Man Finally Recovers His $3 Million Bitcoin Wallet After He Lost His Password In 2013
Electrical engineer Joe Grand and his little team of security researchers were able to hack into an encrypted file holding 43.6 bitcoins, unlocking a cryptocurrency wallet worth $3 million and ultimately saving a man who had forgotten his password 11 years ago.
Taking to his popular YouTube channel on Tuesday (May 28), Joe uploaded a video showing how he had been hired to hack into a man’s highly valuable encrypted file, which he had not been able to access since 2013.
Michael, whose identity was blurred during the 21-minute-long video, which has amassed nearly 300,000 views, emailed Joe for help last year.
Joining forces with his fellow hacker friend Bruno, Joe was able to reverse engineer the RoboForm password generator in order to regenerate passwords that have been generated in the past.
Electrical engineer Joe Grand and his little team of security researchers were able to hack into an encrypted file holding 43.6 bitcoins
Image credits: Joe Grand
RoboForm is a password management software that helps users generate, store, and manage passwords securely.
It creates complex, unique passwords for different accounts, stores them in an encrypted vault, and can autofill login information on websites and applications.
Michael had used a 20-character password with uppercase and lowercase letters, numbers, and special characters.
Image credits: Joe Grand
The password management software then generated the password, which Michael promptly copied and put in the passphrase of his wallet.
He further put the password in a text file that he had subsequently encrypted on his computer.
Unfortunately, a holder of data got corrupted, which caused Michael to lose his password, ultimately locking him out of his cryptocurrency wallet.
They unlocked a cryptocurrency wallet worth $3 million
Image credits: Joe Grand
“At this time I was like okay crap a couple of thousand euros which was painful but okay,” Michael said. “But then that’s when we found out what’s the price [of] Bitcoin.”
At the time, 43 Bitcoin was worth €1.6 million.
“I have this fortune, I can see it, but yeah I can’t use it because I don’t have the password,” Michael recalled.
Image credits: Joe Grand
In 2022, upon discovering that Joe had helped another crypto owner recover access to over $2 million in cryptocurrency, Michael contacted the technology savant.
The IT expert recalled responding that the project wouldn’t work unless they could exploit a bug in RoboForm, so he initially declined to help Michael.
Joe noted that brute-forcing the password—generating a vast list of possible passwords and testing them one by one—was an impractical solution due to its complexity.
Joe and his friend Bruno ultimately saved a man who had forgotten his password 11 years ago
Image credits: Joe Grand
“If we had to try every possible password combination, that’s more than 100 trillion times the number of water drops in the entire world,” the hacker explained.
However, a year later, Michael asked Joe to reconsider, and within that time frame, Brune had done some work in reverse engineering a different type of password generator for a different project.
After accepting helping Michael this time, Joe used a tool developed by the US National Security Agency to disassemble the password generator’s code.
“In a perfect world, when you generate a password with a password generator, you expect to get a unique, random output each time that no one else has,” he explained.
Joe continued: “[But] in this version of RoboForm, it was not the case.
“While RoboForm’s passwords appear to be randomly generated, they’re not.
“With the older versions of this software, if we can control the time, we can control the password.”
RoboForm is a password management software that helps users generate, store, and manage passwords securely
Image credits: Pexels/Karolina Grabowska
Joe was able to trick the system by changing the time back to 2013 when the password was generated, and after a few failed attempts, it finally led to the same password being recreated.
“There was something interesting that we found in that change,” the hacker recalled as he worked on RoboForm’s 2013 version. “It just so happens that Michael was using this earlier version where [the] randomness of the password had not been fixed.”
Joe and Bruno worked to generate millions of potential passwords, and eventually, they cracked the code.
Image credits: joegrandofficial
“Moral of the story: Use insecure password generators,” a viewer commented.
A YouTube user wrote: “That password generator really just generated a password for every second of time lmao.”
A person noted: “Password generator… You had one job!”
A separate individual chimed in: “Moral of the story: Don’t attack the password, attack the system that created the password.”
