Beautiful Virgin Islands

Friday, Apr 03, 2026

BitcoinPaperWallet ‘Back Door’ Responsible for Millions in Missing Funds, Research Suggests

BitcoinPaperWallet ‘Back Door’ Responsible for Millions in Missing Funds, Research Suggests

It was just past midnight on Jan. 7, 2021, when “Nick Wendell” (a pseudonym) lost half a million dollars in bitcoin.

Bitcoin’s price was roaring toward $40,000, and Wendell was moving some of his bitcoin to a paper wallet generated by BitcoinPaperWallet.com. These wallets allow you to store your private key on a pdf that can then be printed out or saved as a computer file.

Within a minute of depositing 14.5 BTC, worth over $500,000 at the time (and now worth over $700,000), it was all gone. Someone had swept the funds from Wendell’s wallet and, after playing blockchain hopscotch across multiple addresses, sent them to the Binance exchange.

The situation set Wendell’s world spinning.

“Within one minute I realized what happened and it felt like I was falling but [wouldn’t] hit the ground for several minutes. I remember walking in circles around the kitchen as if I were dizzy,” Wendell told CoinDesk.

Wendell is one of at least half a dozen users who claim to have lost dizzying sums to the paper wallet. A quick Google search reveals posts on Reddit, Bitcointalk and elsewhere that tell several individual accounts of a multi-million dollar collective heist: Someone with access to the site appears to be filching user funds through a back door in the code that gives them access to private keys.

In fact, some users of the most popular bitcoin paper wallet generator on Google’s search ranking claim to have collectively lost millions of dollars worth of bitcoin over the past two years, CoinDesk has learned.

It’s poetic if tragic that something called a “paper wallet” is so fragile. While it might seem intuitively sensible to store your bitcoin offline on a slip of paper or a USB drive to protect it from hackers, doing so can be fraught with risk.

Before loss or degradation, a couple of risks associated with storing bitcoin this way, the primary concern is private key generation – in other words, how you are creating your private keys. If you’re using a third-party software to generate a paper wallet, you’re trusting that the generator creates the private key securely.

If the software isn’t honest, then your wallet is vulnerable at its core.

The BitcoinPaperWallet.com back door


According to security researchers, BitcoinPaperWallet.com sends a copy of every private key it generates on behalf of its users to the site’s servers. Whoever has access to the BitcoinPaperWallet’s back end can then access these keys and steal the funds associated with wallets generated on the site.

Colin and Bryan Aulds, two brothers who run the PrivacyPros blog, nearly purchased the website last year. But after they were tipped off to the series of heists during the negotiation process, they began investigating it for fraud and published their findings on their blog.

If you have the MetaMask or MyEtherWallet (MEW) extensions installed on your computer, the app will automatically redirect you to a page warning you that BitcoinPaperWallet.com unsafe. According to MetaMask, the site is registered on their “domain warning list” because “it has been explicitly identified as a malicious site.”

In May of last year, Ethereum wallet provider MyCrypto released a video and tweet thread warning about a “vulnerability” in BitcoinPaperWallet which creates “a back door that leaves you at risk of your funds being stolen.”

The Aulds brothers mention that the code for this particular exploit no longer exists in BitcoinPaperWallet’s build. But something new has replaced it and people are still losing money because “someone is actively changing [the back door] once the current exploit is published widely,” Bryan Aulds told CoinDesk.

CoinDesk spoke with some of the wallet’s victims. One, who asked to remain anonymous, had made incremental deposits into his wallet throughout August 2020. On the 21st of the month, his funds were gone, on their way to the Binance exchange.

“I mistook it for another legit website that I had used years ago. Basically, I googled ‘Bitcoin paper wallet’ and this scam comes up first,” they told CoinDesk.

Another victim interviewed by CoinDesk lost 50.1 BTC in December. The person deposited funds into a wallet generated by the website, went to get a COVID-19 test and came back to find an empty wallet address.

Still another, who also asked to remain anonymous, lost 1.8 BTC in May 2019. One user on Reddit reported losing BCH to the site as well.

