You refresh your wallet and the balance is gone — or worse, you're staring at a transaction hash you never signed. What you do in the next hour determines whether you save what's left or hand a second payday to the same criminals. This isn't a rare event: the FBI's Internet Crime Complaint Center (IC3) logged $11.366 billion in crypto-related fraud losses in the US in 2025 alone — a 22% jump from 2024 — across 181,565 complaints, itself a 21% year-over-year increase. Separately, blockchain security firms tracking on-chain theft (distinct from investment-scam losses) recorded more than $4.04 billion stolen directly from wallets and platforms in 2025, up 34.2% from $3.01 billion in 2024.
This guide is the checklist IT Cares gives clients in the minutes after they realize something is wrong: what to do immediately, what's actually recoverable, and how to avoid the second scam that catches almost as many victims as the first. None of this is financial or investment advice — it's IT security guidance for limiting damage and securing your accounts and devices after a breach.
The numbers behind these headlines matter because they tell you what kind of situation you're actually in. IC3's 2025 data puts the average reported individual loss in crypto fraud cases at $62,604, and 18,589 victims lost more than $100,000 each — this isn't a niche problem affecting only large holders, it's a mainstream one hitting everyday wallets. Whether you lost $80 in a small token or a life-changing amount, the first-hour response is identical: contain the damage, figure out how it happened, and don't let a second predator use your panic against you. That last part deserves its own emphasis, because it's the step people skip: fraudsters specifically monitor public complaints, support forums, and social media posts about wallet drains to find fresh victims for a follow-up "recovery" scam, covered in detail further down this guide.
First: don't panic, but don't get scammed twice
The instinct is to freeze, post about it publicly, or click the first "wallet recovery" link that lands in your inbox. Do none of that yet. Speed matters — an attacker who still has access can keep draining — but accuracy matters just as much. Work through this list in order, verify every tool and URL you use is one you already knew and trusted before today, and never enter your seed phrase anywhere to "verify," "unlock," or "recover" your wallet.
Is Your Wallet Actually Compromised? Signs to Check First
Before you do anything drastic, confirm what you're actually dealing with. Not every scare is a full wallet compromise — sometimes it's a single malicious approval, sometimes it's your exchange account, and sometimes it's a false alarm caused by a delayed transaction. Check for these signs:
- Unexpected outgoing transactions you never signed — check your wallet's transaction history and the relevant block explorer for your chain.
- Unauthorized token approvals — a permission that lets a smart contract move your tokens without asking you each time.
- Unfamiliar dApp connections — check your wallet's "Connected Sites" or "Connected Apps" list for anything you don't recognize.
- A small "test" transaction you don't remember making — a common precursor to a larger drain.
- Seed phrase exposure signs — you typed your recovery phrase into a website, a "wallet support" chat, took a screenshot of it, or stored it in a note-taking or cloud app that's since been compromised.
It's worth checking each of these methodically rather than assuming the worst from a single symptom. A block explorer for your specific chain shows the full, permanent transaction history for any public wallet address — search your address there first, independent of what your wallet app shows you, since a compromised device could theoretically alter what's displayed locally (rare, but worth ruling out). Cross-reference the timestamps of any suspicious transactions against your own activity: were you actively using a dApp, minting something, or clicking a link around that time? That correlation often points directly at the entry point.
| What You're Seeing | What It Likely Means |
|---|---|
| Outgoing transaction you never authorized | Wallet-level compromise (seed phrase or private key exposed) |
| Token approvals to unfamiliar contracts | A malicious dApp/contract was granted spending rights |
| Wallet connected to a site you don't recognize | Active dApp session from a phishing site |
| Funds gone but the wallet still opens with your usual password | Exchange/custodial account takeover — different from a self-custody breach |
| Antivirus flags recent malware or an odd background process | Device-level compromise (keylogger or clipboard hijacker) |
Not sure if your device is the entry point?
Our certified bilingual technician remotes in, scans for malware/keyloggers, and locks down your accounts on the spot — same day, from $119.99. No fix, no fee.
10 Things to Do in the First Hour
Don't Panic — Act Fast, But Don't Get Re-Scammed
Every step below can be done from a device you're confident is clean. Move deliberately through the list in order rather than jumping straight to whichever step feels most urgent — a rushed, out-of-order response is exactly what a follow-up scammer is counting on. Resist three specific impulses: posting your wallet address publicly asking for help (it invites scammers, not just sympathy), searching "recover my stolen crypto" and clicking the first paid result (many are scam operations themselves), and calling any phone number a "support agent" gives you unsolicited. Every legitimate action you need to take is listed here, using tools and channels you already know.
