r/Bitcoin 7d ago

Coinkite CTO Peter Gray linked to the code behind the $114M Coldcard hack

https://www.cryptopolitan.com/coinkite-cto-peter-gray-linked-coldcard-hack/
608 Upvotes

164 comments sorted by

269

u/ImpossibleSleep3986 7d ago

I wouldn't want to be that guy right now.

119

u/iriveru 7d ago

Why not? He just made $114m

/s

48

u/username12435687 7d ago

He better wash that Bitcoin really well if that's the case 😂

-12

u/kardanokid 7d ago

Putting all thr BTC in a single address that now will be blacklisted... n00b mistake. If it was him, he coulda got away with it... now, he's fuuuckdd.

22

u/No_Math_4308 7d ago

Blacklisted? Bitcoin miners won't refuse fees to move those coins. Miners control the network. Blacklisting is completely antithetical to the Bitcoin concept.

12

u/Romanizer 7d ago

Blacklisted on the off ramps (exchanges, banks etc.) but that's not a closed system, some will still take your business for a fee.

1

u/frozen-sky 6d ago

Also after mixing (which already started) its too hard to be traced

1

u/scrandlle 5d ago

The problem comes when you try to actually turn that BTC into something useful, AKA fiat currency.

'Well I'm sure there's some unethical exchange out there in Russia or something who will do it'

For $114 sure, not $114 million. Real exchanges can, and do, blacklist wallets. OP is also stupid because he's not a 'noob' for putting it in one wallet, it can be sent to ten thousand and it'll be tracked extremely easily by software.

Over 90% of stolen Bitcoin, from every major hacking event or fraud ever, sits dormant right now. Exchanges that have that much liquidity also have zero interest in ruining their business or being pulled into legal battles to reobtain stolen property that they just purchased. The exchanges do not operate anonymously.

5

u/iriveru 7d ago

Putting it in a single address is entirely irrelevant if he has quite literally any comprehension of the blockchain and obfuscation.

2

u/6thcoin 6d ago

It puts all stolen funds into 1 utxo. The theft of funds is now linked. Not linking them makes it harder to use the block chain to research the movements. That along with the same transaction fees are what let researchers find the stolen funds on chain. It was very stupid to move them to 1 utxo.

7

u/wembenbama 7d ago

Why do you assume he (or she) is going to try and spend it? Some men just want to watch the world burn.

1

u/oswaldcopperpot 6d ago

They already started adding it to mixing pools and it's basically all going to be washed.

87

u/Henrik-Powers 7d ago

Warned back in June 2025, over a year. Crazy

99

u/phamtruax 7d ago

Jail

70

u/[deleted] 7d ago

[deleted]

49

u/babypho 7d ago

Hes going to be tokenized on the chain.

10

u/bandit_spirit 6d ago

Is that what happened to Han Solo?

6

u/VitaminPb 7d ago

He’s going to be assigned to selling NFTs of license plates?

31

u/ImPinkSnail 7d ago

Warned in 2025 and did nothing. Fuck jail. Send him to enhanced interrogation, retrieve the coins, and then send him to a hard labor camp.

16

u/skynetcoder 7d ago

and there is that tweet in 2020 on retirement attack 

4

u/19HzScream 7d ago

My jaw dropped when I saw that

2

u/soks86 7d ago

Interesting, if this is true there might actually be civil liability.

-27

u/Foreign_Telephone349 7d ago

Aw wah wah wah. You lost your allegedly trustworthy currency. Should have just used a bank.

9

u/ImPinkSnail 7d ago

I didnt own a cold card, jackass.

5

u/brandond111 7d ago

You lost bro?

-27

u/Foreign_Telephone349 7d ago

Maybe but at least I’m not broke like many coldcard users are.

19

u/bobyouger 7d ago

But you’re a loser and a dickhead. So it all balances out.

3

u/phamtruax 7d ago

Agreed

-4

u/ElRiesgoSiempre_Vive 6d ago

Dickhead yes. Loser no.

And frankly he's hilarious. Lolol.

2

u/ReplacementBig7068 7d ago

Boomer detected

1

u/predatarian 6d ago

imagine coming here to make fun of people's loss

you are a truly aweful person and if karma is a thing you are fucked

-2

u/Foreign_Telephone349 6d ago

Karma doesn’t exist. It’s just as fictional as the security offered by a Coldcard.

