Timeline of #Coldcard Heist.
2010
Peter D. Gray and Rodolfo Novak (NVK) begin working together at Ripe Apps, an iPhone/iPad app development studio in Toronto. Predates their Bitcoin involvement by a year.
2011
Gray discovers the Bitcoin whitepaper and shares it with Novak, his existing business partner.
2012
The pair builds https://t.co/1Oc8qHMHnH, a visual blockchain explorer, as a Ripe Apps side project. Later that year they build PCI-certified Bitcoin payment terminals and begin international deployment, ahead of incorporating.
2012–2013
Peter D. Gray and Rodolfo Novak (NVK) co-found Coinkite in Toronto. Gray becomes CTO, Novak becomes CEO. Debuts a working terminal at the Bitcoin Conference. Raises a $120K seed round, the company’s only funding round to date. Remains a team of around five.
November 7, 2013
Peter D. Gray creates his GPG key (uid “Peter D. Gray [email protected]”). This key later signs dozens of commits under the switck identity, including the critical libngu changes.
Early 2016
Coinkite shuts down its web wallet/exchange service, citing legal complications and DDoS attacks, and pivots fully to hardware — the turn that leads to Opendime and eventually Coldcard.
December 2017
Coinkite announces the Coldcard hardware wallet. Pre-orders open for 2018 shipping.
July 25, 2018
First Coldcard Mk1 units ship.
August 2019
Peter creates the anonymous identity “switch,” named after the Matrix character Switch, using a still of that character as the profile picture. First posts note DEF CON is a good time to start a new identity. Later commits under this name are often single-word or extremely terse.
2019–2020 onward
Bitcoin educators and influencers, including BTC Sessions, begin promoting Coldcard as one of the most secure Bitcoin hardware wallets.
July 2020
Foundation Devices announces the Passport, built in part on Coldcard’s then-GPLv3 firmware.
Early 2020s
Ten31 becomes Coinkite’s sole external investor, confirmed on record by NVK in podcast disclosures.
January 8, 2021
Coldcard firmware 3.2.1 announces the license change from GPL to MIT + Commons Clause.
January 5, 2021
Domain https://t.co/fE09496thO is registered via a privacy service. The switck account posts the single word “got” the same day.
January 28, 2021
Under switck, the vulnerable preprocessor guard (#ifndef MICROPY_HW_ENABLE_RNG) is committed to libngu. This fails to force the hardware TRNG when the macro is set to zero. The library is co-maintained with scgbckbone.
March 1, 2021
Under doc-hex, the commit “First pass w/ libNgU” (b18723dd) replaces remaining Trezor-derived GPL crypto and BIP-39 code with libngu. Seed generation switches from hardware path to ngu.random.bytes(). This is the point real hardware entropy is replaced by the weak software PRNG. Coinkite release notes later thank @switck for the library.
March 17, 2021
Firmware v4.0.0 released, stating all crypto and BIP39 code had been replaced and the last remaining GPL code removed.
March 29, 2021
Firmware 4.0.1 ships. Seeds generated under this and later affected versions fall back to the software PRNG, yielding roughly 40 bits of effective entropy on Mk2/Mk3 (roughly 72 bits on later models with limited secure-element mixing).
Around April 2021
Public users begin questioning the libngu rewrite and the replacement of the prior crypto stack.
2022
As DocHex, Gray publicly states that as CTO he encourages Coinkite developers to operate under nyms and stay low-profile about their employer, and notes he may appear to author his own GitHub commits under a different identity. In a podcast appearance the same year, Novak refers to Gray directly as “Doc Hex, my co-founder.”
May 2025
James O’Beirne audits the firmware, identifies the low-star, pseudonymously maintained libngu library as the RNG source. In his own words, posted on X: he wanted to figure out conclusively where the Coldcard RNG was sourced from, and traced it to a shady library. He contacts Coinkite. Reported response: if something were wrong, they’d likely already know about it by now. The warning is not acted on.
