Theft

Crypto Wallet Hacked: Where to Start

Dark desk with a laptop and headphones, illustrating compromised access to a crypto wallet
In brief

If your crypto wallet has been hacked, first identify the likely scenario: a leaked seed phrase, phishing or malware, or a malicious approve transaction. In the first steps, stopping further outflow matters more than promises of complete recovery. Create a new clean wallet on a safe device, preserve the TxIDs, and stop depositing to the old address. Use emergency response for the urgent route.

How to identify the compromise scenario

A wallet hack almost never means someone broke the blockchain. It usually means access was compromised: you entered a seed phrase on a fake page, shared it with supposed support, stored it in cloud notes or on an infected device, or installed a malicious extension or app. The attacker can then sign outgoing transfers without you. Treat the address as permanently unsafe for new deposits.

A malicious approve or token-spending permission is a separate scenario. You retain the key, but a contract has permission to move tokens. Revoking permissions and moving the remaining assets may help. See the first-hour drainer approval checklist for the details. If you cannot distinguish a seed phrase leak from an approval, assume the worse scenario: create a new wallet on a clean device and make no further deposits to the old address.

Indicators of an access compromise include outgoing TxIDs that you did not authorize, a balance emptied after entering a seed phrase or completing a security check, gas that disappears immediately after you send it, a phishing domain in browser history, or a recently installed helper app or remote-access tool. Preserve these facts rather than relying only on a general belief that the wallet was hacked.

First steps

  1. Open a blockchain explorer and preserve every outgoing TxID, network, amount, recipient address, and block time as screenshots and a text list.
  2. From a clean device or new browser profile, create a new wallet. Record the seed phrase offline and do not enter it elsewhere.
  3. Move the remaining assets to the new address, beginning with the most liquid assets.
  4. Do not send gas to the old address if incoming gas is removed immediately.
  5. If you suspect a malicious approve, rather than a complete seed phrase leak, revoke permissions by typing the revocation service URL manually and follow the first 60 minutes after a drain.
  6. Change the passwords and 2FA for email and exchange accounts connected to the same device or phishing incident.

Do not install recovery bots or submit the seed phrase through a chat. Legitimate assistance does not request the recovery phrase. If some assets have reached an exchange, a TxID package may support a request for freezing and exchange engagement, but first remove access to your own wallet.

A new clean wallet and device

A new clean wallet means a new address derived from a new seed phrase, created outside the infected environment. Do not restore the old phrase on the same phone or in the same browser with questionable extensions; malware or information stealers may capture the key again. Do not connect the new wallet to the same Google or Apple account if that account may have been part of the compromise.

After moving the remainder, treat the old address and every account derived from the same seed phrase as permanently compromised. Changing an extension password does not repair a leaked seed phrase. A hardware wallet may be suitable for new assets, but only with a seed phrase that has never been exposed on the infected computer. Moving the same exposed phrase to a Ledger does not make it secure.

Update the operating system, remove suspicious extensions and remote-access programs, and check whether the seed phrase was stored in cloud notes, screenshots, or a password manager. Blockchain analytics can document the outflow in parallel, but analytics does not replace moving the remaining assets.

What not to do after a compromise

  • Do not enter a seed phrase on hack-check websites, recovery forms, or specialist chats.
  • Do not fund the compromised address for testing or gas.
  • Do not reuse the address for salary payments, P2P, or new deposits.
  • Do not spend the first hour arguing in comments instead of preserving TxIDs and moving the remaining assets.
  • Do not expect an exchange or wallet support team to reverse a self-custody transfer; confirmed transactions are irreversible.

The realistic initial goal after a crypto wallet compromise is to stop further loss, establish a clean storage environment, and preserve a complete evidence package for a possible freeze and investigation. It is not a guarantee of recovery. After closing access and collecting the TxIDs, investigate the attack mechanism in more detail.

Limitations

Risks and limitations

  • Confirmed blockchain transactions are irreversible, and recovery is not guaranteed.
  • A leaked seed phrase makes the old address permanently unsafe for new deposits.
  • Handling the phrase on an infected device or storing it in the cloud can deepen the loss.
  • Fake recovery services and cloned approval-revocation sites may steal the remaining assets.
  • Confusing a malicious approval with complete key compromise can lead to ineffective action and repeated loss.
Sources

Sources used

Next

Related resources

ServiceEmergency responseBack to the blog
Next step

Need an assessment of your situation?

Briefly describe what happened — without seed phrases or private keys. We will outline possible routes and assess their feasibility.

Request a free assessment
Free initial assessment

Describe what happened

Answer a few questions so we can assess the situation and suggest the next steps.

Do not send seed phrases, private keys, passwords, or 2FA codes. They are not needed for an initial assessment.

Do not send seed phrases, private keys, passwords, or 2FA codes.