Skip to content

Millions of dollars in wealth found again after 11 years: How were 43 bitcoins recovered?

Oct 30, 12:23
Millions of dollars in wealth found again after 11 years: How were 43 bitcoins recovered?
Original title: "My brother bought dozens of bitcoins 11 years ago. After losing his password, the hacker went through great pains to help him get it back! The process was too tortuous..."
Original source: International Student Uncle


In 2022, a Spanish man named Michael was troubled by a problem.



As early as 2013, he bought 43 bitcoins, which were not popular at the time, for a total price of US$5,300.



He then deposited these coins into an electronic wallet. In order to prevent theft, he used a password software to generate a 20-digit random password.


Michael was worried that using the same software to save the password was not safe enough. If it was cracked by hackers or the computer was lost, the other party could find the password and withdraw his Bitcoin.


So, he cleverly pasted the long string of passwords into a separate document so that no one could see the purpose of the password. He also set a password for the document and encrypted it.



After all these layers of encryption, Michael thought he had an unbreakable Bitcoin account password, and he could withdraw the money as long as Bitcoin rose.


Unexpectedly, Michael eventually fell into his own hands - the encrypted document where he stored the password broke for no reason, and he couldn't open it at all, let alone paste out the 20-digit password.


At the same time, he watched the value of Bitcoin rise from $123 per coin to over $30,000 per coin.



"I have this wealth, I can see it, but I can't use it because I don't have the password."


Over the past years, Michael has been looking for password cracking experts from all parties to see if anyone can help him retrieve the random password generated by the software that year.


But countless network security experts told Michael: 20-digit random password? ! Forget your Bitcoins, they will never be recovered.


When Michael heard the bad news, he once thought that he would not be able to get this huge fortune in his lifetime.


Until 2022, he learned about an American hacker named Joe Grand through the Internet, and then Michael asked Joe for help.



Joe is a world-famous hardware hacker, an electrical engineer and inventor, and his hacking history can be traced back to when he was 10 years old.


He is recognized by the mainstream and also provides consultation to system developers on how they should prevent hackers like him...


Joe also had the experience of helping two strangers find their lost cryptocurrency passwords.


Once, the other party threw the USB flash drive with the password stored into a lake. After the diver salvaged it, Joe restored the function of the USB flash drive through a series of physical means, allowing the other party to find the password stored in it as if the USB flash drive had never been lost.


Another time, it was about deciphering the password. A son in the family died unexpectedly. Before his death, he told his brothers that the Bitcoin password might be related to their grandmother's name, so Joe helped to conduct a "brute force search" around this clue, trying millions of permutations and combinations one after another...



In 2022, Michael contacted Joe through the Internet, but Joe did not agree as before.


The reason is not complicated: Joe is a hardware hacker, and he is not good at this kind of password randomly generated by software.


At the same time, helping people recover cryptocurrency passwords is not his expertise and interest, no matter how high the other party offers.


So, Joe rejected Mike's request that year.



But last summer, when Michael found Joe again in desperation, Joe agreed to give it a try.


This time, it was not Joe who agreed to Mike because he was soft-hearted, but his German partner, a young software hacker, who suggested that they had a certain chance of recovering Mike's lost password.



The young hacker was named Bruno, a German who specialized in software vulnerabilities. Like Joe, Bruno had shown great interest in finding security vulnerabilities in systems and software since he was a child.



Bruno often received people asking him for help with their lost cryptocurrency passwords, but this was the first time he had seen a situation like Mike's.


He suggested to Joe that they might have a chance, and both talented hackers were extremely interested in these difficult but slim-shot projects.


Joe flew to Europe to join Bruno and Mike.



Michael generated the random password through a software called "RoboForm", which is one of the earliest random password generators in the world and is still in use today.


Both Joe and Bruno tested the software and found that it could generate completely different passwords at every moment.


For the two, finding Joe's random password was like looking for a needle in a haystack:



"If we have to try all possible password combinations, that's equivalent to 100 trillion times the number of water droplets in the world.


If we imagine a password as a drop of water, then we'll find that it could be flowing at the bottom of a river, it could fall from the sky, it could be in any ocean anywhere in the world.


If we can somehow reduce this, then we can turn this insurmountable problem into something we can succeed in."


After the two understood how RoboForm worked, they began to look for clues along the timeline that could narrow the search scope.



They soon noticed that in the software version timeline, the update notes for the 2015 version were a little strange:


"We have increased the randomness of password generation."


This sentence made the two genius hackers suspicious: increased randomness? ?


Does this mean that the passwords generated by versions before 2015 are not so random? ?


As geniuses in computer software and hardware, Joe and Bruno have always known that it is actually "very, very difficult" for computers to continuously generate a string of "completely random" numbers at any time. Many random numbers are often related to some reference parameters:


"If we can manipulate this "randomness", we may be able to get a predictable output that can be used to try to crack Michael's wallet password."



But now it is 2023. How can we go back to 10 years ago when Michael created the password and let the software imitate the same actions as Michael did back then?


At this point, the two’s expertise was revealed: they reverse engineered the software, not only changing the software version back to the 2013 version, but also tampering with system data to make the software believe that it was executing a user command from 2013:


“We can trick the system into going back to 2013. It thinks we are still generating passwords within the time window that Michael generated the password.”


