Timeline of #Coldcard Heist. November 2012 onward Peter D. Gray creates a public Clarity.fm profile under his real name, based in Toronto. 2012–2013 Peter D. Gray and Rodolfo Novak (NVK) co-found Coinkite in Toronto. Gray becomes CTO; Novak becomes CEO. The company starts as a Bitcoin services platform and later shifts to hardware. It remains a small team of roughly five. November 7, 2013 Peter D. Gray creates his GPG key (uid “Peter D. Gray <peter@coinkite.com>”). This key later signs dozens of commits under the switck identity, including the critical libngu changes. December 2017 Coinkite announces the Coldcard hardware wallet. Pre-orders open for 2018 shipping. July 25, 2018 First Coldcard Mk1 units ship. August 2019 Peter creates the anonymous identity “switck,” named after the Matrix character Switch, and uses a still of that character as the profile picture. The name plays on “making the switch.” First post notes DEF CON is a good time to start a new identity. Later commits under this name are often single-word or extremely terse. 2019–2020 onward Bitcoin educators and influencers, including BTC Sessions, begin promoting Coldcard as one of the most secure Bitcoin hardware wallets. July 2020 Foundation Devices announces the Passport, built in part on Coldcard’s then-GPLv3 firmware. Early 2020s Ten31 (Managing Partners include Matt Odell and Marty Bent) becomes Coinkite’s sole external investor. January 8, 2021 Coldcard firmware 3.2.1 announces the license change from GPL to MIT + Commons Clause. January 5, 2021 Domain switck.com is registered via easyDNS using a Toronto-area privacy service (MyPrivacy.net, Etobicoke). The same day the switck account posts the single word “got.” January 28, 2021 Under switck, the vulnerable preprocessor guard (#ifndef MICROPY_HW_ENABLE_RNG) is committed to libngu (f19de05). This fails to force the hardware TRNG when the macro is set to zero. The library is co-maintained with scgbckbone (later linked to Andrej Virgovic). March 1, 2021 Under doc-hex, the commit “First pass w/ libNgU” (b18723dd) replaces remaining Trezor-derived GPL crypto and BIP-39 code with libngu (submodule from switck/libngu). Seed generation switches from the hardware path (ckcc.rng_bytes) to ngu.random.bytes(). This is the point real hardware entropy is replaced by the weak software PRNG. Coinkite release notes later thank @switck for the library. March 17, 2021 Firmware v4.0.0 is released containing the new path. March 29, 2021 Firmware 4.0.1 ships. Seeds generated under this and later affected versions fall back to the software PRNG, yielding roughly 40 bits of effective entropy on Mk2/Mk3 (roughly 72 bits on later models that mixed limited secure-element data). Around April 2021 Public users begin questioning the LibNgU rewrite and the replacement of the prior crypto stack. February 2022 Peter (as DocHex) publicly states that as CTO he encourages Coinkite developers to operate under nyms, stay low-profile about their employer, and notes he may appear to author their GitHub commits. 2022 Early reports of individual Coldcard wallets being drained appear. At least one user claims that reporting the issue to Coinkite resulted in being blocked. May 2025 James O’Beirne audits the firmware, identifies the low-star, pseudonymously maintained libngu library as the RNG source, and reports doubts that the true hardware RNG is in use. He advises removing it. Coinkite replies that if something were wrong “we’d already know about it by now.” The warning is not acted on. July 30, 2026 Attackers begin draining affected wallets. An initial wave takes roughly 594 BTC (\~$38 million) from about 500 addresses in \~25 minutes. Later waves push tracked totals higher (1,000+ BTC / $70–88 million+ range). Coinkite publishes a security advisory the same day acknowledging the 2021 entropy failure. July 31, 2026 Coinkite releases fixed firmware (4.2.0 Mk3, 5.6.0 Mk4/Mk5, 1.5.0Q). Existing weak seeds remain compromised and must be migrated. Multiple reports note NVK is deleting older tweets from the 2020 period related to the license change and open-source decisions. July 31 – August 4, 2026 Researchers link switck to Peter Gray / DocHex via matching GPG signatures on dozens of libngu commits (including the January 2021 guard), the shared phone number ending in 44, the Toronto-area domain registration, the Matrix Switch avatar and name, and overlapping contribution patterns. Peter’s LinkedIn, previously public, is made private. image

Replies (48)

Jimmy's avatar
Jimmy 1 week ago
At best, this is gross negligence, but I wouldn't be surprised if it's worse.
Jimmy's avatar
Jimmy 1 week ago
Yeah, that's why I think probably worse. A planned multi-year con job. Absolutely diabolical.