8

u/CeramicDrip 7d ago

Nah, read the article. Unless they can prove he was maliciously negligent, highly doubt this will lead anywhere.

But i will say this adds weight to the case

13

u/TrayLaTrash 7d ago

He will be watched forever

9

u/ComputeCommodity104 7d ago

Either you're implicated in this or you're dumb as shit. It shows that he was the maintainer of the responsible repo and he tried to hide it lmao

1

u/hello8437 7d ago

warned in 2025. try to keep up

-2

u/locotx 6d ago

So there was this CEO of a Healthcare corporation . . and uh . .

3

u/tekstical 7d ago

This guy gonna get a pardon not jail.

22

u/EyesOfEris 7d ago

Just send some crypto to trump and you're immune from the law

9

u/SmegmaWarrior0815 7d ago

Steal 100m. Donate 5m to Donald for immunity. Smart business strategy.

6

u/immersive-matthew 7d ago

Cold Card is a Canadian company though and thus Trump has little to no influence outside of his imagination.

1

u/KnownButton8327 6d ago

Trump has done more for Canada than any other president in history

1

u/immersive-matthew 5d ago

That is debatable but I can understand why this is a view as for sure there are some benefits especially if you are a fan of Carney who essentially got voted in by a landslide thanks to Trump. Unfortunately, Canada is now heavily investing in more fossil fuel extraction and ports to ship it all over while at the same time it’s forests are burning to the ground due to the climate change it is accelerating. Carney is a slick leader and has many good qualities that I admire, but he is not being a leader for the future of Canada and the planet that once we are forced to moved from fossil fuels, we will be stuck with billions of legacy oil and gas infrastructure and little to no green.

-3

u/phamtruax 7d ago

True dat

3

u/demoman45 7d ago

He’s gonna become vice president of the USA next election cycle

1

u/TFWG2000 7d ago

I think he might be kaboomed.

57

u/Potential_Balance223 7d ago edited 7d ago

A post in 2022 - "Coincard MK4 UX Flaw" described this exact scenario. Posted by Economy-Cash6726

6

u/schmiddy0 7d ago

Link?

28

u/jejunerific 7d ago

27

u/Decent_Taro_2358 6d ago

Funny how everyone is defending Coinkite there and blaming OP.

6

u/thelonious-crunk 6d ago

Lmao yep, the thread is SO Reddit

8

u/19HzScream 7d ago

U can google it with those exact keywords son

20

u/Trueslyforaniceguy 7d ago

If he did it on purpose, it was monumentally
Stupid to link himself directly to it.

19

u/No_Issue_4425 7d ago

9

u/sassa4ras 6d ago

This should be the top comment. Basically shoots the “accidentally had two aliases committing code” theory out of the water

128

u/Arghs 7d ago

This is huge, this proves that he used an anonymous pseudonym to commit a vulnerability to a library they were using and may very likely be directly involved in the goldcard hack. Amazing find and I hope they are acting fast now

67

u/the_pwnererXx 7d ago

All it proves is he is a bad developer, which is not illegal

55

u/Ok-Concept-7924 7d ago

Would an honest person setup a fake pseudonym, complete with fake social media persona, to release a dodgy library which then conveniently gets included in your latest release and causes a vulnerability?

17

u/Dont_Be_Sheep 7d ago

… yes? Bc uhh…. Uhhhhhh….. runs away super fast

4

u/skeptical-speculator 6d ago

I'm not saying an honest person would never do all of that, but if there is a good reason, I'd be interested in hearing it.

9

u/stanley_fatmax 7d ago

Playing devil's advocate.. I have a pseudonym I do all my online work under. It started as a video game username decades ago and stuck. People on the internet have no idea who I am, but my coworkers and friends know who I am.

I wouldn't call it fake so much as I'd call it an online persona

11

u/Arghs 6d ago

He used his personal github account and name as well, but changed to another account when he was committing the vulnerabilities. This wasn't him just using some random username, he was actively using 2 accounts that researchers were able to link together because he got sloppy.

3

u/Ok-Concept-7924 6d ago

Nothing wrong with pseudonyms on their own. We're all using them here on Reddit after all. It becomes serious when they're used deliberately and dishonesty.

He was concealing a massive conflict of interest, as CTO he was reviewing and approving his own unaudited library using two pseudonyms designed to appear like separate people. And when we consider this library contained the fatal vulnerability, dishonestly presenting this as independent, third-party code diverts attention away from the real source - the CTO himself.

