A forgotten MultiBit HD password may be recoverable when an intact supported wallet file and useful password context survive. First distinguish a password problem from missing wallet words, an archive-restore problem or an empty-wallet synchronization issue.
Identify the backup before choosing a recovery method
mbhd.wallet.aes: the primary encrypted HD wallet.rolling-backup/*.wallet.aes: timestamped encrypted wallet snapshots.zip-backup/*.zip.aes: encrypted directory archives that can preserve additional application data.
For the documented software-wallet backup process, the primary wallet and rolling snapshots use password-based encryption; ZIP archives use a backup key derived from wallet words. An application password and wallet words are different recovery inputs. A file extension is a clue, not proof of its contents. A generic wallet.aes.json recipe is not a description of the MultiBit HD primary wallet format.
Build a practical password search
Preserve every original file and run an offline assessment on a copy. Useful context includes approximate length, language, keyboard layout and whether meaningful hints remain. A long random unknown password can make a search infeasible. Never modify the original backup to test a candidate.
Select the correct BTCRecover version and input
The maintained BTCRecover documentation describes installation requirements and supported wallet formats. The original gurnec project and maintained Python 3 versions have different environments. Follow the documentation for the actual version selected; do not combine an old repository with unrelated Python instructions or assume a generic JSON/ZIP filename is supported.
Token files and command options have defined syntax. Validate a search configuration with synthetic data before using sensitive material. This article does not provide an untested universal command or promise that brute force will recover any password.
Wallet words, password and restoration
Preserve the original words in their written order and record the original version if known. Do not identify a wallet solely by word count or assume that every HD wallet has a 13- or 18-word phrase. Keep any wallet date record: it helps choose a synchronization start point, but is not a replacement for the words.
The application password protects local wallet data. It should not automatically be entered into a modern recovery tool’s seed-passphrase field. The reviewed software-wallet creation methods use an empty seed passphrase; hardware-related and historical cases require separate identification.
The source distinguishes a BIP32 software wallet, an older beta implementation and hardware-related types. For the BIP32 software type, the source records the first receiving address at m/0'/0/0; this is not a universal recipe for every version. Verify a previously known address, receiving and change branches, and the search range before treating a zero balance as a failed recovery.
After finding a candidate
Confirm that the candidate opens the intended backup and reproduces the expected addresses. An encrypted file opening is useful evidence, but wallet selection, change branches and transaction history still matter. Modern wallets do not necessarily import an encrypted HD file directly. Plan migration as a separate step after verification.
Software and network problems
MultiBit is discontinued. A failure to synchronize or an address-format error does not prove the password is wrong. Preserve the error, wallet version and backup history, then diagnose the actual compatibility issue instead of making a blanket claim about every server or address type.
Maintained BTCRecover installation documentation
Documentation and further reading
- HD primary wallet, rolling backups and ZIP backups
- Wallet words and verification
- Wallet types, paths and the beta exception
- Original MultiBit HD source at the reviewed revision
Need help with recovery?
Email mail@keychainx.io with the wallet type, approximate date, backup extensions and error message. Describe the problem first; do not send passwords, wallet words, private keys or wallet files in an initial message. KeychainX can assess a wallet you own or are legally authorized to recover. Recovery is not guaranteed.
Technical review: 7 October 2026. Recovery depends on the surviving material and the original wallet version.