Upon successfully hacking into Michael’s crypto wallet, Joe told Wired in an article published on Tuesday (May 28): “We ultimately got lucky that our parameters and time range was right.
“If either of those were wrong, we would have … continued to take guesses/shots in the dark.”
“They should split it 50/50,” a reader suggested
They're not all scams. Some rando I found on the internet brute-forced a wallet for me and didn't steal a dime. Asked for a completely reasonable 20%, but that's it. I even offered 40% and he said 20% would be fine. I dunno if he's still active, but he went by "Crypto Expert Recovery" (with email: CryptoExpertRecovery @ Proton. Me).
In my experience, I lost 2 BTC in November of last year while I was trying to double my income through this online bitcoin investment. I soon realized I was scammed, It was too much to take in. After 3 months of depression that lasted till this year a friend recommended I contact this Crypto Recovery Expert (email: CryptoExpertRecovery@Proton.Me) and within some few days of working I got back my stolen bitcoin. I can't still believe it till this day, I am super grateful.
Load More Replies...My father really wanted to purchase a new house for our family, and was dedicated to trying to get enough money for it through investing in crypto. He started using a website called Debiex where he deposited 140k, and allegedly has made more than one million USDT coins (so more than one million US dollars) in only a few months. Just later, his account was frozen and was asked to deposit ~120k in order to unfreeze the account. After a quick internet search, I found out that the website itself is a scam, and is even flagged by Coinbase itself. I searched for a way to get the 140k back, and came across a "Crypto Expert Recovery" has helps recover stolen of missing crypto currencies. I contacted them (CryptoExpertRecovery@Proton.Me) and after handing them all the transaction details in a few days they recovered back my father's bitcoin. This saved him a lot and ended his depression, I can't thank them well enough for putting in the time to helping out my family.
I woke up one morning and when I logged into my trust wallet my bitcoin of over 2.5million has been wiped out, apparently it was sent to an unknown wallet I didn't authorize. This drove me craze for several months until I was advise to contact CryptoExpertRecovery@Proton.Me This was the crypto specialist recovered back my stolen funds and saved me off my depression, these guys are the best. Reach out to them if you are in a similar situation.
Load More Replies...They're not all scams. Some rando I found on the internet brute-forced a wallet for me and didn't steal a dime. Asked for a completely reasonable 20%, but that's it. I even offered 40% and he said 20% would be fine. I dunno if he's still active, but he went by "Crypto Expert Recovery" (with email: CryptoExpertRecovery @ Proton. Me).
In my experience, I lost 2 BTC in November of last year while I was trying to double my income through this online bitcoin investment. I soon realized I was scammed, It was too much to take in. After 3 months of depression that lasted till this year a friend recommended I contact this Crypto Recovery Expert (email: CryptoExpertRecovery@Proton.Me) and within some few days of working I got back my stolen bitcoin. I can't still believe it till this day, I am super grateful.
Load More Replies...My father really wanted to purchase a new house for our family, and was dedicated to trying to get enough money for it through investing in crypto. He started using a website called Debiex where he deposited 140k, and allegedly has made more than one million USDT coins (so more than one million US dollars) in only a few months. Just later, his account was frozen and was asked to deposit ~120k in order to unfreeze the account. After a quick internet search, I found out that the website itself is a scam, and is even flagged by Coinbase itself. I searched for a way to get the 140k back, and came across a "Crypto Expert Recovery" has helps recover stolen of missing crypto currencies. I contacted them (CryptoExpertRecovery@Proton.Me) and after handing them all the transaction details in a few days they recovered back my father's bitcoin. This saved him a lot and ended his depression, I can't thank them well enough for putting in the time to helping out my family.
I woke up one morning and when I logged into my trust wallet my bitcoin of over 2.5million has been wiped out, apparently it was sent to an unknown wallet I didn't authorize. This drove me craze for several months until I was advise to contact CryptoExpertRecovery@Proton.Me This was the crypto specialist recovered back my stolen funds and saved me off my depression, these guys are the best. Reach out to them if you are in a similar situation.
Load More Replies...
-2
132