer of Murch, and a GPG signature from Murch:
    +
    +    commit 86dfa19bef154c88a3fa4b2185400837f2d6cad9
    +    gpg: Signature made Tue 14 Apr 2026 07:38:03 AM PDT
    +    gpg:                using RSA key 35F4ADA623EB9FE3A3BC7EF67BA035CA5B901713
    +    gpg: Good signature from "Murch <[email protected]>" [full]
    +    gpg:                 aka "Mark Erhardt <[email protected]>" [full]
    +    gpg:                 aka "Mark Erhardt <[email protected]>" [full]
    +    gpg:                 aka "Mark Erhardt <[email protected]>" [full]
    +    Author:     Jameson Lopp <[email protected]>
    +    AuthorDate: Tue Apr 14 16:36:41 2026 +0200
    +    Commit:     Murch <[email protected]>
    +    CommitDate: Tue Apr 14 07:37:58 2026 -0700
    +
    +Crucially, commits have metadata about who actually made the commit. We see Author which is different from Commit, and a signature that matches Commit.
    +
    +So what do we see when we look at libngu? Here is a commit from libngu:
    +
    +    commit 5cf9c5efd68b8d27f299ec82687e4fbdb432b4c7
    +    gpg: Signature made Thu 29 Sep 2022 06:30:45 AM PDT
    +    gpg:                using RSA key D9766C79E77B0198D66975BDF0E6CC6AFC16CF7B
    +    gpg: Good signature from "Peter Gray (@qbert) <[email protected]>" [expired]
    +    gpg:                 aka "Peter Gray <[email protected]>" [expired]
    +    gpg: Note: This key has expired!
    +    Primary key fingerprint: A004 C9BC E217 ABE9 341C  D81A A2DC D558 C2BE 5D7C
    +         Subkey fingerprint: D976 6C79 E77B 0198 D669  75BD F0E6 CC6A FC16 CF7B
    +    Author:     Switck <[email protected]>
    +    AuthorDate: Thu Sep 29 09:30:45 2022 -0400
    +    Commit:     Switck <[email protected]>
    +    CommitDate: Thu Sep 29 09:30:45 2022 -0400
    +
    +As in my BIPs example, the Author does not match the GPG signer.
    +
    +**BUT the GPG signer also does not match the Committer!** That is unusual. If we assume that the Committer and GPG Signer are the same person - and in typical git setups they are - then this suggests that Switck and Peter Gray are the same person.
    +
    +Furthermore, we can also look at the timestamps. In my first example from BIPs, the timestamp for AuthorDate is completely different from CommitDate. But the timestamp of GPG signature is within seconds of the CommitDate. This minor discrepancy is easily explained by someone who has password protected their GPG key, or has it on something like a Yubikey. This suggests that the Author and the Committer are actually separate persons, and the GPG signature was produced by the Committer.
    +
    +But if we look at the timestamps in the libngu commit, we see that they are all almost entirely the same. The AuthorDate, CommitDate, and GPG signature timestamp are all the same. This suggests that all 3 timestamps were produced in the same action, which suggests that the Author, Committer, and GPG signer are all the same person.
    +
    +comment: p20nzbn
    +parent: t3_1vgto2m
    +author: Kokolol_0
    +created_utc: 1786003028
    +edited: false
    +body:
    +Can’t wait to watch the Netflix documentary 
    +
    +comment: p20o7is
    +parent: t3_1vgto2m
    +author: PeachScary413
    +created_utc: 1786003146
    +edited: false
    +body:
    +Some people call it weird, some people call it fraud.
    +
    +comment: p20puvr
    +parent: t1_p209g88
    +author: ZedZeroth
    +created_utc: 1786003985
    +edited: false
    +body:
    +Tripwire hypothesis could explain this: https://www.reddit.com/r/Bitcoin/s/VjRF1gGpr4
    +
    +comment: p20ty37
    +parent: t1_p20nzbn
    +author: BigDik6355
    +created_utc: 1786006032
    +edited: false
    +body:
    +Oceans 21: The Bitcoin Heist. Now on Netflix.
    +
    +comment: p20u6z4
    +parent: t1_p20lemc
    +author: BigDik6355
    +created_utc: 1786006159
    +edited: false
    +body:
    +Seems the author had some kind of schizophrenia.
    +
    +comment: p212sf3
    +parent: t1_p208fiw
    +author: read_more_comments
    +created_utc: 1786010372
    +edited: false
    +body:
    +A few years ago he literally talked about retirement exploit and explained what just happened.
    +
    +comment: p2131z2
    +parent: t1_p20lemc
    +author: read_more_comments
    +created_utc: 1786010495
    +edited: false
    +body:
    +What is weird is a hardware wallet including some random guys security implementation for no reason. Then finding out it's the same guy with a fake name. And is a major exploit. why is just this library?
    +
    +comment: p2136j5
    +parent: t1_p20u6z4
    +author: read_more_comments
    +created_utc: 1786010554
    +edited: false
    +body:
    +Retirement exploitphrenia
    +
    +comment: p213ajz
    +parent: t1_p20ty37
    +author: read_more_comments
    +created_utc: 1786010605
    +edited: false
    +body:
    +Coldcard ceo played by a black lesbian. I'd pay to see it. 
    
