CustodyStress
Archive › Device loss
Part of the CustodyStress archive of observed Bitcoin custody incidents
CS-00570

The ransomware encrypted the wallet file and demanded payment in Bitcoin — a payment

Blocked
Case description
A user who maintained their wallet on an old Windows XP machine found the machine had been infected with ransomware in September 2018. The ransomware encrypted the wallet file and demanded payment in Bitcoin — a payment the user could not make without access to their wallet. A decryption tool was eventually released but it arrived after the wallet passphrase had also been forgotten.
Custody context
Stress conditionDevice loss
Custody systemMobile or software wallet
OutcomeBlocked
DocumentationUnknown
Year observed2018
CountryUnknown
Structural dependencies observed
Hardware device requiredThird-party platform dependency
What this illustrates
The wallet existed only on that device. When the device became inaccessible, there was no other way back in. Access was not recoverable.
Outcome interpretation
Access was not possible under the reported conditions.
Source
Publicly Reported
Evidence type
Forum post
Related cases involving device loss
188 cases involve device loss 572 cases involve mobile or software wallet View archive statistics →
This archive documents observed custody survivability failures. It does not attempt to document all Bitcoin losses or security incidents. Submit a case
← All cases
Framework references
Terms guide
Survives
Access remained possible under the reported conditions.
Constrained
Access remained possible, but only with delay, dependence, or significant difficulty.
Blocked
Access was not possible under the reported conditions.
Indeterminate
There was not enough information to determine the outcome.
Single-person knowledge
Recovery depended on information or capability held by one individual who was unavailable.
Institutional dependence
Recovery depended on a third-party institution or service that was inaccessible or uncooperative.
Documentation gap
Recovery depended on instructions that were missing, incomplete, or unclear.
Authority mismatch
The person with legal authority to act did not have operational access, or vice versa.