Compromised Wallet: What to Do in the First 30 Minutes
In one paragraph. If you suspect your wallet is compromised, the next thirty minutes matter — but panic is the attacker's ally, not yours. The goal in this window is not to "get your coins back"; it is containment (stop further loss), safe migration (move what remains to a wallet the attacker cannot touch), and evidence preservation (so that tracing and any legal action later are possible). Two hard truths up front, because honesty serves you better than comfort here: funds the attacker has already moved are, in the overwhelming majority of cases, not retrievable — crypto transactions are irreversible — and anyone who contacts you after a hack promising to recover stolen funds is almost always a second scam. What you can often do is save what is left, and build a clean evidence trail. This guide walks you through it, minute by minute.
1. First, decide which situation you are in
Before touching anything, work out which of two situations you are in, because they call for different actions.
Situation A — you still control the keys, and some funds remain. The compromise may be a malicious approval, a suspicious device, or a fright rather than a full drain — and you can still sign transactions. This is the situation where speed saves money. Go to §2 and move.
Situation B — the attacker has already drained the wallet, or your seed is fully exposed and emptied. Here, the priority shifts from migration to evidence and reporting, because the moved funds are very unlikely to come back. Painful, but knowing it protects you from the recovery scams in §6. Skip to §5 and §6.
Most people do not know which situation they are in until they have looked calmly at a block explorer (§3, minutes 5–15). That is fine — the early isolation steps are the same either way.
2. The first 30 minutes — a time-ordered checklist
Do these on the assumption that the device you normally use may be compromised. Where a step says "clean device", use a different phone or computer you trust, with up-to-date software.
Minutes 0–5 — Isolate
- Stop signing. Close the wallet app and any connected sites. Do not approve, sign, or "verify" anything — attackers often trigger a fake "security check" prompt to get one more signature.
- Disconnect the suspect device from the internet if you believe it is infected (malware, a fake app, a bad browser extension). This severs clipboard hijackers and remote sessions.
- Do not type your seed phrase anywhere, and especially not into the suspect device or any "security scanner" or "recovery tool". A compromised device is the last place your seed should appear.
- Breathe. The single most expensive mistake in this window is a panic-paste of the seed into the wrong place. Discipline beats speed.
Minutes 5–15 — Assess (on a clean device)
- Open a block explorer on a clean device and look up your address. What is the current balance? Are there pending or recent transactions you did not make? What address did funds go to?
- Identify what remains. If meaningful funds are still there and you still control the keys, you are in Situation A — prepare to migrate (next step). If it is emptied, you are in Situation B — go to evidence (§5).
- Note the attacker's address(es) and the transaction IDs. You will need these for evidence regardless of which situation you are in.
Minutes 15–30 — Migrate what remains, and revoke
- Generate a brand-new wallet on the clean device — a fresh seed phrase, created offline, written on paper, never typed into the compromised environment.
- Move remaining funds to the new wallet. On Bitcoin, this is a straightforward send to a fresh address. Be aware the attacker may be watching the address and racing you; send decisively.
- On Ethereum / EVM chains, revoke malicious token approvals. Many EVM drains work through an approval you were tricked into signing, which lets the attacker pull tokens repeatedly. From a clean device, use a reputable approvals tool (for example,
revoke.cash) to revoke them — and move assets out. Simply "sending the tokens away" without revoking can leave the door open. - Preserve evidence as you go (screenshots, transaction IDs, timestamps, addresses) — see §5.
3. How wallets get compromised — so you can tell what happened
Knowing the likely vector helps both containment and evidence:
- Malware / infected device — keyloggers, remote-access trojans, or fake wallet apps that capture your seed or PIN.
- Phishing approvals (EVM) — you connected to a malicious site and signed an
approveorsetApprovalForAllthat handed token-spending rights to the attacker. The wallet was never "hacked" cryptographically; you were tricked into authorising it. - Seed exposure — the seed was photographed, stored in cloud notes, entered on a phishing page, or found on a written backup.
- Clipboard hijacking — malware silently swaps a copied address for the attacker's, so funds you "sent to yourself" went to them.
- Fake support / fake apps — a "wallet support" agent or an app from an unofficial store walked you into revealing the seed.
The vector matters because it tells you what to secure: a phishing approval needs revocation and migration; a seed exposure means every wallet from that seed is compromised and you must migrate everything to a brand-new seed.
4. Bitcoin vs EVM — what containment looks like
- Bitcoin (and UTXO chains). There are no "approvals". Containment is simply: generate a new wallet with a fresh seed on a clean device and send remaining funds there. If the seed was exposed, all addresses under it are at risk — move everything.
- Ethereum / EVM chains. Containment is two-part: revoke the malicious approvals (so the attacker can no longer pull tokens), and migrate assets to a fresh wallet. Some drains use "sweeper" bots that auto-move any incoming gas, which can make rescuing a compromised EVM account genuinely difficult — in those cases specialist help and careful sequencing matter.
If your funds are not showing because of a derivation-path issue rather than theft, that is a different and far happier problem — see Funds Not Showing? Derivation Paths Explained before assuming the worst.
5. Preserving evidence — properly, from the first minute
Whether or not the funds are recoverable, good evidence is what makes tracing, an insurance claim, a police report, or a civil action possible. Capture:
- Transaction IDs (hashes) of every unauthorised movement.
- The attacker's address(es) that received your funds.
- Timestamps — when you noticed, when transactions occurred.
- Screenshots of the wallet, the explorer, any phishing site, message, or email involved.
- The vector — the link you clicked, the app you installed, the message you received. Keep the originals where you safely can.