Jimmy's avatar
Jimmy 1 week ago
Check this out:
Ben Justman🍷's avatar Ben Justman🍷
Two of Peter Gray’s past engineering projects, prior to becoming the CTO of Coinkite: • Writing the firmware and software for an OEM-sold USB keylogger • Conceiving and programming KVM-over-IP hardware for remotely viewing and controlling computers The keylogger captured keystrokes without software on the target computer. The likely OEM product, KeyGhost, was sold as a dongle or concealed inside a keyboard. The KVM hardware let a remote operator see the screen and control the keyboard and mouse, even before the OS loaded.
View quoted note →
.'s avatar
. 1 week ago
@Laser GLM 5.2 via Tinfoil just said that a bio for twitter account @switck said "Cypher all the things" around August 2020 🤯
That's how it goes these days, nothing is ever straightforward and there's always some dark nefarious storyline to add. Hopefully this is just negligence but I'm sure there will be plenty of conspiracy theories anyway.
Fair enough. Hope you find some time soon, it be best to have a professional address the $100M question - did Peter Gray rob his customers? 🙏 for considering
You posting that photo of a shot up coldcard years ago tangentially resulted in me dropping the device and save me from being a casualty of all this. Thanks man.
This would be the best case scenario no? Drag them out into the town square for a proper flogging. Then force them to return their stolen corn to the people.
Great summary! Just one thing is missing: Peter D. Gray also used the alias "Doc Hex" on LinkedIn and that profile it's still available https://linkedin.com/in/doc-hex-04063811 and shows some interesting things. Before becoming Coinkite's CTO, his profile listed two notable projects: Hardware Keylogger: Wrote firmware for a stealth hardware keylogger (sold by an OEM, likely KeyGhost) that captured keystrokes independently of the host OS, embedded in dongles or keyboards. KVM-over-IP Hardware: Developed remote-access hardware allowing full video, mouse, and keyboard control, even before the OS booted up.
Probably an exit scam planned by NVK and Gray who are probably spooks or spook adjacent. Probably discovered by Kimi K3 and executed by someone else. Timing blows my mind: -AI bubble at peak mania with demonstrably scary capability. -Bottom of Bitcoin bear market. -Clarity Act working through congress and uncertain. -Treasury company blowouts holding the market down. -BIP110 infighting -Japanese Bond market going off the rails and being explicitly propped up by US Treasury action to preserve global liquidity and prevent Japan panic selling UST. Printer is coming! -Extended war in the Middle East that has clear Bitcoin angles on top of energy, fertilizer and shifting global alliances. -Jason Lowery shows back up after 3 years to say “I don’t know the guy” (is he signaling that this was an operation but not a US military one?) I mean guys, what fucking game are we playing in here? $64k is not the price for something this entangled in worlds events. Absolutely tragic that we lost brothers in arms in this one. We need to stop being coy and acknowledge we are at war even if we can’t define the enemy in this fog.
MyPrivacy.net is nothing mysterious - it is simply the legal entity easyDNS uses for Whois Privacy. Every registrar uses a separate legal entity for their whois privacy service (i.e. "Domains By Proxy" for GD, "Contact Privacy Inc" for Tucows.)
To defraud bitcoiners out of $100m+? nevent1qqsqqqqhnlkkhk7czchp444njap988nhv8zjz08jexwn7wq7rrejywqzypj2eaq9t75zd09ts3t7ynhclwn5jz4mremdh2m24p6j55aqadx55jzmwt6
🚨 NEW SWEEP THREAT 🚨 We need eyes on this; plz repost. 🤙
exist270's avatar exist270
#ColdCard funds are getting swept WHILE THE #BITCOIN / #BTC TRANSACTIONS ARE STILL IN THE MEMPOOL. 🫪 The attacker is clearly watching broadcasts, so unless users are signing transactions straight from a miner, this shit is gonna keep getting worse until ALL at-risk funds have been drained. 🫠 Absolute fucking shambles. 🤙 https://x.com/i/status/2085325832285757680 View quoted note →
View quoted note →
🚨 NEW SWEEP THREAT 🚨 We need eyes on this; plz repost. 🤙
exist270's avatar exist270
#ColdCard funds are getting swept WHILE THE #BITCOIN / #BTC TRANSACTIONS ARE STILL IN THE MEMPOOL. 🫪 The attacker is clearly watching broadcasts, so unless users are signing transactions straight from a miner, this shit is gonna keep getting worse until ALL at-risk funds have been drained. 🫠 Absolute fucking shambles. 🤙 https://x.com/i/status/2085325832285757680 View quoted note →
View quoted note →
Rafael Costa 's avatar
Rafael Costa 5 days ago
Coldcards: ✝️ 08/12/2017 – 30/07/2026 ⚰️ #timeline #goodbyecoldcard #bitcoin #nostr #plebchain