A TRX position, bought on a major exchange near the top of the 2017-18 cycle and moved straight into a MyEtherWallet paper wallet. Then eight years of silence. The keys were never lost. The market was never thin. What made this engagement hard is that TRX outlived the chain it was issued on, and the wallet outlived the era that recommended it.
The setup was almost quaint. A holder bought TRX near the top of the 2017-18 cycle, withdrew it from the exchange the same week, and swept it into a MyEtherWallet paper wallet: an address and a private key, generated in a browser, printed onto a sheet of paper, filed away. Then nothing. No sends, no receives, no interaction of any kind for more than eight years.
They wanted to know two things. Is it still there, and can it be turned into something current. The first answer took minutes on Etherscan. The second took the rest of the engagement.
This is the piece almost everyone gets backwards, including, initially, us. Tron launched TRX in 2017 as an ERC-20 token on Ethereum. It had no blockchain of its own. The Tron mainnet people associate with the name today did not go live until the middle of 2018, roughly a year after TRX was already trading and already sitting in wallets like this one.
So the paper wallet was never holding a knockoff, a wrapper, or a mistake. It held the original, canonical, only-version-that-existed asset. It became a "legacy" token later, retroactively, because the project built its own chain and migrated everyone across. The holder did not fall behind. The ground moved.
One more thing about that era deserves saying plainly, because holders in this position are often quietly embarrassed. In 2017, a MyEtherWallet paper wallet was the recommended cold storage for ERC-20 tokens. Hardware wallets of that generation barely supported tokens at all, and this token had no hardware support whatsoever. There was no better option. The client did the responsible thing that was available at the time, and doing the responsible thing is precisely what made it awkward to unwind years later.
"It is probably on one of the hardware wallets." There were two devices in the picture, and starting there was the obvious move. We swept both exhaustively: both seeds, the native derivation paths, the Ethereum-twin addresses those seeds also generate, and specifically the legacy ERC-20 contract rather than just the native balance.
Every single address came back never activated. Not low, not dusty. Never touched, verified directly against the chains rather than against any wallet interface. The asset had never been on hardware at any point in its life. That sweep cost real hours and produced no funds, and it was still necessary.
Readers of our first case study will recognize the shape of this. A rigorous negative closes a branch permanently. Without it you carry a nagging maybe into every later decision, and at some point somebody says the word "stolen" out loud. With it, the search narrows to the one artifact left standing: a sheet of paper generated in a browser during the last cycle.
To move anything, the private key has to be loaded into software that can sign. In practice that means importing it into a browser wallet such as MetaMask. This is the step people take casually, and it is the single most consequential decision in the entire engagement.
The moment a paper key touches a browser, that key is hot, and it is hot forever. There is no undo. The key has been in the memory of an internet-connected machine, inside an extension, adjacent to whatever else that browser has ever run. You cannot walk it back to cold by deleting the wallet or wiping the profile. Cold storage is a claim about the entire history of a secret, not about where it is stored right now.
That does not make the import wrong. It makes it a decision with conditions attached, and we hold to three of them. It is justified only when the address is being fully emptied in the same session, so nothing of value is left behind a key whose security model has changed. The owner of that key must be told, in plain language and before it happens, that their cold storage is about to stop being cold. And when the sweep is complete, the address is retired permanently: never reused, never funded again, treated as burned regardless of how careful the machine was.
There was one more wrinkle, small and completely blocking. The address had never sent a transaction in its life, which means it had never held any gas. A wallet holding a fortune in tokens and zero native coin can do exactly nothing. Before any of the interesting work could start, we had to fund the account so it could pay to speak.
Plenty of serious people printed a key during the last cycle, filed it away, and have not touched it since, because every option for touching it feels like a chance to break something. That instinct is worth respecting and worth acting on, in that order. Paper degrades, printers were never trustworthy, memories of where the sheet lives get vague, and the tooling that can still read a key from that era gets thinner every year. More to the point, the project behind your token may have moved somewhere you were never notified about. We can tell you what that address actually holds today, whether the asset still has a path to anything current, and what a clean sweep would involve, all before you touch the key. You keep custody the entire time, and the first conversation costs nothing.
Tron ran an official migration: deposit your ERC-20 TRX with a participating exchange, receive mainnet TRX. That program had a deadline, and the deadline passed years before this engagement began. There is no appeals desk. Nobody at the foundation can reopen it for one holder, however sympathetic the story.
Which reframes the whole problem. With the official path shut, the legacy token is not convertible, it is merely tradeable. The route from old asset to current asset runs through the open market, not through the issuer, and every constraint that follows is a market and mechanics constraint rather than an administrative one.
Tron does not price transactions the way Ethereum does. Instead of a simple gas fee, contract calls consume energy, an execution budget you obtain by holding or staking TRX, alongside a second metered resource called bandwidth. If the account has neither, contract calls do not merely cost more. They do not execute. Tron adds one more trap for newcomers: a brand-new account does not fully exist on-chain until it is activated by receiving TRX, and until then some wallets will display it as empty even while tokens sit against it on Tronscan.
