Beautiful Virgin Islands

Wednesday, Jan 21, 2026

BitcoinPaperWallet ‘Back Door’ Responsible for Millions in Missing Funds, Research Suggests

BitcoinPaperWallet ‘Back Door’ Responsible for Millions in Missing Funds, Research Suggests

It was just past midnight on Jan. 7, 2021, when “Nick Wendell” (a pseudonym) lost half a million dollars in bitcoin.

Bitcoin’s price was roaring toward $40,000, and Wendell was moving some of his bitcoin to a paper wallet generated by BitcoinPaperWallet.com. These wallets allow you to store your private key on a pdf that can then be printed out or saved as a computer file.

Within a minute of depositing 14.5 BTC, worth over $500,000 at the time (and now worth over $700,000), it was all gone. Someone had swept the funds from Wendell’s wallet and, after playing blockchain hopscotch across multiple addresses, sent them to the Binance exchange.

The situation set Wendell’s world spinning.

“Within one minute I realized what happened and it felt like I was falling but [wouldn’t] hit the ground for several minutes. I remember walking in circles around the kitchen as if I were dizzy,” Wendell told CoinDesk.

Wendell is one of at least half a dozen users who claim to have lost dizzying sums to the paper wallet. A quick Google search reveals posts on Reddit, Bitcointalk and elsewhere that tell several individual accounts of a multi-million dollar collective heist: Someone with access to the site appears to be filching user funds through a back door in the code that gives them access to private keys.

In fact, some users of the most popular bitcoin paper wallet generator on Google’s search ranking claim to have collectively lost millions of dollars worth of bitcoin over the past two years, CoinDesk has learned.

It’s poetic if tragic that something called a “paper wallet” is so fragile. While it might seem intuitively sensible to store your bitcoin offline on a slip of paper or a USB drive to protect it from hackers, doing so can be fraught with risk.

Before loss or degradation, a couple of risks associated with storing bitcoin this way, the primary concern is private key generation – in other words, how you are creating your private keys. If you’re using a third-party software to generate a paper wallet, you’re trusting that the generator creates the private key securely.

If the software isn’t honest, then your wallet is vulnerable at its core.

The BitcoinPaperWallet.com back door


According to security researchers, BitcoinPaperWallet.com sends a copy of every private key it generates on behalf of its users to the site’s servers. Whoever has access to the BitcoinPaperWallet’s back end can then access these keys and steal the funds associated with wallets generated on the site.

Colin and Bryan Aulds, two brothers who run the PrivacyPros blog, nearly purchased the website last year. But after they were tipped off to the series of heists during the negotiation process, they began investigating it for fraud and published their findings on their blog.

If you have the MetaMask or MyEtherWallet (MEW) extensions installed on your computer, the app will automatically redirect you to a page warning you that BitcoinPaperWallet.com unsafe. According to MetaMask, the site is registered on their “domain warning list” because “it has been explicitly identified as a malicious site.”

In May of last year, Ethereum wallet provider MyCrypto released a video and tweet thread warning about a “vulnerability” in BitcoinPaperWallet which creates “a back door that leaves you at risk of your funds being stolen.”

The Aulds brothers mention that the code for this particular exploit no longer exists in BitcoinPaperWallet’s build. But something new has replaced it and people are still losing money because “someone is actively changing [the back door] once the current exploit is published widely,” Bryan Aulds told CoinDesk.

CoinDesk spoke with some of the wallet’s victims. One, who asked to remain anonymous, had made incremental deposits into his wallet throughout August 2020. On the 21st of the month, his funds were gone, on their way to the Binance exchange.

“I mistook it for another legit website that I had used years ago. Basically, I googled ‘Bitcoin paper wallet’ and this scam comes up first,” they told CoinDesk.

Another victim interviewed by CoinDesk lost 50.1 BTC in December. The person deposited funds into a wallet generated by the website, went to get a COVID-19 test and came back to find an empty wallet address.

Still another, who also asked to remain anonymous, lost 1.8 BTC in May 2019. One user on Reddit reported losing BCH to the site as well.

