Theft

Unauthorized Crypto Withdrawal from a Wallet: The First Hours

Dark desk with a monitor and keyboard, illustrating the first hours after an unauthorized wallet withdrawal
In brief

If someone made an unauthorized crypto withdrawal from your wallet, the priority in the first hours is not an immediate promise of full recovery. Stop further loss: preserve the TxIDs and addresses, move the remaining assets to a new clean wallet from a safe device, and send nothing back to the compromised address. The stolen crypto is already moving, and the opportunity to freeze it at a destination exchange may be brief. Use emergency response for the urgent route.

What an unauthorized withdrawal means right now

This is not your normal withdrawal to an exchange. It is an unauthorized outflow: an attacker has already sent a transaction from your address. You may see an unknown transfer, a series of withdrawals, or an emptied token balance. This is not an exchange dispute or a pending withdrawal. Transactions from a self-custody wallet are irreversible. They cannot be rolled back; the immediate tasks are to limit the damage and preserve the trail.

Some incidents involve a live approve permission that allows a contract to spend tokens, while others involve a stolen seed phrase. In the first scenario, revoking approvals and moving the remainder may still help. In the second, the address must be treated as permanently unsafe. If you are unsure, assume the attacker controls the key: create a new wallet on a clean device and do not make any new deposits to the old address. See the first 60 minutes after a malicious approval for the approve scenario.

First-hours checklist

  1. Open a blockchain explorer and preserve every outgoing TxID, network, amount, recipient address, and block time as screenshots and a text list.
  2. Create a new wallet on a clean device; never enter or photograph the seed phrase unnecessarily.
  3. Move the remaining assets to the new address, starting with the most liquid assets. Do not send gas to the old address if incoming gas is removed immediately.
  4. Do not move the remainder back to the same wallet or make new deposits to the compromised address.
  5. If you suspect a malicious approve, revoke permissions on every affected network and type the revocation service URL manually.
  6. Change email and exchange passwords and 2FA if the same device or phishing incident may have exposed them.

At the same time, do not waste the response window on recovery services found through search or chats requesting a seed phrase or remote access. Legitimate assistance does not request a recovery phrase. If some assets have reached a centralized exchange, a package of TxIDs can support a request for freezing and exchange engagement, but secure your own wallet first.

TxIDs, tracing, and an exchange freeze

A TxID is the primary anchor for analytics and reports. Without it, showing the outflow path, destination addresses, and timing is difficult. Add the affected networks, a screenshot of any phishing page or message, the contracts authorized to spend tokens, and the discovery time. This information is needed for blockchain analytics and for platform requests if the stolen crypto reaches an exchange deposit address.

GoalRealistic action in the first hours
Stop further outflowNew wallet and, where relevant, revoke approvals
Preserve the trailTxIDs, addresses, networks, and discovery time
Freeze at an exchangePossible only while the assets remain in an exchange account
Full recoveryNot guaranteed; depends on the transaction path and exchange

An exchange freeze is possible only while the assets remain in an exchange account and the platform is willing to act on a substantiated request. Success is not guaranteed. Mixers, bridges, and rapid OTC disposal narrow the opportunity. Do not rely on promised recovery percentages. The realistic first-hours goal is to stop further loss and preserve a complete evidence package.

What not to do in a panic

  • Do not top up the compromised address with a small amount to fund gas or run a test.
  • Do not install recovery extensions or bots from advertisements.
  • Do not submit a seed phrase through a website form or chat.
  • Do not reuse the address for new incoming funds, even temporarily.

Do not spend the first hours arguing in comments or trying to assign blame. While assets remain at the address or are moving toward an exchange, speed matters more than a perfect attack theory. After stopping the outflow and preserving the TxIDs, investigate the mechanism and the next step.

Limitations

Risks and limitations

  • Confirmed blockchain transactions are irreversible, and recovery of stolen cryptocurrency is not guaranteed.
  • Adding funds to the same compromised wallet may accelerate the loss of the remaining assets.
  • Fake recovery services and cloned approval-revocation sites can steal assets that have not yet moved.
  • A destination-exchange freeze depends on timing, jurisdiction, and whether the assets have already moved onward.
  • Handling a seed phrase on an infected device can deepen the loss even after passwords are changed.
Sources

Sources used

Next

Related resources

ServiceEmergency responseBack to the blog
Next step

Need an assessment of your situation?

Briefly describe what happened — without seed phrases or private keys. We will outline possible routes and assess their feasibility.

Request a free assessment
Free initial assessment

Describe what happened

Answer a few questions so we can assess the situation and suggest the next steps.

Do not send seed phrases, private keys, passwords, or 2FA codes. They are not needed for an initial assessment.

Do not send seed phrases, private keys, passwords, or 2FA codes.