Taking the “time machine” back to around 10, the two used a software tool also used by the NSA to try to figure out the pattern of password generation in the past:


“This software is like Russian nesting dolls. Our target is the little doll in the middle that generates passwords.”



Through calculations and tests, the two were pleasantly surprised to find that there was indeed a pattern in the generation of random passwords back then, and that pattern was the system time!


It turns out that the software in 2013 will generate a "pseudo-random password" that is strictly linked to the time when the user creates the password. The password at each moment is directly related to the creation time.


Joe and Bruno were very excited to get the important clues about the password and the time when Mike created the password.


This means that their needle in the haystack range can be greatly narrowed. As long as they know the day and approximate time when Michael created the random password, they can calculate a limited number of passwords and try them one by one.


But unexpectedly, Michael could not remember the exact month and day he opened the software to generate the Bitcoin password ten years ago...


Joe and Bruno did not lose heart and further investigated with great patience.


They found out the time when Michael deposited Bitcoin into the electronic wallet: April 2013.


According to common sense, Michael should have created a random password within a few months before and after this date. So Joe and Bruno set the search time to March to the end of April of that year.


They discussed and calculated all night, waiting for the computer to run the results, but the results disappointed them: no result could unlock Michael's Bitcoin account.



The two had no choice but to contact Michael again and asked him to think carefully about the exact date.


But Michael was also confused. After all, who could remember things that happened 10 years ago so clearly?


However, this time Bruno asked Michael to send him several other passwords he created using the software that year. Joe and Bruno hoped to find some clues from other passwords Michael created using the same software.


The two found that Michael's other two passwords did not contain any special characters (¥…& and similar).


Whether special characters appear in random passwords can be set by the user. Joe and Bruno held on to a glimmer of hope and removed the option of special characters from the search range, and extended the search time to June 1, 2013.


On an ordinary early morning, a special string of numbers and letters suddenly popped up on the computer in front of Bruno:


A unique result popped up on the computer screen!



This result was unexpected by Bruno, the software expert himself. There was actually only one result!



Bruno was overjoyed



The result showed that Michael clicked to create this password at 4:10:40 pm on May 15, 2013…


Last November, Joe and Bruno hid this amazing news from Michael. They ordered a huge foam board with a message saying "$1.6 million for Michael" and successfully checked the board in by plane to Barcelona.



Then, when Michael was still telling the story of how he lost this huge fortune in front of the camera, Joe and Bruno suddenly appeared in front of Michael and told him the good news with a medal!


All three of them were extremely happy.



After 5 months of hard work, Joe and Bruno really turned the previously impossible thing into 100%!


In return, Joe and Bruno received a specific proportion of Bitcoin from Michael's Bitcoin account after successfully cracking the password (they reached an agreement with Michael before looking for the password that they would only charge a fee after the successful decryption).


In November last year, Michael's Bitcoin had risen from $5,300 10 years ago to $1.6 million.


Joe and Bruno made the whole story into a short and exquisite documentary. When the documentary was broadcast in May this year, the $1.6 million had risen to $3 million...


At the end of last year, Michael sold some coins, gave some coins to his benefactors, and kept 30 coins for himself.


He plans to sell the remaining coins when Bitcoin rises to $100,000 per coin.


Finally, in addition to thanking Joe and Bruno, Michael also thanked himself for his “outsmarting”:


“If I hadn’t lost my password, I might not have waited 10 years and would have sold it long ago.”


Well, if it weren’t for the dedicated help of the two hacker geniuses and the fact that the software happened to have a huge system vulnerability in the previous version, Michael’s password would have been thrown into the Pacific Ocean long ago.


I hope he will learn his lesson…


Ref:
https://english.elpais.com/technology/2024-08-14/i-hacked-time-to-recover-3-million-from-a-bitcoin-software-wallet.html
https://www.wired.com/story/roboform-password -3-million-dollar-crypto-wallet/
https://www.forbes.com/sites/daveywinder/2024/05/30/how-bitcoin-hackers-recovered-3-million-from-wallet-locked-in-2013/
https://www.youtube.com/watch?v=o5IySpAkThg


Original link


Recommended

The Wall Street Journal: How is AI Trading Stealing the Limelight from Cryptocurrency?

Aug 15, 14:00
The Wall Street Journal: How is AI Trading Stealing the Limelight from Cryptocurrency?

Tencent Still Has a Dream

Aug 15, 11:27
Tencent Still Has a Dream

To Catch North Korean Hackers, They Set Up a Fake Project

Aug 15, 10:00
To Catch North Korean Hackers, They Set Up a Fake Project

From Litigation to Settlement: Positive Signal Released by HTX's Negotiation with FCA

Aug 14, 19:32
From Litigation to Settlement: Positive Signal Released by HTX's Negotiation with FCA

11,742 Shipping Addresses Exposed Alongside Trezor Orders

Aug 14, 19:01
11,742 Shipping Addresses Exposed Alongside Trezor Orders

Founder Interview: FOMO Creator Explains How They Added 30,000 Users in One Day and Became One of the Fastest-Growing Crypto Apps

Aug 14, 18:37
Founder Interview: FOMO Creator Explains How They Added 30,000 Users in One Day and Became One of the Fastest-Growing Crypto Apps