Skip to content
Saturday, August 29, 2026 · Global Edition
L4 News
BLOCKCHAIN · WEB3 · ASSETS
Loading market quotes…
BTC · ETH · SOL · XRP · ADA · DOGE · AAPL · MSFT · NVDA · AMZN · GOOGL · TSLA
Market data by TradingView
Home / Security

What to do if your wallet is compromised

Move first, revoke second, report third — and walk past anyone who promises to recover it all for a fee paid upfront.

Infographic showing three emergency steps for a compromised wallet
Order matters: whatever remains moves first, permissions die second, reports follow.

If your wallet is compromised, create a brand-new wallet and move what remains into it immediately, starting with the most valuable assets; then revoke the old wallet's outstanding approvals; then report to the FBI's IC3 and the FTC. Funds already transferred out are almost certainly gone — these steps decide how much else goes with them.

L4 News publishes information, not investment advice, and no security practice makes self-custody risk-free. This is an emergency checklist, written to be read now and remembered later — ideally before you ever need it.

How do I know the wallet is actually compromised?

Outgoing transfers you don't recognize, tokens or NFTs that left without your action, approvals you never granted, or a dapp suddenly able to act on your behalf. Check a block explorer for your address rather than trusting the wallet's own display — some scam tokens fake a 'stolen' look to panic you into exactly the wrong click. Verify before you act, but verify fast.

The distinction matters because the response differs. An unknown token appearing is not a breach; a missing balance is. A wallet app showing wrong numbers is usually display trickery, while the explorer shows the chain's actual record. Panic is the attacker's ally in both directions — it makes people either freeze or click the 'fix' link inside the very interface that lied to them.

What comes first: moving assets or revoking approvals?

It depends on what leaked. If your recovery phrase was exposed — typed into a site, read aloud to a 'support agent', photographed — everything is at risk: transfer first, right now, high-value assets ahead of the rest. If only a signature leaked — a bad approval on an otherwise safe wallet — revoking that approval comes first, and transfers may not be needed at all.

Most people won't know which happened, and the safe default is the heavier response: assume the phrase is exposed, move everything, and treat revocation as cleanup. Moving assets costs some fees; moving them unnecessarily is an inconvenience, while not moving them when the phrase was taken is the end of the story.

Step by step through the first hour

  1. Create a brand-new wallet on a device you trust. Fresh recovery phrase, written offline, never typed anywhere. Caveat: if you don't know how the compromise happened, a 'trusted' device may not deserve the word — a second compromise at this step loses the rescue, so clean beats convenient.
  2. Move the most valuable assets first, gas-aware. Transfers need the old wallet's gas balance — if the attacker swept that too, tokens can be stranded until you send a little gas in, and gas you add can itself be watched and front-run. Caveat: an active drainer with bots may race your transfers; speed and adequate fees beat tidiness when every second counts.
  3. Work chain by chain. Assets and approvals live on separate chains independently — your Ethereum move does nothing for your holdings on other networks. Caveat: each chain needs its own gas and its own pass; don't declare victory after one.
  4. Revoke the old wallet's approvals. Use a revocation tool whose domain you verified and bookmarked, and cancel unlimited allowances on anything you hold. Caveat: if the phrase itself leaked, this step is ritual — the attacker doesn't need approvals and won't be slowed by them; it matters in the signature-only scenario and as general hygiene.
  5. Find the hole, or assume it's still open. A phished seed-entry page, a malicious extension, a spoofed update, a copied clipboard — something let this in. Caveat: if you can't identify it, the new wallet inherits the same exposure that killed the old one, and this incident becomes a rerun.
  6. Report and preserve evidence. File with the FBI's Internet Crime Complaint Center at ic3.gov and the FTC at reportfraud.ftc.gov, with transaction hashes, addresses, and the scam site's URL saved. Caveat: a report almost never returns funds — its value is enforcement over time, so skip it only if you want the attackers kept anonymous.

What about services that promise to recover stolen crypto?

Most are the second half of the scam, and that is not a figure of speech. 'Recovery agents' message victims publicly or privately, show plausible-looking tracing dashboards, and ask for an upfront fee or wallet access to 'chase' the funds — then vanish. The mechanism is a mailing list: victims of the first scam are the warmest audience for the second. Legitimate help — law enforcement, licensed attorneys — does not arrive by direct message, and does not require your keys.

The cruel design detail is timing. These offers peak exactly when victims are most desperate and least skeptical, in the days after a loss. The rule that survives contact with that desperation: anyone who promises recovery, contacts you first, and wants payment or access upfront is operating the follow-up. Real avenues are slower, quieter, and initiated by you.

What can't be recovered, realistically?

A confirmed on-chain transfer to an attacker's wallet is final in the overwhelming majority of cases. The narrow exceptions run through enforcement: funds that reach a regulated exchange can sometimes be frozen there during an investigation — which is exactly why the ic3.gov report matters — and that path is slow, rare, and partial. Everything else that promises reversal is selling something.

What remains after the loss is accounting and prevention. The events worth recording: what was taken, from which addresses, through which approval or phrase exposure, and on what date — both for tax documentation in jurisdictions that treat thefts specially, and for the report. And the habits worth keeping afterward read like a summary of this entire category: bookmarked domains, hardware-wallet confirmations, spend-limited approvals, and a wallet whose job is holding, not experimenting.

The last line of the checklist is emotional, and it belongs in writing: losses in self-custody are total and unappealable, which is exactly why the calm version of these steps — read, understood, maybe even rehearsed with a small wallet — is worth an hour of anyone's time before the emergency, rather than during it.

Rekha Patel

Independent editorial contributor focused on agriculture, food production, rural business, sustainability.

Rekha Patel follows the seasonal work behind agriculture, farm technology, and the products that eventually reach a shelf.

More about Rekha Patel

Frequently Asked Questions

Should I just delete the compromised wallet?
No — and it wouldn't help anyway. The wallet exists on the chain regardless of any app, and its history is evidence for your report. Keep read-only access to the address, keep the transaction records, and simply treat its keys as burned. Deleting an app removes your view, not the attacker's.
Can the police or FBI actually get crypto back?
Occasionally, when stolen funds pass through an exchange subject to legal process — that is the realistic path, and it starts with a report at ic3.gov. It is slow, usually partial, and never guaranteed. Direct wallet-to-wallet movement by an experienced thief offers little to seize; set expectations accordingly.
Is moving tokens to the same wallet with a new password enough?
There is no password to change — the recovery phrase is the credential, and it cannot be rotated like one. A 'new password' on the same wallet changes a local app lock, nothing more. The only real reset is a new wallet with a new phrase, funded by transferring what remains.
Why do drainers sometimes wait months before stealing?
Because an unlimited approval is a standing permission with no expiry, and waiting has advantages: batches avoid drawing attention, victims let their guard down, and the triggering site is long gone by the theft. This is also why revoking old approvals periodically matters even when nothing has happened — yet.