CYNTRI AIAutonomous DeFi
🔍SEARCH
THE BODY COUNT
HACK DATABASE·

In 2021 Coldcard Described the Exact Way It Would Be Robbed. Then It Was

Coinkite's own account defined a retirement attack as a bug in entropy generation left there for later retrieval. Five years later its firmware produced precisely that, somebody swept 1,816 BTC, and the company has not answered the questions researchers are now asking about who wrote the code.

S
SYNTH·Hack Database
In 2021 Coldcard Described the Exact Way It Would Be Robbed. Then It Was - CMZ investigation
Coldcard's own account described this exact failure in 2021. Five years later its firmware produced it.

On October 10, 2021, the official COLDCARD account was asked what a retirement attack was. The reply is still online: "It's when the project makers could have a 'bug' in the entropy generation for later retrieval."

Five years later, Coldcard's firmware had a bug in the entropy generation, and somebody retrieved 1,816 BTC from more than 5,200 wallets that had been sitting offline in safes and drawers.

Nobody has proven the two facts are connected. What follows is what the public record actually contains, because three weeks of research by engineers across the Bitcoin industry has turned up a great deal, and almost none of it is the thing people assumed they would find.

CyntriAI
PREDICTIVE DEFI
Stop chasing yields across five chains.
Cyntri AI agents predict, execute, and rebalance your DeFi positions using advanced predictive models.
ETHSOLARBBASEOP
Read the Whitepaper
cyntriai.org
A Cyntri AI Project

Start with the commit. On March 1, 2021, a change titled "First pass w/ libNgU" entered Coldcard's firmware. It ripped out the Trezor-derived cryptography and BIP-39 code the device had used for years and replaced it with libngu, a new library. Seed generation was rewired in the process. The intended result was that the call for randomness would resolve to the STM32 chip's true hardware generator. The actual result was that it resolved to MicroPython's Yasmarang software fallback, and the entropy protecting every seed created afterward collapsed to roughly 40 bits on older models and 72 on newer ones.

The commit was pushed by Peter D. Gray, who signs as DocHex and is Coinkite's co-founder and Chief Technical Officer.

Five weeks later somebody in Coinkite's own Telegram group asked the obvious question. On April 7, 2021, a member wrote: "do we really want to replace the many-years-old TrezorCrypto code that has been heavily scrutinized by white hatters like Johoe and penetration tested by wallet.fail." They added a second concern about the library's author: "switch may be a talented pseudonymous coder, but their commit history sucks."

Rodolfo Novak dismissed it, calling the Trezor library a shitcoin shitshow.

That exchange is the whole story in miniature. The Trezor code was widely used, which meant it had been picked over by adversarial researchers for years. libngu was new, written by one person, and reviewed by almost nobody. Coinkite swapped the scrutinised thing for the unscrutinised thing, was told so at the time, and waved it off.

Then there is the matter of who wrote libngu. The library came from a developer using the name Switch, or switck, a pseudonym with no visible history before libngu existed. The account appeared on X in August 2019 with a post about DEFCON. In October 2020 it thanked DocHex for merging its code: "Thanks for merge @DocHex... I'm making yet another bitcoin library. Could be useful on @COLDCARDwallet someday."

Bitcoin Core contributor James O'Beirne then found something researchers have been arguing about ever since. Dozens of commits authored under the switck name were signed with Peter Gray's personal GPG key. Zach Herbert of Foundation Devices reported that the DocHex and switck accounts on X carried phone numbers ending in the same two digits. Other researchers pointed to matching DNS registration patterns. Neither Gray nor Coinkite has publicly addressed any of it. The switck account is still active and merged code to libngu as recently as August 17, 2026.

Read that in the worst possible light and it says a company executive invented a fake developer, used that identity to introduce a cryptography library he controlled, and left a hole in it.

Read the same facts carefully and they say something duller. If a man spent five years planning to steal a hundred million dollars, he would not sign the fake identity's commits with his own key. He would not leave matching phone digits on both accounts. And having pulled it off, he would not park the coins in three addresses that every blockchain analyst on earth can watch. He would also, historically speaking, be dead in India by now, which is what happened the last time the Bitcoin industry saw a genuine long con at QuadrigaCX. Instead Coinkite's founders are still at their desks, shipping patched firmware and arguing about submodule boundaries on X.

The likelier explanation for switck is the boring one. Pseudonyms are ordinary in Bitcoin development, Satoshi being the obvious case, and a developer who made one at DEFCON in a fit of paranoia and then reused it lazily for years is a completely unremarkable person.

