{"investigation":{"slug":"coinkite","entity_name":"Coinkite","trust_score":15,"severity_base":null,"score_modifier":0,"confidence":0.72,"status":"published","content_type":"investigation","summary":"Coinkite Inc. is a small, privately held Toronto-based Bitcoin hardware company that manufactures the Coldcard wallet. A firmware defect introduced into Coldcard seed generation in March 2021 went undetected for roughly five years — including, per public claims from the developer who flagged it, a specific warning to Coinkite in May 2025 that was dismissed — until attackers began draining wallets on July 30, 2026, ultimately taking an estimated 1,816 BTC (roughly $116–155 million) from more than 5,200 victims. Coinkite has publicly apologized and shipped fixed firmware, but now faces credible, still-unfiled class-action and product-liability litigation threats from law firms in Canada and the UK, alongside separate allegations — unconfirmed by the company — that its own CTO authored the flawed code.","sections":[{"content":"Coinkite Inc. is a privately held Bitcoin hardware and software company headquartered in Toronto, Canada, co-founded by Rodolfo Novak (CEO) and Peter Gray (CTO), who began working together on Bitcoin projects around 2011 and incorporated Coinkite in 2013. The company built its reputation making self-custody hardware including Opendime, Coldcard, Tapsigner, and Satscard, positioning Coldcard in particular as a security-focused alternative to larger competitors such as Ledger and Trezor. Third-party business-data aggregators (PitchBook, Owler, Kona Equity) offer widely varying and unverified estimates of the company's size — from roughly 5 to 100 employees and annual revenue in the low single-digit millions of dollars — but Coinkite does not appear to publicly disclose financial statements, and none of these figures should be treated as authoritative. The company's small apparent scale is relevant to its capacity to satisfy the $116–155 million in claimed losses attributed to the 2026 Coldcard exploit.","heading":"Corporate Profile","sources":[{"url":"https://www.ivey.uwo.ca/media/3784305/coinkite-profile.pdf","name":"Coinkite Profile — Ivey Business School","type":"other","credibility":2},{"url":"https://pitchbook.com/profiles/company/66008-62","name":"Coinkite 2026 Company Profile — PitchBook","type":"other","credibility":3},{"url":"https://www.owler.com/company/coinkite","name":"Coinkite, Inc. Company Profile — Owler","type":"other","credibility":3}],"severity":"medium"},{"content":"The vulnerability traces to a firmware change made around March 2021 that routed Coldcard seed generation through a software library ('libngu') instead of the device's STM32 hardware random-number generator, first shipping in firmware version 4.0.0 (published March 17, 2021 per the post's own metadata) and persisting through versions up to 4.1.9. Coinkite has stated the flaw reduced effective entropy on Mk2/Mk3 devices to roughly 40 bits (from an expected 128) and to roughly 72 bits on Mk4, Mk5 and Q devices — weak enough that private keys could be brute-forced offline without physical access to the device. According to Bitcoin developer James O'Beirne, he identified and flagged the suspicious randomness-handling code to Coinkite during a firmware audit in May 2025 — about fourteen months before the exploit became public — and was told the issue would likely have surfaced already if it were real, rather than receiving a technical rebuttal. This account, reported by CoinDesk and several crypto trade outlets citing O'Beirne's own public statements, is corroborated across multiple outlets but rests substantially on O'Beirne's own disclosures; Coinkite has not publicly confirmed or denied the specifics of the May 2025 exchange. If accurate, it indicates the company had a specific, technically-grounded warning about the exact defect roughly a year before exploitation and did not commission a