Home › Knowledge Hub › If your wallet is compromised
Wallet compromised: what to do in the first ten minutes
If funds are moving or have moved, work through this in order. Move remaining assets to a new wallet before anything else, because attackers commonly run scripts that sweep a compromised address the moment something arrives in it. Revoking approvals comes second. Documenting comes third. Everything else can wait an hour.
Do these now
Read the rest afterwards. If this is live, minutes matter.
1. Create a new wallet and move everything. A fresh wallet, on a device you trust, with a recovery phrase that has never existed anywhere before. Move every remaining asset to it. Do not wait to understand what happened.
2. Revoke approvals on the compromised address. Use Revoke.cash or Etherscan's Token Approval Checker. Type the address rather than following a link. Repeat on every chain you have used.
3. Do not send anything back to the old address. Not a test transaction, not a small amount to check, not gas to pay for a revocation. Automated sweeping is standard, and anything arriving there is likely gone within seconds.
4. If your recovery phrase may have been exposed, revoking will not help. The phrase is the wallet. Step 1 is the only thing that matters.
Once assets are safe, continue below.
Work out which kind of compromise this is
The right response differs, and people often assume the wrong one.
| What happened | What the attacker holds | What actually helps |
|---|---|---|
| You approved a malicious transaction or signature | Permission to move specific tokens | Revoking approvals |
| You entered your recovery phrase somewhere | The wallet itself, permanently | Moving funds to a new wallet |
| Malware on your device | Possibly the keys, possibly the clipboard | New wallet on a clean device |
| Your exchange account was accessed | Account access, not your keys | Exchange support, password, 2FA |
| You sent to the wrong address | Nothing. This was an error, not an attack | Contacting the recipient or exchange |
If you are unsure, assume the worst case that fits. Treating an approval compromise as a phrase compromise costs you the price of moving funds. Treating a phrase compromise as an approval compromise costs you everything.
Signs of each
An approval compromise usually shows one token type disappearing while others remain, often some time after you interacted with a site. Your wallet still works and you still control it.
A phrase compromise typically empties everything, across multiple tokens and sometimes multiple chains, in quick succession. New transactions may continue appearing after you think you have stopped it.
Malware often shows as funds going to an address that looks almost like the one you intended, because clipboard hijackers swap addresses at the moment of pasting.
Exchange account access shows as withdrawals you did not make, usually with login alerts you may have missed, and often preceded by your phone losing service if a SIM swap was involved.
Securing the rest
Once assets are moved, work outwards from your email. Email controls password resets for everything else, so it comes before exchanges.
Email. New password, unique. Two-factor authentication on, ideally with an authenticator app rather than SMS. Then check forwarding rules and filters you did not create. This step gets skipped constantly, and it is how attackers keep reading your mail after you have locked them out.
Exchange accounts. New password, 2FA on, then review login history, connected devices, API keys and withdrawal allowlists. An API key with withdrawal permission is a standing door that a password change does not close.
The device. If you suspect malware, do not move funds to a new wallet on the same machine. Use a different device, then deal with the compromised one separately.
Your phone, if service dropped unexpectedly. Call your carrier from another line and say the words "SIM swap". Our SIM swap guide covers what follows.
What does not help
Worth saying plainly, because each of these wastes time people do not have.
Changing your wallet password. The password protects the local application. It is not what an attacker used and it is not what protects your funds.
Uninstalling and reinstalling the wallet. The keys are derived from your recovery phrase, not stored in the app. Reinstalling changes nothing.
Contacting the wallet provider. They cannot reverse a transaction, freeze an address, or recover funds. There is no support process for this because there is nothing support can do.
Posting publicly asking for help. Within minutes you will receive replies from accounts impersonating support, offering to recover the funds. This is the single most reliable way to be defrauded a second time.
Sending funds to "secure" them elsewhere on someone's instruction. Nobody legitimate will ever ask this.
Then document it
Once the immediate danger has passed, preserve what you have. Do this before accounts disappear.
- The transaction hash of the draining transaction, and the network
- The attacker's address, visible in that transaction
- The approval transaction if you can find it, and its date
- The site or application you interacted with, including the exact URL even if it is now dead
- The message, advert or post that led you there
- Screenshots of any signature prompt you approved
- Login history from your exchange, exported if possible
Our evidence checklist covers this in full, including why transaction identifiers decide whether a report can be acted on.
Report it
Reporting is free and it is the step with the best documented odds, which is why it comes before considering anyone paid.