July 30, 2026
Attackers begin draining wallets. Initial wave: roughly 594 BTC (~$38M) from about 500 addresses in ~25 minutes. Coinkite publishes a security advisory the same day acknowledging the 2021 entropy failure.
July 31, 2026
Coinkite releases fixed firmware (4.2.0 Mk3, 5.6.0 Mk4/Mk5, 1.5.0Q). Existing weak seeds remain compromised and must be migrated. Independent verification beyond Coinkite’s own account: Bitcoin Core developer instagibbs reproduces the vulnerability on a fresh Mk3 device. Kevin Loaec of Wizardsardine is among the first to publicly sound the alarm. Peter Todd flags a specific multisig risk for 2-of-3 setups using compromised Coldcards. Multiple reports note NVK deleting older tweets related to the 2020–2021 license change and open-source decisions.
----
Authors:
- Contra [npub14hq5lgadtyy9dhvtszq46dnl0s0xwdddqr7e32rdqqhma8a4xhsspxjjzu]
- Laser [npub1vjk0gp2l4qnte2uy2l3ya78m5ays4wc7wmd6k64gw5498g8tf49qtkd33q]
A few days ago, someone asked me what dystopian regulations the EU had introduced.
I'll start right away with MiCA:
1. Thanks to this regulation, all European crypto exchanges have delisted anonymous cryptocurrencies (such as Monero or Zcash), which, as a company, we can no longer legally purchase from a regulated exchange anywhere in the EU. This doesn't just apply to anonymous cryptocurrencies but also, for example, to USDT, which has refused to address this compliance issue (I should note that USDT is the most widely accepted stablecoin in the world).
2. All crypto ATMs in the EU (except Poland) have started requiring KYC from scratch due to MiCA, AMLR, and DAC8.
The costs of the KYC process are so high that many companies have given up on it and moved outside the EU.
3. Bitcoin payments have become impractical. Almost all services that aren't P2P require KYC.
4. The costs of MiCA compliance are so enormous that many small, great services (such as https://t.co/jHwZbXh7wU) are shutting down in the EU because of MiCA. I just received an email about this, and I’m really angry at EU bureaucrats.
Out of 3,000+ crypto firms as of 2024, only ~194–210 have a license; ~75% are being forced out by July 1, 2026.
5. The largest crypto exchange, Binance, is still not 100% compliant. If it leaves the EU market because of MiCA, it will be as if Google had left the EU.
It is evident that the EU is strongly opposed to financial anonymity (a true hallmark of a dystopian society) and to crypto services that are not MiCA/DAC-8 compliant, so EU bureaucrats approve only users'regulated crypto services that engage in widespread surveillance and threaten users’ privacy.
ssh is an obscure but widely-deployed command. It stands for Secure Snake Home and was made in the 90s to securely play snake online
I made a massively multiplayer backend for it with support for thousands of concurrent snake players
ssh snakes dot run to join!
Michael Saylor got cooked by Epstein’s publicist Peggy Siegel who basically said
“He’s so creepy I don’t even know if I can take his money I don’t even know how to blackmail him he has no personality and doesn’t understand social behavior.��
Michael Saylor was saved by his autism.
BASED. 😂 😂 😂
I have had a lot of fun lately letting Claude fully control my old ThinkPad.
This finally feels like the correct way to interact with computers, like something’s been missing this entire time until now.
Give Claude a laptop to live in, you won’t regret it.
Writing is thinking
Outsourcing the entire task of writing to LLMs will deprive us of the essential creative task of interpreting our findings and generating a deeper theoretical understanding of the world.
🌐 Bridging Bitchat + MeshCore: Resilient communication when infrastructure fails
Bitchat = Bluetooth mesh on phones you already have (~100m range)
MeshCore = LoRa long-range mesh (km+ with cheap hardware)
The bridge connects them. Your phone talks to the city-wide mesh network.
Perfect for disasters, protests, internet shutdowns.
Code: https://t.co/YbP7eVXWiW
Releases: https://t.co/vUVkAY2vjf
Read more: https://t.co/sgRvezRGeC