dedicated entropy audit in response.","heading":"The Entropy Flaw and Coinkite's Prior Knowledge","sources":[{"url":"https://www.coindesk.com/tech/2026/08/17/how-a-bug-in-coldcard-s-code-went-unnoticed-for-years-leading-to-usd100-million-in-hacked-funds","name":"How a bug in Coldcard's code went unnoticed for years, leading to $100 million in hacked funds — CoinDesk","type":"news_article","credibility":2},{"url":"https://phemex.com/academy/coldcard-security-flaw-warning","name":"Coinkite Was Warned 14 Months Early About the Coldcard Flaw — Phemex Academy","type":"community_report","credibility":3},{"url":"https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/","name":"Coldcard Security Advisory — Coinkite Blog","type":"official","credibility":1},{"url":"https://blog.coinkite.com/version-4.0.0-released/","name":"Version 4.0.0 Released — Coinkite Blog","type":"official","credibility":1}],"severity":"critical"},{"content":"Following the exploit, James O'Beirne published an analysis alleging that commits to the vulnerable 'libngu' library, submitted under a pseudonymous GitHub account, are cryptographically traceable via GPG signing keys to Coinkite co-founder and CTO Peter Gray — the same person O'Beirne says dismissed his May 2025 warning. This claim has circulated through multiple crypto-trade outlets (Cryptopolitan, Bitcoin Ethereum News, Cryptonews.net) but originates from O'Beirne's own technical write-up and public posts rather than an independent or regulatory verification, and Coinkite has not publicly responded to the identity claim. This should be treated as an unverified, alleged connection — technically detailed but not corroborated by a neutral third party or by Coinkite — and is flagged as lower-confidence pending independent confirmation.","heading":"Alleged Link Between Coinkite's CTO and the Vulnerable Code","sources":[{"url":"https://www.cryptopolitan.com/coinkite-cto-peter-gray-linked-coldcard-hack/","name":"Coinkite CTO Peter Gray linked to the code behind the $114M Coldcard hack — Cryptopolitan","type":"news_article","credibility":3},{"url":"https://bitcoinethereumnews.com/finance/coinkite-cto-peter-gray-linked-to-the-code-behind-the-114m-coldcard-hack/","name":"Coinkite CTO Peter Gray linked to the code behind the $114M Coldcard hack — Bitcoin Ethereum News","type":"news_article","credibility":3}],"severity":"high"},{"content":"Coinkite published its first Coldcard Security Advisory acknowledging weakened seed entropy, which the company itself dates as originally published July 30, 2026 and updated August 1, 2026. CEO Rodolfo Novak posted a public apology stating the company was taking 'full accountability for the firmware bug,' writing 'I'm sorry and I'm devastated,' and urging affected users to move funds immediately using updated best practices. Coinkite released patched firmware (5.6.0 and later for Mk4/Mk5, 1.5.0Q and later for Q, 4.2.0 and later for Mk3) but has been explicit that firmware updates do not retroactively repair a seed already generated under the vulnerable code — affected users must generate and migrate to an entirely new seed. Coinkite has suggested, without firm attribution, that AI-assisted code review may have been how an attacker (or attackers) found the flaw, given that the Coldcard firmware source has long been publicly auditable. Separately, Coinkite has disputed suggestions that it had definitive advance knowledge of the specific defect, pointing to its own historical disclosure page, which lists 23 prior security-relevant findings dating back to 2019 — though none of those prior disclosures addressed the libngu entropy defect itself.","heading":"Corporate Response to the Exploit","sources":[{"url":"https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/","name":"Coldcard Security Advisory — Coinkite Blog","type":"official","credibility":1},{"url":"https://www.cryptopolitan.com/coldcard-overhauls-data-retention-policy/","name":"Coldcard