Move Any Remaining Funds to a Brand-New Wallet Immediately
If the drain isn't complete, your first priority is stopping further loss. Create a brand-new wallet with a brand-new seed phrase generated on a device you trust. Do not reuse the compromised seed phrase, even partially — attackers with the original phrase can regenerate every address derived from it, including ones you haven't touched yet, so a "new account, same words" approach fixes nothing. Transfer any remaining tokens, NFTs, and crypto using the fewest transactions possible. Each signed transaction from a compromised wallet is a moment an attacker's automated "sweeper" bot can front-run and steal the funds mid-transfer, because these bots watch the mempool for any incoming gas deposit or outgoing transfer from known-compromised addresses and race to drain the wallet the instant it has enough gas to move. If you don't have enough of the network's native token left to cover gas fees for the transfer itself, that's a separate obstacle attackers count on — some wallet tools support sending gas and the asset transfer together in one bundled transaction specifically to defeat sweeper bots.
Revoke All Token and Contract Approvals
Most drains happen because you unknowingly signed an approval giving a malicious contract permission to move your tokens — not because someone stole your seed phrase directly. Use a reputable approval-checker tool for your blockchain to see every contract your wallet has approved, and revoke anything you don't explicitly recognize and still need. Pay particular attention to "unlimited" or "infinite" approvals, which let a contract move any amount of a token at any time in the future, not just the amount involved in your original transaction — these are the single biggest source of delayed drains, where an approval granted weeks or months earlier is finally exploited long after you've forgotten about it. Make revocation a recurring habit going forward (see the prevention section below), not just a one-time cleanup after an incident.
Disconnect the Wallet From Every Connected App
Open your wallet's connected-sites or connected-apps list — in the browser extension or mobile settings — and disconnect every dApp, marketplace, and site, even ones you recognize. Do the same in any WalletConnect session manager you use. This closes any lingering session an attacker's script could still use to prompt further approvals.
Determine: Seed Phrase, Device, or Exchange Account?
This determines everything that follows. Seed phrase exposure (typed into a phishing site or fake support chat) means the wallet is permanently compromised — a new wallet is mandatory, and there is no way to "re-secure" the old one because the underlying secret is out. Device-level compromise (malware, a keylogger, or clipboard-hijacking software that swaps a copied address for the attacker's own) means every account accessed from that device is suspect, not just the wallet — a factory reset or full malware removal on a clean install is the only reliable fix, and it should happen before you trust that device with a new wallet. Exchange account compromise is different entirely — someone accessed your account on a centralized platform, not your self-custody wallet, and the fix is contacting that platform directly (step 6), not creating a new wallet at all. Getting this diagnosis wrong wastes precious time: moving funds to a new wallet on a still-infected device just hands the attacker your new seed phrase too.
If It's an Exchange, Contact Support and Freeze the Account
If the theft happened on a centralized exchange, contact its official support channel immediately — through the app or website you already have bookmarked, never through a number or link someone sends you unsolicited. Ask them to freeze the account, halt any pending withdrawal, and force a password and 2FA reset. Most major exchanges have a dedicated "account compromised" or "unauthorized transaction" flow that gets priority handling over a general support ticket; use it if it exists. Then change the password on that account, on your email, and on any other account that shared the same password, from a device you're confident is clean — reusing a compromised device to reset credentials can hand the attacker your new password too.
Document Everything Before It Disappears
Save every relevant transaction hash, the exact date/time with timezone, the wallet addresses involved (yours and the attacker's), screenshots of your transaction history and any approvals you found, and copies of any phishing messages, emails, or fake support chats that led to this. Block explorers are permanent, but your own browser history, notification timestamps, and the specific link or app that prompted the fatal approval are not — browser history in particular can be cleared automatically or simply age out, so capture it now rather than after you've filed your reports. You'll need this documentation for your exchange, for a police report, and for your own reference if you ever notice a similar pattern again.
