Home
/
Regulatory news
/
Legal cases
/

Ceo and cto face probable charges over coin theft evidence

Retirement Attack Fallout | Top Executives Suspected in Coldcard Coin Theft

By

Daniel Kim

Aug 5, 2026, 05:59 PM

Edited By

Alex Johnson

3 minutes estimated to read

A serious investigation scene showing a CEO and CTO discussing documents about a Bitcoin theft case, looking worried and concerned.
popular

A growing controversy surrounds the leadership at Coinkite, as new findings suggest the CEO and CTO may have played pivotal roles in the theft of over $114 million in Bitcoin. This allegation arises from a series of incidents dating back to 2020, casting a shadow over the companyโ€™s security practices.

Warning Signs Ignored

The timeline begins in December 2020 when CEO Rodolfo Novak, known as NVK, publicly dismissed concerns about a potential retirement attack, suggesting that equipment from vendors would be safe. Interestingly, just ten weeks later, Coinkite's CTO, Peter Gray, implemented questionable changes to the Coldcard's code that affected its randomness generator, which is crucial for secure transactions.

"Look, my money is on people screwing themselves out of their BTC before any vendor tries a retirement attack," Novak had stated, attempting to ease user fears.

As time passed, security researchers flagged the vulnerabilities, but their warnings went unheeded. The CTO shipped flawed updates with a PRNG that jeopardized Bitcoin assets for five years. Notably, a user within a Telegram group observed the issue but was ignored, adding layers to this unfolding narrative of negligence.

The Looming Threat

In a pivotal moment in May 2025, James O'Beirne conducted an audit, raising alarm over the RNG sourced from a suspicious library. Coinkite's response? "If something was wrong, weโ€™d already know about it by now," was their defense, sounding more like a cover-up than a genuine reassurance.

Significant Comments from the Community

The community has voiced mixed feelings, with many demanding accountability:

  • โ€œThis is an inside job waiting to blow up.โ€

  • โ€œWhy werenโ€™t issues addressed earlier?โ€

  • โ€œThe company misled its customers about data privacy and security.โ€

While some maintain skepticism about the potential for executive culpability, patterns indicate a deeper issue within the company's governance. The sentiment surrounding Coinkite ranges from outrage to disbelief, with many folks suggesting that the leadership's actions align suspiciously with the window in which the theft occurred.

Key Insights and Implications

  • ๐Ÿ’ฑ Allegations suggest executives ignored multiple warnings spanning four years.

  • โš ๏ธ Community outcry centers on accountability and transparency in security practices.

  • ๐Ÿ“‰ Observations indicate that many users relied on default settings, leading to losses.

Interestingly, this saga raises questions about corporate responsibility in the tech space. With the heist now a part of public dialogue, attention shifts towards how Coinkite manages its crisis response.

Are we witnessing a failure in security, or something much darker at play? Only time may reveal the truth behind this unfolding drama.

Whatโ€™s Next for Coinkite?

As this scandal continues to unfold, thereโ€™s a strong chance we will see intensified scrutiny from both regulatory bodies and the crypto community. Experts estimate that if charges are filed against the CEO and CTO, it could lead to a significant loss of trust from users, potentially resulting in a sharp decline in user engagement and asset value. Furthermore, if legal actions ensue, Coinkite may face financial penalties that could threaten its operations. This situation could compel the company to implement drastic changes in governance, focusing on security protocols and transparency to regain community confidence.

Echoes of the Past

In an unexpected twist, this scenario mirrors the infamous 2016 Dunbar's number incident in the financial sector, where executives ignored critical warnings about systemic flaws. Just as Coinkite's leadership appeared indifferent to user concerns, executives back then neglected signs showing vulnerabilities in their systems. This case serves as a reminder that sometimes, the loudest alarms can be drowned out by arrogance or complacency, leading to disastrous outcomes. Just like the fallout from Dunbar's number reverberated through the industry for years, Coinkite risks leaving a lasting mark on the crypto landscape unless it addresses these issues head-on.