Three ways to hack Bitcoin

A properly set up and used Bitcoin address is virtually impossible to hack. The vastness of possible private keys ensures that it is practically impossible to bruteforce one (or several) Bitcoin addresses. Humans are not machines, however, and humans do make mistakes.

Here, we will list a couple of disasters that have led to compromised private keys and resulted in Bitcoin theft. Consider this a list of how to not produce and use private keys. And maybe as a source of inspiration for finding other exploitable weaknesses when it comes to human handling of private keys.

A good private key should be perfectly random, and until we devise a machine that can output true randomness (if such a thing even exists), we are bound to rely on so-called pseudorandom functions to create private keys. Bitcoin wallet software uses pseudorandomness to create new keys, and until this day, it has worked out very well, which strongly suggests that these methods are good enough. In fact, there is not a single known collision in the history of Bitcoin, i.e. an accidental keypair generation that has led to person A being able to control peron B’s coins. In other words, when your wallet software or your script outputs a new keypair, looking up that the resulting public addresses have been used before is unnecessary and is typically never done.

There are thousands of articles describing the art of creating cryptographically safe private keys. You don’t have to read any of them. With a single line of code in Bash (“sudo apt-get install openssl” first, if necessary)

openssl rand -hex 32

you will produce a 64 character hexadecimal string (256 bits or 32 bytes, if you will) such as

7ed821b0cfa039a69d8403f8b93d5ca008e8c11f6bf9ee3e422854165519f56a

which can be used as an unbreakable private key. Our example is synonymous with these two private keys

5Jn9eY6hNux6Dct7w67b1587bNyxa8iBmouEDiPjurpf3uwXjvT
L1UHAgG9DiiA2hNdbja55KCQ6k2QHF2nYn1XM7hNQJuLwcKFBcDM

that, in turn, control these four public addresses

14z8XV5zRs1iHR4ScppvkjPaz34CLZcTRN
1DLdKSMvgh6C7QEvy8zYXSPp9DhYQGQrU4
35LbfTGPfUAqjsAAr6vsRa8ou5766xhzZH
bc1qsatm4dxhxe8a756xznh6c2p52cctxzqgwkx7lc

The point here is that there isn’t, and will likely never be, enough computational power in the universe to bruteforce these, so unless we hadn’t just written out the private keys, you could never have hacked these public addresses.

Now on to the title list, in order of appearance:

1. Google and the cloud

Until 2014 or so, it was fairly easy to find a decent amount of unencrypted Bitcoin Core wallet files that had unspent Bitcoin in them using a simple Google search phrase, such as “site:dropbox.com wallet.dat”. At the time, all Dropbox accounts came with a public folder, so that everything you put there was exposed to the web, and much of it was picked up and indexed by Google. People were sloppy (or just plain stupid?), and more than one person decided this folder was the perfect place to store a backup of their Bitcoin wallet in. Let us be redundantly clear: saving your wallet file in a public folder, unencrypted too, accessible in any browser, is a really bad idea.

It doesn’t matter that Bitcoin Core has always produced cryptographically safe keypairs, when users make them public online. For the record, another popular search phrase was “inurl:’index of’ wallet.dat”, which would take you to webpages under construction and lists of all files in certain folders. Typically, you never want to make your folder structures open on the web, and this was probably the result of misconfigured web servers.

Nevertheless, why some people decided to upload their wallet files to their webpages in the first place is still an unsolved mystery; we can just conclude that it happened a number of times.

By now in 2020, it seems that Google has finally decided to strike down on these ridiculously simple hacks, and to the best of our knowledge, such search phrases will no longer help you find wallet files. If you know of other search phrases, perhaps using other search engines than Google, that still work, please let us know! We would not be surprised if there still were wallet files to be found on the web that you could right-click and “save as.”

2. Bitcoin ATMs and social media

Bitcoin ATMs are fantastic and will hopefully make the average person more curious and less skeptical about Bitcoin. Since Bitcoin is a digital currency, what you get when you buy Bitcoin in an ATM is not a stack of bills, but rather a simple receipt containing – you guessed it – a private key, practically enough in the form of a QR-code.