Newsletter

Related Articles

Beautiful Virgin Islands
0:00
0:00
Close
Trump’s Strategic Pressure on UK Seen as Push for Stronger Alignment and Fairer Terms
UK Focuses on Trade Finance to Secure Critical Materials for Defence and Energy Sectors
Majority of UK Businesses Hit by Middle East Conflict While Confidence Holds Firm
UK Royal Navy Faces Renewed Scrutiny as Debate Intensifies Over Capability and Readiness
Reform UK Faces Mounting Distractions as Policy Agenda Struggles to Gain Traction
Investigation Launched Into Northern Cyprus IVF Clinics After UK Families Receive Incorrect Sperm
International Meeting Issues Unified Call to Safeguard Navigation Through Strait of Hormuz
Potential Strait of Hormuz Closure Raises Concerns Over UK Food and Medicine Supply Chains
UK Leads Coalition of Over Forty Nations Urging Iran to Reopen Strait of Hormuz
UK Secures Tariff-Free Access for Medicines in Landmark US Pharma Trade Agreement
King Charles III Invited to Address Joint Session of U.S. Congress in Rare Diplomatic Honor
Debate Grows Over Whether Expanded North Sea Drilling Can Reduce UK Energy Bills
UK Faces Heightened Risk of Jet Fuel Shortages, Airline Chief Warns
UK Ends Police Investigations into Lawful Social Media Posts After Review Finds Overreach
Abramovich Moves to Establish Charity for Frozen Chelsea Sale Proceeds Amid UK Dispute
Starmer Reaffirms NATO Commitment While Responding to Trump’s Strategic Critique
UK Aid Reductions Raise Fears of Severe Human Impact Across Parts of Africa
UK Signals Renewed Push for EU Cooperation as Iran Conflict Reshapes Security Landscape
Bank of England Signals Caution as Bailey Advises Markets Against Expecting Rate Hikes
UK to Convene Global Coalition to Restore Shipping Through Strait of Hormuz
Trump Signals Possible NATO Reassessment, Emphasizes Stronger U.S. Strategic Autonomy
Australia Joins British-Led Efforts to Reopen Strait of Hormuz Amid Escalating Tensions
King Charles Plans US State Visit as UK Strengthens Ties with Trump Leadership
UK Regulator Launches Investigation Into Microsoft’s Business Software Practices
Kanye West Set for High-Profile Return to UK Stage at Wireless Festival
Trump Presses Europe to Strengthen Commitment as Iran Conflict Escalates
UK to Deploy Additional Troops to Middle East Amid Rising Regional Tensions
UK Authorities Face Claims of Heavy-Handed Measures in Monitoring Released Pro-Palestine Activists
Trump Calls on UK to Secure Its Own Energy as Iran Conflict Intensifies
Nigel Farage Declines Invitation to UK Conservative Conference Led by Liz Truss
Trump Warns Allies to Take Responsibility as Rift Deepens with UK and France Over Iran Conflict
How Britain’s Prime Minister Controls U.S. Bomber Access in Escalating Iran Conflict
Trump Urges Allies to Secure Their Own Oil Supplies as Hormuz Crisis Disrupts Global Energy
Russia Expels British Diplomat as UK Pushes Back Against Pressure
White House App Faces Scrutiny After Claims of Continuous User Location Tracking
BBC Faces Scrutiny Over Allegations of Paid Content Linked to Saudi Arabia
UK-France Coastal Patrol Agreement Nears Breakdown Amid Migration Pressures
UK Police Detain Pro-Palestine Activist Again Weeks After Bail Release
FTSE 100 Advances as Energy and Mining Shares Gain Amid Middle East Tensions
Eli Lilly Seeks UK Pricing Deal to Unlock Renewed Pharmaceutical Investment
Three Arrested in UK After Massive Cocaine Haul Discovered Hidden in Banana Shipment
UK Fuel Prices Poised for Further Surge Amid Global Energy Pressures
Apple Subsidiary Penalized by UK Authorities for Breach of Moscow Sanctions
Western Allies Intensify Coordinated Sanctions Strategy Against Russia
UK Lawmakers Face Criticism Over Renewed Push for Social Media Restrictions
Starmer Signals UK Crackdown on Addictive Social Media Features
Rising Costs Push One in Five UK Hospitality Businesses to the Brink of Closure
Man Arrested on Suspicion of Attempted Murder After Car Strikes Pedestrians in UK, Injuring Seven
Escalating Conflict Involving Iran Tightens Fiscal Pressures and Highlights UK Economic Vulnerabilities
UK Moves to Confront Russian ‘Shadow Fleet’ Operating in Its Waters
×