How much crypto has been lost forever?
Nobody can count lost coins exactly, because a wallet that never moves looks the same as one whose owner is simply patient. Analysts estimate it from how long coins have sat untouched. In 2017 Chainalysis estimated that between 2.78 and 3.79 million bitcoin were already gone for good, about 17% to 23% of all bitcoin mined at the time (Fortune).
Later reporting put it at roughly 20% of the 18.5 million bitcoin then in existence, sitting in lost or stranded wallets, again according to Chainalysis (The New York Times). Treat these as estimates, not a final count: some of those coins belong to long-term holders who still have their keys.
Why is a lost private key so final?
In a self-custody wallet, the private key is the only thing that can approve moving the coins. Your recovery phrase (12 or 24 words) is a backup that can recreate that key. If both are gone, there is no "forgot password" link, because there is no company in the middle holding a copy. That is the point of self-custody, and also its risk (ethereum.org).
The coins are not deleted. They stay at the same address on the blockchain forever, where anyone can see them and no one can move them. New to these words? Start with what a crypto wallet actually holds.
Who is James Howells, the man searching a landfill?
In 2013, a hard drive holding the keys to about 8,000 bitcoin belonging to James Howells, an IT worker in Newport, Wales, was thrown out with household rubbish and ended up in the city's Docksway landfill. For more than a decade he has tried to get permission to dig for it, including offers to fund the search and share the coins with the city.
The courts said no. In January 2025 the High Court struck out his claim against Newport City Council, and in March 2025 the Court of Appeal refused permission to appeal, saying the appeal had no real prospect of success (Decrypt). He then said he would take the case to the European Court of Human Rights and offered to buy part of the landfill (The Block). Even if he ever got access, a drive buried for over ten years may no longer be readable.
The lesson: one copy of a key, on one device, is one accident away from being gone.

What happens when you forget the password to your wallet?
Stefan Thomas, a programmer in San Francisco, was paid 7,002 bitcoin in 2011 for making a video explaining bitcoin. He kept the keys on an encrypted USB drive called an IronKey and wrote the password on a piece of paper, which he then lost. The drive allows ten guesses before it wipes itself for good. When The New York Times reported his story in 2021, he had used eight (The New York Times).
The same article reported that a wallet recovery service was receiving around 70 requests a day from people locked out of their own coins. Forgotten passwords, lost PINs and encrypted files with no surviving password are among the most common ways people lose access.
The lesson: a password protecting your backup needs its own backup, stored somewhere you will still find in ten years.

Can a hacker recover a lost crypto wallet?
Sometimes, but only when there is a flaw to exploit. In 2022 hardware hacker Joe Grand recovered the PIN of an old Trezor One holding more than $2 million in tokens for its owner, Dan Reich, who had already used 12 of the 16 attempts before the device wipes itself. Grand used a voltage "fault injection" attack on the chip that needed full physical access; Trezor says the underlying issue was fixed in 2017 (Decrypt).
In 2024 Grand and a fellow researcher helped a man who had generated his wallet password with an old version of a password manager in 2013 and then lost it. That version created passwords based on the computer's clock, which made it possible to recreate the password and unlock 43.6 bitcoin (The Block).
These are the exceptions that made the news. Both worked only because of old bugs that have since been fixed. A well-made modern wallet with a strong password and no backup is, by design, not recoverable.