The complication is that most countries run several channels doing very different things. Some can begin a police investigation; others collect intelligence and will never respond to you. Our country guides label each one by what it actually does.
If funds reached an identifiable exchange, contact that exchange's compliance team directly with the transaction hashes. Where the theft is recent and the funds have not moved on, a fast report is occasionally enough for a freeze. That window is measured in days.
Is recovery realistic?
Usually less so than for scams involving payments from an exchange, and it is worth being direct about why.
With a fake investment platform, you sent funds from an account with records, which gives investigators a starting point. With a drained wallet, funds moved directly from your address to the attacker's, often within seconds, and frequently through a mixer or bridge before you noticed.
It is more realistic if the theft is very recent and the trail ends at a regulated exchange rather than a mixer. Our guide on what is actually recoverable sets out the factors honestly.
Report it regardless. Drainer operations run against thousands of wallets at a time, and aggregated reports are how the infrastructure behind them gets identified.
Expect a second approach
Anyone who loses crypto is targeted afterwards, usually within weeks. The approach may reference details of your loss, which feels like proof and is not. Victim lists are traded.
Offers to "reverse the transaction" or "recover from the smart contract" describe things that do not exist. Read how to spot a crypto recovery scam before replying to anyone.
Red flags in the hours afterwards
- Anyone contacting you first about the loss
- An offer to recover funds for a fee paid upfront
- A request for your recovery phrase to "restore" the wallet
- A "recovery tool" or "revocation site" sent to you rather than found by you
- Someone claiming to work with law enforcement
- Pressure to act immediately on any of the above
Checklist
First ten minutes
- [ ] New wallet created on a trusted device
- [ ] All remaining assets moved to it
- [ ] Approvals revoked on the old address, every chain
- [ ] Nothing sent back to the compromised address
Within the hour
- [ ] Email password changed, 2FA on, forwarding rules checked
- [ ] Exchange passwords changed, API keys reviewed
- [ ] Carrier contacted if phone service dropped
- [ ] Device checked or replaced if malware suspected
Same day
- [ ] Transaction hashes and attacker address recorded
- [ ] Site, message and prompt screenshots saved
- [ ] Receiving exchange contacted if identifiable
- [ ] Report filed through the right channel for your country
What this guide cannot do
Acting quickly improves the odds. It does not guarantee recovery, and in most cases funds taken from a compromised wallet are not returned. This page is written to stop further loss and preserve what makes anything else possible.
This is general information, not legal or financial advice.
Use Chain Pursuit's free tools to understand your options, preserve evidence, and identify possible recovery scams. Do not share your seed phrase or private keys with anyone.
Frequently asked questions
Should I move my funds or revoke approvals first?
Move funds first, always. Revoking is a transaction that takes time to confirm, and during that time an attacker with an active approval can still act. If your recovery phrase was exposed, revoking achieves nothing at all and moving is the only step that matters.
The attacker left some tokens behind. Why?
Usually because those tokens were not covered by the approval they exploited, or were not worth the gas to move. It does not mean the wallet is safe. Move everything remaining to a new wallet.
Can I keep using the same wallet after revoking approvals?
If the compromise was an approval and your recovery phrase was never exposed, technically yes. In practice, create a new one. The cost is minutes and it removes any uncertainty about what else you may have approved and forgotten.
I sent gas to the compromised wallet to pay for revoking. It disappeared.
That is expected. Automated sweeping takes anything that arrives, often within a block. Revoke from a wallet that already holds gas, or accept that the approval remains and rely on having moved the assets.
Should I tell my exchange even though the theft was from my own wallet?
Yes, if the funds reached that exchange. They may be able to restrict the receiving account or preserve records. They will not identify the account holder to you, and they are not obliged to act on your request alone.
Does reinstalling my wallet app help?
No. Your keys are derived from the recovery phrase, not stored in the application. Reinstalling changes nothing about who can access the funds.
How do I know whether it was malware or a bad approval?
An approval compromise usually takes specific tokens, some time after you interacted with a site, while the wallet keeps working. Malware often sends funds to an address resembling one you intended, because clipboard hijackers swap addresses at paste. If unsure, assume the more serious case and move to a new wallet on a different device.
Someone has offered to trace my funds for a fee. Is that worth it?
Not before you have reported it, which is free. And never pay before anything is recovered. In the United States charging an advance fee for recovery services is prohibited under the FTC's Telemarketing Sales Rule. Read our recovery scam guide first.
Once the immediate steps are done
Ten questions showing which documentation and reporting routes are available in your case.
Recovery pathway assessment