<oembed><type>rich</type><version>1.0</version><author_name>HODL (npub1rt…djtfs)</author_name><author_url>https://nostr.ae/npub1rtlqca8r6auyaw5n5h3l5422dm4sry5dzfee4696fqe8s6qgudks7djtfs</author_url><provider_name>njump</provider_name><provider_url>https://nostr.ae</provider_url><html>From James Obeirne on x “I haven&#39;t told the full story yet, but I came to the same conclusion back in May 2025 when I started doing an audit of `coldcard/firmware`. &#xA;&#xA;I wanted to figure out conclusively where the CC RNG was getting sourced from, and found that it backed up to some shady library called libngu (github.com/switck/libngu) that had literally 6 stars on github and was maintained solely by a pseudoanon tranny.&#xA;&#xA;I knew from past experience that linking to libsecp256k1 from Python was pretty easy, which seemed to be the stated purpose of the library use, and so I was confused about why it was there.&#xA;&#xA;I sent a report to the CC team that I had doubts about whether the true RNG was actually in use, and pointed out that the hardcoded yasmarang constants in libngu were sloppy. I advised they rip the whole thing out and link against libsecp256k1 directly.&#xA;&#xA;I was told that if something was wrong &#34;we&#39;d already know about it by now&#34; and that everything was properly configured for the real boards.&#xA;&#xA;I didn&#39;t follow up rigorously, which was a horrible mistake on my part.”</html></oembed>