Cryptocurrency Users Claim Popular Bitcoin Paper Wallet Generator Compromised, Millions Allegedly Stolen – Bitcoin News


Various forum posts and tweets say that the website bitcoinpaperwallet.com is compromised and people have said that they have lost bitcoin using the paper wallet generator. Three years ago, the website’s domain changed ownership and losses have since been reported on Reddit forums, bitcointalk.org, Twitter, and other public places. The owner of the web portal that generates the paper wallet denies that the platform’s code base is compromised and claims that it has been audited by a security expert.

Bitcoinpaperwallet.com wallet generator site accused of being compromised and insecure

Years ago, a website that was once owned and operated by Canton Becker called bitcoinpaperwallet.com was once an extremely popular paper wallet generator. However, when the website was sold in 2018, the reviews for bitcoinpaperwallet.com turned very negative. The complaints continue to this day and a month ago on Reddit, a user named u / heroiclife created a thread asking people to help him shut down the website.

“Help me crack down on the bitcoinpaperwallet.com scam,” the post explains.

Cryptocurrency Users Claim Popular Bitcoin Paper Wallet Generator Compromised, Millions Allegedly Stolen

Reddit user u / heroiclife said that he was not personally affected, but that he was a cryptocurrency recovery service provider that learned of several cases.

“I have heard from clients who had Bitcoin stolen there. It’s silly to use a paper wallet in 2021, but not everyone knows it, ”said the individual. He also asked if bitcoiners could help send abuse complaints to Enom, the domain registrar, report the abuse to Linode, the web host, and flag the website in Google Safe Browsing as malicious.

Twitter is also full of poles who say that bitcoinpaperwallet.com has been compromised. On January 3, 2021, on the 12th anniversary of Bitcoin, Dustin Dettmer saying: “A friend has just lost all their properties using this website, which appears to be a total scam. How do we close it? We should spread the word about this particular bitcoinpaperwallet.com scam, ”added Dettmer.

On December 13, 2019, a Reddit user named u / maff1989 said that he lost funds after receiving a paper wallet inside a Christmas card.

User claims his $ 700,000 in Bitcoin was sent to another wallet one minute after loading the paper wallet

A month ago, on the web portal stackexchange.com, a user said that he took advantage of the offline bitcoinpaperwallet.com website and sent 14.5 BTC ($ 700k +) to the wallet’s public key. A minute later, his 14.5 BTC were sent to another wallet. “Any advice on what I can do?” I ask. “I have accepted the loss and the lesson (I should have used the generator offline), but I want to make sure this doesn’t happen to others.”

Cryptocurrency Users Claim Popular Bitcoin Paper Wallet Generator Compromised, Millions Allegedly Stolen

After the site was sold in 2018, some Reddit users accused the current owner of becoming “dishonest.” Others have said that it is obvious that the website is not producing private keys as it should. Reddit user u / senor_curioso explains that it can be tested and said:

“Yes, this is how you can prove that the current site is producing predictable keys.

  • Save the HTML generator on the computer
  • Find the long set of “test keys” represented by eckey_test =[{,,,}]; and replace it with a single key pair like this: eckey_test =[{pub:”MUtDQ25Td05uQ0I0Y05ZN0hFc0hja1M4Vjk5bUxFNjJKZQ==”,priv:”NUpreTZtM2lZS2FxTm1NZ2NvaEdYb2o0dXVyVTNXaXhiak54R1N4NmNlbmU3S25FWGR6″}];
  • Now load the generator. It will generate the exact same (predictable) wallet over and over again.
  • The server gives each visitor a different set of “test keys”. They are not used as evidence. They are used as seeds for the random number generator and are obviously kept on the server so they can be stolen later. “

Website owner claims ‘Paper Wallet Generator servers are clean’ and audited by security expert

A recent report written by the author, Colin Harper, details that the website that generates the paper wallet is currently maintained by an individual named Sarkis Sarkissian. In the report, Sarkissian is quoted as saying that the owner has “received complaints from users claiming to have lost their bitcoins while using our website.”

It appears that he was available for comment on the matter at hand. Sarkissian emphasized, however, that the complaints were likely “resolved” or the user found it to be “his own fault.” Harper also asked Sarkissian if he was aware of a “back door” in the codebase of bitcoinpaperwallet.com.

“We have searched our source code for problems present in those documents and we cannot reproduce the same results,” Sarkissian said. “Our servers and source code have been verified clean by [our security expert Jonel Richard]. It is still in reserve and continues to investigate, trying to reproduce the problem found by others ”, insisted the current owner of the website.

The creation of a paper wallet must be handled with great care and it is possible that user error was involved with several of the accusations towards the domain spread around the web. It’s always mentioned in many step-by-step guides, no matter what kind of wallet generator is taken advantage of, it should always be done completely offline. A person trying to create a cryptocurrency paper wallet online, while connected to the web, is extremely vulnerable to hacking attacks.

What do you think of the website bitcoinpaperwallet.com accused of being compromised? Let us know what you think on this topic in the comment section below.

Tags in this story

Accusations, Back Door, Bitcoin, Bitcoin (BTC), Bitcoin Paper Wallet, BTC, BTC Paper Wallet, Claims, Colin Harper, Complaints, Crypto Users, Dustin Dettmer, Exploit, Losing Money, paper wallet, Paper Wallet Generator, Reddit Forums , Sarkis Sarkissian, Stolen Bitcoin, Twitter, Insecure, Vulnerable

Image credits: Shutterstock, Pixabay, Wiki Commons, stackexchange.com,

Disclaimer: This article is for informational purposes only. It is not an offer or direct solicitation of an offer to buy or sell, nor is it a recommendation or endorsement of any product, service or company. Bitcoin.com does not provide investment, tax, legal or accounting advice. Neither the company nor the author are responsible, directly or indirectly, for any damage or loss caused or allegedly caused by or in connection with the use of or reliance on any content, goods or services mentioned in this article.



Source link