Researchers have pinned the code behind a $114 million Coldcard wallet breach to Peter Gray, Coinkite's co-founder and CTO. A Bitcoin developer warned Gray about the faulty randomness bug back in May 2025. He didn't act.

The exploit has drained over 5,200 addresses across four waves since July 30, and Coinkite confirmed the hack is still active. Developer James O'Beirne published a cryptographic breakdown on August 4 showing how a pseudonymous GitHub account called Switch, which published the buggy library libngu, actually belongs to Gray. The proof sits in GPG commit signatures. Fifty-eight commits authored as "Switch" carry valid signatures from Gray's personal key, the same one he uses to sign work under his real name in the same repository.

The faulty library ended up as a dependency in Coldcard's production firmware. Security firm Wizardsardine identified it as one of three repositories involved in the vulnerability. O'Beirne's May 2025 warning apparently went nowhere. The exploit has now cost users close to $120 million, making it one of the largest losses in hardware wallet history.

This article covers factual reporting on a security incident and does not constitute financial advice. Always verify wallet security updates and keep software current.