overhauls data retention policy, prepares for 'legal obligations' from $100M exploit — Cryptopolitan","type":"news_article","credibility":2},{"url":"https://bitcoinmagazine.com/business/coinkite-releases-fixed-firmware-after-coldcard-bug-ai-likely-involved-in-the-hack","name":"Coinkite Releases Fixed Firmware After Coldcard Bug; AI Likely Involved In The Breach — Bitcoin Magazine","type":"news_article","credibility":2},{"url":"https://coinkite.com/historical-disclosures","name":"COLDCARD Security Disclosure History — Coinkite","type":"official","credibility":1}],"severity":"medium"},{"content":"As of mid-August 2026, no class-action lawsuit against Coinkite had been publicly confirmed as filed, but multiple law firms have published victim-facing legal analyses actively assessing litigation. Toronto firm WeirFoulds LLP, working alongside London firm Edmonds Marshall McMahon, identified two potential recovery routes for victims: (1) a direct claim against Coinkite for product liability, negligence, or breach of contract, on the theory that a device marketed for secure self-custody generated private keys from materially weaker entropy than represented, and (2) tracing and attempting to freeze stolen bitcoin as it moves toward exchanges or fiat off-ramps. WeirFoulds partners Benjamin Bathgate and Jessica Stansfield stated they were 'presently assessing potential litigation and investigative steps as part of what might become a broader asset recovery mandate.' WeirFoulds' analysis also flags that Coinkite's terms of service may contain an arbitration clause, and cites UK precedent (Chechetkin v Payward Ltd) suggesting courts have been willing to strike down arbitration clauses that undermine consumer protections — offering victims 'cause for hope' that such clauses could be challenged. UK firms Fieldfisher and Irwin Mitchell have separately published guidance for affected customers analyzing similar product-liability theories. Separately, Thomas Braziel of 117 Partners — a firm previously known for brokering FTX bankruptcy claims — has begun organizing Coldcard victims, according to the Globe and Mail, with Canadian users said to account for over 25% of reported losses. Because Coinkite is a Canadian-registered company, litigation is expected to be centered in Canada, though UK and other jurisdictions' victims may pursue parallel or coordinated claims. The financial exposure implied by these claims ($116–155 million in aggregate victim losses cited across sources) appears large relative to Coinkite's apparent size as a small private company, raising practical questions — separate from liability itself — about victims' ability to recover damages even if litigation succeeds.","heading":"Legal Exposure and Class Action Threat","sources":[{"url":"https://www.weirfoulds.com/the-coldcard-exploit-why-victims-may-have-two-routes-to-recovery","name":"The Coldcard Exploit: Why Victims May Have Two Routes to Recovery — WeirFoulds","type":"other","credibility":2},{"url":"https://www.fieldfisher.com/en/insights/coinkite-coldcard-hack-what-victims-need-to-know","name":"Coldcard hack: what happened and what victims can do to recover — Fieldfisher","type":"other","credibility":2},{"url":"https://www.irwinmitchell.com/news-and-insights/expert-comment/post/102ng7a/coinkite-coldcard-exploit-what-happened-and-what-victims-should-do","name":"Coinkite Coldcard Exploit - What happened and what victims should do — Irwin Mitchell","type":"other","credibility":2},{"url":"https://www.theglobeandmail.com/business/article-ftx-claims-broker-now-courting-victims-155-million-coinkite-inc/","name":"This FTX claims broker is now courting victims of a $155-million hack of a Canadian bitcoin firm — The Globe and Mail","type":"news_article","credibility":1},{"url":"https://news.bitcoin.com/regulation-and-legal/coinkite-faces-class-action-threat-as-bitcoin-wallet-bug-costs-users-over-1300-btc/","name":"Coinkite