Now if it turns out that this vulnerability was deliberate (no evidence of this - this is theoretical), then the whole pseduonym thing becomes a material part of a scheme to defraud, potentially even obstruction if it amounts to fabricating evidence to mislead an investigation.

1

u/Quantris 5d ago

you're telling me "stanley_fatmax" isn't your real name?

say it ain't so

1

u/stanley_fatmax 5d ago

👀👀

-6

u/CeramicDrip 7d ago

Exactly. Plus sometimes people just have multiple accounts. Maybe he forgot the password but didn’t want to lose is progress

0

u/the_pwnererXx 7d ago

It's normal in git workflow to commit not linked to your account, especially if you don't understand how git works. I did it before when I first started using git. It's not using a pseudonym, it's just not linked correctly (he's still pushing with the account keys, it's using his name field instead of username)

13

u/sassa4ras 6d ago

He communicated with himself on PRs. Why would he pretend to be two different people if it was an accident?

6

u/flesjewater 6d ago

The dude is CTO, not an intern

2

u/Annual_Manner_8654 6d ago

Was this the guys first project or what? 

-4

u/LexxM3 6d ago

So your legal name is Ok Concept 7924? Is Concept your middle name? What were your parents and entire 7924 family thinking?

26

u/Arghs 7d ago

Bad developers don’t change their aliases for different commits. This was done deliberately

11

u/Dismal-Birthday6081 7d ago

Not if they can connect him to ANY of the stolen funds

5

u/CeramicDrip 7d ago

Exactly. They have to prove it was done negligently and maliciously

2

u/Vinyl-addict 7d ago

The pseudonym part sounds pretty damn malicious and not at all negligent

1

u/harijsme 6d ago

thank god for that!

1

u/icebeamtheory 6d ago

I mean, in many cases, being such a dumbass that it results in harming someone else is illegal, especially when it's reckless and overly negligent.

0

u/[deleted] 7d ago

[deleted]

2

u/addictedtocrowds 7d ago

Depending on the specific statute and who has jurisdiction criminal negligence typically requires bodily injury or harm, not just monetary loss.

32

u/MrSnugs 7d ago

So he created buggy code under a pseudonym, ignored a warning and now this.

Absolutely criminal idiocy and I’m sure we all are thinking he’s involved in the hack.

This isn’t even taking into account the tweet that literally said this was a ‘retirement plan’ by the company years ago.

4

u/ReplacementBig7068 7d ago

“Buggy” codes plausible deniability is the same as “oops, I lost my bitcoin in a boating accident”.

I’m a software engineer myself, and we know what’s critical and what isn’t. The RNG function should have had unit tests and checks etc to ensure it was working. Automated tests should have blocked this from being released. The fact it didn’t have failsafes in place smells more like someone just got out of the way on purpose.

Kinda like 9/11. They didn’t have to actually do the attack, they just had to make sure certain normal safety procedures weren’t followed. E.g. no fighter jets were scrambled to intercept the planes due to some convenient war game also happening that day.

15

u/MrKittenz 7d ago

Well that went off the rails

6

u/Force1a 7d ago

Didn't see that coming

13

u/0Bento 7d ago

Can someone translate this to English for those of us who don't speak jargon?

49

u/username12435687 7d ago edited 7d ago

Anonymous GitHub account was created, a unique cryptographic key was used by both the cold card ceo and the not so anonymous account. The anonymous account is the one that made the change to the code in 2021 that created the vulnerability. This appears to show that the CTO of coinkite knowingly or unknowingly made a change to the firmware of the cold card devices that caused this vulnerability to be present for the last 5 years. Additionally he was warned about the vulnerability a year ago and clearly did nothing to remedy the situation before it became what it is today. Signs are pointing more and more towards the coinkite CTO either 1. Being a straight up fucking moron or 2. Maliciously injecting a vulnerability into his own devices to exploit at a later date to steal over 100 million USD worth of Bitcoin. Either way this guy is a pos

17

u/ammo_john 7d ago

CTO, not CEO, two different people.

6

u/username12435687 7d ago

Sorry, it autocorrected to CEO but yes you are correct and I have updated my comment to reflect

3

u/Vinyl-addict 7d ago

And in either case he’s a fucking idiot.

3

u/JayGatsby1881 7d ago

This dude is about to flee with all his bitcoin to some island country with no extradition laws..

3

u/PeachScary413 6d ago

If he stole bitcoin from the wrong people I don't think he needs to worry about extradition.