    Extracted text as captured
    post: 1vgto2m
    author: inner_engineering08
    created_utc: 1785989265
    title: The weirdest part of the Coldcard mess: was Peter D. Gray talking to himself through “switck”?
    body:
    I’m not going to re-explain the RNG bug. That part has already been documented. What I want to know is who exactly was behind `switck`, and why this identity existed in the first place.
    
    Someone checked the actual Git signatures in the `switck/libngu` repository. They found **58 commits authored as “Switck” signed with Peter D. Gray’s personal GPG key**. The same key also signed commits under Peter’s real name, with both identities being used during overlapping periods. Unless Peter shared or lost control of his private signing key, the obvious conclusion is that GitHub `switck` was Peter Gray operating under another name.
    
    Now look at the social-media side.
    
    In 2019, u/switck posted: “#defcon seems like a good time to start a new identity. Follow me!”
    
    https://preview.redd.it/w5rmzok8sohh1.png?width=588&format=png&auto=webp&s=ebe00de9eacaac13e2bdb4aea73ec5eb7401d621
    
    That tweet is real and still online.
    
    Later, the account promoted `switck/libngu`, thanked u/DocHex for a merge and said the library might someday be useful on Coldcard.
    
    So the account that announced it was starting a “new identity” was apparently Peter’s alias, publicly speaking to Peter’s main identity as though they were two different developers. 
    
    https://preview.redd.it/x33a7a85sohh1.png?width=609&format=png&auto=webp&s=461d44b0b6c4ffe05191c03a2d0dde29d9a47159
    
    The same thing appears on GitHub. `doc-hex` opened issues in the `switck/libngu` repository. In one pull request, `doc-hex` added four commits, then `switck` merged them. GitHub lists **no reviews**.
    
    And this wasn’t some unrelated side project. `switck/libngu` became part of Coldcard. The `switck` account introduced a critical piece of the vulnerable RNG path, and `doc-hex` later integrated libNgU into the Coldcard firmware. Coinkite itself confirms that this migration moved wallet-seed generation onto the wrong RNG implementation.
    
    None of this proves Peter intentionally created the vulnerability, knew it could be exploited or had anything to do with the thefts.
    
    But it is still extremely fucking weird.
    
    Why was a security-critical Coldcard library hosted under a pseudonymous personal account instead of Coinkite or Coldcard?
    
    Did Coinkite know that `switck` and `doc-hex` were apparently the same person?
    
    Why create the public appearance of two developers interacting, submitting code and merging each other’s work?
    
    Who independently reviewed the library and the Coldcard integration if the library author and the person integrating it were apparently using the same private signing key?
    
    And why has Coinkite explained the technical bug without addressing who controlled the `switck` identity?

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  5. Earliest copy held
    seen · Captured here 5,058 chars
    Extracted text as captured
    post: 1vgto2m
    author: inner_engineering08
    created_utc: 1785989265
    title: The weirdest part of the Coldcard mess: was Peter D. Gray talking to himself through “switck”?
    body:
    I’m not going to re-explain the RNG bug. That part has already been documented. What I want to know is who exactly was behind `switck`, and why this identity existed in the first place.
    
    Someone checked the actual Git signatures in the `switck/libngu` repository. They found **58 commits authored as “Switck” signed with Peter D. Gray’s personal GPG key**. The same key also signed commits under Peter’s real name, with both identities being used during overlapping periods. Unless Peter shared or lost control of his private signing key, the obvious conclusion is that GitHub `switck` was Peter Gray operating under another name.
    
    Now look at the social-media side.
    
    In 2019, u/switck posted: “#defcon seems like a good time to start a new identity. Follow me!”
    
    https://preview.redd.it/w5rmzok8sohh1.png?width=588&format=png&auto=webp&s=ebe00de9eacaac13e2bdb4aea73ec5eb7401d621
    
    That tweet is real and still online.
    
    Later, the account promoted `switck/libngu`, thanked u/DocHex for a merge and said the library might someday be useful on Coldcard.
    
    So the account that announced it was starting a “new identity” was apparently Peter’s alias, publicly speaking to Peter’s main identity as though they were two different developers. 
    
    https://preview.redd.it/x33a7a85sohh1.png?width=609&format=png&auto=webp&s=461d44b0b6c4ffe05191c03a2d0dde29d9a47159
    
    The same thing appears on GitHub. `doc-hex` opened issues in the `switck/libngu` repository. In one pull request, `doc-hex` added four commits, then `switck` merged them. GitHub lists **no reviews**.
    
    And this wasn’t some unrelated side project. `switck/libngu` became part of Coldcard. The `switck` account introduced a critical piece of the vulnerable RNG path, and `doc-hex` later integrated libNgU into the Coldcard firmware. Coinkite itself confirms that this migration moved wallet-seed generation onto the wrong RNG implementation.
    
    None of this proves Peter intentionally created the vulnerability, knew it could be exploited or had anything to do with the thefts.
    
    But it is still extremely fucking weird.
    
    Why was a security-critical Coldcard library hosted under a pseudonymous personal account instead of Coinkite or Coldcard?
    
    Did Coinkite know that `switck` and `doc-hex` were apparently the same person?
    
    Why create the public appearance of two developers interacting, submitting code and merging each other’s work?
    
    Who independently reviewed the library and the Coldcard integration if the library author and the person integrating it were apparently using the same private signing key?
    
    And why has Coinkite explained the technical bug without addressing who controlled the `switck` identity?

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

How to check this yourself

The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.

Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.