Faces Class Action Threat as Bitcoin Wallet Bug Costs Users Over 1,300 BTC — Bitcoin.com News","type":"news_article","credibility":2}],"severity":"high"},{"content":"Attackers began draining Coldcard wallets on July 30, 2026, with an initial wave removing approximately 594 BTC (about $38 million at the time) from roughly 500 wallets within 25–41 minutes, according to TRM Labs and multiple news outlets. Across four distinct waves between July 30 and August 3, 2026, total losses reached an estimated 1,816 BTC (approximately $116 million) from more than 5,200 addresses, with some later estimates (Galaxy Research, Elliptic, and the Globe and Mail citing a $155 million figure) placing cumulative losses higher as additional affected wallets were identified. TRM Labs found that transaction construction differed across the four waves, suggesting multiple, seemingly unsophisticated and possibly opportunistic actors rather than a single coordinated group; TechCrunch separately reported blockchain-monitoring firms' assessment that at least a dozen distinct hackers appeared to be involved. This is reported as the largest hardware-wallet exploit on record and one of the largest crypto losses of 2026 overall.","heading":"Scale of the Exploit and Financial Impact","sources":[{"url":"https://www.trmlabs.com/resources/blog/the-largest-hardware-wallet-exploit-of-2026-inside-the-usd-116-million-coldcard-hack","name":"The Largest Hardware Wallet Exploit of 2026: Inside the USD 116 Million Coldcard Hack — TRM Labs","type":"research","credibility":2},{"url":"https://techcrunch.com/2026/08/04/hackers-steal-over-130-million-by-exploiting-bug-in-offline-hardware-wallets/","name":"Hackers steal over $130M by exploiting bug in offline hardware wallets — TechCrunch","type":"news_article","credibility":1},{"url":"https://finance.yahoo.com/markets/crypto/articles/damage-coldcard-hack-reaches-130-142500652.html","name":"Damage From Coldcard Hack Reaches $130 Million — Yahoo Finance","type":"news_article","credibility":1}],"severity":"critical"},{"content":"Coinkite maintains a public historical-disclosures page listing 23 security-relevant findings on Coldcard dating back to January 2019, covering issues such as side-channel and fault-injection attacks against secure elements, coordinator-trust bypasses, and USB debug-interface exposures — several of which were identified through paid third-party audits, including a March 2022 professional review of Mk4 PIN handling and entropy hardening prior to that model's release. This history indicates the company has generally engaged outside security researchers and disclosed findings over its operating life. However, the March 2022 entropy-hardening audit did not catch, and was not scoped to catch, the pre-existing libngu defect already shipping in Mk2/Mk3 firmware since March 2021, and no dedicated end-to-end audit of the seed-generation entropy path across the whole product line appears to have been conducted between the March 2021 introduction of the bug and its public discovery in July 2026 — a gap of roughly five years during which, per CoinDesk's reporting, reviewers (including AI-assisted reviews Coinkite says were run on the code) 'confirmed that the component existed but failed to follow the seed-generation process from beginning to end' to verify which random-number source was actually being used.","heading":"Security Disclosure History and Audit Practices","sources":[{"url":"https://coinkite.com/historical-disclosures","name":"COLDCARD Security Disclosure History — Coinkite","type":"official","credibility":1},{"url":"https://www.coindesk.com/tech/2026/08/17/how-a-bug-in-coldcard-s-code-went-unnoticed-for-years-leading-to-usd100-million-in-hacked-funds","name":"How a bug in Coldcard's code went unnoticed for years, leading to $100 million in hacked funds — CoinDesk","type":"news_article","credibility":2}],"severity":"high"}],"timeline":[{"date":"2013","event":"Coinkite