Skip to content

Forgotten your password? How AI agents reopen an old Bitcoin wallet

Reading time: seven minutesSecurity and GDPR

A MultiBit wallet from 2015, a forgotten password, no way back in. Using a real case, we show how our SMarTrPenTester approaches recovery, what is realistic, and where the hard limit lies. Honest, with no miracle promises.

The moment the access is gone

There is this one moment. You find an old file, an old folder, maybe a USB stick in a drawer, and on it sits a wallet from years ago. Bitcoin was worth a fraction back then, you bought a small amount and forgot the whole thing. Now you want in, you type the password you thought was safe, and it does not fit. One more try. Nothing again. The password is gone, and with it, seemingly, everything behind it.

This exact case landed on our desk. A MultiBit Classic wallet from 2015, a program that has long since disappeared, with a password nobody could remember. No support, no reset function, no email with a link. With a self custodied wallet there is nobody to ask. That is the price of independence and, at the same time, its biggest trap.

We worked this case with our AI agents, and because it is exactly the kind of task where many people get stuck on their own, we describe here how we went about it. Not as a guide to breaking into other people’s accounts, that would be a crime and is not our topic. But as an honest report of what is technically possible with your own forgotten wallet.

Why a forgotten wallet password is not the same as a lost one

First the good news, and it holds under one condition only. As long as you still have the wallet file, the case is not hopeless. With MultiBit these are small files with endings like .wallet, .key and .info. Inside them sits your private key, but encrypted. The password is the key to the key.

And now the distinction that matters. There are two completely different emergencies that get mixed up all the time:

Password forgotten, file present. The private key is there, just behind a password. This is workable. A forgotten password is a computing problem, not the end of the world.

Wallet file lost or seed gone. If the file itself is missing and you no longer have the recovery words, the so called seed, then access is usually truly unrecoverable. No tool on earth guesses twelve random words out of nothing. That is mathematics, not a question of effort.

The case we are talking about here was the first. File present, password gone. That is the case where work pays off.

How SMarTrPenTester approaches recovery

Our security agent SMarTrPenTester is really there to attack our own platform from the outside before a stranger does. The very same tools that find weaknesses also help bring back a forgotten password on your own wallet. Here is the approach, step by step, the way it ran for us.

Step one: back up before anything happens. The first rule with an old wallet is to touch nothing on the original. We first made a copy of all wallet files and did everything else on the copy only. Anyone who tinkers with the single existing file and damages it may lose the last lifeline. Backing up costs nothing and protects against the most expensive mistake.

Step two: extract the check value. The encrypted part of the wallet file can be turned into a form a recovery tool can compute with, a so called hash. For MultiBit Classic there is a fixed path for this. This hash does not yet reveal the password, it is only the touchstone against which every guess is measured.

Step three: guess smartly instead of blindly. Now the actual tool comes into play, a program called hashcat, which runs on the graphics card and can try millions of passwords per second. There is a dedicated mode for MultiBit. But the decisive point is not raw speed, it is cleverness. Nobody really tries every character combination, that would blow past the age of the universe for a longer password. Instead you work with what is known about the person.

People do not choose random passwords. They take a name, a birth year, the dog from back then, a favourite word with a number tacked on, a capital B instead of a small one. Our agent builds word lists from this and applies rules that reproduce exactly these human patterns. From a remembered fragment, say that the password started with a pet’s name, thousands of plausible variants are formed systematically. That is the difference between a guess that takes years and one that finishes overnight.

Step four: the human stays in charge. While the graphics card computes, SMarTrITGott watches the run, sorts results and reports progress. But the important decisions are always made by a human. Which scraps of memory feed the word lists, how long an approach is allowed to run, when to switch strategy. That is our guiding idea, human with machine. The machine takes on the dull work, the human keeps judgment and control.

What comes next is the most important part

Suppose the password shows up. Then the reflex is understandable, to look straight into the old wallet. Yet this is exactly where the most expensive mistakes happen, which is why this section is the most important in the whole text.

A wallet from 2015, a discontinued program, a password that just became visible again on a networked computer: this combination does not belong back in everyday use. If there really is still something on the wallet, the only safe path is to move the balance to a fresh wallet whose private key was never visible on an internet connected system. Old keys count as burned after such an operation. You trust nothing valuable to them anymore.

On top of that, three principles we give everyone who comes to us with a case like this:

Never type your private key or seed anywhere it could end up. No form on the web, no app that asks for it, no helpful message promising to rescue your wallet for an upfront fee. Anyone who asks for your seed wants your money, not your wellbeing. That is true without exception.

Recovery words belong offline. On paper, in two separate places, never as a photo in the cloud and never in an email to yourself. A seed in the cloud is a seed that is no longer yours alone.

Beware of recovery services that demand upfront payment. A whole scam industry has grown around lost wallets. Trustworthy is whoever never wants to see your seed and never makes you pay in advance.

What AI agents can do for you, and what they cannot

This case stands for a whole class of tasks. A forgotten password, an old file, an access that seems lost. People meet this not only with Bitcoin, but with encrypted archives, old documents, accounts whose security question answers nobody remembers. The method behind it is always the same: back up, extract the check value, guess smartly instead of blindly, and let the human decide.

What our agents contribute is the patient, systematic work for which a human lacks the time and often the tools. What they cannot do is magic. A truly random, long password with no clue at all stays out of reach, and a lost seed stays lost. This honesty is part of the deal, because anything else would be exactly the kind of promise we warned about above.

If you have a similar case, your own old wallet, an encrypted archive, an access you are stuck on, then take a look at what SMarTrAgents can do for you. Nine AI agents in one team, hosted on servers in the EU, at a fixed monthly price. Humans and machine working on a task together, until the access is back or until it is clear that, honestly, it will not be.

And if you are in exactly that moment, the one with the password that no longer fits: keep the file. As long as it exists, nothing is decided yet.


This post describes the recovery of your own forgotten wallet. Accessing other people’s wallets, accounts or devices without permission is a crime. SMarTrAgents assists only with your own access.

More on this: What SMarTrAgents can do · SMarTrPenTester, your security agent · AI against AI, how we secure ourselves

Nine AI agents, one workspace

The agents draft quotes, keep the calendar and sort the inbox, and nothing goes out before you approve it.