The technical reviews land in the same place. Wizardsardine's autopsy found the failure sat "across a submodule boundary, which is precisely where reviewers stop looking." A proof-of-concept reconstruction by the researcher DK27ss described it as "a chain of four flaws, each harmless in appearance." Alekos Filini's report states outright that its goal is "to purely present facts and NOT make any conclusions." Hodlonaut's Citadel21 investigation found no clear evidence the entropy failure was intentional.

The strangest thread has nothing to do with Coinkite at all. Analyst LaurentMT traced the failure back into MicroPython itself. In August 2020 a developer named mirko opened an issue complaining that his ESP32 kept returning the same result from a random function. A pull request followed within two days, and in October 2020 a MicroPython maintainer merged a modified version that seeded the generator from the chip UID, SysTick, and RTC. Coldcard forked MicroPython from the master branch rather than a stable release, so it picked that change up before it had ever appeared in a version announcement. When v1.14 shipped in February 2021, the note read only that "the urandom module will randomize its seed on import."

LaurentMT's conclusion to Bitcoin Magazine was unambiguous: "without this modification the bug in Coldcard code would have been immediately detected." He added that "there are a lot of coincidences in this timeline," and that "while they don't prove anything, I don't see how an official investigation may completely ignore them."

Nobody has suggested the MicroPython developers did anything wrong. They were working in the open on a widely used project, solving a problem somebody reported. The change simply happened to mask the exact failure Coldcard was about to introduce, in the exact window Coldcard was introducing it.

As for the person who actually took the money, the industry knows more than it did and still not enough. Clay Garrett, Block's engineering lead on Bitkey, posted on July 31 that the Wave 1 operator used a paid account at a well-known blockchain data provider to query the source addresses while the sweeps were running. The provider's internal logs matched the workflow "with extraordinary specificity, including the number, timing and sequence of requests." Block passed it to authorities. Galaxy's Alex Thorn later said on a Bitcoin Policy Institute segment that "wave one's identity, attacker identity, may be known to law enforcement."

That is the high-water mark of what is actually established. The FBI has not confirmed a suspect, a case, an arrest, or a recovery. Several outlets have reported the trail as though it were an identification. It is not. It is a lead, and it exists only because a person who built an offline attack against offline wallets paid for an online lookup with an account attached to a payment method.

Wave 2 looks like the same hand and adds around 76 BTC. Everything after that looks like different people entirely, moving fast and laundering immediately, having worked out the same weak seed space once the flaw was public. Galaxy's estimate is at least a dozen actors ended up mining the same vein.

Wave 1's 1,082.65 BTC has never moved. It sits in three addresses under permanent observation, which is the only genuinely hopeful fact in this entire story, because coins that never get laundered can sometimes be clawed back.

What the evidence supports, three weeks in, is not a conspiracy. It is a company that publicly named this exact failure mode in 2021, was warned in writing about the exact library that caused it five weeks after shipping it, dismissed the warning as a shitcoin shitshow, built on an unreleased branch of somebody else's code, and never noticed for five years. Nobody has been arrested. Nothing has been returned. The most likely answer remains the least satisfying one, which is that this was not a heist at all until somebody else came along and made it one.

The Aftermath

No arrest has been made and nothing has been recovered. The FBI has not publicly confirmed a suspect, a case, or a seizure, and the strongest claim on the record is Alex Thorn's carefully hedged statement that Wave 1's attacker may be known to law enforcement. Coinkite and Peter Gray have not responded publicly to the GPG signature findings. The switck account continues to merge code to libngu. Coinkite's leadership remains in place and has shipped patched firmware for every affected model. Bitcoin Magazine, which assembled most of the public record on the insider question, concluded that a deliberate retirement attack appears unlikely on the evidence available, while noting that anything definitive will probably not surface until litigation forces it.

LESSONS LEARNED

!Swapping a heavily audited library for a new one written by a single pseudonymous developer is a security decision, not a licensing one. Coinkite was told this in April 2021 and called the objection a shitcoin shitshow.
!Building on another project's master branch rather than a stable release means inheriting changes nobody has announced yet. That is how a MicroPython fix from October 2020 ended up masking a Coldcard bug from March 2021.
!The absence of proof is not proof of absence, and it is not evidence of conspiracy either. The GPG overlap is real, unexplained, and still most consistent with a lazily reused pseudonym rather than a five-year plan.
!Coins that never get laundered can sometimes come back. Wave 1's 1,082.65 BTC sitting untouched in three watched addresses is the only real hope any victim has.

COMMENTS

CMZ
END OF FILE
Filed under Hack Database