Bitcoin Forum
September 27, 2026, 09:36:30 PM *
News: Latest Bitcoin Core release: 31.1 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: 0.5 BTC Reward (~40,000 USD) for recovering the password (hashcat)  (Read 132 times)
mrb000 (OP)
Jr. Member
*
Offline

Activity: 38
Merit: 2


View Profile
September 25, 2026, 03:59:49 PM
Last edit: Today at 02:41:42 PM by mrb000
 #1

0.5 BTC Reward – Recovering a Lost Electrum / LUKS Password

In 2013, someone created an Electrum wallet and set a password on their computer:

Bitcoin address

They used the password daily for approximately two months before moving on to other activities and abandoning the project.

Six months later, they tried to access the system again but could no longer remember the exact password.

What makes this case unusual is that the password had been used repeatedly for two months.

During the first month, they copied it from a piece of paper. After discarding the paper, they continued using the password from memory for another month.

What they remember about the password

They believe they still remember several key characteristics:

  • It contained three uppercase X characters.
  • There were two words placed between the Xs.
  • The prefix was either !x or !z.
  • The suffix was either !@#$% or (12345, depending on whether Shift was being held.
  • The two words they remember are ngn and ymb.
  • They strongly believe that both words had the same length.

Example candidate:

Code:
!zXngnXymbX@#$%

Testing password candidates

For anyone who wants to test password candidates manually, an offline page is available here:

http://mrbianchi.github.io/16btc-luks1/

For those who prefer brute-force or dictionary attacks using Hashcat, the wallet hash is available here:

http://mrbianchi.github.io/16btc-luks1/#/hashcat

My background

I have been recovering cryptocurrency wallets for nearly 10 years within one of the most popular and pioneering Spanish-language Bitcoin communities.

The first public recovery call, in 2018, involved a Litecoin wallet:

Facebook group post – 2018 Litecoin recovery

This was posted on Facebook, not Telegram.

The second public call was made earlier this year:

Reddit – 0.5 BTC reward for recovering the wallet

Feel free to explore the Facebook group to verify my track record or ask other members about me.

Discussion / additional information

I also created a Telegram group to answer questions and exchange ideas, research, and password candidates:

Telegram discussion group

More information provided by the original owner is available there, including:

  • Images
  • PDFs
  • Previously tested password candidates
  • Additional memories and details

The original owner is also participating in the group and can answer questions directly.

Important disclaimer

Quote
Unlike previous cases, I do not possess the encrypted drive, and the Bitcoin address is hypothetical—the result of an analysis.

In the event of a successful recovery, the exchange must take place in person.

The recovered password must not be published, posted, or shared anywhere.
nc50lc
Legendary
*
Offline

Activity: 3276
Merit: 9192


Self-proclaimed Genius


View Profile
Today at 06:49:13 AM
 #2

What makes this case unusual is that the password had been used repeatedly for two months.
Hmm, while your other solved public recovery call looked plausible, this one has some uncertain detail like that.
You're the original poster of this previous public call, right? (posted by someone else in Bitcoin Discussion board)
link: /index.php?topic=5585867.0

And also, please disclose some important information shared in the Telegram Group like the other poster did.
Not all of us here use Telegram.

BTW, this looks more of a "Bitcoin Discussion" topic since it's not about the technicalities of recovering an old Electrum wallet.
The technical skills related to its password-recovery is Linux-related (LUKS) but the main topic is about Bitcoin anyways.

mrb000 (OP)
Jr. Member
*
Offline

Activity: 38
Merit: 2


View Profile
Today at 02:40:50 PM
 #3

What makes this case unusual is that the password had been used repeatedly for two months.
Hmm, while your other solved public recovery call looked plausible, this one has some uncertain detail like that.
You're the original poster of this previous public call, right? (posted by someone else in Bitcoin Discussion board)
link: /index.php?topic=5585867.0

And also, please disclose some important information shared in the Telegram Group like the other poster did.
Not all of us here use Telegram.