Report It to the FBI's IC3 and Local Authorities
File a report at ic3.gov (the FBI's Internet Crime Complaint Center) even if you're outside the US — other countries have equivalent bodies, including the Canadian Anti-Fraud Centre for Canadian residents. Also file with your local police and ask for a case number; some exchanges and insurers require one. Recovery isn't guaranteed, but every report feeds the data that eventually helps track repeat-offender wallets and drainer operations.
Beware "Recovery Service" Scams
The moment word gets out that your wallet was drained — a public complaint, a support ticket, a community post — you become a target a second time. Fraudsters posing as blockchain investigators or "ethical hackers" will offer to trace and recover your funds for an upfront fee. FBI IC3 data attributes an additional $1.4 billion in 2025 losses specifically to these recovery scams. See the warning box below before you respond to anyone.
Audit and Secure Every Other Account That Shares Credentials or a Device
A wallet compromise rarely happens in isolation. If your device was infected or you reused a password, assume every account touching that device or password is at risk — email, exchanges, cloud storage, password managers, even unrelated shopping or banking accounts. Switch two-factor authentication from SMS to an authenticator app wherever possible (SIM swapping is a known path from "hacked phone number" to "drained exchange account"), and review your email's forwarding rules, recovery options, and connected third-party apps line by line, since email is usually the master key attackers use to reset everything else once they have a foothold in it. If you use a password manager, run its built-in breach/reuse audit and rotate anything flagged.
Set your expectations honestly: most drained crypto is not recoverable
Blockchain transactions are irreversible by design — there's no bank to call that can claw back a confirmed transfer, no chargeback, and in most cases no way to freeze the destination wallet unless it sits on a centralized exchange that cooperates with law enforcement (and only if the funds haven't already moved again). Law enforcement occasionally recovers funds in high-profile cases with clear exchange trails, but for the average victim of a straightforward wallet drain, the honest odds of recovery are low. Everything in this guide is about stopping further loss and preventing a repeat — not guaranteeing your funds come back.
The second scam: fake "crypto recovery" services
Once you've been drained, expect contact from people claiming they can trace your funds through "blockchain forensics" and get them back — for an upfront "gas fee," a percentage of recovered funds paid in advance, or access to your remaining accounts "to verify your identity." None of this is how legitimate recovery works. Real blockchain investigations, the kind used by law enforcement and licensed forensic firms, don't cold-DM victims, don't ask for upfront payment in crypto, and don't need your seed phrase, private keys, or remote access to your computer to "assess" your case. The FBI's IC3 attributes an additional $1.4 billion in 2025 losses specifically to recovery scams targeting people who had already been victimized once. If someone reaches out unprompted offering to recover your funds, block them — do not send money, do not share your seed phrase or private keys, and do not install any software they recommend.
Why Crypto Wallets Get Drained (And How to Stop It Happening Again)
Understanding how the drain happened helps you close the door it came through — and helps you recognize the same tactic before it works on you again. Most wallet drains trace back to one of six root causes:
Phishing Sites and Fake dApps
Convincing replicas of real marketplaces, exchanges, or DeFi platforms trick you into connecting your wallet and approving a transaction that looks routine but actually grants the attacker spending rights. These sites are often promoted through search ads that outrank the genuine project, fake social media accounts impersonating real projects (complete with stolen branding and a purchased "verified" checkmark in some cases), or links shared in Discord/Telegram DMs from a compromised or impersonated community moderator account. The visual polish of these fakes has improved dramatically — a mismatched URL is often the only visible tell, which is why bookmarking official sites matters so much.
Malicious Approvals and "Blind Signing"
Many wallet prompts ask you to approve a transaction without showing you, in plain language, what it actually does — you see a wall of hexadecimal data instead of "this will let address 0x... spend unlimited amounts of your USDC." Attackers disguise a total-access approval as something routine, like "claim your airdrop" or "connect to mint," knowing most users click through prompts quickly during high-excitement moments like a new token launch. Always read what a transaction is requesting before you confirm it, and treat any request framed with urgency ("only 12 left," "offer ends in 5 minutes") as an additional red flag, not just a reason to hurry.
Seed Phrase Phishing
Fake wallet-support chats, fraudulent "wallet sync" tools, and phishing emails asking you to "verify your recovery phrase" are all designed to get you to type your seed phrase somewhere it doesn't belong. Some of these are disguised as browser extensions that mimic a legitimate wallet's interface closely enough that entering your phrase feels routine. No legitimate wallet provider, exchange, or support agent will ever ask for your seed phrase, under any circumstance, for any reason — treat every request for it, no matter how official-looking the source, as an attack.
