Price:

James O'Byrne links CoinKite CTO to fatal Coldcard bug

Aug 11, 2026Summary from 4 podcasts.
  • Cryptographic signatures tied CoinKite's chief technology officer directly to the broken Coldcard entropy code.
  • Attackers and researchers are using cheap AI models to scan open-source Bitcoin projects for exploitable bugs.
  • The security failure is pushing sovereign Bitcoin holders away from self-custody and into institutional vaults.

Cryptographic evidence now ties CoinKite's chief technology officer to the flawed firmware commit that wiped out $130 million in self-custodial Bitcoin. Security researcher James O'Byrne revealed on Bitcoin And that 58 GitHub commits authored under an alias were cryptographically signed using the personal GPG key of Peter Gray, CoinKite's chief technology officer.

The single-line code change from March 2021 disabled Coldcard's hardware random number generator to resolve a compiler error. Devices fell back to predictable software entropy, leaving private keys vulnerable to automated brute-force scripts. Speaking on TFTC, Galaxy Research head Alex Thorn noted the victims were long-term holders with a median coin dormancy of nearly four years who followed standard best practices.

"The median dormancy of drained coins was nearly four years, belonging to long-term holders who deposited funds and never spent a single satoshi."

- Alex Thorn, TFTC: A Bitcoin Podcast

Passive single-signature cold storage under a bed is effectively broken. To protect remaining multi-signature vaults, users turned to private transaction relays like Marathon's Slipstream. On Ungovernable Misfits, researcher Orange Surf detailed how Slipstream routed signed transactions directly to miners, keeping revealed public keys safe from front-running mempool snipers.

The breach has accelerated into a systemic open-source security crisis. Armed with cheap, open-weight language models like Kimi K3, independent researchers and hostile actors are running continuous automated static analysis across open-source codebases. On Stacker News Live, hosts Keon and Carr highlighted how developer Rob Hamilton ran AI scans against repositories like BTCPay Server, uncovering hundreds of code bugs instantly.

A broader coalition named the Bitcoin Red Team spent $40,000 on models including Claude Opus and GPT Sol to scan 390 repositories, flagging 85 critical vulnerabilities. On Bitcoin And, host David Bennett discussed how the flood of findings forced services like Boltz and Zeus to pause operations while maintainers raced to deploy patches before automated scripts could exploit them.

"Flawed code accomplished what regulatory crackdowns could not: driving sovereign Bitcoin back into regulated vaults."

- David Bennett, Bitcoin And

The breakdown in hardware security is driving sovereign stackers toward regulated institutional options. Bennett pointed out that migrating assets to managed custodians like Coinbase or Unchained forces users to surrender privacy. Panicked emergency wallet transfers consolidated non-KYC holdings on-chain, exposing private transaction histories to public view.

Personality-driven social trust in hardware vendors has collapsed. Coinkite founder NVK deleted historic posts as former community allies distanced themselves from the firm. The era of storing life savings on single-key devices backed by founder posturing is over, replaced by multi-signature quorums and mandatory third-party code audits.