~/blog/what-to-do-if-wallet-hacked

All articles

Wallet Hacked? The First 10 Things to Do Right Now

Crypto wallet hacked? A step-by-step emergency plan: move funds, revoke approvals, lock down accounts, and report the incident safely.

Paperino Academy7 min read
Wallet Hacked? The First 10 Things to Do Right Now
On this page

Realizing your wallet has been hacked is a terrifying moment, and the first instinct is usually panic. But the worst thing you can do right now is act rashly — or freeze up. The first few minutes matter, and the good news is there's a clear, ordered set of steps you can follow to limit the damage and protect what's left.

Take a deep breath, open this checklist, and start from the top.

Before You Start: Make Sure It's Really a Hack

Sometimes a delayed transaction or a display glitch causes panic for nothing. But if you see any of the following, treat it as a real hack immediately:

  • Outgoing transactions you didn't make.
  • Your balance suddenly disappearing, or a string of transfers to an unfamiliar address.
  • An app or website asked for your "Seed Phrase," and funds started moving shortly after.
// warning

If your seed phrase or private key has been exposed (typed into a site, sent to someone, or stored on an infected device), consider the entire wallet permanently burned. It cannot be "fixed" — everything must be moved to a brand-new wallet.

The Emergency Plan: 10 Steps, In Order

1. Disconnect Immediately

Take the device offline if you can, and close any open wallet or platform sessions. If the breach came through a browser extension or app, shut it down. The goal: stop the bleeding before you think about anything else.

2. Set Up a Clean New Wallet

On a different device you trust (not the compromised one), create a brand-new wallet with a brand-new seed phrase. A hardware wallet is best if you have access to one. Never reuse the old seed phrase, ever.

3. Move Your Valuable Assets First

Transfer whatever is left to the new wallet, starting with what's most valuable and easiest to move: stablecoins like USDT first, then larger holdings. Watch the network fees, and double-check the address character by character before sending.

4. Revoke Dangerous Approvals

Many thefts don't even need your private key — it's enough that you once granted a smart contract permission to withdraw. Use a trusted revoke tool (like the official revoke pages on blockchain explorers) to pull any open approvals.

ItemDo This Now
Old token approvalsRevoke all of them, especially "unlimited" ones
dApp connectionsDisconnect every active session
Unfamiliar tokens you receivedDon't touch or sell them

5. Change Passwords From a Safe Device

From a clean device, change your email password first (since it's the key to everything), then move on to connected platforms and apps. Use strong, unique passwords for every service.

6. Enable 2FA and End All Sessions

Turn on 2FA using an authenticator app (not SMS, if you can help it), and log out of every device on your important accounts. Review the list of trusted devices and remove anything you don't recognize.

7. Scan Your Device for Malware

The root cause could be malware or a fake extension. Run a full scan, and remove any browser extension you don't remember installing. If in doubt, wipe and reset the device to a clean state before using it for funds again.

8. Check Your Email and Recovery Settings

Confirm the recovery settings on your email and phone number haven't been changed, and that no strange forwarding rules were added to your inbox. Attackers sometimes leave a "backdoor" in your email to come back later.

9. Document Everything

Record the suspicious transaction hashes, timestamps, amounts, and any link or message you received. Screenshots matter. This documentation helps when reporting the incident and helps you understand how it happened.

10. Report It to the Right People

  • The platform or service where the breach happened: open a support ticket right away — sometimes an account or a related transaction can be frozen.
  • Local authorities in your country if a financial theft has occurred — in the US the FBI's IC3, in the UK Action Fraud, in the UAE eCrime; elsewhere, your police cybercrime unit. Attach the transaction hashes and addresses you documented in the previous step.
// note

Blockchain transfers cannot be reversed. No one can bring back funds that have already left an address. The point of reporting is to secure what's left and prevent another breach — not to recover what's lost. Be extremely wary of "recovery experts" who promise to get your funds back for a fee; that's a second scam.

Once the Storm Has Passed

Once the urgent steps are done, take time for a calm review:

  • Understand the entry point: Was it a phishing link? A seed phrase written down somewhere it shouldn't have been? A malicious extension? Knowing the cause prevents a repeat.
  • Separate your layers: Keep a "cold" wallet for long-term savings that never connects to any site, and a small "hot" wallet just for everyday use.
  • Golden rule: No one — not even genuine support staff — will ever ask for your seed phrase. Anyone who does is a scammer.

Quick Reference: Do's and Don'ts

DoDon't
Move funds to a clean new walletDon't reuse the old seed phrase
Revoke open approvalsDon't share your key with a "recovery expert"
Enable 2FA and end all sessionsDon't click "support" links in private messages
Document and reportDon't rush to pay any fee to "recover" your funds

A hack is a harsh experience, but it isn't the end of the road. What matters now is acting calmly and in order: stop the bleeding, save what's left, then rebuild your security on stronger foundations. Users who learn from one incident often end up far more secure than most.

Frequently asked questions

Can crypto wallets actually be hacked?

Yes, though the wallet software is rarely the weak point. Losses almost always come from the recovery phrase being entered somewhere it should not have been, a malicious transaction being approved, or malware on the device. Well-known wallet apps are not routinely broken into; the person holding the phrase is the part attackers go after.

Can stolen crypto be recovered?

Rarely, and almost never by acting alone. Blockchain transfers cannot be reversed, so recovery depends on the funds reaching a regulated platform that can freeze them, which requires law enforcement or the platform acting on a report. It is worth reporting for exactly that reason. It is not worth paying anyone who guarantees a result.

How did they get in if I never shared my recovery phrase?

The common routes do not involve the phrase at all. Approving a malicious transaction or a token allowance hands over spending rights on specific assets; malware can swap a copied address or read a screenshot; and a phrase typed into a convincing fake wallet site was still typed by you. Reconstructing which one happened matters, because it decides whether your other devices are safe.

Can I keep using the same wallet once I have removed the malware?

No. If the phrase or key was exposed, the attacker keeps it permanently, and a clean device does not change that. Anything sent to those addresses later can be taken at any time, sometimes by automated scripts that watch for incoming funds. Move to a wallet created from a new phrase on a device you trust.

Should I report the theft to the police?

Yes, and to the platform involved if there is one. A police report is often what a regulated exchange needs before it will act on an address, and it is the only route to any formal recovery. Expect the process to be slow and the chances of recovery to be poor, and file anyway with the transaction hashes and addresses documented.

Someone has offered to recover my funds for a fee. Is that real?

Almost certainly not. People who have just been robbed are the specific target of a second scam, and unsolicited approaches after a loss are the standard form it takes. No one can reverse a blockchain transaction, so an upfront fee, a demand for your recovery phrase, or a guarantee of success all identify the same thing.

// warning

This article is for general security awareness only and is not financial, legal, or security advice tailored to your situation. The right steps depend on the type of wallet, network, and nature of the breach. When in doubt, stop before sending anything, and consult a trusted or qualified source before taking any step that may not be reversible.

Related articles

~/cryptoCrypto