London Daily

Focus on the big picture.
Monday, Mar 23, 2026

BitcoinPaperWallet ‘Back Door’ Responsible for Millions in Missing Funds, Research Suggests

BitcoinPaperWallet ‘Back Door’ Responsible for Millions in Missing Funds, Research Suggests

It was just past midnight on Jan. 7, 2021, when “Nick Wendell” (a pseudonym) lost half a million dollars in bitcoin.

Bitcoin’s price was roaring toward $40,000, and Wendell was moving some of his bitcoin to a paper wallet generated by BitcoinPaperWallet.com. These wallets allow you to store your private key on a pdf that can then be printed out or saved as a computer file.

Within a minute of depositing 14.5 BTC, worth over $500,000 at the time (and now worth over $700,000), it was all gone. Someone had swept the funds from Wendell’s wallet and, after playing blockchain hopscotch across multiple addresses, sent them to the Binance exchange.

The situation set Wendell’s world spinning.

“Within one minute I realized what happened and it felt like I was falling but [wouldn’t] hit the ground for several minutes. I remember walking in circles around the kitchen as if I were dizzy,” Wendell told CoinDesk.

Wendell is one of at least half a dozen users who claim to have lost dizzying sums to the paper wallet. A quick Google search reveals posts on Reddit, Bitcointalk and elsewhere that tell several individual accounts of a multi-million dollar collective heist: Someone with access to the site appears to be filching user funds through a back door in the code that gives them access to private keys.

In fact, some users of the most popular bitcoin paper wallet generator on Google’s search ranking claim to have collectively lost millions of dollars worth of bitcoin over the past two years, CoinDesk has learned.

It’s poetic if tragic that something called a “paper wallet” is so fragile. While it might seem intuitively sensible to store your bitcoin offline on a slip of paper or a USB drive to protect it from hackers, doing so can be fraught with risk.

Before loss or degradation, a couple of risks associated with storing bitcoin this way, the primary concern is private key generation – in other words, how you are creating your private keys. If you’re using a third-party software to generate a paper wallet, you’re trusting that the generator creates the private key securely.

If the software isn’t honest, then your wallet is vulnerable at its core.

The BitcoinPaperWallet.com back door


According to security researchers, BitcoinPaperWallet.com sends a copy of every private key it generates on behalf of its users to the site’s servers. Whoever has access to the BitcoinPaperWallet’s back end can then access these keys and steal the funds associated with wallets generated on the site.

Colin and Bryan Aulds, two brothers who run the PrivacyPros blog, nearly purchased the website last year. But after they were tipped off to the series of heists during the negotiation process, they began investigating it for fraud and published their findings on their blog.

If you have the MetaMask or MyEtherWallet (MEW) extensions installed on your computer, the app will automatically redirect you to a page warning you that BitcoinPaperWallet.com unsafe. According to MetaMask, the site is registered on their “domain warning list” because “it has been explicitly identified as a malicious site.”

In May of last year, Ethereum wallet provider MyCrypto released a video and tweet thread warning about a “vulnerability” in BitcoinPaperWallet which creates “a back door that leaves you at risk of your funds being stolen.”

The Aulds brothers mention that the code for this particular exploit no longer exists in BitcoinPaperWallet’s build. But something new has replaced it and people are still losing money because “someone is actively changing [the back door] once the current exploit is published widely,” Bryan Aulds told CoinDesk.

CoinDesk spoke with some of the wallet’s victims. One, who asked to remain anonymous, had made incremental deposits into his wallet throughout August 2020. On the 21st of the month, his funds were gone, on their way to the Binance exchange.

“I mistook it for another legit website that I had used years ago. Basically, I googled ‘Bitcoin paper wallet’ and this scam comes up first,” they told CoinDesk.

Another victim interviewed by CoinDesk lost 50.1 BTC in December. The person deposited funds into a wallet generated by the website, went to get a COVID-19 test and came back to find an empty wallet address.

Still another, who also asked to remain anonymous, lost 1.8 BTC in May 2019. One user on Reddit reported losing BCH to the site as well.

