/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

How researchers recovered access to ~$2M worth of bitcoin stored in a software wallet, using a flaw in a decade-old version of the RoboForm password manager

Thanks to a flaw in a decade-old version of the RoboForm password manager and a bit of luck, researchers were able to unearth …

Wired Kim Zetter

Context & Ripple Effects

The recovery extends a recurring custody problem: users can lose access to crypto when passwords or PINs disappear, while specialists sometimes find technical paths back into old devices or software. A prior hardware-wallet recovery through fault injection showed that access barriers can be bypassed long after the original setup.

This case shifts the focus to legacy password-manager behavior. It also contrasts with the earlier Electrum vulnerability that enabled remote bitcoin theft: the reported RoboForm flaw was used to regain access, but it highlights how old credential-generation weaknesses can affect wallet security years later.

First-order effects

  • Researchers regained access to roughly $2 million in bitcoin in a software wallet by exploiting a flaw in a decade-old RoboForm version.
  • The finding makes credentials tied to that legacy RoboForm release a concrete security concern, especially where they protect high-value wallet access.

Second-order effects

  • Wallet holders and recovery specialists have a reason to review old password-manager installations and archived wallet credentials for exposure or recovery opportunities.
  • The technique reinforces the dual-use nature of crypto recovery research: methods that restore an owner's access can also sharpen the risk assessment for similarly protected wallets.

Third-order effects

  • Crypto custody remains dependent on the durability of software and credential tools, not just the cryptography of the underlying asset; legacy implementation flaws can outlive their original products.
  • If similar cases continue, the market for specialist recovery and legacy-security audits may grow alongside pressure to distinguish legitimate recovery from unauthorized access.

The trend: This is one data point in the growing recognition that long-lived crypto assets inherit the security and recovery limits of the legacy software used to secure them.

Discussion

  • @alexrblackwell @alexrblackwell on x
    @UK_Daniel_Card ... As someone at NSA once told me: If a photon can get in or out, so can we.
  • @kimzetter Kim Zetter on x
    @joegrand @roboform This means that if any of RoboForm's current 6 million users are using passwords generated by the @roboform password manager prior to 2015, before the company silently fixed the flaw, they may have passwords that can be cracked in the same way.
  • @mtoecker @mtoecker on x
    This is significantly worse than presented. Anyone w/ computing resources can work through all the generated combinations for RoboForm. There is a finite amount of time between now and March of 2013, and a finite number of combos to put in. This is rainbow table territory.
  • @k8em0 @k8em0 on x
    One more reason we include Communication in the @LutaSecurity Maturity Model for Vulnerability Coordination. It's an important indicator of measurable security maturity, along side engineering & Organizational maturity. What good are patches that aren't known to affected users?
  • @kimzetter Kim Zetter on x
    Note that @roboform learned of this problem in 2015 and appears to have fixed it in subsequent versions. But the company never told customers about it or urged them to create new passwords. RoboForm also won't say what exactly it did to fix the problem so the fix can be verified
  • @kimzetter Kim Zetter on x
    My latest for @wired. How researchers hacked time to crack an 11-year-old password protecting $3 million in cryptocurrency. They found a significant flaw in RoboForm's password manager that made its pseudo-random-number generator not so random https://www.wired.com/...
  • r/CryptoCurrency r on reddit
    How Researchers Cracked an 11-Year-Old Password to a $3 Million Crypto Wallet
  • r/Bitcoin r on reddit
    How Researchers Cracked an 11-Year-Old Password to a $3 Million Crypto Wallet