Damus
Laser profile picture
Laser
@Laser
Timeline of #Coldcard Heist.

November 2012 onward
Peter D. Gray creates a public Clarity.fm profile under his real name, based in Toronto.

2012–2013
Peter D. Gray and Rodolfo Novak (NVK) co-found Coinkite in Toronto. Gray becomes CTO; Novak becomes CEO. The company starts as a Bitcoin services platform and later shifts to hardware. It remains a small team of roughly five.

November 7, 2013
Peter D. Gray creates his GPG key (uid “Peter D. Gray <[email protected]>”). This key later signs dozens of commits under the switck identity, including the critical libngu changes.

December 2017
Coinkite announces the Coldcard hardware wallet. Pre-orders open for 2018 shipping.

July 25, 2018
First Coldcard Mk1 units ship.

August 2019
Peter creates the anonymous identity “switck,” named after the Matrix character Switch, and uses a still of that character as the profile picture. The name plays on “making the switch.” First post notes DEF CON is a good time to start a new identity. Later commits under this name are often single-word or extremely terse.

2019–2020 onward
Bitcoin educators and influencers, including BTC Sessions, begin promoting Coldcard as one of the most secure Bitcoin hardware wallets.

July 2020
Foundation Devices announces the Passport, built in part on Coldcard’s then-GPLv3 firmware.

Early 2020s
Ten31 (Managing Partners include Matt Odell and Marty Bent) becomes Coinkite’s sole external investor.

January 8, 2021
Coldcard firmware 3.2.1 announces the license change from GPL to MIT + Commons Clause.

January 5, 2021
Domain switck.com is registered via easyDNS using a Toronto-area privacy service (MyPrivacy.net, Etobicoke). The same day the switck account posts the single word “got.”

January 28, 2021
Under switck, the vulnerable preprocessor guard (#ifndef MICROPY_HW_ENABLE_RNG) is committed to libngu (f19de05). This fails to force the hardware TRNG when the macro is set to zero. The library is co-maintained with scgbckbone (later linked to Andrej Virgovic).

March 1, 2021
Under doc-hex, the commit “First pass w/ libNgU” (b18723dd) replaces remaining Trezor-derived GPL crypto and BIP-39 code with libngu (submodule from switck/libngu). Seed generation switches from the hardware path (ckcc.rng_bytes) to ngu.random.bytes(). This is the point real hardware entropy is replaced by the weak software PRNG. Coinkite release notes later thank @switck for the library.

March 17, 2021
Firmware v4.0.0 is released containing the new path.

March 29, 2021
Firmware 4.0.1 ships. Seeds generated under this and later affected versions fall back to the software PRNG, yielding roughly 40 bits of effective entropy on Mk2/Mk3 (roughly 72 bits on later models that mixed limited secure-element data).

Around April 2021
Public users begin questioning the LibNgU rewrite and the replacement of the prior crypto stack.

February 2022
Peter (as DocHex) publicly states that as CTO he encourages Coinkite developers to operate under nyms, stay low-profile about their employer, and notes he may appear to author their GitHub commits.

2022
Early reports of individual Coldcard wallets being drained appear. At least one user claims that reporting the issue to Coinkite resulted in being blocked.

May 2025
James O’Beirne audits the firmware, identifies the low-star, pseudonymously maintained libngu library as the RNG source, and reports doubts that the true hardware RNG is in use. He advises removing it. Coinkite replies that if something were wrong “we’d already know about it by now.” The warning is not acted on.

July 30, 2026
Attackers begin draining affected wallets. An initial wave takes roughly 594 BTC (\~$38 million) from about 500 addresses in \~25 minutes. Later waves push tracked totals higher (1,000+ BTC / $70–88 million+ range). Coinkite publishes a security advisory the same day acknowledging the 2021 entropy failure.