- A short written timeline of events while it is fresh.
In the UK, report the theft to Action Fraud (and obtain a crime reference number), and tell any relevant exchange immediately — if stolen funds move to an exchange, a timely report with transaction IDs can occasionally lead to a freeze. This evidence is also exactly what a forensic tracer or a solicitor will need if you pursue civil recovery.
This is where a firm like ours genuinely helps: not by "reversing" the theft (no one can), but by producing a forensic trace of where the funds went and a clear report your solicitor or the authorities can act on. We work alongside law firms on exactly this kind of case — see our For Law Firms page.
6. The hard truth — and the recovery scam that follows every hack
You deserve this plainly:
- Crypto transactions are irreversible. Funds the attacker has already moved are, in the large majority of cases, gone — no service can cryptographically claw them back. What is sometimes possible is tracing them to an exchange and acting through legal or law-enforcement channels, which is slow, uncertain, and depends entirely on good evidence.
- Be ruthless about the second scam. Within hours of a public loss — a Reddit post, a Twitter reply, a forum thread — victims are flooded with DMs from "recovery experts", "white-hat hackers", and "blockchain specialists" promising to get the funds back, usually for an up-front fee or by asking for your seed. These are virtually all scams, engineered to take a second bite from someone already hurting. A legitimate firm does not cold-DM hack victims, does not ask for your seed to "trace" funds (tracing uses public data), and does not promise to recover moved crypto.
Read that twice if you have just been hit: the person sliding into your DMs to help is, almost certainly, the next attacker.
7. What NOT to do
- Do not enter your seed on the compromised device, or into any "scanner", "recovery tool", or website. If the seed is exposed, the only safe move is migrating everything to a new seed on a clean device.
- Do not install random "security" or "recovery" software in a panic. Much of it is malware aimed precisely at people in this moment.
- Do not engage with the attacker or pay any "ransom" to "unlock" your wallet. It does not work and marks you as a payer.
- Do not post identifying details publicly while it is live — it invites the recovery scammers of §6 and can compromise any later legal action.
- Do not trust DMs from "crypto recovery experts" on social media. See §6. This is the most important "do not" on the page.
- Do not pay an up-front fee to "recover" already-moved funds, and never pay anyone in cryptocurrency for recovery help.
8. Frequently asked questions
My wallet was just drained. Can you get the funds back? Honestly, almost never the moved funds themselves — crypto transfers are irreversible and no one can reverse them. What is sometimes possible is tracing the funds to an exchange or service and supporting a report to the police or a civil claim through your solicitor. We will tell you at assessment whether tracing is worthwhile in your specific case, rather than sell you false hope.
Someone messaged me offering to recover my stolen crypto. Are they legitimate? Almost certainly not. Unsolicited "recovery expert" messages after a hack are themselves a scam — the second wave. A legitimate firm does not cold-message victims, does not need your seed to trace funds, and does not guarantee to recover moved crypto. Do not engage; do not pay; do not share your seed.
I still have some funds left. What is the single most important thing? Move them to a brand-new wallet, with a fresh seed generated on a clean device, now — and on EVM chains, revoke malicious approvals first or in parallel. Speed and a clean device are everything in Situation A.
Should I reuse my wallet after removing the malware? No. If the seed may have been exposed, treat the entire seed as burned and migrate to a completely new one. "Cleaning" the device does not un-expose a seed.
Is reporting to the police even worth it? Yes — report to Action Fraud and get a crime reference number. It is the basis for any insurance claim, any exchange freeze request, and any future civil action, and a documented, timely report with transaction IDs occasionally makes a real difference if funds hit a regulated exchange.
How can you help if the funds are gone? By producing a clear forensic trace of where the funds went and an evidence pack your solicitor or the authorities can use — and by helping you secure everything that remains. We work with law firms on civil-recovery and fraud matters; we do not promise to retrieve moved coins, because no honest firm can.
Which jurisdictions do you serve? The UK, the EU, and most jurisdictions where we can complete sanctions and money-laundering checks. We do not currently engage clients resident in the United States or Canada.
9. Emergency response — working with us
If you are in the middle of a live compromise and still control some funds, time matters. You can reach us for guided emergency containment:
- Email: legal@arcana-crypto.com
- WhatsApp (emergency): +44 7835 822143
We guide the migration; you execute every transaction — we never take custody of your funds or ask for your seed. Communications are over encrypted channels, and we will help you preserve evidence as you go.
If the funds are already gone, contact us when you are ready for a calm, free assessment of whether a forensic trace is worthwhile and what an evidence pack for your solicitor would involve. There is no rush in that case, and there is no honest emergency that requires you to pay an up-front fee to a stranger in your DMs.
A closing note. A compromised wallet is one of the worst feelings in self-custody, and the people who profit from it are counting on your panic — both the original attacker and the "recovery expert" who appears minutes later. The disciplined response is unglamorous: isolate, look calmly at the chain from a clean device, save what remains, and preserve your evidence. Keep your seed off every screen you do not fully trust, and treat every unsolicited offer of help as the scam it almost certainly is. If you want steady, honest guidance — during the incident or after it — write to us at
legal@arcana-crypto.com.
Arcana Crypto LTD — registered in England and Wales (no. 16371124). Recovery and forensics for cryptoasset wallet-loss cases. UK + EU engagements. Sole Director: R. Macri.
Guide version 1.0 · Published 14 June 2026 · Last reviewed 14 June 2026 · Reviewed by counsel. This guide is general information, not legal or financial advice. The engagement letter is the operative contract for any engagement, and its specific terms — not this guide — govern the relationship.