Need Help with Python Script for Recovery Seed

18 replies 324 views
shrimpNewbie
Posts: 289 · Reputation: 20
#1Jan 1, 2022, 06:33 PM
I messed up bad. One word in my recovery seed is wrong. I know it’s the sixth word because my Safepal S1 won't accept the one I have written down. I wrote a Python script to brute force this word using the BIP-0039 word list. The issue? I have no idea how to run this code. Can anyone lend a hand?
3 Reply Quote Share
orbit1337Senior Member
Posts: 434 · Reputation: 941
#2Jan 1, 2022, 08:13 PM
Honestly, no API needed for this. Just keep your seed offline, man.
3 Reply Quote Share
Posts: 224 · Reputation: 87
#3Jan 2, 2022, 02:22 AM
Why start a new thread? I saw your other post with the same code. Why not just keep asking there?
1 Reply Quote Share
dave.forkMember
Posts: 375 · Reputation: 185
#4Jan 2, 2022, 05:43 AM
This is a super risky move. I just checked your brute_force_seed function. Why are you even sending requests to Safepal with your seed phrase? That's a huge no-go. Also, your Python code has no indentation.
2 Reply Quote Share
shrimpNewbie
Posts: 289 · Reputation: 20
#5Jan 2, 2022, 07:16 AM
I figured a new post made sense since I’m asking about the code itself. If it’s an issue, I can delete one. The other thread was more about general solutions.
5 Reply Quote Share
shrimpNewbie
Posts: 289 · Reputation: 20
#6Jan 2, 2022, 10:11 AM
I’m not sharing my seed online. It’s written down on paper. I'm just a total noob, and I tried fixing what AI suggested.
1 Reply Quote Share
whale420Senior Member
Posts: 727 · Reputation: 853
#7Jan 2, 2022, 02:32 PM
I told you before, use FinderOuter to brute-force that seed. No programming skills needed. Also, don't use AI to generate your brute force script. It can create garbage code that won’t work or even leak your seed.
3 Reply Quote Share
Posts: 6 · Reputation: 3
#8Jan 2, 2022, 05:43 PM
Sure, there are tools for this. But remember: 1. NEVER send your seed to any website. THEY WILL STEAL YOUR FUNDS! 2. Don’t write code if you're not sure what you're doing. 3. Avoid AI-generated code. Just find existing tools.
6 Reply Quote Share
tom2014Legendary
Posts: 79 · Reputation: 4721
#9Jan 3, 2022, 02:24 PM
Why are you trusting AI with your code? You said you’re not that experienced. There are open-source tools made by experts who have tested them. Better to stick with what’s proven instead of AI-generated stuff.
3 Reply Quote Share
orbit1337Senior Member
Posts: 434 · Reputation: 941
#10Jan 5, 2022, 04:20 AM
If I use those tools, it'll only be for the one problematic word. The rest of my mnemonic is fine, so no need to take extra risks.
3 Reply Quote Share
shrimpNewbie
Posts: 289 · Reputation: 20
#11Jan 5, 2022, 07:58 AM
By the way, it’s not SafePal, it’s isafepal. Looks like you might be promoting a phishing tool.
3 Reply Quote Share
0xNodeMember
Posts: 671 · Reputation: 80
#12Jan 6, 2022, 05:50 PM
FinderOuter isn’t working for me, so I’ll give btcrecover a shot. And yeah, I know AI can generate off-target code. That’s why I made changes. I don’t code well but I get the gist.
2 Reply Quote Share
shrimpNewbie
Posts: 289 · Reputation: 20
#13Jan 7, 2022, 09:01 PM
First off, use code tags for your script. Makes it way easier to read. Second, brute forcing over a network is slow as hell. Your network speed, ping, and rate limits from the server all factor in. No one does it this way.
1 Reply Quote Share
0xNodeMember
Posts: 671 · Reputation: 80
#14Jan 8, 2022, 01:46 AM
If it’s not an API, what am I supposed to run the code against?
0 Reply Quote Share
shrimpNewbie
Posts: 289 · Reputation: 20
#15Jan 8, 2022, 04:41 AM
Find out what type of wallet you’re trying to brute force. I suspect you’re not clear on which wallet you actually have. Once you get that sorted, see if there’s a Python package that can help you open and read it. You could even use ChatGPT if it’s a well-known package, but at least learn some basics of Python to write it yourself.
2 Reply Quote Share
dave.forkMember
Posts: 375 · Reputation: 185
#16Jan 8, 2022, 09:39 AM
My wallet is a Safepal, and I have a legacy address.
4 Reply Quote Share
atlas21Senior Member
Posts: 3 · Reputation: 1624
#17Jan 9, 2022, 06:00 PM
There’s nothing at isafepal dot com right now. They might do something later, but as of now, it’s empty. They claimed AI helped write it, so it could just be a blunder. Why create a new program when two tested tools already exist? Plus, given the lack of technical skill, it’s naive to think they can pull this off properly. Sounds more like a DoS attack than a brute force attempt.
4 Reply Quote Share
Posts: 3523 · Reputation: 35
#18Jan 9, 2022, 08:30 PM
Also, Safepal uses Cloudflare DNS for its site. So if they protect their API that way, you’re gonna hit major hurdles trying to brute force it. You’ll likely get throttled or even banned.
1 Reply Quote Share
Posts: 3523 · Reputation: 35
#19Jan 10, 2022, 01:56 AM
As others mentioned, check if you can access a file instead and run your code against that. Using an API isn't gonna help you without risking getting blacklisted.
3 Reply Quote Share

Related topics