After Unciphered developed a crack for an old IronKey USB drive to recover 7,002 BTC, the owner declines their help because he agreed to work with other experts
Now a team of hackers has shown they can crack the drive and unlock its fortune. The problem: Thomas doesn't seem to want to let them. — Read: https://www.wired.com/... … @mhoye@mastodon.social : “the process had taken only 200 trillion tries.” — By which they mean, most of one day. — It's difficult to cultivate any sort of intuitive sense of how fast modern computers are. — https://www.wired.com/... Andrew Couts / @couts@mastodon.social : NEW: A team of hackers has done what was supposed to be impossible—they cracked an encrypted IronKey USB drive. One of these drives is believed to hold 7,002 bitcoins, worth today ~$235 million. Now, they just have to get the key's owner to let them try to guess his lost password. @agreenberg has the scoop: https://www.wired.com/... LinkedIn: Eric Michaud : Sometimes it doesn't always go the way you want it. Hell of a ride summiting Project: EVEREST though! — The story of how we made an exploit to open Stefan Thomas 7,002 BTC IronKey. … Forums: r/CryptoCurrency : They Cracked the Code to a Locked USB Drive Worth $235 Million in Bitcoin. Then It Got Weird
Context & Ripple Effects
The case sits within a recurring problem of inaccessible self-custodied crypto: earlier coverage documented people locked out of bitcoin after losing credentials, including the broader wave of stranded bitcoin holdings.
It also extends a pattern in which physical attacks turn supposedly unrecoverable wallet access into a specialist service, following a fault-injection recovery of a Trezor wallet. The unusual wrinkle here is that the demonstrated capability has not yet won the owner’s mandate.
First-order effects
- Unciphered gains a public proof point for its ability to defeat protections on an older IronKey drive, while Stefan Thomas retains control over who attempts the recovery.
- Thomas’s agreement with other experts means the disclosed technical advance does not automatically translate into access to the 7,002 BTC or a commercial engagement for Unciphered.
Second-order effects
- Recovery firms competing for high-value locked wallets will have to differentiate on trust, contractual terms, and operational process—not only on whether they can demonstrate an exploit.
- Owners of older encrypted devices may reassess whether a lost credential is truly final, while vendors and users must distinguish a demonstrated weakness in an old device from the security of other hardware and configurations.
Third-order effects
- If similar recoveries become repeatable, the line between permanently lost crypto and recoverable crypto becomes less fixed, creating a more formal market for specialist recovery services.
- The episode reinforces a long-term tension in self-custody: stronger user control can leave asset recovery dependent on scarce hardware-security expertise when authentication fails.
The trend: Cryptocurrency self-custody is increasingly exposing a recovery market built around exploiting aging hardware and software assumptions.