Remember when teenagers could get VISA cards and when #MyFirstCreditCard was a thing on Instagram? Same thing here again. Some people are so proud that they just bought their first pieces of a Bitcoin and can’t wait to tell the world. This would be all good if it wasn’t for the fact that enthusiastic newcomers snap photos of their receipts, in which you can clearly see the QR code, and post them on Facebook and Twitter.

Here is one such example, image courtesy Twitter:

Bitcoin ATM receipt

Bitcoin ATM receipt

Let’s hope that is was the rightful owner who spent the coins from

5KENaH6zZfjrmhim96ygs657kVWTZ5b9AaS193XNhLUwByW2sKc
1EmoMxgGMr1KdYNQVzfs7u6YJYBoR2C3Nj

Unfortunately, this is far from the only example we are aware of. Take home message: Do not take photographs of your private keys, and if you do, don’t post them on social media unless you are asking to be robbed in a matter of minutes.

3. Brainwallets

Alright, the story goes something like this. Until 2015, there was a webpage called brainwallet.org, that took any password, calculated its SHA256 hash, and used that as the private key (and it was kind enough to print the corresponding public address). What’s so wrong with that? Using this method you can create keypair that you can easily regenerate – “store them in your brain.” Well, many things are wrong. Humans suck at choosing good and memorable passwords or passphrases. The human brain is terrible with what we call entropy. Tech researcher Ryan Castellucci and co-worker has a splendid talk about it, which we warmly recommend you to watch.

Even though one site ceased operations, the web is littered with similar services still (which we will not link to). Do not use brainwallets! Computers are good at entropy, humans suck, OK? Do not try and store private keys in your brain. We would even say that using a private key that is the hash of something known is a terrible idea.

We have played around with Ryan’s tool Brainflayer and come to the conclusion that people are still using such services or solutions to create keypairs.

One, out of more than 20,000, that we found ourselves is (we don’t think that it has been published elsewhere)

SHA256(“the crow flies at midnight”)
Kz7XDN9UJvpWEq2sVogcUYNeonG9FKxdyxrGfyUqNAKV8jfjcctB
15ytti5HgCvuBXmspJ89Qyfiuv9gNxLqaA

In summary, stay away from brainwallet. Let computers do the computing. Use safe private key generation, as in the beginning of this artkce and you are as safe as can be.

Other methods

Your turn! What else do we have? Of course, there are more attack vectors than these. A relatively recent scientific publication gives us additional leads. But there must be even more. Show us what you got!

One more thing!

Consider the donation address at the bottom of the page. We re-invest all contributions into new projects for btcleak.com. Help us create new content and remain ad-free forever. Thank you.

19 Replies to “Three ways to hack Bitcoin”

  1. Weak generated private keys can also be bruteforced using brainflayer/bitcrack. Some of the guys also using pollard rho to find private keys using public key (see bitcoin talk), of course you would need to know the correct range the keys reside for this to be effective.. also need the compute power to pull off such tasks.

    Reply

  2. By the way, if you want to use Python instead to produce a cryptographically safe private key (HEX), it can be done with two lines of code

    >>> import binascii, os
    >>> binascii.hexlify(os.urandom(32)).decode()
    ‘34914bbaded69c4583666a6a22fc39356307148347815c9efbb5bf6666704470’

    Reply

    1. can you help me please
      i messed up trying to get money for my dad as he is living in france in poviety. If you dont help I will understand.
      thank you

      Reply

  3. swissreplica.io@gmail.com February 14, 2021 at 5:38 PM

    Please contact me, I need to do some work with btc.

