Bitcoin News said in a post on X that new evidence suggests the anonymous account "switck," which wrote LibNgU code tied to the COLDCARD entropy fault incident, may actually belong to Coinkite co-founder and CTO Peter Gray. According to researchers cited in the post, Gray’s GPG key signed dozens of switck commits, while other identifiers also appear to connect the two identities. Bitcoin developer James O’Beirne said he warned Coinkite in May 2025 that LibNgU’s RNG implementation looked suspicious and recommended removing it. He said the response he received was that any issue would likely have already been found if one existed. Screenshots referenced in the post also indicate that users had questioned the LibNgU rewrite as early as April 2021. If the findings are accurate, the report said, the engineer who introduced the code was later connected to an incident involving the theft of more than 1,800 BTC and had received direct warnings about the RNG implementation more than a year before the vulnerability was publicly disclosed.
Bitcoin News said in a post on X that new evidence suggests the anonymous account known as switck, which wrote LibNgU code at the center of the COLDCARD entropy fault incident, may in fact be Coinkite co-founder and CTO Peter Gray.
Researchers cited in the post said Gray’s GPG key signed dozens of switck commits. They also said other identifiers appear to tie the two identities together.
Bitcoin developer James O’Beirne said he warned Coinkite in May 2025 that LibNgU’s random number generator, or RNG, implementation looked suspicious. He said he recommended that the implementation be removed, but described Coinkite’s response as saying that any problem would probably already have been discovered if one existed.
Screenshots referenced in the post also showed that questions about the LibNgU rewrite had surfaced much earlier. According to the material cited, users had already raised doubts in April 2021.
Bitcoin News said that if the findings are correct, the engineer who introduced the code was later connected to an incident involving the theft of more than 1,800 BTC. The post also said direct warnings about the RNG implementation had been received more than a year before the vulnerability was publicly disclosed.
This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan. Disclaimer:
The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.
Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.