When you realise you cannot get into a wallet, the instinct is to start trying things immediately. That instinct is right about the urgency and usually wrong about the actions. Most of the damage I see in recovery cases was done by the owner, in the first few hours, while trying to help.
Here is the honest version of "fast": a recovery is quick when the evidence is intact and the owner remembers something specific. It is slow, or impossible, when the evidence has been overwritten and the memory is vague. Almost everything you do in the first hour pushes your case toward one of those two outcomes.
Step one: work out whether this is loss or theft
Locked out of a wallet like this one?
I repair hardware wallets, crack forgotten passwords, and rebuild broken seed phrases — on my own bench in Denver.
These are different problems with different clocks.
Loss means you still control the wallet, you just cannot open it. A forgotten password, a seed phrase with a missing or misread word, a corrupt file, a hardware wallet that will not boot. The coins are sitting where you left them. Nobody else is racing you for them. Take the extra ten minutes to do this properly.
Theft means someone else has the keys. If your seed was phished, typed into a fake site, stored in a cloud note that leaked, or entered on a compromised machine, an automated sweeper bot is very likely watching that address already. If coins have already moved out on-chain, they are gone, and no service can reverse a confirmed Bitcoin or Ethereum transaction. Anyone who tells you otherwise is running a second scam on top of the first.
There is a narrow middle case that is genuinely time-critical: the keys are compromised but assets are still sitting there, often because they are staked, vesting, an NFT, or a token the bot's script does not handle. That is a race against a bot, measured in seconds, and it needs a prepared transaction rather than a panicked one. That is what hacked wallet rescue is for.
Step two: stop writing to the device
If any part of your problem involves a deleted or missing file, this is the single most important thing on the page.
Deleted data survives only until something else is written over it. Every minute a computer stays powered on, it writes: logs, updates, browser cache, temp files, indexing. If you deleted a wallet.dat and then spent an afternoon downloading recovery software onto the same drive, you may have overwritten the thing you were looking for with the tool you were looking for it with.
So: shut the machine down. Do not install anything on it. If the wallet file lived on an SSD, understand that the odds were already poor before you started, because TRIM erases deleted blocks within minutes of the delete, not days. On a spinning hard drive, a powered-off disk is a preserved disk, and file carving has a real chance.
Step three: make copies before you touch anything
Copy the wallet file, the keystore, the backup folder, the phone backup, whatever you have, onto at least two separate devices. Then work only on a copy, never on the original.
This matters more than it sounds. Wallet files get corrupted by half-finished repair attempts. Bitcoin Core will rewrite a wallet.dat on open. Some "repair" tools truncate the file they fail on. If you keep an untouched original, a failed attempt costs you nothing. If you do not, a failed attempt can cost you the wallet.
Copies also make the assessment faster on my end, because I can work from a file rather than from a description of a file.
Step four: write down what you remember, before you forget it
This is the step people skip, and it is the one that most often decides whether a password case is winnable.
A password search is only as good as the clue set it starts from. "I do not remember it" is not a starting point. "It was probably a phrase from a song, capital first letter, a number and an exclamation mark at the end, and I was using a Czech keyboard layout that year" is a starting point that can be turned into a finite search.
Open a text file and dump everything, unfiltered:
- Passwords you used for other things around that time, even if you are sure you did not reuse this one
- Your habits: capitalisation, substitutions, appended years, appended punctuation
- The approximate date you created the wallet, and which software and version
- Which machine you were on, which operating system, which keyboard layout and language
- Any physical place you might have written something down: notebooks, a book, the back of a photo, a safe
- Anything you told anyone at the time, in an email or a chat
Do this now, while you are still upset and thinking about it. Detail decays fast, and it does not come back.
What actually makes a case fast
In order of how much they help:
- A complete, untouched wallet file or backup. Everything else is guesswork without it.
- Specific memory. Fragments, patterns, and habits shrink a search from astronomical to finite. This is the difference between "impossible" and "a weekend of GPU time".
- Knowing the exact wallet software and version. Derivation paths, encryption schemes, and file formats changed a lot between 2011 and now, and searching the wrong format finds nothing no matter how long you run it.
- The original device. Old keychains, browser password stores, and forgotten backup folders live on it.
- Not having run random tools on it first.
What kills a case
- Overwriting the drive that held the deleted file
- Factory-resetting a hardware wallet you cannot get into, which erases the only copy of the key
- Entering a PIN repeatedly on a Trezor or Ledger until the device wipes itself
- Typing your seed phrase into any website, which converts a recovery problem into a theft problem
- Paying an upfront fee to a stranger who contacted you first
- Waiting years and then trying to reconstruct the details from memory
What happens when you contact me
The assessment is free and it is a real assessment, not a sales call. I look at what you actually have, tell you whether it is worth attempting, and give you an honest read on the odds for your specific situation rather than a generic promise. If a case is not winnable, I say so, which is why the pricing works the way it does: the fee is a percentage of what is recovered, and nothing is owed if nothing is recovered.
If you want to calibrate your expectations first, the recovery odds by scenario article lays out which situations are usually solvable, which are genuinely uncertain, and which are not worth paying anyone for.
Bring the copies and the notes. Those two things decide most of it.
