The first hour after a compromise
- Author
- CRYPTO PORT Editorial
- Published
- Updated
- Reading time
- 7 min
In short
Decide the order in advance: move what remains, revoke approvals, contact the exchange, preserve evidence. Recovery is not guaranteed, but stopping further loss usually is. And do not, in the panic, reach out to anyone promising to get it back.
Key points
- First priority: move whatever remains to a fresh, clean wallet
- Then revoke the compromised wallet's approvals to stop further drainage
- If an exchange account is involved, ask them to suspend withdrawals or freeze it
- Preserve transaction hashes, timestamps, counterparty addresses and message logs
Definition
The sequence of immediate actions taken on discovering that a wallet or account has been compromised, to stop further loss and preserve a record.
Fix the order in advance. Judgement degrades badly in the minutes after you realise what has happened, so you want to follow a procedure rather than invent one. The order is: move what remains, revoke approvals, contact the exchange, preserve evidence. Working out how it happened, and who did it, can wait until those four are done.
First, move the assets. If the compromised wallet still holds a balance, move it now to a wallet you create fresh — different device, different seed phrase. What matters here is that changing a password or reinstalling the app does nothing: if the seed phrase or private key has leaked, the attacker can move funds with the same key. Where assets are staked or locked and cannot move immediately, take out what you can first. Be careful about sending gas in to rescue funds — attackers often run automated watchers that sweep anything that arrives.
Second, revoke approvals. In an approval-based theft, moving your balance is not enough: anything that later arrives at that address is drained again. List your live approvals and revoke those pointing at the attacker's contract. Third, the exchange. If you suspect unauthorised access or an unauthorised withdrawal, go in through your bookmark and ask them to suspend withdrawals or freeze the account. Where stolen funds land at an exchange, the operator may be able to freeze them, so contacting them promptly with the transaction hashes is worth doing.
Fourth, preserve evidence. Collect the transaction hashes, timestamps, destination addresses, amounts and screenshots of the correspondence (emails, DMs, the URLs involved) into one chronological file. You will need all of it for the exchange, for any report to the authorities, and for sorting out the tax treatment. Records decay with time, so gather them as part of the response, not once you have calmed down. And be clear-eyed: stolen crypto is often not recovered. Accept that, and put your energy into preventing the next loss.
Watch out for
- · Anyone promising they can definitely get it back is running a second scam
- · Do not move assets back into the compromised wallet — the leaked key or live approvals may still be there
- · Changing a password or reinstalling the app does nothing about a leaked seed phrase
Frequently asked questions
Is there any point tracing the stolen funds myself?
You can follow the funds in a block explorer, and identifying the point at which they reach an exchange gives your report something concrete. Do not contact anyone at the other end, though — victims get drawn into a second loss through 'negotiations'. Use what you find as material for the exchange and the authorities.