Recovery specialists crack $1B crypto wallet... but find just $10
Bitcoin’s BIP39 standard uses a list of 2,048 words. Source: GitHub Krauss says ReWallet once recovered a 20-character password protecting roughly $3 million after reverse-engineering a flawed password generator. Other cases depend less on technical exploits than on understanding how a particular person creates passwords. That means asking clients about personal preferences like favorite foods and places, children’s names and birthdays, personal milestones or memories. In one case, he says a customer was convinced she had used her children’s names, only to remember that the password was actually a phone number connected to a local delivery service: “She didn’t know why, but then she thought about it, and she realized, oh, okay, it was because on this day I got the package delivered to the store and I thought, okay, this would be a nice password.” Tom Bennet, a Bitcoin educator who has studied wallet security, says there is another particularly confusing category: the passphrase. A passphrase is an additional piece of information layered on top of a seed. Enter a different passphrase, and you don’t necessarily get an error message. You can simply get another valid wallet. He tells Magazine: “A wrong passphrase doesn’t throw an error; it succeeds and shows you a zero balance.” So you can have the correct seed phrase and enter it correctly, and still think your BTC has vanished. “Passphrases also don’t have any features to protect users from themselves; no list of 2,048 valid words, no checksum. So if you’ve forgotten a passphrase, it’s basically the same question again: how random was your passphrase? If it’s sufficiently random, there’s often no way to recover it.” With lost or broken hardware wallets, even having the broken device isn’t always much help. If the wallet’s backup seed phrase survives, the keys can generally be restored on another device. That’s why recovery specialists don’t necessarily need the original hardware, but enough information to reconstruct access to the keys. Related: Irish police open Bitcoin wallet years after keys were apparently lost Recovery can also mean fixing mistakes rather than recovering a lost wallet. Crypto sent to the wrong blockchain, like BNB to Ethereum, may sometimes be recoverable if the receiving wallet is under the user’s control. Brooks says Crypto Asset Recovery has been contracted to crack more than 3,000 wallets belonging to around 1,500 people, and has cracked passwords for about 63% of them. There is, however, a hard boundary. Bennet says: “If your seed is truly random and you lose it completely, your Bitcoin is gone.” That is one of the fundamental trade-offs of self-custody. A Bitcoin wallet does not have a bank-style recovery system or a central administrator who can verify your identity and restore your account. Lucien Bourdon, Bitcoin analyst at hardware wallet maker Trezor, puts it even more starkly. If the wallet backup is lost and the wallet containing the keys is inaccessible, “no recovery company can help.” He warns: “If they could, the wallet could be cracked, and self-custody would be fundamentally compromised.” Thanks to randomness, crypto wallets make guessing a private key effectively impossible. In the recent case of Bitcoin hardware wallet Coldcard, a firmware bug weakened seed randomness on some wallets, making the seeds brute-forceable without physical access. Weak random number generation is not a new problem. Source: Jameson Lopp But if a genuinely random seed or private key has been completely destroyed, the number of possibilities is simply too large. Krauss says recovery specialists can occasionally find technical paths into wallets that owners had assumed were permanently inaccessible, and that old wallet software, corrupted files, poorly generated passwords and hardware vulnerabilities can all create unusual opportunities: “Don’t give up on edge cases.” There is an uncomfortable irony in the recovery business. The person who may be able to help you regain access to your crypto needs the very information that gives someone access to it. A seed phrase isn’t like a password that can be changed after someone sees it. Anyone who possesses the necessary wallet backup can often control the funds. That makes choosing a recovery specialist a security decision in itself. Bourdon says: “If you decide to do it, do the homework. Look for firms with a real track record and reviews you can trace to actual customers. Check that they charge on success rather than up front. And move your funds to a fresh wallet with a new backup as soon as you’re back in.” He says users should also be wary of any unsolicited messages claiming that someone can recover their funds. Krauss says other warning signs include people pushing users onto WhatsApp or contacting them from personal email addresses like Gmail, demanding upfront payments or asking them to open accounts at an exchange. Recovery firms that charge a percentage of successfully recovered funds are not unusual; but paying money upfront to someone who promises to recover a wallet should set alarm bells ringing. Brooks learned another lesson from the Rusty case. While crypto recovery might sound like a technical job, a person who believes they are sitting on millions or billions of dollars can also be a security risk. Crypto Asset Recovery no longer flies out to meet clients in person as it did with Rusty. The company now handles cases remotely, with sensitive wallet information processed through automated and air-gapped systems. Brooks says around 71% of the wallets they crack contain less than $100, and the company doesn’t charge a fee for asset recovery under that amount. If there’s one thing he wishes crypto users knew about asset recovery, it’s this: “Learn what in the world a recovery seed is and why they’re important. That’s the simplest way to make sure you never have to talk to us.” Magazine: Mystery surrounds why an OG burned $1M in Bitcoin
Comments
No comments yet. Start the discussion.