Theft

Company Lost Crypto: What Businesses Should Do

An office desk with a laptop, printed TxIDs, and a corporate crypto-incident checklist
In brief

If a company lost crypto, the first 24 hours are about stopping further outflow, preserving TxIDs, and keeping communications tight. A treasury incident is not the same as theft from a personal wallet: signers, authority to act, and freeze requests from a legal entity follow a different path. See emergency response for the urgent route.

How a corporate incident differs from private theft

A private case is usually one wallet, one signer, and a short loop: close the gap, then preserve evidence. A company also has treasury wallets, multisig, rebalancing bots, exchange API keys, and several employees with access. The loss may be external (phishing, a malicious token approval, a leaked seed phrase) or internal: one signer is compromised. The personal-wallet checklist is in hacked crypto wallet: what to do; this article covers the layer that a private case does not have.

The second axis is communications. A public project cannot stay silent forever: the chain is visible to outside observers. An early "we were hacked" post without facts or a freeze request often backfires: counterparties panic, and attackers speed up withdrawals. Name a small circle in advance: who speaks to exchanges, who speaks to counsel, who speaks to investors — and what is not published until the TxID package exists.

The third axis is the form of the request. Platforms treat an approach from a legal entity differently: they expect proof of authority, company identifiers, and a coherent route report, not a chat screenshot. That is not a promise that assets will be frozen; it is a different entry into the same process described in freezing stolen crypto on an exchange.

The first 24 hours: checklist

  1. Stop further outflow: revoke dangerous token approvals, move the remainder to a new key set, and disable bots and scripts that used the old keys or API credentials.
  2. Record TxIDs, networks, addresses, block times, affected treasury addresses, and access logs for signing if you have them.
  3. Define a tight communications circle: one channel to exchanges, one to counsel, and a ban on unofficial social posts.
  4. Check whether a compromised multisig signer is still active; change the threshold and key set if needed.
  5. Assemble authority to act for the company before a mass email to every partner.
  6. Do not enter a seed phrase or send API secrets in a ticket, a chat, or a helper found through search.

In parallel, assess whether the assets reached a centralized-exchange deposit: the window for a hold request is shorter than an internal meeting cycle. Mapping hops belongs in blockchain analytics, not in a single explorer screenshot. If the wallet gap is still open, close it first — every hour can add new outgoing transfers.

Freeze requests, partners, and the legal track

A freeze request asks a platform to hold a deposit while the assets remain in its accounts. It does not reverse a blockchain transfer. From a company, platforms typically want a coherent package: TxIDs, the route, the mechanism (phishing, approval, insider), and proof of authority. The exchange decides; you do not set its response time. Anonymized write-ups without promised outcomes are in case studies.

ObjectiveWhat may be realistic in the first day
Stop further outflowNew key set, stop bots and approvals
Evidence packageTxIDs, addresses, times, access logs
Freeze requestOnly while assets remain in a platform account
Full recoveryNot guaranteed

Partners and investors are better served by a short factual note after the first evidence capture than by silence until a leak or a panicked post. The legal layer — authority, contracts, a report to authorities — is a separate track, not a substitute for stopping the loss; see a lawyer after crypto theft. A public statement before the evidence package rarely speeds up a freeze.

What not to do

  • Do not publish raw incident details until the TxID package exists and destination platforms have been contacted.
  • Do not leave a compromised key in the multisig "for later."
  • Do not pay a recovery guarantor or put a seed phrase in a ticket.
  • Do not confuse freezing someone else's deposit with unfreezing your own exchange account.

Do not spend the first day assigning blame in chats. The window while remainder sits on an address or an exchange deposit is shorter than internal alignment. Stop the outflow and preserve evidence first; then shape the public narrative.

Limitations

Risks and limitations

  • Some assets may already have been withdrawn, and recovery is not guaranteed.
  • A premature public post can speed up withdrawals and complicate freeze requests.
  • Sharing a seed phrase, keys, or API secrets in a ticket or with a helper increases the loss.
  • If a compromised signer remains in the multisig, outflow can continue.
  • A freeze at an exchange is the platform's decision; the window before withdrawal can close in hours.
Sources

Sources used

Next

Related resources

ServiceEmergency responseBack to the blog
Next step

Need an assessment of your situation?

Briefly describe what happened — without seed phrases or private keys. We will outline possible routes and assess their feasibility.

Request a free assessment
Free initial assessment

Describe what happened

Answer a few questions so we can assess the situation and suggest the next steps.

Do not send seed phrases, private keys, passwords, or 2FA codes. They are not needed for an initial assessment.

Do not send seed phrases, private keys, passwords, or 2FA codes.