Crypto Stolen From a Wallet: A Calm Response Plan

If cryptocurrency was stolen from your wallet, first stop any further outflow and preserve evidence—the TxIDs, addresses, times, and screenshots. Then prepare a report for the destination exchange while assessing possible recovery options. Recovery is not guaranteed. For a calm response path, see emergency response.
Theft is more specific than “the funds just left”
The word “stolen” is appropriate when there are signs of unauthorized access or deception: unknown outgoing TxIDs, a phishing page, a malicious approve signature, an exposed seed phrase, fake “support” in a chat, or a malicious browser extension. Keep a mistaken-address transfer or another transfer you knowingly authorized in a separate category; the analysis and likely outcomes differ.
The goal in the first hours is not to prove to the internet who is responsible. It is to close the security gap and build the evidence package that an exchange, law-enforcement agency, or blockchain analyst will need. If token withdrawals are continuing through contract permissions, also follow the first 60 minutes after a malicious approval.
Do not confuse wallet theft with an exchange withdrawal freeze. If the assets remain in your exchange account and you control the account, the appropriate route is exchange unfreezing, not a stolen-wallet response.
A calm checklist
- Record the outgoing TxIDs, recipient addresses, networks, amounts, and times, using both explorer screenshots and a text list.
- Do not delete messages, emails, browser history, or notifications before preserving them.
- Use a clean device to create a new wallet; never enter or photograph the seed phrase.
- Move the remaining assets to the new address, starting with liquid assets.
- If the mechanism resembles a malicious approve permission, revoke permissions through a legitimate revocation service whose address you type manually.
- Change the passwords and 2FA for email and exchanges linked to the same device or phishing incident.
- Do not send a small amount of gas to an address that is actively being drained if incoming gas is immediately removed.
- Do not install “recovery bots” or browser extensions found through search results.
- Do not reuse the compromised address for new deposits.
- Do not submit your seed phrase through a website form or chat.
If you cannot determine whether the compromise involved the seed phrase or a malicious approve permission, respond to the more severe scenario: treat the address as compromised, move the remaining assets, and preserve the evidence. Blockchain analytics can then examine the collected TxIDs.
Evidence and a report to the exchange
A package for the destination exchange will usually include your source address, recipient addresses and intermediate hops, the transaction-chain TxIDs, amounts, networks, UTC times, a concise description of how the theft occurred, and the steps already taken to protect the remaining assets. A timely, precise package gives a manual review a better chance to examine the deposit before it is withdrawn, but the exchange decides whether to freeze it and there is no guarantee.
If the funds remain at an exchange deposit address or arrived recently, contacting the exchange is a priority alongside protecting the remaining assets. If the funds have already moved through a mixer, a long chain of swaps, or an OTC off-ramp, the likelihood of a rapid freeze decreases. The focus then shifts toward tracing and legal options rather than expecting to “recover everything overnight.”
Do not send a seed phrase, private keys, or complete wallet backups in a support request. The exchange needs evidence of fund movement and proof of control over the source address according to its procedure—not unrestricted control of your keys.
Recovery options and a police report
Partial recovery of stolen cryptocurrency may be possible when the transaction chain reaches a centralized platform and the response is fast. A confirmed blockchain transaction cannot be reversed. The outcome depends on the current location of the assets and decisions by third parties. A promise to “recover 100% for an up-front fee” is a common second fraud targeting victims.
A police report creates an official record and may support formal requests to exchanges and civil or criminal proceedings. Prepare the same TxIDs, addresses, amounts, times, and account of the incident while preserving the original screenshots. Filing a report is not a substitute for urgently protecting the remaining assets, and it does not guarantee recovery.
Law-enforcement agencies in different jurisdictions request similar core evidence: wallet addresses, transaction hashes, amounts, and dates. FBI IC3 materials on cryptocurrency crime provide one example of the information included in a complaint; confirm the local procedure where you live. At the same time, avoid “recovery” schemes: up-front payments for “unfreezing the channel” or a “recovery guarantor” are separate frauds after the theft. See case studies for analyses of related incidents.
Risks and limitations
- Some or all of the funds may already have been moved; recovery is not guaranteed.
- Handling a seed phrase on an infected device or trusting “helpers” found through search results may expose the remaining assets.
- An exchange decides whether to freeze funds, and the window before withdrawal may close within hours.
- A police report records the incident but does not by itself return assets transferred on-chain.
- Fake revocation services and “recovery” forms may steal the assets that remain.
Sources used
- FBI IC3 — Cryptocurrency: what to report after theft or scam
- FBI IC3 PSA — false cryptocurrency recovery services (up-front fee schemes)
- Revoke.cash — inspect and revoke token approvals
- DefCrypt emergency-response practice for wallet theft (anonymized)