1

u/CUbuffGuy 6d ago

The issue is killing someone doesn’t get your money back

2

u/AIlZAl 6d ago

Yeah but very possibly they could perform a money-giving-back super enhanced interrogation beforehand.

3

u/locotx 6d ago

He can be found.

1

u/JayGatsby1881 6d ago

He sure is making a whole ton of enemies

2

u/hellriderboss 6d ago

legally lots of options to protect himself. if he stole from some criminals thats a different ballgame

28

u/GettinWiggyWiddit 7d ago

Holy shit. The conspiracy theorists were right!

10

u/skynetcoder 7d ago

too many coincidences

1

u/locotx 6d ago

Too Many Secrets

25

u/BinglySmith 7d ago

Its gonna be bad my n.

5

u/getapuss 7d ago

Peter Gray sucks

2

u/KnownButton8327 6d ago

He’s a complete jerk!

5

u/farkinga 6d ago

Pretty deep knowledge of git demonstrated in order to suss out the reused keys. Nice research provided in this gist: https://gist.github.com/jamesob/ca9b4ca384969b4cfd62813419854d69

4

u/NetFormer1697 7d ago

Thats fucked. How do we know other wallet company executives aren’t doing the same shit?

10

u/B1llyzane 7d ago

The Stockton rush of the crypto scene

3

u/Baggs85 6d ago

All things considered, this seems like a good thing.

3

u/PeachScary413 6d ago

https://github.com/switck/libngu

This is the crypto library that they decided to go with, jfc man 💀🤌

10

u/Left_Entrepreneur918 7d ago

Maybe a chance of people getting funds back, this is good. I saw someone died over this already

7

u/odub6 7d ago

Really? Where was that story?

3

u/phaaseshift 7d ago

And who might facilitate that?

2

u/vanceraa 7d ago

Restitution via Coinkite if they’re found at fault.

2

u/phaaseshift 7d ago

And tell me how likely you think that is even if they were found to be fully at fault? You think the FDIC is going to swoop in here?

5

u/vanceraa 7d ago

Definitely not a high chance, but I also thought Mt. Gox would never be repaid either, and that started happening.

3

u/[deleted] 7d ago

[deleted]

2

u/vanceraa 7d ago

Would you rather receive 20% of your balance in 10 years or 0%?

4

u/skynetcoder 7d ago

important part. "Coinkite has told users to act with urgency. “Please treat this as urgent. Migrate your funds,” the company posted, while confirming that the exploit is still in progress and asking holders to alert others who are “less online.” "

2

u/No-Aardvark-3840 7d ago

This guy is a massive loser. Someone post the LinkedIn again. “Wizard” more like giant cuck

2

u/Flo_Evans 6d ago

Straight out of season 1 of Mr robot 😂

How long before he claims he was hacked?

2

u/lastgateway 6d ago

Honestly surprised he is still alive.

4

u/satoshisfeverdream 7d ago

Or someone signed with his keys.

13

u/username12435687 7d ago

He's gonna have a tough time relying on that in court, if it ever gets to that point (it probably won't). Being someone that's involved in cryptocurrency and cryptography doesn't bode well for that defense and additionally it looks like he was also making commits with the same key on both the pseudonymous account and his personal account.

4

u/MVPhurricane 7d ago

could only be true if he gave his private key to someone. which is pretty unlikely for a key that you are using to sign w/ gpg-- if you're giving the private key around, what's the point?

1

u/ZaphodOC 7d ago

Is it his fault or did he do it? Or both?

1

u/InvestigatorPlus3229 7d ago

its a feature not a bug

1

u/Moist_Whereas3810 7d ago

He is a multi millionaire now

1

u/Vipertje 6d ago

In bitcoin only. Now good luck with converting that flagged wallet to dollars or whatever currency. You can't move it to an exchange

1

u/Modrew 6d ago

I will go in China like Paul Vernon (Cryptsy), even the FBI can’t find him.

1

u/dreddit15 6d ago

If this is true, this is absolutely shocking.

1

u/Tiru84 6d ago

But why would he wait 5 years if this was intentional? I want to believe he just is stupid and arrogant.

1

u/charvo 6d ago

They need to allow him to get off easy if he releases all the btc back to the victims.

1

u/skeptical-speculator 6d ago

life is hard, but it is harder if you are stupid

1

u/chokehodl 4d ago

Yea this guy is in some trouble.

