Arab Press

بالشعب و للشعب
Sunday, Apr 26, 2026

BitcoinPaperWallet ‘Back Door’ Responsible for Millions in Missing Funds, Research Suggests

BitcoinPaperWallet ‘Back Door’ Responsible for Millions in Missing Funds, Research Suggests

It was just past midnight on Jan. 7, 2021, when “Nick Wendell” (a pseudonym) lost half a million dollars in bitcoin.

Bitcoin’s price was roaring toward $40,000, and Wendell was moving some of his bitcoin to a paper wallet generated by BitcoinPaperWallet.com. These wallets allow you to store your private key on a pdf that can then be printed out or saved as a computer file.

Within a minute of depositing 14.5 BTC, worth over $500,000 at the time (and now worth over $700,000), it was all gone. Someone had swept the funds from Wendell’s wallet and, after playing blockchain hopscotch across multiple addresses, sent them to the Binance exchange.

The situation set Wendell’s world spinning.

“Within one minute I realized what happened and it felt like I was falling but [wouldn’t] hit the ground for several minutes. I remember walking in circles around the kitchen as if I were dizzy,” Wendell told CoinDesk.

Wendell is one of at least half a dozen users who claim to have lost dizzying sums to the paper wallet. A quick Google search reveals posts on Reddit, Bitcointalk and elsewhere that tell several individual accounts of a multi-million dollar collective heist: Someone with access to the site appears to be filching user funds through a back door in the code that gives them access to private keys.

In fact, some users of the most popular bitcoin paper wallet generator on Google’s search ranking claim to have collectively lost millions of dollars worth of bitcoin over the past two years, CoinDesk has learned.

It’s poetic if tragic that something called a “paper wallet” is so fragile. While it might seem intuitively sensible to store your bitcoin offline on a slip of paper or a USB drive to protect it from hackers, doing so can be fraught with risk.

Before loss or degradation, a couple of risks associated with storing bitcoin this way, the primary concern is private key generation – in other words, how you are creating your private keys. If you’re using a third-party software to generate a paper wallet, you’re trusting that the generator creates the private key securely.

If the software isn’t honest, then your wallet is vulnerable at its core.

The BitcoinPaperWallet.com back door


According to security researchers, BitcoinPaperWallet.com sends a copy of every private key it generates on behalf of its users to the site’s servers. Whoever has access to the BitcoinPaperWallet’s back end can then access these keys and steal the funds associated with wallets generated on the site.

Colin and Bryan Aulds, two brothers who run the PrivacyPros blog, nearly purchased the website last year. But after they were tipped off to the series of heists during the negotiation process, they began investigating it for fraud and published their findings on their blog.

If you have the MetaMask or MyEtherWallet (MEW) extensions installed on your computer, the app will automatically redirect you to a page warning you that BitcoinPaperWallet.com unsafe. According to MetaMask, the site is registered on their “domain warning list” because “it has been explicitly identified as a malicious site.”

In May of last year, Ethereum wallet provider MyCrypto released a video and tweet thread warning about a “vulnerability” in BitcoinPaperWallet which creates “a back door that leaves you at risk of your funds being stolen.”

The Aulds brothers mention that the code for this particular exploit no longer exists in BitcoinPaperWallet’s build. But something new has replaced it and people are still losing money because “someone is actively changing [the back door] once the current exploit is published widely,” Bryan Aulds told CoinDesk.

CoinDesk spoke with some of the wallet’s victims. One, who asked to remain anonymous, had made incremental deposits into his wallet throughout August 2020. On the 21st of the month, his funds were gone, on their way to the Binance exchange.

“I mistook it for another legit website that I had used years ago. Basically, I googled ‘Bitcoin paper wallet’ and this scam comes up first,” they told CoinDesk.

Another victim interviewed by CoinDesk lost 50.1 BTC in December. The person deposited funds into a wallet generated by the website, went to get a COVID-19 test and came back to find an empty wallet address.

Still another, who also asked to remain anonymous, lost 1.8 BTC in May 2019. One user on Reddit reported losing BCH to the site as well.

