Skip to content
Crypto Wallet Password Recovery - Crypto Wallet Recovery New Zealand

Wallet password recovery

Crypto Wallet Password Recovery

Constrained-search password recovery against encrypted wallet files

Encrypted wallet files protect their key material behind a password-derived key. When the password is forgotten but the file survives, recovery is a constrained search problem, not blind guessing. People choose patterns, reuse stems, and apply consistent substitutions, so a candidate set built from what you remember is vastly smaller than the full keyspace - and the wallet's format determines how quickly those candidates can be tested. Where the password was genuinely random and nothing is remembered, we tell you that rather than run an open-ended search.

10%recovery fee
Only charged on successful recovery

Meet the team

Meet our recovery experts

A team built on years of experience across New Zealand's most complex crypto matters.

Our methods

How we recover a wallet password

Every recovery is methodical and fully offline. Your key material never leaves our air-gapped equipment, and the work happens in an environment of your choosing.

Constrained brute-force search

Exhaustive testing within a targeted candidate space, rather than against the full keyspace.

  • Modern GPU hardware tests enormous numbers of candidates against an extracted hash
  • Against a constrained, habit-derived space, that throughput is often enough to exhaust every realistic possibility
  • The full keyspace of a strong random password remains out of reach for anyone, so the skill is in narrowing it
  • Masks and rules define the space precisely from remembered length, structure, and character patterns
  • Candidates ordered by likelihood, so probable passwords are tested first
  • Where the space genuinely cannot be constrained, we say so rather than run forever

Habit-based candidate generation

Building a targeted search space from how you actually choose passwords, not from generic wordlists.

  • Interview-led reconstruction of your password habits, reused stems, and recurring components
  • Passwords from other accounts in the same period, since people reuse structure even when they vary the detail
  • Words, names, dates, and number sequences you tend to build passwords around
  • Capitalisation, symbol placement, and suffix conventions specific to you
  • Generic wordlists deprioritised against a personally-derived candidate set
  • Length and composition estimates from anything you remember about the original

Rule-based variation expansion

Generating realistic variations from a small set of remembered fragments.

  • Capitalisation and case patterns applied across remembered stems
  • Character substitutions you habitually make, such as letters for numbers or symbols
  • Appended years, dates, symbols, and suffixes in the positions you tend to use
  • Keyboard-adjacent typos and common mistypes, since the original may have contained one
  • Concatenation of multiple remembered fragments in plausible orders
  • A handful of fragments expanding into a structured, ranked candidate set

Format-aware key derivation testing

Matching the search strategy to the wallet file's actual encryption and derivation format.

  • Wallet format and key derivation function identified before any quote is given
  • Bitcoin Core wallet.dat, with its per-wallet dynamic iteration count read directly from the file
  • Electrum, MultiBit, Armory, and JSON keystore formats, each with their own derivation
  • GPU-accelerated testing where the format's derivation cost permits high throughput
  • Memory-hard or high-iteration formats assessed honestly for realistic candidate rates
  • Throughput and expected coverage stated before any work is agreed

Hash extraction and offline execution

Working from an extracted hash, never the live wallet, on isolated hardware.

  • The password-verification hash extracted from the file, so testing never touches the wallet itself
  • All work performed offline on air-gapped equipment that has never been networked
  • The wallet file never uploaded, transmitted, or stored on any online system
  • Candidate testing parallelised across local GPU hardware
  • The original file left untouched and returned or destroyed at handover

Feasibility assessment and honest scoping

Telling you whether this is worth attempting before you commit to anything.

  • A realistic read on recoverability from what you remember, given the file's derivation cost
  • A clear distinction between a pattern-based password, often recoverable, and a strong random one, which is not
  • Expected candidate coverage and rough timeframe set out before work begins
  • No open-ended "still processing" engagements or vague assurances
  • An honest no on the first call where the numbers do not support proceeding

Failure modes

Failure modes we handle

  • Partial memory of the password stem

    The strongest possible starting position. A remembered core plus systematic variations is a small, fast search space.

  • A short list of candidate passwords from that period

    A handful of likely passwords with substitutions and suffixes applied across each. Frequently resolved same-day.

  • Months of manual guessing in the wallet interface

    Manual entry tests a few candidates a minute. Purpose-built tooling tests orders of magnitude more, and covers variations you would never think to type by hand.

  • A remembered password the wallet keeps rejecting

    Often a character-encoding, keyboard-layout, or capitalisation issue rather than a wrong password. We test the near-variants of what you believe it was.

  • Encrypted wallet file with no password memory at all

    Harder, but rarely hopeless. Password habits are personal and consistent, so what you used elsewhere in that period is genuinely informative.

  • An old wallet.dat from a client version you no longer run

    The file's format and iteration count are read directly from it, so the original software is not needed to attempt recovery.

Scam Warning

Most “crypto recovery” services are scams

If someone contacts you first about recovering your crypto, it's a scam - we only ever work with people who come to us. The rest ask for payment upfront, promise results nobody can promise, and want your recovery phrase typed into a website. Scammers also trade lists of people who've responded before, which is often how they found you.

You'll hear back from Nic or Harry directly - not a call centre. Beware of scammers.

Contact us

Describe your situation in general terms - no recovery phrases or private keys through this form. We will call you back within 24 hours with an honest read on whether wallet password recovery is possible in your case.

  • No fee unless we succeed

    10% of what's recovered, agreed in writing beforehand. Nothing if we fail.

  • We can come to you

    Anywhere in New Zealand, at our cost, for cases of significant value.

  • Nothing is retained

    Keys and phrases are destroyed or returned at the end of the engagement. NDA signed before we start.

Never send a recovery phrase or private key through this form, or through any website. Describe the situation in general terms and we will handle the sensitive detail securely on the call.

No fee unless we succeed. We respond within 24 hours.

FAQ

Wallet password recovery - common questions

Can a forgotten wallet password actually be recovered?

Sometimes. A password built from patterns, remembered fragments, or your usual habits is often recoverable through a targeted search. A long, genuinely random password with nothing remembered about it generally is not, and any service claiming otherwise is not being honest. We tell you which situation you are in on the first call.

Isn't the encryption too strong to break?

The encryption itself is not the thing we defeat. We do not attack AES or the key derivation directly. We test candidate passwords built from your own habits against the file, which is a completely different and far smaller problem than breaking the cipher.

Will you know my password afterwards?

The recovered password is used only to open your wallet, then handled entirely as you instruct. Nothing is retained, all work happens on air-gapped equipment, and funds are moved to a wallet you control at handover.

Can you tell me if it's worth trying before I commit?

Yes, and we would rather do that than take a fee on a long shot. The free assessment gives you a realistic read based on what you remember and the wallet's encryption format. If the numbers do not support it, we say so.

Which wallet file formats do you handle?

Bitcoin Core wallet.dat, Electrum, MultiBit, Armory, and standard JSON keystore files, among others. Each uses a different key-derivation method, which we identify from the file before quoting, because it determines how quickly candidates can be tested.

My wallet file is from an old version I can't run anymore. Does that matter?

No. The encryption parameters, including the iteration count and salt, are read directly from the file itself, so we do not need the original software version to work on it.

How is this different from the recovery "tools" I've seen online?

Anything asking you to upload your wallet file to a website, or to type your password into a form, is a scam. Legitimate password recovery works from an extracted hash on offline hardware, never from your live file on someone else's server.