    Reply

  4. Dear Sir or Madam
    Hello, I hope you are well and healthy wherever you are in the world.
    I hope you are successful in your work and life.
    I am in Iran, if you have a good financial situation, please help me financially.
    Finally, I am honest, I am married and have two children and I live in a rented house.
    I am not in a good financial position, I am living in hardship due to severe US sanctions and unemployment caused by the Corona virus.
    Please note, we know and everyone knows this world is a mortal world.
    We know and everyone knows that what will remain stable in the sight of God Almighty is goodness and humanity and helping the weak and poor people.
    We know, and everyone knows, that these are governments that oppose each other and cause livelihoods and economic problems for the general public.
    I wish that one day governments would make peace with each other and nations would have a good life together in peace of mind and away from the problems of livelihood and income.
    Please note, my letter is to those who are rich and live in prosperity and peace.
    My letter is addressed to those who have great financial ability.
    So that they can help me financially and I can buy a house.
    I will not hesitate to do you any service I can.
    I desperately ask you not to hesitate to help me financially if you are rich.
    I thank you in advance for your humanity and respect.
    I will be indebted to your service and love for a lifetime.

    Bitcoin wallet address for donation:

    bc1qfqe385evje20u6u55s88nm7974zhpuvdqxxmrj

    Yours Faithfully, H.M
    My Gmail Address:
    Hir.m1350@gmail.com

    Reply

    1. I hope you are well. I just sent you 10,000 BTC to your bitcoin wallet because I felt bad for you. I hope you will now be “indebted to my service” for a lifetime. I expect you to come mow my lawn tomorrow.

      Reply

      1. skata4phyloffasiey@gmail.com July 2, 2021 at 11:23 AM

        If U helpme I’ll pay U back in a year please 1btc

        Reply

      2. Respected all
        I hope you are well and healthy wherever you are in the world.
        we hope you are successful in your work and life.
        if you have a good financial situation, please help me financially.
        Finally, I am honest, I am married and having child children and I live in a own house.
        my two children are studying in MBBS in private college who fees is too high, before COVID-19 my business was sound and having good earnings but due to pandemic i lost my business and now i am not able to pay her MBBS fees.
        Now i sold my own house and living a rented home but still condition is very bad, if i cant pay then may be her studying is affect and i don’t have resorcess for that.

        Please note, we know and everyone knows this world is a mortal world.
        We know and everyone knows that what will remain stable in the sight of God Almighty is goodness and humanity and helping the weak and poor people.
        We know, and everyone knows, that these are governments that oppose each other and cause livelihoods and economic problems for the general public.
        I wish that one day governments would make peace with each other and nations would have a good life together in peace of mind and away from the problems of livelihood and income.
        Please note, my letter is to those who are rich and live in prosperity and peace.

        My letter is addressed to those who have great financial ability.
        So that they can help me financially .
        I will not hesitate to do you any service I can.
        I desperately ask you not to hesitate to help me financially if you are rich.
        I thank you in advance for your humanity and respect.
        I will be indebted to your service and love for a lifetime.
        Please donate of your peny, when my finacial condition will become good then i insha allah i will help to anothers

        Bitcoin wallet address for donation: 3KZC4K4NEfbMiSGALQ3gWfxv33WKKSRwSW
        3DiFTSJyz9YXLcSRG8U4j47RbCsXMCcm5J
        Name Raju
        mail :- jamshedpurscame@gmail.com
        whats app :- +919262658744

        Reply

  5. Hi, my name is Andrew and I am in a very stupid situation because at Covid-19 I lost my job and I can no longer pay the installments at the bank, these installments being for my parents who died last autumn! And for my child’s operation, which cost me 30,000 pounds! if anyone can help me with some money I am very grateful to him and I will always thank him all my life! I wish you all a pleasant day!

    Please contact me if you want to make a payment ! Thank you !
    pdohot@gmail.com

    ETH: 0x81b096f991D2bE24abAf5b00d3445372075D0606
    BTC: 3GYyG5eVngpMEuYCcppywTFnLfZRoVSsY8

    Reply

  6. Good day,

    I’m from Soweto JHB (South Africa), hoping to achieve something positive in mylife threw bitcoin but so far been having no luck…

    Please assist…

    Seeking some donations if possible my BTC address:

    32Pn4AWvq4uyiFBnm1VJGxbBNeyHdUpHye

    Regards

    Reply

  7. Emmanuel Popoola May 30, 2021 at 9:16 AM

    Dear Sir/Ma
    Hello, I am desperately hopeless here with sickness and also short of hope due to the effect of the great pandemic which have brought my business to a ruin.
    Life have been bad here in the hospital which I have been unable to foot the bill here. I also recently wrote a book. I cannot print bulk because of the world pandemic. I am useless now though I wanted to get out of the hospital first then looking for my business to bounce back. I do not really understand how things shall work for me.
    I need an helper that will assist me to overcome liver disease. I do not want to get worse because liver transplant is a real power. I can cope now which means if I am able to foot the bill here things could be better. I want my health first then business later.

