Skip to content

被盜加密貨幣恢復:DriveSavers 如何從 10 個缺失單詞中重建 Trezor 種子短語

被盜加密貨幣恢復:

DriveSavers 如何從 10 個缺失單詞中重建 Trezor 種子短語

裝置:
Trezor 硬件錢包

挑戰:
重建遺失的 10 個恢復種子短語單詞

恢復過程:
法證影片分析及專有加密貨幣恢復軟件

最終恢復階段:
5 小時,以每秒 280 億次猜測的速度進行

結果:
所有加密貨幣資產均在竊賊存取錢包之前成功恢復

DriveSavers 的加密貨幣恢復服務結合法證影片分析與專有恢復軟件,成功解決一個最初被認為在運算上不可行的暴力破解問題。

背景

竊賊偷走了一個保險箱,內有一個 Trezor 硬件錢包,以及一張寫有其 20 個單詞恢復種子短語的紙張。客戶僅保留了前 10 個單詞的副本。其餘 10 個必須迅速重建。若沒有完整短語,客戶便無法在替代硬件上恢復錢包,亦無法在竊賊轉移資金前保障資產安全。

Trezor 硬件錢包本身設有 PIN 碼保護,但那組 20 個單詞的恢復種子短語才是主備份。任何持有完整短語的人都可以在新硬件上恢復錢包並轉移資金。重建該短語是客戶唯一的選擇。對竊賊而言,紙本備份是通往數碼資產——金錢——最直接的途徑。

為何標準恢復不可行

此 Trezor 的種子短語源自 SLIP-0039 Shamir 備份單詞列表,該列表包含 1,024 個可能單詞。在已知有 10 個位置缺失的情況下,可能的組合數量極為龐大,使直接暴力破解變得不可行。

在標準硬件上,以暴力破解方式嘗試找出缺失的 10 個單詞,約需 803 萬億年。即使以每秒 1 萬億次猜測的速度進行,搜尋仍需約 400 億年。單純的原始搜尋並不可行。在進行高速運算之前,必須大幅縮小搜尋空間,才能填補差距。

根據保安攝錄畫面

辦公室的保安攝錄機拍攝到客戶正在寫下種子短語。該段影像是缺失單詞唯一剩下的紀錄。

一支外部法證影片分析團隊已檢視該段影像,並判定解析度過低,無法辨識任何缺失的單詞。影片中沒有任何畫面能清晰顯示筆在紙上的細節,以致無法讀取文字內容。

DriveSavers 的工程師再次檢視該段影像,確認讀取限制依然相同,並尋找其是否還能提供其他線索。許多單詞是在客戶的手幾乎完全離開鏡頭的情況下寫下的。至於出現在畫面中的單詞,其可見程度各不相同。有幾個單詞可見客戶手部的末端;另一些則只看到部分拇指。

影片清楚顯示了部分已印刷的 Trezor 恢復卡,其為每個單詞位置提供一致的字元格線;然而,一些看似字元的痕跡後來證實只是墨水污漬。

縮小搜尋範圍

印刷的 Trezor 恢復卡本身提供了一個可靠的參考依據,根據字元長度,將每個單詞位置的候選數量由 1,024 個縮減至約 200 個。

To interpret the limited hand motion visible in the video, the team asked the client for separate handwriting samples. The client’s way of forming letters proved distinctive. Certain letters were written top to bottom, others bottom to top. One had a preliminary loop that wasn’t part of the letter itself. Another had a shape closer to a lightning bolt than a typical curve.

For positions where partial hand motion was visible, engineers used these patterns to eliminate incompatible candidates from the SLIP-0039 word list. Identifying Word 11, combined with accelerated hardware, reduced the remaining brute-force estimate from 803 trillion years to 33 years. Word 13 reduced it further to 59 days. By Word 15, the remaining combinations were within computational reach.

Word 16

Word 16 introduced a critical ambiguity. The Trezor recovery card showed 8 character boxes for that position, but the video suggested the client had written only 6. Because SLIP-0039 words are fixed, using the wrong character length would eliminate the correct answer entirely. The team worked through the evidence and concluded the real word was most likely 6 characters. Two of the marks on the backup paper had likely smudged into each other, creating the appearance of additional characters.

Rather than relying on a single uncertain assumption, the team locked in only high-confidence constraints and allowed the recovery software to evaluate the remaining valid candidates.

Completing the Recovery

At this stage, the remaining uncertainty was small enough to make computation viable. With the high-confidence words locked in and the remaining pool narrowed, DriveSavers proprietary cryptocurrency recovery software executed the final brute-force effort at 28 billion guesses per second. The correct seed phrase was identified in 5 hours, enabling successful wallet recovery.

From there, the wallet was restored on replacement hardware and the cryptocurrency was transferred to a secure wallet before the thieves could act.

“Brute-forcing the 10 missing words would have taken over 800 trillion years on standard hardware, so we had to find another way. The video was too blurry to read the words, but we could see the client’s hand move. Once we matched those movements against the word list Trezor uses, the final verification ran at 28 billion guesses per second and identified the correct phrase in five hours, after weeks of forensic analysis and search-space narrowing.”

Mike Cobb

Director of Engineering, DriveSavers Data Recovery

Other Recovery Scenarios

Most cryptocurrency losses stem from a handful of scenarios: a stolen wallet, a partial seed phrase, a forgotten password, a corrupted wallet file, or a physically damaged storage device. Some of these scenarios are recoverable. Others are not. Each depends on the specific failure conditions.

DriveSavers crypto recovery experts handle partial and damaged seed phrases, lost crypto wallet passwords, corrupted wallet.dat files, hardware wallet PIN recovery, and physical damage to storage media containing wallet data. The approach shown in this case combined forensic video analysis and proprietary recovery software. That combination fits a specific and uncommon set of circumstances for crypto asset recovery.

To recover cryptocurrency, or to discuss a partial seed phrase, contact DriveSavers Crypto Recovery Services at 1 (800) 440-1904.

DriveSavers 高级市场经理
您是在撰写有关 DriveSavers、数据恢复或其他技术相关主题的内容吗?
联系我们。

Back To Top
Search