BTW, this looks more of a "Bitcoin Discussion" topic since it's not about the technicalities of recovering an old Electrum wallet.
The technical skills related to its password-recovery is Linux-related (LUKS) but the main topic is about Bitcoin anyways.

The link that you shared is of my past open call and is resolved, this is a new one.

The telegram link expired: https://t.me/+KaMUnFrrVSZmNGU5
And I apologize for not offering alternative to telegram, I just need to centralize the discussion
Cricktor
Legendary
*
Offline

Activity: 1624
Merit: 4492



View Profile
Today at 02:51:44 PM
Last edit: Today at 03:07:30 PM by Cricktor
 #4

To me there's even more uncertainties:

So, is Bitcoin address 15npoeYGso1qyFAo7Wzw35s4fXMDh5ryrj confirmed or not (not really relevant to crack the password)?

I have issues with the "clarity" of remembered fragments of the password:
  • There were two words placed between the Xs.
  • The two words they remember are ngn and ycm.
  • They strongly believe that both words had the same length.
When you speak of "words", you mean lowercase strings of characters a--z, not words from some dictionary, between the "X"? It could be valid dictionary words, but it must not necessarily be dictionary words, correct?

Any further constraints regarding word length, minimum 3, maximum length?

If the lowercase strings are not of same length, by how much could they possibly differ?

How about the assumption, that both strings have to differ, i.e. must not be the same?


  • The prefix was either !x or !z.
  • The suffix was either !@#$% or (12345, depending on whether Shift was being held.
Can we assume an American PC keyboard layout? "!z" or "!x", "z" and "x" are in close proximity. I wonder if it also could be uppercase "Z" and "X", because for "!" you have to hold down the shift key.

Suffix !@#$% (shift key held) or 12345 makes sense. You have also "open parenthesis" before the numbers. Why is that, can you clarify?


Code:
!zXngnXycmX@#$%
Your example makes only partly sense, because your suffix is truncated. Huh Should a truncated suffix be considered a valid partial fragment?


I'm trying to narrow ambiguity down to as little as possible because otherwise it blows up the search space or hampers potential cracking success.

And also, please disclose some important information shared in the Telegram Group like the other poster did.
Not all of us here use Telegram.
I don't like it, too, that possibly other valuable information is hidden behind some Telegram group. OP should present everything relevant here when they open a topic here.


At first, it doesn't look like a terrible cracking job, but considering that OP has presumably some years of experience, I wonder why this recovery still resisted cracking. Something's a bit off, I just don't know yet what.

It makes sense to me to attack this with some sort of rule and known fragments based attack via hashcat. Question to OP: has your or the used toolchain been verified that the encryption hash has been correctly extracted?

You state that you had no access to the encrypted LUKS partition. I assume the original owner still has access. Has the original owner verified that they know how to properly extract the encryption hash? (I would always verify my toolchain before I start a potentially lengthy and possibly costly recovery!)

whanau
Member
**
Offline

Activity: 140
Merit: 50


View Profile
Today at 07:46:47 PM
 #5

OOh look, I have this wallet too.

encrypted ckey: a2feb7491bb265c7b839b89d058010b7c69bc4c28d27229bf214d12582c6100a3e1f1b63913cf16 a4f35a63ec97eeca0
public key    : 034a34a670a6c4c2c8e528e9287c1755f9c5641f8211a871db1a8ad49e0286a779
public address: 15npoeYGso1qyFAo7Wzw35s4fXMDh5ryrj

Wallet master if you want to burn power.

Encrypted mkey: 0b381ff38aa27cdf4d35cc22d3fe2208beee3a4519bd860e383f3a114b3a08cb4e7199248ea06d3 92fd9af52c042b4db
IV    : beee3a4519bd860e383f3a114b3a08cb
CT    : 4e7199248ea06d392fd9af52c042b4db
salt  : b6a4588ae3ba3e36

Another waste of time.

Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!