The period right after discovering a theft is the most valuable window you have. Some of what an investigation depends on, device state, exact timestamps, session records, can disappear quickly if it is not captured early. Most of what determines whether a case is workable gets decided in these first few hours, not weeks later once a formal investigation begins.
What to capture immediately
- The transaction identifier (hash) of every unauthorized transfer.
- The sending and receiving wallet address for each transaction.
- A screenshot of the transaction on a block explorer, with the timestamp visible.
- The exact time you first noticed the funds were missing, even if approximate.
This does not need to be polished. A rough folder of screenshots captured within the hour is worth more than a tidy summary written a week later from memory, since exact timestamps and transaction details are easy to misremember once the initial shock has worn off.
Secure what is left before doing anything else
If any part of the affected wallet, exchange account, or connected application is still accessible, stop interacting with it beyond what is strictly necessary to secure it. Do not attempt to move remaining funds using the same device or browser session that may have been compromised, and do not sign any further transactions until you understand how access was lost in the first place.
If a device may have been the point of compromise, resist the instinct to immediately factory reset it. That reset often destroys the exact evidence, malicious files, browser extension logs, unusual login activity, that would otherwise explain how the theft happened.
The second scam to watch for
Avoid interacting further with the compromised wallet, and be cautious of anyone who contacts you offering to recover your funds instantly, especially if they ask you to send additional cryptocurrency first. That is a common secondary scam, and it frequently arrives within days of the original theft, sometimes from someone who already seems to know the details of your case.
Legitimate investigative work never begins with a guaranteed outcome or a payment demanded before any analysis has taken place. Treat any unsolicited offer along those lines as a warning sign rather than a lead.
Preserve any related communication, including phishing emails, suspicious messages, or account recovery notices, exactly as it arrived rather than summarizing it from memory. This record often becomes the starting point for understanding how access was originally lost.
What happens once you have secured everything
Once the account is secured and the record is captured, the next reasonable step is deciding who should review it, an investigator, counsel, or both, depending on the amount involved and whether a business or an individual is affected. You do not need every detail perfectly organized before reaching out. An early, honest record is worth far more than a polished one assembled after the trail has gone cold.