Inc. is incorporated in Toronto by Rodolfo Novak and Peter Gray, following earlier collaboration on Bitcoin projects from around 2011.","source":"Ivey Business School Coinkite Profile","source_url":"https://www.ivey.uwo.ca/media/3784305/coinkite-profile.pdf"},{"date":"2021-03","event":"A firmware change routes Coldcard seed generation through a software library ('libngu') instead of the device's hardware random-number generator, reportedly stemming from a commit made around this time.","source":"Cryptopolitan / CoinDesk reporting on Coinkite CTO code linkage","source_url":"https://www.cryptopolitan.com/coinkite-cto-peter-gray-linked-coldcard-hack/"},{"date":"2021-03","event":"Coinkite publishes firmware version 4.0.0 ('All New Code, Same Great Features'), the first release containing the vulnerable seed-generation code; the flaw persists through firmware 4.1.9.","source":"Coinkite Blog","source_url":"https://blog.coinkite.com/version-4.0.0-released/","date_evidence":"Page metadata records \"datePublished\": \"2021-03-17T00:00:00-12:00\" for the post.","date_original":"2021-03-17"},{"date":"2025-05","event":"Bitcoin developer James O'Beirne says he flagged the suspicious 'libngu' randomness-handling library to Coinkite during a firmware audit and was told the issue would probably have surfaced already if it were real; Coinkite has not confirmed the specifics of this account.","source":"CoinDesk / Phemex Academy","source_url":"https://www.coindesk.com/tech/2026/08/17/how-a-bug-in-coldcard-s-code-went-unnoticed-for-years-leading-to-usd100-million-in-hacked-funds"},{"date":"2026-07-30","event":"Exploitation begins; an initial wave drains roughly 594 BTC (~$38 million) from about 500 Coldcard wallets within 25–41 minutes. Coinkite publishes its first Coldcard Security Advisory the same day.","source":"Coinkite Blog / TRM Labs","source_url":"https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/","date_evidence":"The Coinkite advisory is described as \"Originally published July 30, 2026.\""},{"date":"2026-08-01","event":"Coinkite updates its security advisory with expanded technical guidance and mitigation steps for affected users.","source":"Coinkite Blog","source_url":"https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/","date_evidence":"The advisory is noted as \"updated August 1, 2026 at 2:35 p.m. EDT.\""},{"date":"2026-08","event":"Total attack losses across four waves reach an estimated 1,816 BTC (~$116 million) from over 5,200 addresses by August 3; blockchain monitors Galaxy Research and Elliptic later put combined losses as high as roughly $130-155 million. CEO Rodolfo Novak publicly apologizes and says the company takes 'full accountability for the firmware bug.'","source":"TRM Labs / TechCrunch / Globe and Mail","source_url":"https://www.trmlabs.com/resources/blog/the-largest-hardware-wallet-exploit-of-2026-inside-the-usd-116-million-coldcard-hack"},{"date":"2026-08","event":"Coinkite reverses its customer data-deletion policy, citing the security incident and anticipated legal proceedings; the company had previously routinely erased customer records beyond email and country of residence.","source":"Cryptopolitan","source_url":"https://www.cryptopolitan.com/coldcard-overhauls-data-retention-policy/","date_original":"2026-08-07"},{"date":"2026-08","event":"James O'Beirne publishes analysis alleging that GPG-signed commits to the vulnerable library are traceable to Coinkite CTO Peter Gray, the same person he says dismissed his May 2025 warning; Coinkite does not publicly respond to the claim.","source":"Cryptopolitan / Bitcoin Ethereum News","source_url":"https://www.cryptopolitan.com/coinkite-cto-peter-gray-linked-coldcard-hack/"},{"date":"2026-08","event":"Toronto firm WeirFoulds LLP (with London's Edmonds Marshall McMahon) and UK firms Fieldfisher and Irwin Mitchell publish legal guidance for victims outlining product-liability and negligence claims against