The search never gets the wallet.
An operator can inspect password candidates on its own machine, including a password it finds. The operator never receives the wallet or spending keys needed to use it.
Why the password alone is not enough
The search runs on operator-controlled hardware. A determined operator can inspect locally tested candidates and may see the exact password if its machine finds it. Result sealing protects the password after it leaves that machine; it does not hide it from the machine owner.
The operator never receives the full wallet, complete spending keys, complete address list, balance,
transaction history, or direct customer identity fields. The password alone therefore cannot move
wallet funds. Safe-piece metadata is format-specific: after a correct match, an older Electrum BIE1
piece may reveal a prefix of the first wallet address, while a MultiBit Classic .key piece reveals
a bounded, non-spendable prefix of the encrypted WIF. A reported match is sent back for verification
before any recovery or payout begins.
What the local search can see
- ✓A safe test piece
- ✓An assigned batch of password candidates
- ✓The exact password if this machine finds it
- ✓A random case reference
Wallet and direct customer data
- ×The full wallet
- ×Spending keys
- ×Direct name or contact fields
- ×Complete address lists, balances, or transaction history
A found password may be visible to the machine owner. It can carry privacy or password-reuse risk, but it is not enough to move funds without the wallet and spending keys. Safe-piece metadata is wallet-specific: an older Electrum BIE1 piece may reveal a prefix of the first address, while a MultiBit Classic .key piece reveals a bounded, non-spendable WIF prefix after a match.
Choose who holds the encrypted wallet.
Distribrute handles the wallet-side work.
You send the encrypted wallet through secure intake. We create the safe test piece, verify a recovered password, and complete settlement. The fleet still never receives the wallet.
Trust required: you trust Distribrute with the encrypted wallet and settlement.
The wallet stays on your computer.
You create the safe test piece locally. After a match, Distribrute guides a local session to unlock the wallet, build the payout, and sign only after you review and approve it.
Trust required: you trust your own computer and the guided application.
Additional controls
- The agent accepts only signed jobs and approved recovery tools.
- Matches are verified before they count as a recovery.
- Operators receive random case references, not customer names or contact details.
- Operators are reviewed and identity-verified before joining the fleet.
Honest limits
- Distribrute is trust-minimized, not completely trustless.
- Custodial recovery gives Distribrute the encrypted wallet and responsibility for settlement.
- Non-custodial recovery runs on a customer-controlled computer; no application can prove that host is free from malware or inspection.
- Many wallets do not expose usable public addresses before decryption, so their spendable balance may be impossible to verify before compute begins. A correct password can open an empty wallet and produce no operator payout.
- We recover forgotten passwords for supported encrypted wallets. We do not recover missing seed phrases.
- No password search is guaranteed to succeed.
Report a security issue
Email security@distribrute.com with a clear description and steps to reproduce.