American engineer Joe Grand and his friend Bruno recovered $3 million in Bitcoin by exploiting an old flaw in the RoboForm password manager. In a YouTube video, Grand explained that they helped a European crypto owner named Michael, who had lost access to his Bitcoin wallet due to a forgotten 20-character password.
Grand and Bruno spent months reverse-engineering the 2013 version of RoboForm, discovering that passwords were predictable based on the computer’s date and time. This loophole allowed them to generate millions of potential passwords and brute force their way to Michael’s Bitcoin, unlocking 43.6 BTC.
Investigative journalist Kim Zetter highlighted that current users of RoboForm, if their passwords were generated before 2015, might still be vulnerable. RoboForm has not made any public statements on this issue.
Joe Grand, known as “Kingpin,” has a notable history in hardware hacking, including a 2022 incident where he recovered $2 million in BTC from a Trezor One wallet. This event underscores the ongoing importance of robust digital security measures.