The practical consequence is one of the least intuitive states in crypto. An account can hold a substantial token balance and be completely unable to transact. Nothing is wrong with the account, nothing is wrong with the tokens, the balance reads correctly everywhere you look, and every attempt to move it fails. This stalled the engagement outright until we diagnosed it, and the diagnosis is the entire fix: fund the account with a small amount of the native coin first, then everything works.
Anyone moving value onto an unfamiliar chain should ask one question before they start: what does this network charge for computation, and in what. The answer is rarely "the same as the last one," and finding out after your funds have already arrived is how positions end up stranded on the far side of a transfer.
We evaluated four separate routes for the conversion. Not because we enjoy the exercise, but because each one failed a different way and the failures were only visible from the inside.
One cross-chain bridge was ruled out on security grounds. It had been exploited twice, and not by two unrelated flukes: both incidents came from the same class of attack, which tells you the fix addressed an instance rather than the underlying design. A protocol that gets hit the same way twice is telling you something about its threat model, and a client's assets are not the right place to test whether the third time is different.
One was ruled out for being custodial. It would have worked. It also would have meant handing the position to an intermediary, mid-flight, in exchange for a promise, which is the precise arrangement this client had spent eight years avoiding. Convenience is not worth reintroducing counterparty risk into a self-custody position at the last step.
The route that actually worked, a cross-chain swap through OKX's Web3 DEX aggregator carrying USDT from Ethereum to native TRX on Tron, was found by building the transactions and seeing which ones executed, exactly as in our second case study. It was proven with a small test tranche, confirmed landing on Tronscan, before real size followed. The winner was not the best known name, the best designed interface, or the one with the most confident pricing. It was the one whose orders built cleanly and settled.
Our second case study documented a position so large relative to its only pool that the client effectively was the market, and every decision bent around that scarcity. This engagement was the exact inversion. Legacy ERC-20 TRX still trades in an enormous, deep, thoroughly arbitraged Ethereum pool. Price impact on the full position was close to nothing. Sizing, tranching, timing: none of it mattered, and we spent almost no effort there.
All the difficulty sat upstream of the trade. Establishing which device or sheet of paper actually held the asset. Understanding that the token predated the chain that later claimed the name. Accepting the permanent cost of converting cold to hot. Diagnosing a gas model that silently froze an account holding real value. Discarding two routes on grounds that had nothing to do with price.
Liquidity is the part of this work people expect to be hard, and it is the part most often trivial. The hard part is custody archaeology and chain mechanics: figuring out where the asset really lives, what it really is, and what the network it is landing on actually requires. That work is unglamorous, it does not show up in a quote, and skipping it is how people conclude their funds are gone when they are sitting exactly where they were left.
Token breakdown: 840,067,913 cache read · 29,112,429 cache write · 2,223,932 output. Models: Claude Opus 5 (1,427 turns) and Claude Fable 5 (376 turns) drove the work, with GPT-5.6 Sol consulted across three structured rounds during the Zcash engagement. All four case studies in this series ran inside the same window and share these totals. Full technical detail for this engagement is held in our internal report series.
Plenty of "old" tokens were the canonical asset when they were bought. The project migrated to its own chain afterward. The holder did nothing wrong and still ended up stranded.
A browser-generated paper wallet was the correct answer for tokens in 2017. Custody decisions age, and reviewing yours every few years is cheaper than discovering the drift in a crisis.
Importing a paper key into a browser wallet permanently changes its security model. Do it only to empty the address completely, tell the owner before it happens, and retire the address afterward.
A wallet that has never sent anything cannot send anything. Fund it before you plan around it, and never assume the balance you can see is a balance you can move.
Ethereum charges gas. Tron meters energy and bandwidth and requires account activation. An account holding tokens with no TRX is frozen solid while looking perfectly healthy.
Rule out venues on security history, not brand recognition, then pick among the survivors by what actually builds and settles. Test, do not trust.
Almost every recovery we take on ends the same way: the assets were exactly where the client left them, and the obstacle was eight years of accumulated change around them. Chains launched. Migration windows opened and closed. Tooling was written for hardware and formats that came later. Fee models diverged. None of that is visible from a wallet screen, and none of it gets simpler by waiting. If you are holding something from a prior cycle and you do not know whether it still has a path to anything current, that is a question with a definite answer, and finding it does not require you to hand anyone your keys. Thirty minutes, no obligation, and an honest verdict including the unwelcome one if the job is not worth doing.
Coins, chains, and tools in this study are named as they were used. Client identifiers, addresses, transaction hashes, amounts, and the venues we ruled out are withheld. Previous in the series: Case Study No. 02 · Selling into a pool that barely exists, and Case Study No. 01 · The device the manufacturer forgot.