Introduction

The recurring theme of summer 2026 following the shock of the inCulCard1 case, for those who missed the article I recommend reading Alea iacta est: entropy is fucked! was entropy.

Natalie Brunell interviews Jonathan Goodman who lost 18 Bitcoin, roughly equivalent to $1,250,000, since the COLDCARD attack, see the interview on YouTube .

They just stole over a million dollars from me, I don’t have any Bitcoin left… they were savings set aside for my children, being robbed is one thing, being robbed of that amount is another!

Lest we forget, even today the company on display tells us Secure Your Bitcoin….

inCulCard

I hacked a wallet, let’s see how it’s done

If you know of a security flaw and you put together a few machines to process it you get the same result as the hacker attack, this time it happened to COLDCARD tomorrow we don’t know.

Clearly, the purpose is educational but, I’ll show you that I took out a wallet with some funds and I’ll publish it in this article. It is not a sensationalist question, it is a journey of awareness on how, and with disarming simplicity to say the least, it is possible to eliminate all the funds in a crypto wallet.

The school case is a zero entropy in which someone has decided to transact, I transcribe the 24 word seed where you can derive the private key of the wallet and verify the ledger in person and, if someone has inserted funds in the meantime you could theoretically withdraw them and transfer them to your wallet.

The seed: abandon abandon abandon abandon abandon abandon abandon abandon abandon abandon abandon abandon abandon abandon abandon abandon abandon abandon abandon art

The entropy: 00000000000000000000000000000000000000000000000000000000000000

Currently the balance is zero with 28 transactions, the last transaction dates back to 03/19/2026 and the first to 06/15/2022.

inCulCard

It makes sense to use hardware wallet

Teachings of computer gurus:

  • No computer is safe, the only one is the one disconnected from the network and with the plug removed.
  • The more you put elements within a computer chain, the more the attack surface increases.

If you put a hardware wallet in a chain you only increase the risks. Ah, what are hardware wallets? They are those little plastic boxes, so cute and technological, that allow the companies that produce them to earn enormous amounts of money, receiving in exchange the possibility of making, so to speak, your crypto life simpler.

Hardware wallets, in addition to having IT bugs, are all hackable at the hardware level. Through laser abrasion with sophisticated machines by those who are in physical possession of the device, it is possible to recover the seed (the private key) written on the memory chip.

It is not known, but it is plausible that some insert hidden values ​​in the transaction signature, subsequently read on the blockchain, which would allow the wallet manufacturer to carry out reconstructions of sensitive data.

These hardware wallets are very simple and inexpensive (even if you pay ten times more for them than for gold), often use MicroPython as the programming language and make use of the external processing capacity of cryptographic processors.

Do you trust the companies that produce little plastic box?

Do you trust the companies that produce the hardware wallet if even they are not able to protect themselves from hacker attacks?

I’ll give you two examples from memory:

  1. June 2020 - Ledger data breach more than one million personal data with email addresses, source .
  2. August 2028 - Trezor warns 14,000 customers after fulfillment partner suffers data breach, source .

BalziBox hardware wallet

Some time ago I thought about creating a company that created the BalziBox hardware wallet, I would have made a little money which doesn’t hurt. Well I should have moved to Switzerland because that’s how it works, a Swiss company has more emotional credibility. By staying in Naples I would have sold the only device to aunt Clorinda!

I’ve been playing around a bit with the Microchip ATECC608 cryptographic processor. Among the various features it has Internal high-quality FIPS 800-90 A/B/C Random Number Generator (RNG) at least stronger than COLDCARD!

ATECC608

  1. June 2020 - Ledger data breach more than one million personal data with email addresses, source .
  2. August 2028 - Trezor warns 14,000 customers after fulfillment partner suffers data breach, source .

  1. A little vulgar, I apologize to the readers. Read as fuck Cold Card or for all those who took it fucked by the company Coinkite producer of the Bitcoin COLDCARD hardware wallet. ↩︎