CCamoCrypt
Security

My wallet was compromised — what to do now

A calm, ordered response after a wallet compromise: record evidence, move funds to a new wallet, revoke approvals, retire the seed, report, and avoid recovery scams.

Quick answer

Record the transaction hashes and addresses first. Create a new wallet on a clean device, then move remaining assets to it. Revoke all approvals you still control on every chain. Never reuse the compromised seed phrase on any chain again. Then report to IC3 or Action Fraud, and ignore anyone offering paid fund recovery.

Key points

  • Record transaction hashes and addresses before doing anything else.
  • Move remaining funds to a new wallet created on a clean device.
  • Revoke approvals and permanently retire the compromised seed phrase.
  • On-chain theft is usually final; set realistic recovery expectations.
  • Recovery services that contact you are almost always a second scam.
  1. Record the evidence first. Before anything else, note the transaction hashes of the suspicious activity, the wallet addresses involved, and the approximate times. Screenshot your wallet and a block explorer. This takes two minutes and is the foundation of every report you may file later.
  2. Create a brand-new wallet on a clean device. Generate a fresh wallet with a new seed phrase on a device you trust and that shows no sign of compromise. Do not reuse any existing wallet. Write the new seed phrase down offline.
  3. Move remaining assets to the new wallet. Transfer whatever the attacker has not yet taken to the new wallet. Start with the most valuable and most liquid assets. Expect a race: if approvals are still live, an automated drainer may compete with your transactions.
  4. Revoke all approvals on the compromised wallet that you can still control, across every chain it has used, using a reputable tool. This closes standing permissions the attacker may be relying on.
  5. Never reuse the compromised seed phrase again, on any chain. The same seed controls the same addresses on every EVM network and beyond. A compromised seed is compromised everywhere, permanently. Retire it completely.

Understand what happened before you act further

Once your remaining funds are safe, work out the nature of the compromise, because it determines what else is at risk. Broadly there are two cases. In the first, an attacker obtained your seed phrase or private key, for example through a fake wallet app, a phishing form, malware, or a photograph of a written phrase. In this case the attacker controls every address derived from that seed, on every chain, and can act at will; moving funds out is urgent and the wallet must be abandoned entirely.

In the second case, you granted a malicious approval or signature but your key is not exposed. Here the attacker can only move what a specific approval permits, on a specific token or collection. Revoking the approval and moving assets away removes the threat, and the wallet’s key itself was never the weak point, though caution is still warranted. If you are unsure which case applies, treat it as the more severe key-compromise case.

The race condition

If the attacker has your key or a live unlimited approval, automated bots may monitor the address and attempt to grab any incoming or remaining funds instantly, sometimes front-running your own rescue transactions. There is no guaranteed way to win this race. Prioritize the largest, most liquid holdings, and be aware that dust or illiquid tokens may not be worth the gas to rescue. Do not send more gas tokens into a compromised wallet than you need for the rescue itself, because those too can be swept.

What is and is not recoverable, honestly

This is the part most articles soften. It is kinder to be direct.

  • On-chain transactions are final. Once assets have left your wallet in a confirmed transaction, there is no undo button, no support line that can reverse it, and no password reset. This is a deliberate property of public blockchains.
  • Self-custodied stolen funds are rarely recovered. Realistically, assets moved out of a self-custody wallet by a thief are usually gone. Occasionally funds are frozen or returned when they pass through a centralized exchange or a stablecoin issuer that can act, or through law-enforcement seizure, but this is the exception and typically involves large cases and long timelines.
  • Centralized-platform balances may have more options. If the compromise involved an account on a centralized exchange rather than a self-custody wallet, that platform’s support and security team may be able to freeze the account or assist. Contact them immediately.
  • Reporting can still help. Even when your own funds are unlikely to return, reports feed investigations that can freeze funds elsewhere, disrupt infrastructure, and help other victims. Filing is worthwhile.

Setting a realistic expectation protects you from the follow-on scams described below, which prey specifically on the hope of getting money back.

Reporting the theft

Report promptly and include the evidence you recorded in step one: transaction hashes, wallet addresses, timestamps, amounts, and how the attacker first reached you.