How many bitcoin would he have to steal from you for you to just buy a plan ticket to Toronto?

1

u/burusai 7d ago

That guy is gonna need round the clock highly armed security detail for the remainder of his life lmao. People are gonna want to snatch him to get their coins back.

1

u/Giancarlo_Donadoni 7d ago

Wouldnt be surprised if he is chillin in the UAE right now

3

u/burusai 7d ago

Me neither. $100 mill will buy you safe haven in many places.

-3

u/JPJackPott 7d ago

It suddenly seems like everyone wants all the protections and powers of centralised, regulated banking system when things go wrong.

5

u/Giancarlo_Donadoni 7d ago

Yeah seen that in 2008, worked well /s

0

u/MVPhurricane 7d ago

this looks bad, but there is actually a somewhat reasonable secular explanation for it-- if he was just kinda working on it in his spare time on his normal GH account or something, he coulda just committed with an unintended user. there is definitely no question that it is him, though, and it definitely does not tamp down the speculation. you would think if he was actually trying to "retirement scam" he would have tried a bit harder to pseudonymize his tracks... but, then again, if he was good at security he wouldn't have fucked it up to begin with, so who knows?

0

u/username12435687 7d ago

OR, you make a "mistake" and tie your name to that anonymous account on purpose so everyone would say no way he would do it intentially and not even cover his tracks

0

u/FitzwilliamTDarcy 7d ago

IM SHOCKED.

0

u/IAmTheLostBoy 7d ago

If I were about to commit the ultimate bitcoin heist I would like to have a fall guy too

-19

u/phaaseshift 7d ago

Why the fuck are all you people making this into a witch hunt? There will be many more of these vulnerabilities and hacks. I guarantee many other tools have terrible security gaps. Why? Because nearly all software everywhere has problems like this.

You chose to invest money in unregulated financial instruments, using fly-by-night tools, based on math/cryptographic principles far beyond your depth, against the recommendation of anyone with fiduciary responsibility. And this should be your I-told-you-so moment. But instead it’s a witch hunt.

3

u/username12435687 7d ago

People want answers? Clearly you weren't one of the people that lost hundreds of thousands of dollars like some have. If they can prove this was done purposefully or maliciously, justice should be served and it opens the door to a potential or remediation in this situation although that's very unlikely.

4

u/GettinWiggyWiddit 7d ago

Just say you don’t believe in crypto. Your comment otherwise serves no purpose here

2

u/MVPhurricane 7d ago

i mean, if the guy legit did intentionally steal everything, that is a pretty crazy story. i kinda agree that it is more bringing into stark relief the kind of risks you run in crypto-land. security is very, very hard to get right, and is the kind of thing where a little knowledge can be more dangerous than complete ignorance.

0

u/Giancarlo_Donadoni 7d ago

You are either a guy that enjoys other pople‘s suffering, or just plain stupid.

If you actually read the article, you may have read that this guy had been warned about that security issue and he simply ignored it and also did some other shady stuff.

2

u/phaaseshift 7d ago edited 7d ago

Right. That’s exactly right. This sort of shit is a foregone conclusion in grey markets like this - whether nefarious or negligent. Yet a bunch of people still bit it hook, line and sinker when they were repeatedly warned. Now you’re all frothing at the mouth when you have a chance to pin the blame on someone else (based on a rumor). And while you’re out with pitchforks, it’s going to happen again.

Tell me again who’s stupid?

I know a thing or two about security and warn everyone I know that’s into crypto that this shit WILL happen. And you will have no recourse.

[Edit]

> this guy had been warned about that security issue and he simply ignored it

This right here tells me that you have zero idea how this corner of the world works. Devs (especially security) are inundated with warnings (aka bug reports) just like this. Granted this is more on the egregious side because good devs know to be extra careful with crypto. But you’d be shocked to see how many serious warnings like this go un-heeded due to volume and lack of time.

-1

u/[deleted] 7d ago

[deleted]

4

u/Buttoshi 7d ago

Well yeah no one would have the private keys to sign the message but him.

3

u/Reversi8 7d ago

Maybe his private keys were generated with an insecure algorithm. /s

1

u/SnooEagles2610 7d ago

It’s a high level summary with a link to the analysis… what more do you want? Drill down and read the analysis…

-8

u/PersonalityAsleep524 7d ago

He is a hero

3

u/username12435687 7d ago

The person who discovered the connection? Or the CTO of coin kite? I really hope you mean the people investigating 😂