Newsletter

Related Articles

0:00
0:00
Close
Duchess of Sussex Secures ‘As Ever’ Trademark Rights in Australia Ahead of High-Profile Visit
UK Reaffirms Security as Officials Reject Claims of Immediate Iranian Missile Threat
Rising Middle East Tensions Spark ‘Trumpflation’ Debate Over Impact on UK Households
UK Minister Says No Evidence Iran Can Strike Europe Despite Heightened Warnings
British-Iranians Voice Safety Concerns to Authorities as Regional Conflict Intensifies
Confirmed Meningitis Cases Linked to Kent Outbreak Revised Down to Twenty
UK Government Sees No Evidence Iran Can Strike London Amid Rising Regional Tensions
Debate Grows Over Recognition of Indigenous Cultural Icons in the United Kingdom
Iran Missile Launch Toward Diego Garcia Raises Questions After Failed Strike on US–UK Base
Donald Trump Amplifies Viral Satirical Clip Highlighting UK–US Political Dynamics
UK Satirical Show Draws Attention with Sketch Referencing Trump and Prince Andrew
Meghan Markle’s Possible UK Return Sparks Renewed Attention on Sussex Role
Starmer Convenes Urgent Talks on Cost-of-Living Pressures Linked to Iran Conflict
Starmer Convenes Urgent Talks on Cost-of-Living Pressures Linked to Iran Conflict
UK Investors Eye Bargain Shares Ahead of ISA Deadline Amid Market Volatility
UK Investors Eye Bargain Shares Ahead of ISA Deadline Amid Market Volatility
Northern Lights Expected Over UK Skies Tonight Amid Strong Solar Activity
UK Condemns Iran Missile Strike and Warns Against Threats to British Personnel
UK Warns of Global Flight Disruptions as Iran Conflict Escalates Under Trump’s Leadership
UK Condemns Iran After Missile Strike Targets Strategic Diego Garcia Base
Deadly Meningitis Outbreak in UK Reinforces Urgency of Vaccination Campaigns
Iran Launches Long-Range Missile Strike on Remote US-UK Base, Signaling Expanded Reach
Iran Launches Long-Range Missile Strike on Remote US-UK Base, Signaling Expanded Reach
UK Rules Out Cyprus Base Role in Joint US Self-Defence Framework
UK Ends Hereditary Peerage Rights in Parliament in Historic Constitutional Reform
Lord Walney Warns of Expanding Iranian Influence Networks Within the United Kingdom
Iranian National Among Two Arrested After Attempt to Access UK Nuclear Submarine Base
Deregulation, Artificial Intelligence, and Fraud Laws Reshape UK Financial Services Landscape
UK Considers Lower Speed Limits to Reduce Fuel Use Amid Escalating Energy Crisis
UK Borrowing Costs Surge to Post-Crisis High as Markets React to Inflation and War Risks
UK Government Prepares Emergency Economic Measures as Iran Conflict Fuels Financial Risks
Meningitis B Outbreak in the UK Raises Urgent Health Warnings as Cases Surge
Iran Issues Stark Warning to Britain Over US Base Access Amid Expanding Conflict
United Kingdom Authorizes US Strikes from British Bases as Iran Threatens Key Shipping Routes
Reform UK Suspends Scottish Candidate Following Financial Misconduct Allegations
Apple issues an unusual warning: this is how your iPhone can be hacked without you doing anything
UK and Nigeria Reach Agreement to Accelerate Return of Irregular Migrants
UK Sets New Aid Priorities Following Significant Budget Reductions
Cyprus President Urges Open Dialogue Over Future of British Sovereign Base Areas
Cyprus President Urges Open Dialogue Over Future of British Sovereign Base Areas
UK Plans 50% Steel Tariffs in Bold Move to Protect Domestic Industry
Iran Conflict Sends Shockwaves Through UK Economy as Energy Costs and Trade Risks Surge
UK Health Officials Warn Kent Meningitis Outbreak Still Active as Cases Continue to Rise
UK Climate Progress Faces Scrutiny Over Reliance on Carbon Accounting Methods
UK Deploys Advisers to United States to Shape Plan for Reopening Strait of Hormuz
Amazon Bets on AI-Driven Alexa Upgrade to Revive UK Smart Speaker Market
UK Abortion Law Changes Spark Strong Response from Church Leaders and Pro-Life Advocates
UK Abortion Law Changes Spark Strong Response from Church Leaders and Pro-Life Advocates
GB News Faces Regulatory Complaints Over On-Air Remarks on ‘Genocide’ Claims
UK Signals Expanded Support for Gulf Allies as Iranian Attacks Intensify Regional Threats
×