Substantial amounts are inaccessible because of lost credentials, and an industry has formed around this, containing both legitimate specialists and a great deal of fraud.

What is genuinely recoverable

Partially known passwords, where the search space can be narrowed.

Damaged or partially transcribed recovery phrases, where the checksum constrains possibilities.

Wrong derivation paths, where the funds were never lost at all.

Which are real problems with real solutions.

What is not recoverable

A completely unknown password or phrase.

Which is protected by the same cryptography protecting everything else, and no service can bypass it.

Anyone claiming otherwise is describing something impossible.

Funds sent to a wrong address

Irreversible, unless the recipient chooses to return them.

Which no service can compel.

Recovery services offering to reverse transactions are fraudulent without exception.

Stolen funds

Tracing is possible and recovery generally requires law enforcement action or cooperation from a venue holding the funds.

Which is a slow process with low success rates.

Services promising recovery of stolen funds for an upfront fee are the most common form of secondary fraud.

How legitimate services operate

Contingency fees taken from recovered funds rather than upfront payment.

Which aligns incentives and is the clearest distinguishing feature.

They also decline cases they cannot solve, which fraudsters never do.

The security concern

Recovery requires sharing sensitive information with a third party.

Which is a substantial risk even with a legitimate service.

Reputable operators use processes limiting what they see, and understanding those processes is part of due diligence.

The secondary fraud pattern

Victims of losses are targeted by fake recovery services, sometimes repeatedly.

Which is documented extensively by consumer protection agencies.

Unsolicited contact offering recovery is fraudulent in essentially all cases.

Prevention

Tested backups, recorded derivation paths and documented passphrase use.

Which is the only reliable approach, since recovery is a poor substitute for not losing access.

Password search techniques

Where a user remembers structure but not detail, the search space can be constrained.

Which turns an impossible problem into a computational one.

Providing accurate information about what you remember is what determines whether this works.

Old wallet formats

Early wallet files and formats no longer supported by current software.

Which requires specialist knowledge to extract keys from.

This is a genuine and shrinking niche as such wallets are recovered or forgotten.

Hardware wallet damage

A damaged device does not mean lost funds if the recovery phrase exists.

Which is the entire purpose of the phrase.

Attempting physical extraction from a device is generally unnecessary and carries its own risks.

Verification before payment

Legitimate services can generally demonstrate progress before requiring payment.

Which is a reasonable thing to request.

Any demand for full payment before any demonstrated capability is a warning sign.

The prevention framing

Every hour spent on backup practice is worth more than any recovery service.

Multisignature recovery

Arrangements where losing one key is survivable by design.

Which removes the need for recovery services entirely for that failure mode.

The complexity is the barrier, and it is decreasing as tooling improves.

Social recovery accounts

Programmable accounts allowing designated parties to restore access.

Which addresses the same problem architecturally.

Adoption is growing and requires migrating from a conventional account.

Estate planning

A substantial share of permanently lost assets belong to people who died without documenting access.

Which is a solvable problem that very few people address.

Arrangements range from sealed instructions with a solicitor to timelock mechanisms.

Institutional recovery

Organisations losing access face the same problem with more at stake.

Which is why documented key ceremonies and tested recovery procedures exist.

The distinguishing question

Ask a service exactly what information they need and what they will do with it.

Legitimate operators answer specifically; fraudulent ones deflect and press for payment.

Insurance considerations

Personal policies rarely cover loss of self-custodied assets.

Which is worth confirming rather than assuming.

Specialist cover exists for institutional holdings and is not generally available to individuals.

The realistic summary

Partial information can sometimes be recovered; complete loss cannot.

Anyone offering to reverse a transaction or recover an unknown phrase is running a fraud.

Documenting access while you can

The wallet software used, the derivation path, whether a passphrase exists and where the backup is stored.

Which is four pieces of information that between them resolve most apparent losses.

Writing them down and storing them separately from the phrase itself takes ten minutes and prevents the situation entirely.

Testing a recovery on a spare device once confirms that the information is complete and correct.

The scale of the problem

Estimates of permanently inaccessible holdings run into very large figures across major assets.

Which is a direct consequence of a design where the user is solely responsible for their keys.

That responsibility is the feature, and the losses are its unavoidable cost.

Which is why the documentation habit matters more than any service on offer.