MultiversX Tracker is Live!

The guide to recovering a blockchain.info `wallet.aes.json` password (2013-era wallets).

Bitcoin Reddit

More / Bitcoin Reddit 10 Views


I keep seeing people give up on old blockchain.info wallets thinking the password is gone forever. Usually is but sometimes it isn't. The password is fine — the hash extraction is silently broken, so even the correct password never verifies and people brute-force for months against garbage. Here's the whole process, every gotcha, in order. I've had an aes file for about 10 years now that I got from an old coworker who at the time told me 'if I can get into it I can have it'. Today I figured I'd make a write up about it

None of this cracks a password from nothing. It tests variations of what you remember. If you recall zero fragments and have no seed phrase, I hope you live for a very long time we're gonna be here for a while. —


0. Before anything: work on a copy

cp wallet.aes.json wallet_backup.aes.json 

Never touch the original. A corrupted source file is the one way to actually lose access.


1. Know which version you have

Looks like Version Extractor flag hashcat mode
Raw base64 blob, no { } v1 --base64 12700
JSON with "pbkdf2_iterations" v2 / v3 / v4 --json 15200

2013 wallets are almost always v1 (a plain base64 string). Peek at it:

head -c 40 wallet.aes.json

Letters/numbers with no braces = v1. Starts with {" and has pbkdf2_iterations = v2+.


2. THE #1 SILENT KILLER: a UTF-8 BOM

If you ever opened the file in Notepad, Windows may have saved it with a byte-order mark — 3 invisible bytes (EF BB BF) at the front. This corrupts extraction and guarantees no password will ever match. Check:

head -c 8 wallet.aes.json | xxd

Starts with efbbbf? You have a BOM. Strip it:

sed '1s/^\xef\xbb\xbf//' wallet.aes.json | tr -d '\r\n' > wallet_clean.aes.json

This single issue is behind a huge share of "correct password won't crack" posts. Check it first, every time.


3. Extract the hash — with the RIGHT tool

The hash prefix tells you which tool actually ran. Get this wrong and nothing downstream works:

Tool Prefix For
bitcoin2john $bitcoin$ Bitcoin Core wallet.dat — NOT this
blockchain2john $blockchain$ / $blockchain$v2$ blockchain.info aes.json — THIS

Extract (v1):

python3 blockchain2john.py --base64 wallet_clean.aes.json

Extract (v2/v3/v4 — the --json flag is mandatory or it errors/misparses):

python3 blockchain2john.py --json wallet_clean.aes.json

blockchain2john.py ships with John the Ripper (jumbo). If yours is old and chokes on v4, grab the latest from the openwall/john repo.


4. Verify the extraction BEFORE you crack

  • Prefix: must be $blockchain$ (v1) or $blockchain$v2$ (v2+). If you see $bitcoin$, you used the wrong tool.
  • Length math (v1): hash is $blockchain$<len>$<hex>. <len> must be a clean multiple of 16 (AES block size). Odd or weird number = broken extraction (usually a leftover BOM).
  • Known false negatives: some wallets whose decrypted JSON starts with address_book (instead of guid) get reported as "wrong password" even when correct. If you're certain of the password and it won't verify, this or a BOM is why — not your memory.

5. Prove the pipeline with a known-answer test

The step everyone skips. Make a throwaway wallet with a password you KNOW, extract it the same way, and crack that first. If the known password pops out, your tool + mode + format are all verified. Now you can trust a "not found" to mean "not in the wordlist" — not "my setup is broken."


6. Crack it

hashcat -m 12700 -a 0 wallet.hash wordlist.txt -r rules/best64.rule

  • -m 12700 for v1, -m 15200 for v2/v3/v4.
  • v1 is only 10 PBKDF2 rounds = fast, millions/sec on a mid GPU. v2+ uses many more iterations = much slower, so lean harder on a targeted wordlist.
  • hashcat flags a hit when the decrypt comes out as clean printable ASCII (valid JSON).

Wordlist beats brute force. Seed it from memory — old passwords, pet/family names, handles, street numbers, the year (2012/2013), favored symbols — then let rules mangle it. Forgotten passwords fall to the owner's own habits. (Real example: The wallet I did today whose password was just Name + birth year'.best64` catches that instantly.)

Prefer a GUI/CPU path? btcrecover runs straight against the aes.json with a token list and handles all versions internally — slower but foolproof for format issues.


7. "I only have my Wallet ID, not the file"

blockchain.info serves the encrypted blob to anyone with the wallet identifier (GUID) — it's encrypted, so that's safe. btcrecover's download-blockchain-wallet.py pulls it down; then you crack it offline. This is the move most people miss when support says "we can't help you."


8. You cracked it — now get your coins

  1. Decrypt offline (btcrecover, or blockchain's official decrypt tool) → you get the private key(s).
  2. Import/sweep into Electrum (New wallet → import keys → sweep) → sends the balance to a fresh address you control. ~10 min.
  3. One private key = TWO legacy addresses (compressed + uncompressed). Old wallets were inconsistent about which they showed — always check both.

9. Check the balance (permanent, all-time ledger)

https://blockstream.info/api/address/<ADDRESS>


Common failure modes (and the real cause)

Symptom Actual cause Fix
"Correct password won't crack" BOM in the file Strip EF BB BF (step 2)
Hash starts $bitcoin$ Wrong tool (bitcoin2john) Use blockchain2john
v2+ won't extract / errors Missing --json flag Add --json
Hash <len> is odd/weird Broken extraction (often BOM) Re-clean, re-extract
Certain password still fails address_book-prefixed wallet false negative Use btcrecover, or newer tooling
"No hashes loaded" Malformed/partial hash Re-extract from a clean copy

TL;DR

Sometimes the password isn't the problem. Check for a BOM, extract with the right tool, verify the length is block-aligned, prove your pipeline on a known wallet, then crack with a memory-seeded wordlist. Diagnose the tooling and you'll solve it in an afternoon with a decent GPU.

Happy to help. Don't send your backup files to weirdos.

submitted by /u/guywhoisry
[link] [comments]
Get BONUS $200 for FREE!

You can get bonuses upto $100 FREE BONUS when you:
💰 Install these recommended apps:
💲 SocialGood - 100% Crypto Back on Everyday Shopping
💲 xPortal - The DeFi For The Next Billion
💲 CryptoTab Browser - Lightweight, fast, and ready to mine!
💰 Register on these recommended exchanges:
🟡 Binance🟡 Bitfinex🟡 Bitmart🟡 Bittrex🟡 Bitget
🟡 CoinEx🟡 Crypto.com🟡 Gate.io🟡 Huobi🟡 Kucoin.



Comments