SIM Swaps Leading to Exchange Account Takeover
If your phone number is hijacked — an attacker convinces your carrier to port it to a new SIM, often using social engineering or a bribed insider rather than any technical exploit — any account using SMS-based two-factor authentication, including exchange accounts, becomes vulnerable to a password reset. This is different from a self-custody wallet drain but is one of the most common paths to losing funds held on an exchange, and victims often don't realize what happened until their phone loses signal entirely (a telltale sign the number has already been ported away). See our full guide on SIM swap attacks and crypto account recovery for the complete process.
Malware and Clipboard Hijackers
Some malware silently monitors your clipboard and swaps any copied wallet address for the attacker's own — you paste what you think is a friend's address, and the funds go to a visually similar attacker-controlled address instead. Because wallet addresses are long strings that most people only glance at, this substitution frequently goes unnoticed until after the transaction confirms. Other malware logs keystrokes to capture typed seed phrases or passwords directly, or takes periodic screenshots hoping to catch a recovery phrase written down digitally "just this once." Our guide on warning signs your computer is hacked covers how to spot this kind of infection before it costs you anything.
Fake Wallet Apps
Counterfeit wallet apps, sometimes even appearing briefly in official app stores before being removed, are built to either steal a seed phrase during "setup" or generate a wallet using a seed the attacker already knows in advance, so any funds sent to it are visible to them from the start. Only download wallet software from the official project website you already know — bookmark it — never from a search result, an app store search, or a link in an ad, all of which can be spoofed by a convincing copycat listing.
How to Prevent This From Happening Again
None of the habits below are complicated, but they compound — most victims we talk to were missing two or three of these, not all five.
- Use a hardware wallet for anything beyond spending money — private keys never touch an internet-connected device, even when interacting with a dApp, since the device physically requires a button press to approve each transaction and displays the actual transaction details on its own screen rather than trusting whatever your computer shows.
- Store your seed phrase offline, on paper or metal, never as a photo, cloud note, or text file. Consider splitting a backup across two physical locations so a single fire, flood, or theft doesn't destroy your only copy — but never store the full phrase in a single digital file, even an encrypted one, if you can avoid it.
- Run periodic approval audits (monthly is reasonable for active users) with the same revocation tool from step 3, even when nothing seems wrong — treat it like checking your credit report, a quiet habit that catches problems long before they become expensive ones.
- Use an authenticator app, not SMS, for two-factor authentication on every exchange and wallet-related account — this removes SIM swapping as a viable attack path entirely, since there's no phone number for an attacker to hijack.
- Bookmark the official URLs for every wallet, exchange, and dApp you use regularly, and only navigate to them through your bookmarks, never through search results, ads, or links shared in messages, even from accounts you recognize.
- Consider a separate "hot" wallet for everyday interactions with new or unfamiliar dApps, keeping only small amounts in it, so a bad approval or a drainer site can only ever reach a limited, acceptable loss.
What Actually Happens After You Report It
It's worth setting realistic expectations about the reporting process itself, since disappointment with a slow or inconclusive outcome sometimes pushes victims toward the recovery-scam offers this guide warns against. Filing with IC3 or the Canadian Anti-Fraud Centre does not trigger an individual investigation into your specific case the way a stolen car report might. Instead, these reports feed a much larger dataset that agencies use to identify patterns: repeat-offender wallet addresses, clusters of victims tied to the same phishing kit, and money-laundering paths through specific exchanges or mixing services. Individual cases occasionally get pursued directly, especially when the amount is large, the trail is clear, and funds moved through a centralized exchange that can be legally compelled to identify the account holder — but this is the exception, not the norm.
What a report reliably gives you is a paper trail. If you plan to claim a capital loss for tax purposes, dispute a related charge, or file an insurance claim (a small but growing number of policies now cover certain crypto losses), having an official case number from IC3 and your local police is often a prerequisite. It's also worth checking whether the exchange or platform involved has its own internal fraud team — many do, and they sometimes act faster than external law enforcement, particularly when funds are still sitting on that same platform and can be administratively frozen before being withdrawn.
What Is a Wallet Drainer Attack?
