Independent platform · No upfront fees · We are not a recovery firm

Home › Knowledge Hub › If your wallet is compromised

Wallet compromised: what to do in the first ten minutes

By Yair Revach · Co-founder, Chain Pursuit · 9 min · Last updated 1 October 2026

If funds are moving or have moved, work through this in order. Move remaining assets to a new wallet before anything else, because attackers commonly run scripts that sweep a compromised address the moment something arrives in it. Revoking approvals comes second. Documenting comes third. Everything else can wait an hour.

Do these now

Read the rest afterwards. If this is live, minutes matter.

1. Create a new wallet and move everything. A fresh wallet, on a device you trust, with a recovery phrase that has never existed anywhere before. Move every remaining asset to it. Do not wait to understand what happened.

2. Revoke approvals on the compromised address. Use Revoke.cash or Etherscan's Token Approval Checker. Type the address rather than following a link. Repeat on every chain you have used.

3. Do not send anything back to the old address. Not a test transaction, not a small amount to check, not gas to pay for a revocation. Automated sweeping is standard, and anything arriving there is likely gone within seconds.

4. If your recovery phrase may have been exposed, revoking will not help. The phrase is the wallet. Step 1 is the only thing that matters.

Once assets are safe, continue below.

The order that matters
Move fundsto a new walletRevokeevery chainSecure emailthen exchangesDocumentthen reportRevoking before moving leaves a window open. Attackers sweep compromised addresses automatically.
Each step protects the one after it. Moving funds before revoking is the difference between losing some and losing everything.

Work out which kind of compromise this is

The right response differs, and people often assume the wrong one.

What happenedWhat the attacker holdsWhat actually helps
You approved a malicious transaction or signaturePermission to move specific tokensRevoking approvals
You entered your recovery phrase somewhereThe wallet itself, permanentlyMoving funds to a new wallet
Malware on your devicePossibly the keys, possibly the clipboardNew wallet on a clean device
Your exchange account was accessedAccount access, not your keysExchange support, password, 2FA
You sent to the wrong addressNothing. This was an error, not an attackContacting the recipient or exchange

If you are unsure, assume the worst case that fits. Treating an approval compromise as a phrase compromise costs you the price of moving funds. Treating a phrase compromise as an approval compromise costs you everything.

Signs of each

An approval compromise usually shows one token type disappearing while others remain, often some time after you interacted with a site. Your wallet still works and you still control it.

A phrase compromise typically empties everything, across multiple tokens and sometimes multiple chains, in quick succession. New transactions may continue appearing after you think you have stopped it.

Malware often shows as funds going to an address that looks almost like the one you intended, because clipboard hijackers swap addresses at the moment of pasting.

Exchange account access shows as withdrawals you did not make, usually with login alerts you may have missed, and often preceded by your phone losing service if a SIM swap was involved.

Securing the rest

Once assets are moved, work outwards from your email. Email controls password resets for everything else, so it comes before exchanges.

Email. New password, unique. Two-factor authentication on, ideally with an authenticator app rather than SMS. Then check forwarding rules and filters you did not create. This step gets skipped constantly, and it is how attackers keep reading your mail after you have locked them out.

Exchange accounts. New password, 2FA on, then review login history, connected devices, API keys and withdrawal allowlists. An API key with withdrawal permission is a standing door that a password change does not close.

The device. If you suspect malware, do not move funds to a new wallet on the same machine. Use a different device, then deal with the compromised one separately.

Your phone, if service dropped unexpectedly. Call your carrier from another line and say the words "SIM swap". Our SIM swap guide covers what follows.

What does not help

Worth saying plainly, because each of these wastes time people do not have.

Changing your wallet password. The password protects the local application. It is not what an attacker used and it is not what protects your funds.

Uninstalling and reinstalling the wallet. The keys are derived from your recovery phrase, not stored in the app. Reinstalling changes nothing.

Contacting the wallet provider. They cannot reverse a transaction, freeze an address, or recover funds. There is no support process for this because there is nothing support can do.

Posting publicly asking for help. Within minutes you will receive replies from accounts impersonating support, offering to recover the funds. This is the single most reliable way to be defrauded a second time.

