Bitcoin Forum
August 07, 2026, 12:27:29 AM *
News: COLDCARD users only: critical vulnerability risks funds stored on COLDCARD devices; immediate action required
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: The weirdest part of the ColdCard mess: Peter D. Gray (aka "doc-hex")  (Read 42 times)
Stalker22 (OP)
Legendary
*
Offline

Activity: 2324
Merit: 1616



View Profile
August 06, 2026, 10:17:27 AM
 #1

Honestly, I still cant wrap my head around this whole Coldcard situation.  We spent years telling people that open-source code is our best line of defense and advocating for a full public commit history, but then you try to look under the hood of what actually went down here, and it feels less like a serious engineering setup and more like a lame, amateurish one-man theater show.

Beyond the actual RNG vulnerability that hit the firmware, the weirdest part of this entire story is the strange relationship between Coinkite's co-founder and CTO, Peter D. Gray (DocHex), and a pseudo-anonymous developer named "switck".

Here is a link to a discussion I came across on the r/Bitcoin board, but to keep it simple, here is a quick AI-assisted recap with links to some external sources:

Quote
“Switck” is an online alias and GitHub account heavily scrutinized in the recent Coldcard security controversy, with cryptographic proof showing it was operated by Coinkite CTO Peter D. Gray.

The "Switck" and Peter D. Gray Connection
  • Shared GPG Keys: An analysis of Git commits in the switck/libngu repository revealed 58 commits authored by "Switck" that were cryptographically signed using Peter D. Gray's personal GPG key (peter@conalgo.com).[1][2]
  • Overlapping Timelines: Gray's real-name identity and the "Switck" alias signed commits and interacted in overlapping periods.
  • Public Self-Interaction: Under the u/switck social media and GitHub handles, Gray appeared to announce his alias as a "new identity" and later publicly thanked his own primary developer account (doc-hex) or promoted code libraries as though they belonged to an independent third party.[3]

Connection to the Coldcard Vulnerability
  • The Code Timeline: In early 2021, code under the switck alias introduced a defective feature check into libNgU.
  • RNG Path Switch: Shortly after, Peter Gray's primary developer alias (doc-hex) imported that code, disabled hardware random number generation, and routed master-seed generation to the flawed path.
  • The Fallout: This vulnerability eventually surfaced during investigations into major security and seed-generation flaws impacting certain hardware wallet firmware versions.[4]

What do you make of all this?  Was this just bizarre ego and messy developer habits, or was there something much more calculated about keeping libngu - a core cryptographic library - on a personal account instead of under the official organization?  Why would a lead developer set up an alter ego to approve and maintain their own code?


[1] - switck == doc-hex: proven by GPG commit signatures
[2] - was Peter D. Gray talking to himself through “switck”? : r/Bitcoin
[3] - Inside job? The “bug” conveniently originated in 2021 : r/coldcard
[4] - Retirement Attack: Many more details pointing straight to the CEO and CTO stealing the coins : r/Bitcoin

█████████████████████████
███████▀▀███████▀▀███████
█████▀░░▄███████▄░░▀█████
███▀░░██████▀░▀████░░▀███
██▀░░▀▀▀████████████░░▀██
██░░█▄████▀▀███▀█████░░██
██░░███▄▄███████▀▀███░░██
██░░████████████████░░██
██▄░░████▄▄██████▄▄█░░▄██
███▄░░██████░░████░░▄███
█████▄░░▀███░░▐▀░░▄█████
███████▄▄███████▄▄███████
█████████████████████████
.
 ROOBET .██████. BET ON WORLD CUP  🗺 ⚽︎.██████.
|

█▄█
▀█▀
████▄▄██████▄▄████
█▄███▀█░░█████░░█▀███▄█
▀█▄▄░▐█████████▌▄▄█▀
██▄▄█████████▄▄████▌
██████▄▄████████
█▀▀████████████████
██████
█████████████
██
█▀▀██████████████
▀▀▀███████████▀▀▀▀
|.
   BET NOW   
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!