Crypto recovery specialists encounter clients convinced they own massive fortunes locked in wallets they cannot access. Often, when those wallets finally open, the reality is stark: little or nothing is there.

One case involved a client named Rusty who contacted Chris Brooks, founder and CEO of Crypto Asset Recovery, in 2021. Rusty claimed he and two partners had won 5,000 Bitcoin in a court case—roughly $53 million at the time. During a Zoom call, Rusty displayed a phone showing the balance and said the group could withdraw $300,000 weekly but wanted full access. They offered Brooks and his son millions to fly to Georgia and help crack the wallet.

Brooks and his son booked flights the next day. Over lunch, Rusty, an Army veteran, revealed the wallet contained more than 5,000 Bitcoin. The group drove an hour to a strip mall where one of the men owned an office. In a back room, they received notebooks filled with dozens of recovery seeds.

Brooks and his son spent the day attempting to open wallets from the provided seeds. They ultimately recovered approximately $10 in Bitcoin. Brooks never confirmed whether the wallets had ever contained the 5,000 Bitcoin or Ethereum Rusty claimed to own.

Brooks now suspects Rusty was a victim of a scam—convinced he possessed a large crypto fortune that never existed. The experience became an early lesson for Crypto Asset Recovery: "lost crypto" often means funds were never there.

Wallet recovery specialists do not recover Bitcoin directly from the blockchain. They retrieve the information needed to access an existing wallet—forgotten passwords or incomplete seed phrases. If the wallet is empty, the crypto was never there.

Bruno Krauss, co-founder and chief technical officer of recovery firm ReWallet, explained the mechanics. Bitcoin's BIP39 seed phrase standard uses a list of 2,048 words. If a client remembers most words, specialists can systematically search for missing possibilities. Password recovery works similarly. Krauss's firm once recovered a 20-character password protecting roughly $3 million by reverse-engineering a flawed password generator. Other recoveries depend on understanding a client's personal password habits—favorite foods, places, dates.

Actual crypto losses do occur. The $116 million Coldcard hardware wallet exploit in 2026 demonstrated real fund movement. TRM Labs reported that most victim funds aggregated in a few attacker-controlled addresses. Attackers laundered funds through a single 64.9 Bitcoin deposit into Wasabi Wallet and 200 Ethereum into Tornado Cash on Aug. 4, 2026.