    If anyone is financially buoyant anyone in the world should please assist me. Many people people have turn me down with reason not known to me. I need your financial assistance please. Life has been so difficult with my wife and children. My children school fees is on the high side. We have spend everything my wife business is dead for them to feed is like picking from the dustbin. please wipe my tears and I will appreciate whosoever that assist me.

    I am appealing to the wealthy people anywhere in the world. Anyone who is willing to assist me shall receive it back in manifold. may you never experience what I am currently going through. Let someone offer me assistance and millions of people shall rise to assist you whenever you needs assistance.

    Please sir/ma, assist me if you have except you are like me.

    Bitcoin wallet address for donation:

    1JNSzQ9mQTSNJJ52P6VfHo5CGkvsFVnCMb

    Yours Faithfully, Emmanuel Popoola
    My Gmail Address:
    wisdom4christt@gmail.com

    Reply

  8. سلام عليكم سيدي العزيز
    آمل أن تكون بصحة جيدة و صحيا أينما كنت في العالم.
    آمل أن تكون ناجحا في عملك وحياتك طول عمر
    أنا من المغرب عمري 25 عام عاطل عن العامل بسبب المرض لعين وأنا يتيم الاب وامي مريضة جذا عندي 2 اخوه صغار في العمر وأعيش في منزل مستأجر واريد ان اعالج امي
    نحن نعلم أن ما سيبقى مستقرا على مرأى من الله سبحانه وتعالى هو الخير والإنسانية ومساعدة الضعفاء والفقراء واليتام
    رسالتي موجهة إلى أولئك الذين لديهم قدرة مالية كبيرة.
    حتى يتمكنوا من مساعدتي
    ذا كان أي شخص يمكن أن يساعدني مع بعض المال وأنا ممتن جدا له
    سيدي أطلب منك بشدة ألا تتردد في مساعدتي ماليا إذا كنت غنيا ولو شيئ صغير
    اكتب و دموع في عيني من شدة القهرة
    ارجوك ساعدني سيدي سأكون مدينا لخدمتك والحب لمدى الحياة سيدي
    عنوان محفظة بيتكوين للتبرع
    bc1qy6j390x2pvj86ls6g66kslp5t39t0s9459vg2h
    عنوان Gmail الخاص
    بي:horiya12benrassi@gmail.com

    Reply

  9. Millikah Precious July 21, 2021 at 2:40 AM

    Hello I am in need of your help. I have a 2years old nephew who I take care of, I don’t have the money for his medical bill. He has been seriously sick for a week and 2days. His mother abounded him, am the only person he has to look after him. Please I need your financial help for this little boy. I don’t know what else to do or who to beg for help. Please I know thing are hard but anyone who is touched by this boy’s, please help him it will really make a difference in his life. Thanks you all God Bless.

    Bitcoin wallet for donation: bitcoin:bc1qlwdxlsadgpvy9rw5utucffm6qsflp6wjha6dej

    My email. retonzekel@gmail.com

    Reply

  10. Hello, My name is Ryan Mounkes. I am ex-military and usually to much pride to ask for help. My mom Michelle Dague is on her 6th bout with cancer and I am having difficulty holding a job which has everything to do with my ability to interact with people. I moved to Washington state to help my mom and because of my job issue, I have cost her more than I have helped. It actually pisses me off to have to swallow my pride and even ask this. I have no money, My truck has a blown head gasket as of 3 days ago. I lost the private key to my btc wallet quite some time ago so its just sitting there. Could someone help me get back into my btc address, or send me some bitcoin to my new wallet? Im desperate at this point. I can not lose my mom to colan cancer. she is all I have. please respond to this email, redmounkes28@live.com thank you.