What happened at QuadrigaCX when the only key holder died?
In December 2018 Gerald Cotten, founder of the Canadian exchange QuadrigaCX, died, and the exchange said only he could access its offline "cold" wallets. About C$169 million of customer funds could not be paid out. The story was told for years as a lost-key tragedy.
The regulator's investigation found something else. The Ontario Securities Commission concluded that Cotten had committed fraud, trading with fake balances and using client deposits to cover losses, and that the money was gone before he died (Ontario Securities Commission).
The lesson: on an exchange, you do not hold the keys; the company does. And any plan where one person alone holds the keys, whether a company founder or you, needs a way for someone else to get in if that person cannot.
Can a software bug lock a wallet forever?
Yes. In November 2017 a user accidentally triggered a bug in a shared code library used by Parity's multi-signature wallets and destroyed the library. Wallets holding about 513,774 ETH were frozen, with the keys still in their owners' hands but the wallets unable to move anything (The Register, GitHub issue).
This is a different kind of loss, but worth knowing: smart-contract wallets depend on their code as well as their keys. Prefer wallets built on widely used, openly published account standards, and start with small amounts on anything new.
Should you pay a crypto recovery service?
Be very careful. People who have lost crypto are prime targets for a second scam. The FBI warns about fake "recovery" companies and fake law firms that contact victims, claim they can get funds back and ask for fees up front. Victims reported losing more than $9.9 million to these schemes between February 2023 and February 2024 (FBI IC3, FBI IC3).
- Nobody can "reverse" a blockchain transaction or reset a lost key for a fee.
- Anyone who contacts you first offering recovery is almost certainly a scammer.
- Never give your recovery phrase, or a remaining device, to someone you cannot verify.
- A genuine specialist works only from what you still have (an old file, a partly remembered password, a device) and never needs your phrase sent by message.
Why do people lose access to their wallets?
Almost every case above comes down to a single point of failure: one device, one password, one person, one piece of paper.
- The only device with the wallet was thrown away, broken, stolen or reset.
- The password or PIN protecting the wallet or its backup was forgotten.
- The recovery phrase was never written down, was stored only as a photo on the same phone, or was lost in a move.
- The owner died or became ill and nobody else knew where the backup was.
- The coins were on an exchange that failed, was hacked or froze withdrawals.

How do you avoid losing your private key?
You do not need special equipment, just more than one independent way back in, and a check that it works.
- Keep at least two backups in different places, for example a written recovery phrase at home and another in a safe place elsewhere. Never as a screenshot or a cloud note (ethereum.org).
- Test your backup: restore the wallet from it on a second device, or send a small amount and recover it, before you put real money in.
- Write down every password and PIN that protects a backup, and store it apart from the backup itself.
- Make a simple inheritance note: tell someone you trust that the wallet exists and where to find the instructions, without giving them the phrase today.
- Keep large amounts in self-custody, not on an exchange, and keep only what you need for trading on exchanges.
- Review once a year: check the backups are still there, still readable and still in the right places.
Why does every InfraIO Wallet transaction need your face?
In InfraIO Wallet, tapping Send is not enough to move money. Every transaction must be confirmed with your passkey, and your phone unlocks it only with your face (Face ID), your fingerprint or your device passcode. The check happens on your device; your face is never sent to or stored by InfraIO Pay (Apple).
That changes the stories above. Someone who finds your phone, copies your files or reads a note cannot send your funds, because there is no password or phrase they could type in instead of you. And there is no long secret for you to forget.
Keep your device passcode private: it is the fallback when Face ID cannot be used.

How does InfraIO Wallet make it harder to lose access?
InfraIO Wallet is a self-custody wallet that starts with a passkey instead of a 12-word phrase, so there is no long list of words to lose on day one.
- Your passkey is backed up by your phone's passkey manager. On iPhone, passkeys sync through iCloud Keychain with end-to-end encryption, so a new iPhone signed in to your Apple Account gets them back (Apple). Android passkey managers work the same way (FIDO Alliance).
- Add backup passkeys. You can add a second device or another passkey manager to the same wallet, so losing one phone does not lock you out.
- An optional recovery phrase. You can also create a recovery phrase as an offline backup. It is suggested, not forced, and InfraIO Wallet asks for it before you remove your last passkey.
- Multisig is coming soon. You will be able to add other signers, such as a family member's passkey, and require 2 of 3 before anything moves. This is not available yet.

What can InfraIO Wallet not recover?
Self-custody works both ways. If you lose every passkey and have no recovery phrase, nobody, including InfraIO Pay, can recover the wallet, because we never hold your keys. A passkey wallet makes losing access much less likely; it does not make it impossible.
So the same habits apply: add a backup passkey on a second device, consider writing down the recovery phrase, and test that you can get back in. More on how the pieces fit: Passkey wallets vs seed phrases, How crypto wallets get hacked, How to use InfraIO Wallet, InfraIO Wallet.



