{"type":"rich","version":"1.0","author_name":"HODL (npub1rt…djtfs)","author_url":"https://nostr.ae/npub1rtlqca8r6auyaw5n5h3l5422dm4sry5dzfee4696fqe8s6qgudks7djtfs","provider_name":"njump","provider_url":"https://nostr.ae","html":"From James Obeirne on x “I haven't told the full story yet, but I came to the same conclusion back in May 2025 when I started doing an audit of `coldcard/firmware`. \n\nI wanted to figure out conclusively where the CC RNG was getting sourced from, and found that it backed up to some shady library called libngu (github.com/switck/libngu) that had literally 6 stars on github and was maintained solely by a pseudoanon tranny.\n\nI knew from past experience that linking to libsecp256k1 from Python was pretty easy, which seemed to be the stated purpose of the library use, and so I was confused about why it was there.\n\nI sent a report to the CC team that I had doubts about whether the true RNG was actually in use, and pointed out that the hardcoded yasmarang constants in libngu were sloppy. I advised they rip the whole thing out and link against libsecp256k1 directly.\n\nI was told that if something was wrong \"we'd already know about it by now\" and that everything was properly configured for the real boards.\n\nI didn't follow up rigorously, which was a horrible mistake on my part.”"}