A wallet drainer (or "drainer attack") is malicious code — usually embedded in a phishing website or fake dApp — designed to trick a connected wallet into signing one or more transactions that transfer its tokens, NFTs, or approval rights to an attacker-controlled address, typically within seconds of clicking "Connect" or "Confirm." Once signed, the drainer script often sweeps every valuable asset it can find in the wallet in a single automated batch, rather than a single token, which is why a drain frequently empties multiple different holdings at once rather than just the one you were interacting with. Drainer kits are sold as ready-made toolkits on underground forums, complete with customer support and revenue-sharing arrangements for affiliates who spread the phishing links, part of why this attack type has scaled quickly against everyday holders and not just high-value targets.
Worried Your Device Was the Entry Point?
IT Cares isn't a crypto recovery service — we can't get your funds back, and we'll never claim we can. What we can do: find out whether your computer or phone is still compromised, with malware scans, keylogger detection, browser extension audits, and a full account-hygiene check, so whatever got in doesn't come back for your email, banking, or the next wallet you set up.
Frequently Asked Questions
Can I get my stolen crypto back?
In most cases, no — blockchain transactions are irreversible and there is no central authority that can reverse a confirmed transfer. Recovery is occasionally possible in cases involving large amounts, a clear trail to a cooperating centralized exchange, and law enforcement involvement, but for the average victim of a wallet drain, the honest odds of recovering funds are low. Focus your energy on stopping further loss and securing your other accounts rather than chasing recovery, and be skeptical of anyone who tells you otherwise in exchange for a fee.
Should I pay someone claiming they can recover my funds?
No. Anyone who contacts you unprompted offering to recover stolen crypto for an upfront fee, a percentage cut paid in advance, or access to your remaining accounts is almost certainly running a second scam — the FBI's IC3 attributed $1.4 billion in 2025 losses specifically to these recovery scams. Legitimate blockchain investigators don't cold-DM victims or ask for payment before doing any work.
Is my whole wallet compromised, or just one token?
It depends on what was compromised. If a malicious contract approval was the cause, only the specific tokens or NFTs you approved are at risk, and revoking that approval stops further loss from that vector — the wallet itself and its other assets may still be safe. If your seed phrase or private key was exposed, the entire wallet and everything in it (current and future) must be considered compromised, and you need to move everything to a brand-new wallet with a new seed phrase.
How do I know if it's my seed phrase or my device that's compromised?
Check whether you ever entered your seed phrase into a website, app, or chat message — if so, treat the wallet as permanently compromised regardless of your device's condition. If you never typed or exposed your seed phrase but funds still moved, suspect device-level compromise (malware, a keylogger, or a malicious browser extension) or a malicious approval you unknowingly signed. Running a full malware scan, checking your wallet's approval list, and reviewing recently installed browser extensions will usually clarify which scenario you're in.
Should I report a crypto theft to police even if they can't recover it?
Yes. Filing a report with the FBI's IC3 (ic3.gov), your national fraud reporting center (the Canadian Anti-Fraud Centre for Canadian residents), and local police creates an official record you may need for tax purposes, insurance, or exchange disputes, and it contributes to the data used to track and eventually shut down repeat-offender wallets and drainer operations. It won't guarantee your funds return, but it's still worth doing.
![Crypto Wallet Hacked or Drained? 10 Things to Do Right Now [2026]](/images/blog/crypto-wallet-hacked-drained-what-to-do-hero.jpg)
Comments (3)
Noticed a small test transaction I didn't recognize at 2am, panicked, but moved the rest of my wallet to a new one within 20 minutes using this exact order of steps. Lost maybe $80 in a small token, saved the rest. The "don't reuse the same seed phrase, even partially" line saved me from making it worse — my first instinct was to just make a new account with the same words in a different order.
Had no idea I'd approved a contract from a fake NFT mint three months earlier until I ran a revocation check after reading this. Nothing had actually been drained yet, but the approval was still sitting there active and could have been used at any point. Revoked it and went through everything else on my wallet. Wish I'd known to check this on a regular schedule instead of only after almost getting hit.
Got a DM within an hour of my wallet getting drained from someone claiming to be a "blockchain recovery specialist" who could get my ETH back for a fee paid upfront. Almost sent it out of pure desperation until I found this article and saw the recovery scam warning. Reported the account instead of paying. People genuinely need to know this second wave is coming right after the first hit.
Leave a Comment