Coinkite, plus asset-tracing options; 117 Partners begins organizing victims for potential coordinated claims. No class-action suit is confirmed as filed as of this period.","source":"WeirFoulds / Globe and Mail","source_url":"https://www.weirfoulds.com/the-coldcard-exploit-why-victims-may-have-two-routes-to-recovery"}],"sources_used":[{"url":"https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/","name":"Coldcard Security Advisory — Coinkite Blog","type":"official","archive_url":"http://web.archive.org/web/20260908064733/https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/","credibility":1,"archive_timestamp":"2026-09-08T06:47:33+00:00"},{"url":"https://blog.coinkite.com/version-4.0.0-released/","name":"Version 4.0.0 Released — Coinkite Blog","type":"official","archive_url":"http://web.archive.org/web/20260520170359/http://blog.coinkite.com/version-4.0.0-released/","credibility":1,"archive_timestamp":"2026-05-20T17:03:59+00:00"},{"url":"https://coinkite.com/historical-disclosures","name":"COLDCARD Security Disclosure History — Coinkite","type":"official","archive_url":"http://web.archive.org/web/20260813003856/https://coinkite.com/historical-disclosures","credibility":1,"archive_timestamp":"2026-08-13T00:38:56+00:00"},{"url":"https://www.coindesk.com/tech/2026/08/17/how-a-bug-in-coldcard-s-code-went-unnoticed-for-years-leading-to-usd100-million-in-hacked-funds","name":"How a bug in Coldcard's code went unnoticed for years, leading to $100 million in hacked funds — CoinDesk","type":"news_article","archive_url":"http://web.archive.org/web/20260818105755/https://www.coindesk.com/tech/2026/08/17/how-a-bug-in-coldcard-s-code-went-unnoticed-for-years-leading-to-usd100-million-in-hacked-funds","credibility":2,"archive_timestamp":"2026-08-18T10:57:55+00:00"},{"url":"https://techcrunch.com/2026/08/04/hackers-steal-over-130-million-by-exploiting-bug-in-offline-hardware-wallets/","name":"Hackers steal over $130M by exploiting bug in offline hardware wallets — TechCrunch","type":"news_article","archive_url":"http://web.archive.org/web/20260908064838/https://techcrunch.com/2026/08/04/hackers-steal-over-130-million-by-exploiting-bug-in-offline-hardware-wallets/","credibility":1,"archive_timestamp":"2026-09-08T06:48:38+00:00"},{"url":"https://finance.yahoo.com/markets/crypto/articles/damage-coldcard-hack-reaches-130-142500652.html","name":"Damage From Coldcard Hack Reaches $130 Million — Yahoo Finance","type":"news_article","archive_url":"http://web.archive.org/web/20260810085128/https://finance.yahoo.com/markets/crypto/articles/damage-coldcard-hack-reaches-130-142500652.html","credibility":1,"archive_timestamp":"2026-08-10T08:51:28+00:00"},{"url":"https://www.trmlabs.com/resources/blog/the-largest-hardware-wallet-exploit-of-2026-inside-the-usd-116-million-coldcard-hack","name":"The Largest Hardware Wallet Exploit of 2026: Inside the USD 116 Million Coldcard Hack — TRM Labs","type":"research","archive_url":"http://web.archive.org/web/20260908064819/https://www.trmlabs.com/resources/blog/the-largest-hardware-wallet-exploit-of-2026-inside-the-usd-116-million-coldcard-hack","credibility":2,"archive_timestamp":"2026-09-08T06:48:19+00:00"},{"url":"https://www.theglobeandmail.com/business/article-ftx-claims-broker-now-courting-victims-155-million-coinkite-inc/","name":"This FTX claims broker is now courting victims of a $155-million hack of a Canadian bitcoin firm — The Globe and Mail","type":"news_article","archive_url":null,"credibility":1,"archive_timestamp":null},{"url":"https://www.weirfoulds.com/the-coldcard-exploit-why-victims-may-have-two-routes-to-recovery","name":"The Coldcard Exploit: Why Victims May Have Two Routes to Recovery — WeirFoulds","type":"other","archive_url":"http://web.archive.org/web/20260821175626/https://www.weirfoulds.com/the-coldcard-exploit-why-victims-may-have-two-routes-to-recovery","credibility":2,"archive_timestamp":"2026-08-21T17:56:26+00:00"},{"url":"https://www.fieldfisher.com/en/insights/coinkite-coldcard-hack-what-victims-need-to-know","name":"Coldcard