Edited By
Ethan Walker

A growing number of accusations point to Coinkite's leadership as responsible for a massive theft involving their Coldcard hardware wallets. Recent findings reveal that the company's senior figures may have manipulated the software to exploit vulnerabilities, leaving users exposed for years.
Coinkite's CEO, Rodolfo Novak (alias NVK), and CTO, Peter Gray, are at the center of these claims. Their dismissal of a so-called "retirement attack"βa scenario where wallet makers exploit flaws to drain user fundsβraises flags, especially given the timeline of events.
December 2020: NVK publicly downplays concerns about retirement attacks, suggesting users rely on dice rolls for randomness during seed generation.
October 2021: The company falsely claims that Coldcard devices eliminate these retirement threats, despite mounting evidence to the contrary.
Curiously, two separate warnings about potential vulnerabilities were raised by researchersβonce in 2021 and again in 2025βbut were ignored. As one commentator noted, "Itβs not exactly groundbreaking, but" the negligence is alarming.
In a detailed analysis, experts pointed to the manipulation of random number generation tied to a pseudonymous GitHub account likely belonging to Gray. This raises serious questions about the integrity of Coldcard's security protocols:
Gray's alias, switck, appears to have authored critical code changes, linking the device's entropy generation to a flawed library.
Users who neglected to opt into additional security measures remain at risk, drowning in a sea of broken trust.
"A developer reported the flaw, but Coinkite just shrugged it off," one user remarked, reflecting the sentiment that leadership may have been more concerned with profit than user safety.
In light of the recent investigation, some users are calling for legal action against Coinkite's executives. "If this is true, everyone at Coinkite should be facing prison time," exclaimed another comment.
The sentiment among forum members is overwhelmingly negative. Many feel betrayed, suggesting that the company's actions indicate either gross incompetence or deliberate malfeasance. Quotes from the comments suggest wide acceptance of the latter:
"Intentionally planting a bug in your own code is criminal," one commenter stated.
"This came across like an exit scam for developers," another added, pointing to the severity of their mismanagement.
π© Over 600 compromised wallets belonged to federal investigators.
ποΈ NVK and Gray have faced increased public scrutiny in the wake of the heist.
π Multiple warnings were ignored regarding potential vulnerabilities.
With federal investigations underway, the question remains: how much longer will Coinkite's executives evade accountability for their actions? As more details surface, it becomes crucial for affected users to demand transparency and reform in both security practices and corporate governance.
Whatβs the next step? Only time will tell if these executives will face the justice they seem to have skirted, leaving users to ponder the fate of their investments.
Thereβs a strong chance that we will soon see legal actions escalate against Coinkiteβs leadership as federal investigations gain momentum. As the evidence mounts against CEO Rodolfo Novak and CTO Peter Gray, experts estimate around an 80% likelihood that at least one of them will face criminal charges related to the theft. With many users vocalizing their discontent on forums, itβs likely that civil suits will emerge, potentially driving the company to the brink of insolvency. This could force Coinkite to rethink its corporate strategy and transparency measures, possibly leading to an overhaul of its security protocols to regain user trust.
This scenario echoes the case of early 2000s online banking failures, when institutions overlooked security flaws like expired SSL certificates, exposing millions of accounts to fraud. Just as those banks faced backlash and regulatory scrutiny, Coinkite's situation could serve as a timely reminder for the tech industry about the importance of prioritizing user safety over profit. Such a parallel underscores how negligence in safeguarding potential vulnerabilities can spiral into larger crises, leaving users scrambling and questioning their faith in digital finance.