Sending funds to "secure" them elsewhere on someone's instruction. Nobody legitimate will ever ask this.

Then document it

Once the immediate danger has passed, preserve what you have. Do this before accounts disappear.

Our evidence checklist covers this in full, including why transaction identifiers decide whether a report can be acted on.

Report it

Reporting is free and it is the step with the best documented odds, which is why it comes before considering anyone paid.

The complication is that most countries run several channels doing very different things. Some can begin a police investigation; others collect intelligence and will never respond to you. Our country guides label each one by what it actually does.

If funds reached an identifiable exchange, contact that exchange's compliance team directly with the transaction hashes. Where the theft is recent and the funds have not moved on, a fast report is occasionally enough for a freeze. That window is measured in days.

Is recovery realistic?

Usually less so than for scams involving payments from an exchange, and it is worth being direct about why.

With a fake investment platform, you sent funds from an account with records, which gives investigators a starting point. With a drained wallet, funds moved directly from your address to the attacker's, often within seconds, and frequently through a mixer or bridge before you noticed.

It is more realistic if the theft is very recent and the trail ends at a regulated exchange rather than a mixer. Our guide on what is actually recoverable sets out the factors honestly.

Report it regardless. Drainer operations run against thousands of wallets at a time, and aggregated reports are how the infrastructure behind them gets identified.

Expect a second approach

Anyone who loses crypto is targeted afterwards, usually within weeks. The approach may reference details of your loss, which feels like proof and is not. Victim lists are traded.

Offers to "reverse the transaction" or "recover from the smart contract" describe things that do not exist. Read how to spot a crypto recovery scam before replying to anyone.

Red flags in the hours afterwards

Checklist

First ten minutes

Within the hour

Same day

What this guide cannot do

Acting quickly improves the odds. It does not guarantee recovery, and in most cases funds taken from a compromised wallet are not returned. This page is written to stop further loss and preserve what makes anything else possible.

This is general information, not legal or financial advice.

Use Chain Pursuit's free tools to understand your options, preserve evidence, and identify possible recovery scams. Do not share your seed phrase or private keys with anyone.

Frequently asked questions

Should I move my funds or revoke approvals first?

Move funds first, always. Revoking is a transaction that takes time to confirm, and during that time an attacker with an active approval can still act. If your recovery phrase was exposed, revoking achieves nothing at all and moving is the only step that matters.

The attacker left some tokens behind. Why?

Usually because those tokens were not covered by the approval they exploited, or were not worth the gas to move. It does not mean the wallet is safe. Move everything remaining to a new wallet.

Can I keep using the same wallet after revoking approvals?

If the compromise was an approval and your recovery phrase was never exposed, technically yes. In practice, create a new one. The cost is minutes and it removes any uncertainty about what else you may have approved and forgotten.

I sent gas to the compromised wallet to pay for revoking. It disappeared.

That is expected. Automated sweeping takes anything that arrives, often within a block. Revoke from a wallet that already holds gas, or accept that the approval remains and rely on having moved the assets.

Should I tell my exchange even though the theft was from my own wallet?

Yes, if the funds reached that exchange. They may be able to restrict the receiving account or preserve records. They will not identify the account holder to you, and they are not obliged to act on your request alone.

Does reinstalling my wallet app help?

No. Your keys are derived from the recovery phrase, not stored in the application. Reinstalling changes nothing about who can access the funds.

How do I know whether it was malware or a bad approval?

An approval compromise usually takes specific tokens, some time after you interacted with a site, while the wallet keeps working. Malware often sends funds to an address resembling one you intended, because clipboard hijackers swap addresses at paste. If unsure, assume the more serious case and move to a new wallet on a different device.

Someone has offered to trace my funds for a fee. Is that worth it?

Not before you have reported it, which is free. And never pay before anything is recovered. In the United States charging an advance fee for recovery services is prohibited under the FTC's Telemarketing Sales Rule. Read our recovery scam guide first.

Once the immediate steps are done

Ten questions showing which documentation and reporting routes are available in your case.

Recovery pathway assessment

Keep reading