hack: what happened and what victims can do to recover — Fieldfisher","type":"other","archive_url":null,"credibility":2,"archive_timestamp":null},{"url":"https://www.irwinmitchell.com/news-and-insights/expert-comment/post/102ng7a/coinkite-coldcard-exploit-what-happened-and-what-victims-should-do","name":"Coinkite Coldcard Exploit - What happened and what victims should do — Irwin Mitchell","type":"other","archive_url":"https://web.archive.org/web/20260912022028/https://www.irwinmitchell.com/news-and-insights/expert-comment/post/102ng7a/coinkite-coldcard-exploit-what-happened-and-what-victims-should-do","credibility":2,"archive_timestamp":"2026-09-12T02:20:28+00:00"},{"url":"https://news.bitcoin.com/regulation-and-legal/coinkite-faces-class-action-threat-as-bitcoin-wallet-bug-costs-users-over-1300-btc/","name":"Coinkite Faces Class Action Threat as Bitcoin Wallet Bug Costs Users Over 1,300 BTC — Bitcoin.com News","type":"news_article","archive_url":"http://web.archive.org/web/20260803091125/https://news.bitcoin.com/regulation-and-legal/coinkite-faces-class-action-threat-as-bitcoin-wallet-bug-costs-users-over-1300-btc/","credibility":2,"archive_timestamp":"2026-08-03T09:11:25+00:00"},{"url":"https://www.cryptopolitan.com/coldcard-overhauls-data-retention-policy/","name":"Coldcard overhauls data retention policy, prepares for 'legal obligations' from $100M exploit — Cryptopolitan","type":"news_article","archive_url":null,"credibility":2,"archive_timestamp":null},{"url":"https://bitcoinmagazine.com/business/coinkite-releases-fixed-firmware-after-coldcard-bug-ai-likely-involved-in-the-hack","name":"Coinkite Releases Fixed Firmware After Coldcard Bug; AI Likely Involved In The Breach — Bitcoin Magazine","type":"news_article","archive_url":"http://web.archive.org/web/20260910092733/https://bitcoinmagazine.com/business/coinkite-releases-fixed-firmware-after-coldcard-bug-ai-likely-involved-in-the-hack","credibility":2,"archive_timestamp":"2026-09-10T09:27:33+00:00"},{"url":"https://phemex.com/academy/coldcard-security-flaw-warning","name":"Coinkite Was Warned 14 Months Early About the Coldcard Flaw — Phemex Academy","type":"community_report","archive_url":"http://web.archive.org/web/20260821175002/https://phemex.com/academy/coldcard-security-flaw-warning","credibility":3,"archive_timestamp":"2026-08-21T17:50:02+00:00"},{"url":"https://www.cryptopolitan.com/coinkite-cto-peter-gray-linked-coldcard-hack/","name":"Coinkite CTO Peter Gray linked to the code behind the $114M Coldcard hack — Cryptopolitan","type":"news_article","archive_url":"http://web.archive.org/web/20260805021222/https://www.cryptopolitan.com/coinkite-cto-peter-gray-linked-coldcard-hack/","credibility":3,"archive_timestamp":"2026-08-05T02:12:22+00:00"},{"url":"https://bitcoinethereumnews.com/finance/coinkite-cto-peter-gray-linked-to-the-code-behind-the-114m-coldcard-hack/","name":"Coinkite CTO Peter Gray linked to the code behind the $114M Coldcard hack — Bitcoin Ethereum News","type":"news_article","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://www.ivey.uwo.ca/media/3784305/coinkite-profile.pdf","name":"Coinkite Profile — Ivey Business School","type":"other","archive_url":null,"credibility":2,"archive_timestamp":null},{"url":"https://pitchbook.com/profiles/company/66008-62","name":"Coinkite 2026 Company Profile — PitchBook","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://www.owler.com/company/coinkite","name":"Coinkite, Inc. Company Profile — Owler","type":"other","archive_url":"http://web.archive.org/web/20260515070447/https://www.owler.com/company/coinkite","credibility":3,"archive_timestamp":"2026-05-15T07:04:47+00:00"}],"source_tags":[],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-code-investigator","created_at":"2026-09-11T23:23:31.00562+00:00","updated_at":"2026-09-12T02:23:01.100706+00:00"}}