MultiversX Tracker is Live!

The weirdest part of the Coldcard mess: was Peter D. Gray talking to himself through “switck”?

Bitcoin Reddit

More / Bitcoin Reddit 8 Views

I’m not going to re-explain the RNG bug. That part has already been documented. What I want to know is who exactly was behind switck, and why this identity existed in the first place.

Someone checked the actual Git signatures in the switck/libngu repository. They found 58 commits authored as “Switck” signed with Peter D. Gray’s personal GPG key. The same key also signed commits under Peter’s real name, with both identities being used during overlapping periods. Unless Peter shared or lost control of his private signing key, the obvious conclusion is that GitHub switck was Peter Gray operating under another name.

Now look at the social-media side.

In 2019, u/switck posted: “#defcon seems like a good time to start a new identity. Follow me!”

That tweet is real and still online.

Later, the account promoted switck/libngu, thanked u/DocHex for a merge and said the library might someday be useful on Coldcard.

So the account that announced it was starting a “new identity” was apparently Peter’s alias, publicly speaking to Peter’s main identity as though they were two different developers.

The same thing appears on GitHub. doc-hex opened issues in the switck/libngu repository. In one pull request, doc-hex added four commits, then switck merged them. GitHub lists no reviews.

And this wasn’t some unrelated side project. switck/libngu became part of Coldcard. The switck account introduced a critical piece of the vulnerable RNG path, and doc-hex later integrated libNgU into the Coldcard firmware. Coinkite itself confirms that this migration moved wallet-seed generation onto the wrong RNG implementation.

None of this proves Peter intentionally created the vulnerability, knew it could be exploited or had anything to do with the thefts.

But it is still extremely fucking weird.

Why was a security-critical Coldcard library hosted under a pseudonymous personal account instead of Coinkite or Coldcard?

Did Coinkite know that switck and doc-hex were apparently the same person?

Why create the public appearance of two developers interacting, submitting code and merging each other’s work?

Who independently reviewed the library and the Coldcard integration if the library author and the person integrating it were apparently using the same private signing key?

And why has Coinkite explained the technical bug without addressing who controlled the switck identity?

Peter, if you read this: was switck you?

If it wasn’t, why were dozens of Switck commits signed with your personal GPG key?

If it was, why did you publicly talk to that account as though it belonged to someone else? Did NVK and the rest of Coinkite know? Who was actually reviewing your work?

There may be an innocent explanation. But after this code path left customer wallets vulnerable and people lost bitcoin, hiding behind silence is not an explanation.

submitted by /u/inner_engineering08
[link] [comments]
Get BONUS $200 for FREE!

You can get bonuses upto $100 FREE BONUS when you:
💰 Install these recommended apps:
💲 SocialGood - 100% Crypto Back on Everyday Shopping
💲 xPortal - The DeFi For The Next Billion
💲 CryptoTab Browser - Lightweight, fast, and ready to mine!
💰 Register on these recommended exchanges:
🟡 Binance🟡 Bitfinex🟡 Bitmart🟡 Bittrex🟡 Bitget
🟡 CoinEx🟡 Crypto.com🟡 Gate.io🟡 Huobi🟡 Kucoin.



Comments