Newsletter

Related Articles

Arab Press
0:00
0:00
Close
News Roundup
Strategic Saudi-Bahrain Causeway Closed Amid Security Concerns as Trump Deadline Approaches
Saudi Arabia Keeps Red Sea Oil Exports Flowing Despite Regional Tensions
Pipeline Attack Cuts Significant Share of Saudi Arabia’s Oil Export Capacity
Saudi Business Leader Abudawood Appointed Chairman of Merit Incentives Group
TotalEnergies Confirms Damage at Saudi Refinery Following Security Incident
Saudi Arabia Launches Early Construction Phase for King Salman Stadium Project
Saudi Shift Away from Longstanding Dollar Oil Framework Gains Attention Amid Iran Conflict
Türkiye and Saudi Arabia Resolve Long-Running Transit Visa Dispute
Saudi Oil Capacity and Pipeline Flows Reduced as Supply Risks Intensify
TotalEnergies Reports Damage to Saudi SATORP Refinery Following Security Incidents
Gulf States Assess Prospects of U.S.-Iran Truce as Regional Stability Efforts Intensify
South Korea Resumes Honey Exports to Saudi Arabia Following Sanitary Approval
Saudi Arabia Carries Out Sentences in Eastern Province Following Security Convictions
Saudi Sovereign Wealth Fund Backs King Street’s Regional Credit Strategy
Saudi Arabia Secures World Cup Return as Egypt Celebrates Landmark Qualification
Iran and Saudi Arabia Intensify Diplomatic Engagement Amid Regional Tensions
Russia and Saudi Arabia Open Visa-Free Travel Corridor for Citizens
Saudi Oil Output Capacity Reduced by 600,000 Barrels Per Day Amid Regional Conflict
Saudi Arabia Suspends Operations at Select Energy Sites as Precautionary Measure
Saudi Arabia Halts Operations at Multiple Energy Facilities Amid Heightened Tensions
Global Markets Jolt as Iran Signals Ceasefire Breakdown and Rising Regional Tensions
King Street Aligns with Saudi Sovereign Wealth Fund to Expand Alternative Investments in Middle East
Attack on Saudi Arabia’s Jubail Petrochemical Hub Raises Global Supply Concerns
Debate Emerges Over Saudi Strategic Decisions as Gulf Cooperation Council Dynamics Come Into Focus
Saudi Arabia Expands Full Workforce Localisation to 69 Professions in Major Labour Reform
Emerging Alliance of Pakistan, Turkey, Egypt and Saudi Arabia Signals New Regional Power Dynamic Amid Iran Conflict
Iran Linked to Strikes Across Gulf States Following Refinery Attack Escalation
Saudi Arabia Voices Concern Over Fragile US–Iran Ceasefire Stability
Starmer Warns Sustained Effort Needed to Ensure US–Iran Ceasefire Holds
Saudi Arabia’s Key East-West Oil Pipeline Targeted Following Ceasefire Announcement
Iran Targets Saudi Arabia’s East-West Oil Pipeline in Escalating Regional Tensions
Trump Warns of Civilizational Stakes as Iran Halts Negotiations
Saudi Companies Expand Remote Work Measures Ahead of Iran-Related Security Concerns
Iran Warns of Strikes on Saudi Energy Infrastructure if US Targets Its Facilities
Iran Urges Civilians to Form Human Shields Around Nuclear Sites as Diplomatic Deadline Approaches
Saudi Arabia Raises Oil Prices to Record Premiums Amid Supply Pressures Linked to Iran Conflict
Key Saudi-Bahrain Causeway Closed Amid Heightened Security Concerns Linked to Iran
Formula One Calendar Gap Explained as Fans Await Next Grand Prix
Growing Strain on the Petrodollar System Comes Into Focus Amid Iran Conflict
Reported Strike on Saudi Arabia’s Jubail Complex Raises Global Energy Supply Concerns
FedEx Introduces New Digital Tool to Streamline Imports into Saudi Arabia
Iran Claims Strike on Saudi Arabia’s Jubail Petrochemical Complex Amid Rising Regional Tensions
Taiwan to Source Oil Shipments from Saudi Arabia’s Red Sea Ports
Saudi Arabia Evacuates Riyadh Financial District as Precaution Amid Regional Tensions
Saudi Arabia Balances Ambitious Economic Vision Amid Regional Tensions and Financial Pressures
Budget Saudi Arabia Reports Strong Full-Year 2025 Financial Performance
Saudi Arabia Expands Investment in Capcom With Stake Reaching Six Percent
Saudi Arabia Assesses Significant Economic Impact From Regional Conflict Involving Iran
US Beef Secures Expanded Market Access in Saudi Arabia
×