Recovery Guides — Emergency / Incident Response
Anyone who suspects their wallet is compromised right nowVictims of a phishing approval or drainerPeople who clicked a malicious link or appHolders who need to secure remaining funds and preserve evidence
Published 2026-06-14  ·  14 min read

Compromised Wallet: What to Do in the First 30 Minutes

In one paragraph. If you suspect your wallet is compromised, the next thirty minutes matter — but panic is the attacker's ally, not yours. The goal in this window is not to "get your coins back"; it is containment (stop further loss), safe migration (move what remains to a wallet the attacker cannot touch), and evidence preservation (so that tracing and any legal action later are possible). Two hard truths up front, because honesty serves you better than comfort here: funds the attacker has already moved are, in the overwhelming majority of cases, not retrievable — crypto transactions are irreversible — and anyone who contacts you after a hack promising to recover stolen funds is almost always a second scam. What you can often do is save what is left, and build a clean evidence trail. This guide walks you through it, minute by minute.


1. First, decide which situation you are in

Before touching anything, work out which of two situations you are in, because they call for different actions.

Situation A — you still control the keys, and some funds remain. The compromise may be a malicious approval, a suspicious device, or a fright rather than a full drain — and you can still sign transactions. This is the situation where speed saves money. Go to §2 and move.

Situation B — the attacker has already drained the wallet, or your seed is fully exposed and emptied. Here, the priority shifts from migration to evidence and reporting, because the moved funds are very unlikely to come back. Painful, but knowing it protects you from the recovery scams in §6. Skip to §5 and §6.

Most people do not know which situation they are in until they have looked calmly at a block explorer (§3, minutes 5–15). That is fine — the early isolation steps are the same either way.


2. The first 30 minutes — a time-ordered checklist

Do these on the assumption that the device you normally use may be compromised. Where a step says "clean device", use a different phone or computer you trust, with up-to-date software.

Minutes 0–5 — Isolate

Minutes 5–15 — Assess (on a clean device)

Minutes 15–30 — Migrate what remains, and revoke


3. How wallets get compromised — so you can tell what happened

Knowing the likely vector helps both containment and evidence:

The vector matters because it tells you what to secure: a phishing approval needs revocation and migration; a seed exposure means every wallet from that seed is compromised and you must migrate everything to a brand-new seed.


4. Bitcoin vs EVM — what containment looks like

If your funds are not showing because of a derivation-path issue rather than theft, that is a different and far happier problem — see Funds Not Showing? Derivation Paths Explained before assuming the worst.


5. Preserving evidence — properly, from the first minute

Whether or not the funds are recoverable, good evidence is what makes tracing, an insurance claim, a police report, or a civil action possible. Capture:

In the UK, report the theft to Action Fraud (and obtain a crime reference number), and tell any relevant exchange immediately — if stolen funds move to an exchange, a timely report with transaction IDs can occasionally lead to a freeze. This evidence is also exactly what a forensic tracer or a solicitor will need if you pursue civil recovery.

This is where a firm like ours genuinely helps: not by "reversing" the theft (no one can), but by producing a forensic trace of where the funds went and a clear report your solicitor or the authorities can act on. We work alongside law firms on exactly this kind of case — see our For Law Firms page.


6. The hard truth — and the recovery scam that follows every hack

You deserve this plainly:

Read that twice if you have just been hit: the person sliding into your DMs to help is, almost certainly, the next attacker.


7. What NOT to do


8. Frequently asked questions

My wallet was just drained. Can you get the funds back? Honestly, almost never the moved funds themselves — crypto transfers are irreversible and no one can reverse them. What is sometimes possible is tracing the funds to an exchange or service and supporting a report to the police or a civil claim through your solicitor. We will tell you at assessment whether tracing is worthwhile in your specific case, rather than sell you false hope.

Someone messaged me offering to recover my stolen crypto. Are they legitimate? Almost certainly not. Unsolicited "recovery expert" messages after a hack are themselves a scam — the second wave. A legitimate firm does not cold-message victims, does not need your seed to trace funds, and does not guarantee to recover moved crypto. Do not engage; do not pay; do not share your seed.

I still have some funds left. What is the single most important thing? Move them to a brand-new wallet, with a fresh seed generated on a clean device, now — and on EVM chains, revoke malicious approvals first or in parallel. Speed and a clean device are everything in Situation A.

Should I reuse my wallet after removing the malware? No. If the seed may have been exposed, treat the entire seed as burned and migrate to a completely new one. "Cleaning" the device does not un-expose a seed.

Is reporting to the police even worth it? Yes — report to Action Fraud and get a crime reference number. It is the basis for any insurance claim, any exchange freeze request, and any future civil action, and a documented, timely report with transaction IDs occasionally makes a real difference if funds hit a regulated exchange.

How can you help if the funds are gone? By producing a clear forensic trace of where the funds went and an evidence pack your solicitor or the authorities can use — and by helping you secure everything that remains. We work with law firms on civil-recovery and fraud matters; we do not promise to retrieve moved coins, because no honest firm can.

Which jurisdictions do you serve? The UK, the EU, and most jurisdictions where we can complete sanctions and money-laundering checks. We do not currently engage clients resident in the United States or Canada.


9. Emergency response — working with us

If you are in the middle of a live compromise and still control some funds, time matters. You can reach us for guided emergency containment:

We guide the migration; you execute every transaction — we never take custody of your funds or ask for your seed. Communications are over encrypted channels, and we will help you preserve evidence as you go.

If the funds are already gone, contact us when you are ready for a calm, free assessment of whether a forensic trace is worthwhile and what an evidence pack for your solicitor would involve. There is no rush in that case, and there is no honest emergency that requires you to pay an up-front fee to a stranger in your DMs.


A closing note. A compromised wallet is one of the worst feelings in self-custody, and the people who profit from it are counting on your panic — both the original attacker and the "recovery expert" who appears minutes later. The disciplined response is unglamorous: isolate, look calmly at the chain from a clean device, save what remains, and preserve your evidence. Keep your seed off every screen you do not fully trust, and treat every unsolicited offer of help as the scam it almost certainly is. If you want steady, honest guidance — during the incident or after it — write to us at legal@arcana-crypto.com.


Arcana Crypto LTD — registered in England and Wales (no. 16371124). Recovery and forensics for cryptoasset wallet-loss cases. UK + EU engagements. Sole Director: R. Macri.

Guide version 1.0 · Published 14 June 2026 · Last reviewed 14 June 2026 · Reviewed by counsel. This guide is general information, not legal or financial advice. The engagement letter is the operative contract for any engagement, and its specific terms — not this guide — govern the relationship.