July 31, 2026
Coinkite releases fixed firmware (4.2.0 Mk3, 5.6.0 Mk4/Mk5, 1.5.0Q). Existing weak seeds remain compromised and must be migrated. Multiple reports note NVK is deleting older tweets from the 2020 period related to the license change and open-source decisions.

July 31 – August 4, 2026
Researchers link switck to Peter Gray / DocHex via matching GPG signatures on dozens of libngu commits (including the January 2021 guard), the shared phone number ending in 44, the Toronto-area domain registration, the Matrix Switch avatar and name, and overlapping contribution patterns. Peter’s LinkedIn, previously public, is made private.
4071❤️85🤙11👍7❤️5👀5🔥3
LiveFree · 3w
My goodness
proofofprice.com · 3w
insane research
Jimmy · 3w
At best, this is gross negligence, but I wouldn't be surprised if it's worse.
Matt · 3w
Good work.
xlh155 · 3w
Gray does not look trustworthy in this picture for some reason, whilst Novak looks like a useful idiot.
AlexW · 3w
7/11/2013 when the first news broke out https://npub1vjqenty8jphj9039yghlhgr6xvp8thtvmwypmrfrg3je0z6djsws6z7z70.blossom.band/1f58a5613d9e35dbc59d284c7fd3e814f5f4feccf5b102e7ab1d38578ee400f4.jpg
yupYep · 3w
Read this like the ending credits of a MGS game
47 · 3w
nice work, laser
TBH · 3w
If this was a scam, it was legit long-game. Incredible patience.
Akamaister · 3w
Great work Laser
. · 3w
nostr:nevent1qqsyez2hzmwguamszwq5hq2e2a4v9y8fvyt9p68257ff3ckvsw2ghyqprdmhxue69uhhg6r9vehhyetnwshxummnw3erztnrdakj7q3qak68qfcjj7k95c0jwleu69x72nr8adwv6g80pkwl9xlps6zmkqzqxpqqqqqqz956and
SovereignArab · 3w
This would be the best case scenario no? Drag them out into the town square for a proper flogging. Then force them to return their stolen corn to the people.
blockdyor · 3w
Great summary! Just one thing is missing: Peter D. Gray also used the alias "Doc Hex" on LinkedIn and that profile it's still available https://linkedin.com/in/doc-hex-04063811 and shows some interesting things. Before becoming Coinkite's CTO, his profile listed two notable projects: Hardware Keyl...
Relatively Irrelevant · 3w
In the Matrix, Switch said “Not like this” moments before Cypher remotely disconnected Switch and Apoc from the Matrix by pulling their data probes, causing their deaths because they were still jacked in. https://i.imgflip.com/234t8c.jpg
TallBrian · 3w
Probably an exit scam planned by NVK and Gray who are probably spooks or spook adjacent. Probably discovered by Kimi K3 and executed by someone else. Timing blows my mind: -AI bubble at peak mania with demonstrably scary capability. -Bottom of Bitcoin bear market. -Clarity Act working through...
Mark E. Jeftovic · 3w
MyPrivacy.net is nothing mysterious - it is simply the legal entity easyDNS uses for Whois Privacy. Every registrar uses a separate legal entity for their whois privacy service (i.e. "Domains By Proxy" for GD, "Contact Privacy Inc" for Tucows.)
exist270 · 3w
🚨 NEW SWEEP THREAT 🚨 We need eyes on this; plz repost. 🤙 nostr:nevent1qqsqxzhu3w6zh2y2xqwhd8lj3h2lw7jd2q09rx3x2aadeqndz777cvqpz4mhxue69uhhyetvv9ujuerpd46hxtnfduhsygrvhd2lgzw43nhvny0wkx625pmex8naq7xkf8dxvcfgg2dmv7mfpspsgqqqqqqs3l7s4f
Rafael Costa · 2w
Coldcards: ✝️ 08/12/2017 – 30/07/2026 ⚰️ #timeline #goodbyecoldcard #bitcoin #nostr #plebchain