    Reply

  11. Hello evryone I found this website I’m really in a bad situation I see all these comment above mine but there probaly all scams I have a real story and I think it sad I’m only 17 looking fo a brighter future my mother is homeless and a drug addict also my dad is a recovering drug addict who I live with he does a lot for me but where does my future stand I have nothing so If ask please if anyone is that kind enough to gift me some bitcoin would be very much appreciated or if you wanna talk contact me ryandanieladams12@gmail.com//

    There is my bitcoin address if anyone will please donate.
    3GEKn1QMWviCLPwFr75Lyi3hXzW6L2GnjS

    Reply

  12. I am Perez Turner from Australia , i want to thank Mr Luis Donald for the help he rendered me with the Blank Atm Card that save my life and my family , i lost my job last year during Corona Virus and ever since then it has been very difficult to take care of my family and pay other bills,while hunting for job online i came across one Lady testimony about Mr Luis Donald Blank Atm Card that help her with capital money to start up a business , at first i was scared to contact him because of the trending news about scams, i told my wife about it and she told me to take the risk and i contacted Mr Luis Donald for the card ,after 2-3 days i received the card from him and follows his instruction on how to used the card ,am so happy today to share this because I have use it to get 45,000 dollars. withdraw the maximum of 3,500 USD daily. Luis Donald is giving out the card just to help the poor. Hack and take money directly from any atm machine vault with the use of atm programmed card which runs in automatic mode.hurry now and contact him on how to get yours.Email: besthackersworld58@gmail.com Text & Call or WhatsApp:+1(475)-701-0611

    Reply

  13. HAVE YOU BEEN IN SEARCH FOR GENUINE HACKER’S ONLINE?. ARE YOU LOOKING FOR A WAY TO GET BLANK ATM CARD HERE IS YOUR OPPORTUNITY NOW

    BLANK ATM CARD :We have specially programmed BLANK ATM CARDS that can be used to hack any ATM machine, these ATM cards can be used to withdraw at the ATM or swipe, stores and outlets. We sell this BLANK CARDS to all our customers and interested buyers worldwide, the BLANK CARDS has a daily withdrawal limit of $5000 in ATM and up to $50,000 spending limit in stores. and also if you are in need of any other cyber hacking services, we are here for you at any time any day. Email :
    Email:officialhackingcompany@gmail.com

    -hack into any kind of phone
    _Increase Credit Scores
    _western union, bitcoin and money gram hacking
    _criminal records deletion
    _BLANK ATM/CREDIT CARDS
    _Hacking of phones(that of your spouse, boss, friends, and see whatever is being discussed behind your back)
    _Security system hacking…and so much more. Contact THEM now and get whatever you want at
    Email:officialhackingcompany@gmail.com
    Visit wesbite:https://officialhackingcom.wixsite.com/official

    Reply

  14. I am so grateful to double my bitcoin through Instantfx trade, i started a small package, im grateful that i have double my income through this legit company that helps you grow your bitcoin and make you grow financially…
    Visit the website now https://www.instantfxtrade.com

    Reply

  15. I’m on the verge of suicide. Anyone who sees this news should help me if there are any good-hearten gods,The gods live in a good mood that can only be helped by the gods to save me,
    I live in India and don’t even own a house,I have two sisters,When the two were married off, the debt was on my necks,My father works as a laborer and my mother works as a housemaid.
    I worked in Dubai and lost my job because of Corona,now ism doing daily wages, work Those who gave the money did not agree and told him to return the money and go.
    If i can not give this month, not everyone will keep me alive or I will die.

    If anyone can help me ?, if you help me, I will pray to them like God for the rest of my life

    My Mail Id-ram134a@gmail.com

    My BTC Address- bc1qy608r5xq399vahkqlyrz35zjsw83q9tq838h8s

    Reply

Leave a Reply

Your email address will not be published.