  • United States: File with the FBI’s Internet Crime Complaint Center at ic3.gov. You can file as a guest or create an account to update the complaint later. Include cryptocurrency wallet and receiving addresses, transaction details, and contact information for the scammer. Victims aged 60 or older can use the National Elder Fraud Hotline at 833-372-8311 for help filing. An IC3 report does not replace a local police report, so file both.
  • United Kingdom: Report to Action Fraud, the national fraud and cyber-crime reporting centre, at actionfraud.police.uk or by phone on 0300 123 2040. Relay UK users can dial 18001 then 0300 123 2040. You will receive a crime reference number.
  • Elsewhere: Report to your national or local police and to your country’s equivalent cyber-crime or financial-fraud reporting body. If the theft touched a centralized exchange, report to that exchange as well and ask whether the receiving address can be flagged or frozen.

What not to do

After a theft, you become a target for a second wave of fraud aimed at people who just lost money. Guard against it as carefully as the original attack.

  • Do not trust anyone who contacts you offering to recover your funds. Recovery services that reach out to victims are almost always a second scam. The FBI has repeatedly warned about fraudsters impersonating law firms, and even impersonating the IC3 itself, to charge victims again. Legitimate authorities will not proactively DM you promising to get your crypto back.
  • Do not pay an up-front fee to “release,” “unlock,” or “trace” your funds. This is the defining move of recovery scams: an advance fee, then either silence or demands for more. Genuine agencies such as IC3 never charge to recover losses or refer you to a paid recovery company.
  • Do not enter your seed phrase anywhere, including into any tool or person promising a fix. No legitimate recovery, revocation, or support process requires it. The compromised seed should be retired, not re-entered.
  • Do not send more funds to the compromised wallet beyond the minimal gas needed for a rescue, and do not follow instructions to “validate” or “sync” your wallet on any website.
  • Do not act on unsolicited help in comments or DMs. Announcing a loss publicly attracts impersonators posing as support staff. Initiate contact yourself, only through official channels.

After the immediate response

Once you are on a clean wallet and have filed reports, do a calm review. Identify how the compromise likely started: a fake app or extension, a phishing site, a leaked or photographed seed phrase, malware, or a malicious signature. Address that root cause on your device before you resume activity, for example by rebuilding a device you suspect is infected and by installing wallet software only from official sources. Consider moving long-term holdings to a hardware wallet used carefully, and keep a strict separation between a holding wallet and a low-value wallet you use for interactions. The objective is not only to recover but to ensure the same door cannot be opened twice.

Sources

Frequently asked questions

Can I reverse the transactions that stole my funds?
No. Confirmed on-chain transactions are final. There is no undo, no reversal by support, and no password reset. This is a deliberate property of public blockchains, which is why prevention and fast containment matter so much.
Is it ever safe to reuse the compromised wallet later?
No. A compromised seed phrase or key is compromised on every chain, permanently. Retire it entirely and never re-import it anywhere. Continue with a new wallet whose seed has never touched a compromised device.
Someone messaged me saying they can recover my crypto. Real?
Almost certainly not. Recovery services that contact victims are overwhelmingly a second scam, often impersonating law firms or even the FBI's IC3. Legitimate agencies never charge to recover funds or refer you to a paid recovery company, and they do not DM you offers.
Where do I report a crypto theft?
In the US, file with the FBI's IC3 at ic3.gov and also report to local police. In the UK, report to Action Fraud at actionfraud.police.uk or 0300 123 2040. Elsewhere, contact your national cyber-crime or fraud body, and the exchange if one was involved.
Should I still revoke approvals if the money is already gone?
Yes. Revoking stops any remaining live approvals from being used again and prevents further losses from the same permissions. It will not recover what already left, but it closes open doors.
What if the compromise was on a centralized exchange, not a self-custody wallet?
Contact the exchange's support and security team immediately. Platforms can sometimes freeze an account, block withdrawals, or assist, which is often not possible with self-custody theft. Change credentials and enable the strongest available authentication.

Note: CamoCrypt is security & education only — no prices, no predictions, no investment advice. Verify every address and contract yourself; we cannot recover lost funds and neither can anyone who contacts you claiming they can.