The weirdest part of the Coldcard mess: was Peter D. Gray talking to himself through “switck”?
| I’m not going to re-explain the RNG bug. That part has already been documented. What I want to know is who exactly was behind Someone checked the actual Git signatures in the Now look at the social-media side. In 2019, u/switck posted: “#defcon seems like a good time to start a new identity. Follow me!” That tweet is real and still online. Later, the account promoted So the account that announced it was starting a “new identity” was apparently Peter’s alias, publicly speaking to Peter’s main identity as though they were two different developers. The same thing appears on GitHub. And this wasn’t some unrelated side project. None of this proves Peter intentionally created the vulnerability, knew it could be exploited or had anything to do with the thefts. But it is still extremely fucking weird. Why was a security-critical Coldcard library hosted under a pseudonymous personal account instead of Coinkite or Coldcard? Did Coinkite know that Why create the public appearance of two developers interacting, submitting code and merging each other’s work? Who independently reviewed the library and the Coldcard integration if the library author and the person integrating it were apparently using the same private signing key? And why has Coinkite explained the technical bug without addressing who controlled the Peter, if you read this: was If it wasn’t, why were dozens of If it was, why did you publicly talk to that account as though it belonged to someone else? Did NVK and the rest of Coinkite know? Who was actually reviewing your work? There may be an innocent explanation. But after this code path left customer wallets vulnerable and people lost bitcoin, hiding behind silence is not an explanation. [link] [comments] |