Newsletter

Related Articles

Beautiful Virgin Islands
0:00
0:00
Close
Starmer Steps Back from Trump’s ‘Board of Peace’ Amid Strained US–UK Relations
Prince Harry’s Lawyer Tells UK Court Daily Mail Was Complicit in Unlawful Privacy Invasions
UK Government Approves China’s ‘Mega Embassy’ in London Amid Debate Over Security and Diplomacy
Trump Cites UK’s Chagos Islands Sovereignty Shift as Justification for Pursuing Greenland Acquisition
UK Government Weighs Australia-Style Social Media Ban for Under-Sixteens Amid Rising Concern Over Online Harm
Trump Aides Say U.S. Has Discussed Offering Asylum to British Jews Amid Growing Antisemitism Concerns
UK Seeks Diplomatic De-escalation with Trump Over Greenland Tariff Threat
Prince Harry Returns to London as High Court Trial Begins Over Alleged Illegal Tabloid Snooping
High-Speed Train Collision in Southern Spain Kills at Least Twenty-One and Injures Scores
Meghan Markle May Return to the U.K. This Summer as Security Review Advances
Trump’s Greenland Tariff Threat Sparks EU Response and Risks Deep Transatlantic Rift
Prince Harry’s High Court Battle With Daily Mail Publisher Begins in London
Trump’s Tariff Escalation Presents Complex Challenges for the UK Economy
UK Prime Minister Starmer Rebukes Trump’s Greenland Tariff Strategy as Transatlantic Tensions Rise
Prince Harry’s Last Press Case in UK Court Signals Potential Turning Point in Media and Royal Relations
OpenAI to Begin Advertising in ChatGPT in Strategic Shift to New Revenue Model
GDP Growth Remains the Most Telling Barometer of Britain’s Economic Health
Prince William and Kate Middleton Stay Away as Prince Harry Visits London Amid Lingering Rift
Britain Braces for Colder Weather and Snow Risk as Temperatures Set to Plunge
Mass Protests Erupt as UK Nears Decision on China’s ‘Mega Embassy’ in London
Prince Harry to Return to UK to Testify in High-Profile Media Trial Against Associated Newspapers
Keir Starmer Rejects Trump’s Greenland Tariff Threat as ‘Completely Wrong’
Trump to hit Europe with 10% tariffs until Greenland deal is agreed
Prince Harry Returns to UK High Court as Final Privacy Trial Against Daily Mail Publisher Begins
Britain Confronts a Billion-Pound Wind Energy Paradox Amid Grid Constraints
The graduate 'jobpocalypse': Entry-level jobs are not shrinking. They are disappearing.
Cybercrime, Inc.: When Crime Becomes an Economy. How the World Accidentally Built a Twenty-Trillion-Dollar Criminal Economy
The Return of the Hands: Why the AI Age Is Rewriting the Meaning of “Real Work”
UK PM Kier Scammer Ridicules Tories With "Kamasutra"
Strategic Restraint, Credible Force, and the Discipline of Power
United Kingdom and Norway Endorse NATO’s ‘Arctic Sentry’ Mission Including Greenland
Woman Claiming to Be Freddie Mercury’s Secret Daughter Dies at Forty-Eight After Rare Cancer Battle
UK Launches First-Ever ‘Town of Culture’ Competition to Celebrate Local Stories and Boost Communities
Planned Sale of Shell and Exxon’s UK Gas Assets to Viaro Energy Collapses Amid Regulatory and Market Hurdles
UK Intensifies Arctic Security Engagement as Trump’s Greenland Rhetoric Fuels Allied Concern
Meghan Markle Could Return to the UK for the First Time in Nearly Four Years If Security Is Secured
Meghan Markle Likely to Return to UK Only if Harry Secures Official Security Cover
UAE Restricts Funding for Emiratis to Study in UK Amid Fears Over Muslim Brotherhood Influence
EU Seeks ‘Farage Clause’ in Brexit Reset Talks to Safeguard Long-Term Agreement Stability
Starmer’s Push to Rally Support for Action Against Elon Musk’s X Faces Setback as Canada Shuns Ban
UK Free School Meals Expansion Faces Political and Budgetary Delays
EU Seeks ‘Farage Clause’ in Brexit Reset Talks With Britain
Germany Hit by Major Airport Strikes Disrupting European Travel
Prince Harry Seeks King Charles’ Support to Open Invictus Games on UK Return
Washington Holds Back as Britain and France Signal Willingness to Deploy Troops in Postwar Ukraine
Elon Musk Accuses UK Government of Suppressing Free Speech as X Faces Potential Ban Over AI-Generated Content
Russia Deploys Hypersonic Missile in Strike on Ukraine
OpenAI and SoftBank Commit One Billion Dollars to Energy and Data Centre Supplier
UK Prime Minister Starmer Reaffirms Support for Danish Sovereignty Over Greenland Amid U.S. Pressure
UK Support Bolsters U.S. Seizure of Russian-Flagged Tanker Marinera in Atlantic Strike on Sanctions Evasion
×