I keep seeing people give up on old blockchain.info wallets thinking the password is gone forever. Usually is but sometimes it isn't. The password is fine — the hash extraction is silently broken, so even the correct password never verifies and people brute-force for months against garbage. Here's the whole process, every gotcha, in order. I've had an aes file for about 10 years now that I got from an old coworker who at the time told me 'if I can get into it I can have it'. Today I figured I'd make a write up about it
None of this cracks a password from nothing. It tests variations of what you remember. If you recall zero fragments and have no seed phrase, I hope you live for a very long time we're gonna be here for a while. —
0. Before anything: work on a copy
cp wallet.aes.json wallet_backup.aes.json Never touch the original. A corrupted source file is the one way to actually lose access.
1. Know which version you have
| Looks like | Version | Extractor flag | hashcat mode |
|---|---|---|---|
Raw base64 blob, no { } | v1 | --base64 | 12700 |
JSON with "pbkdf2_iterations" | v2 / v3 / v4 | --json | 15200 |
2013 wallets are almost always v1 (a plain base64 string). Peek at it:
head -c 40 wallet.aes.json
Letters/numbers with no braces = v1. Starts with {" and has pbkdf2_iterations = v2+.
2. THE #1 SILENT KILLER: a UTF-8 BOM
If you ever opened the file in Notepad, Windows may have saved it with a byte-order mark — 3 invisible bytes (EF BB BF) at the front. This corrupts extraction and guarantees no password will ever match. Check:
head -c 8 wallet.aes.json | xxd
Starts with efbbbf? You have a BOM. Strip it:
sed '1s/^\xef\xbb\xbf//' wallet.aes.json | tr -d '\r\n' > wallet_clean.aes.json
This single issue is behind a huge share of "correct password won't crack" posts. Check it first, every time.
3. Extract the hash — with the RIGHT tool
The hash prefix tells you which tool actually ran. Get this wrong and nothing downstream works:
| Tool | Prefix | For |
|---|---|---|
bitcoin2john | $bitcoin$ | Bitcoin Core wallet.dat — NOT this |
blockchain2john | $blockchain$ / $blockchain$v2$ | blockchain.info aes.json — THIS |
Extract (v1):
python3 blockchain2john.py --base64 wallet_clean.aes.json
Extract (v2/v3/v4 — the --json flag is mandatory or it errors/misparses):
python3 blockchain2john.py --json wallet_clean.aes.json
blockchain2john.py ships with John the Ripper (jumbo). If yours is old and chokes on v4, grab the latest from the openwall/john repo.
4. Verify the extraction BEFORE you crack
- Prefix: must be
$blockchain$(v1) or$blockchain$v2$(v2+). If you see$bitcoin$, you used the wrong tool. - Length math (v1): hash is
$blockchain$<len>$<hex>.<len>must be a clean multiple of 16 (AES block size). Odd or weird number = broken extraction (usually a leftover BOM). - Known false negatives: some wallets whose decrypted JSON starts with
address_book(instead ofguid) get reported as "wrong password" even when correct. If you're certain of the password and it won't verify, this or a BOM is why — not your memory.
5. Prove the pipeline with a known-answer test
The step everyone skips. Make a throwaway wallet with a password you KNOW, extract it the same way, and crack that first. If the known password pops out, your tool + mode + format are all verified. Now you can trust a "not found" to mean "not in the wordlist" — not "my setup is broken."
6. Crack it
hashcat -m 12700 -a 0 wallet.hash wordlist.txt -r rules/best64.rule
-m 12700for v1,-m 15200for v2/v3/v4.- v1 is only 10 PBKDF2 rounds = fast, millions/sec on a mid GPU. v2+ uses many more iterations = much slower, so lean harder on a targeted wordlist.
- hashcat flags a hit when the decrypt comes out as clean printable ASCII (valid JSON).
Wordlist beats brute force. Seed it from memory — old passwords, pet/family names, handles, street numbers, the year (2012/2013), favored symbols — then let rules mangle it. Forgotten passwords fall to the owner's own habits. (Real example: The wallet I did today whose password was just Name + birth year'.best64` catches that instantly.)
Prefer a GUI/CPU path? btcrecover runs straight against the aes.json with a token list and handles all versions internally — slower but foolproof for format issues.
7. "I only have my Wallet ID, not the file"
blockchain.info serves the encrypted blob to anyone with the wallet identifier (GUID) — it's encrypted, so that's safe. btcrecover's download-blockchain-wallet.py pulls it down; then you crack it offline. This is the move most people miss when support says "we can't help you."
8. You cracked it — now get your coins
- Decrypt offline (btcrecover, or blockchain's official decrypt tool) → you get the private key(s).
- Import/sweep into Electrum (New wallet → import keys → sweep) → sends the balance to a fresh address you control. ~10 min.
- One private key = TWO legacy addresses (compressed + uncompressed). Old wallets were inconsistent about which they showed — always check both.
9. Check the balance (permanent, all-time ledger)
https://blockstream.info/api/address/<ADDRESS>
Common failure modes (and the real cause)
| Symptom | Actual cause | Fix |
|---|---|---|
| "Correct password won't crack" | BOM in the file | Strip EF BB BF (step 2) |
Hash starts $bitcoin$ | Wrong tool (bitcoin2john) | Use blockchain2john |
| v2+ won't extract / errors | Missing --json flag | Add --json |
Hash <len> is odd/weird | Broken extraction (often BOM) | Re-clean, re-extract |
| Certain password still fails | address_book-prefixed wallet false negative | Use btcrecover, or newer tooling |
| "No hashes loaded" | Malformed/partial hash | Re-extract from a clean copy |
TL;DR
Sometimes the password isn't the problem. Check for a BOM, extract with the right tool, verify the length is block-aligned, prove your pipeline on a known wallet, then crack with a memory-seeded wordlist. Diagnose the tooling and you'll solve it in an afternoon with a decent GPU.
Happy to help. Don't send your backup files to weirdos.
[link] [comments]
You can get bonuses upto $100 FREE BONUS when you:
💰 Install these recommended apps:
💲 SocialGood - 100% Crypto Back on Everyday Shopping
💲 xPortal - The DeFi For The Next Billion
💲 CryptoTab Browser - Lightweight, fast, and ready to mine!
💰 Register on these recommended exchanges:
🟡 Binance🟡 Bitfinex🟡 Bitmart🟡 Bittrex🟡 Bitget
🟡 CoinEx🟡 Crypto.com🟡 Gate.io🟡 Huobi🟡 Kucoin.
Comments