Discovering that a crypto wallet has been hacked triggers a specific kind of panic, made worse by the fact that, unlike a stolen credit card, a confirmed blockchain transaction cannot simply be reversed by calling someone. What happens in the minutes and hours after discovery genuinely determines how much can still be contained, and it is worth having a clear, ordered sequence in mind before it is ever needed.
Immediate containment, in order
Cut off further access first
If the compromise is still active, meaning funds are continuing to move or the attacker still appears to have some form of access, the first priority is cutting that access off rather than assessing the full scope of what happened. Disconnect the affected device from the internet, close any active wallet browser sessions, and disconnect the wallet from every decentralized application it has approval access to.
Move remaining funds to a new wallet
Any assets remaining in the compromised wallet should be moved immediately to a brand new wallet, generated with a freshly created seed phrase on a separate, trusted device. Never reuse the compromised wallet's phrase or private key in any form, even if only part of the wallet's holdings were affected, since there is no reliable way to confirm the remainder of the phrase was not also exposed.
Revoke standing approvals
Once remaining funds are secured, review and revoke any token approvals the compromised wallet had granted, since some attacks rely on a standing approval that can be exercised again later rather than an immediate, one time transfer. Our guide on revoking token approvals walks through this process in detail.
If more than one person had access to the wallet
When a compromised wallet was shared among co founders, a business team, or family members, containment includes an additional step beyond securing the technical access: immediately notifying every other person with legitimate access, since they may hold a piece of a multisig setup, a backup phrase, or an approval on a connected account that also needs to be revoked or rotated. A compromise that started with one person's device can otherwise silently extend to every other person still trusting the same shared wallet infrastructure. Businesses handling a compromise of this kind should also preserve records suitable for a formal business investigation, since the evidentiary standard for a corporate loss is often higher than for an individual one.
A hacked wallet cannot be made safe again. It can only be abandoned in favor of a new one. Continuing to use a compromised wallet, even cautiously, leaves any remaining assets exposed to the same access the attacker already obtained.
A realistic timeline of a well handled response
- Minute zero to five: the compromise is noticed, either through an unexpected transaction alert or a wallet balance that no longer matches expectations, and the affected device is immediately disconnected from the internet.
- Minute five to twenty: remaining funds are moved to a new wallet generated on a separate, trusted device, prioritizing the most valuable assets first if time or gas costs make moving everything at once impractical.
- Minute twenty to sixty: every decentralized application connection and token approval tied to the compromised wallet is reviewed and revoked using a reputable approval checking tool.
- Hour one to three: the incident is documented in detail, including transaction identifiers, destination addresses, timestamps, and screenshots, while the sequence of events is still fresh and easy to recall accurately.
- Hour three to twenty four: reports are filed with any exchange associated with the receiving address and with the appropriate national cybercrime reporting body, and a decision is made about whether a professional tracing investigation is worth pursuing given the amount involved.
Not every case will move through this timeline at exactly this pace, and a compromise discovered days after it occurred obviously cannot recreate the first hour retroactively. The value of thinking in terms of a timeline is that it establishes a default order of operations, so a victim in the middle of a stressful, confusing event does not have to invent a response plan from scratch in real time.
How the situation changes as time passes
In the first hour after a hack, the priority is almost entirely containment, stopping further loss and securing whatever remains. Within the first day, the priority shifts toward documentation and reporting, since the exchanges and platforms that might still be able to freeze funds generally act faster, if at all, the sooner they are notified. By the first week, if the stolen funds have not already been frozen at an exchange, the realistic focus shifts again toward tracing and building a documented record for law enforcement or a civil claim, since the funds have typically moved through enough intermediate wallets by that point that any freeze opportunity at the original destination has likely passed. Understanding which phase applies to a given case helps set realistic expectations. A victim who reports a theft a month after it occurred is not in the same position as one who reports it within the hour, and the appropriate next steps differ accordingly, even though the underlying loss and its emotional impact are the same.
Documentation, before memory fades
- Every unauthorized transaction identifier and the wallet addresses on both ends of each transfer.
- Exact timestamps of when each transaction occurred and when the compromise was first noticed.
- Screenshots of the transactions, any phishing message or fake site involved, and any related account activity notifications.
- A written account of what happened immediately before the compromise, including any site visited, message received, or software installed in the preceding days.
This documentation matters more than most victims initially realize. It is the foundation for a report to law enforcement, for any request to an exchange to flag a receiving address, and for a blockchain tracing effort attempting to establish where the funds ultimately settled. Evidence like this becomes significantly harder to reconstruct even a few days later, once memory of the exact sequence starts to fade.
Reporting the incident
Report the theft to the exchange associated with the receiving wallet address, if one can be identified, since exchanges can sometimes flag or freeze funds that have not yet been withdrawn or converted. Separately, file a report with the appropriate national cybercrime authority, such as the FBI's Internet Crime Complaint Center in the United States, even though recovery through law enforcement alone is uncertain. A documented report also matters for any later insurance, tax, or legal purpose tied to the loss.
- The exact date, time, and time zone the unauthorized transaction occurred, along with the blockchain network involved.
- The full transaction hash or identifier for every unauthorized transfer, not just the first one if multiple occurred.
- The wallet address that sent the funds and every destination address they moved to, if known.
- Any file, message, email, or website believed to be connected to how the compromise happened, attached or described in as much detail as possible.
It is worth setting realistic expectations about what a law enforcement report accomplishes in the short term. Agencies like the FBI's IC3 primarily aggregate reports to identify patterns and larger criminal operations, and an individual case, particularly a smaller one, may not receive a dedicated investigator right away. That does not make the report pointless. Aggregated data from many individual reports is often what eventually supports a larger seizure or prosecution, and a documented report remains necessary for any future insurance, tax, or civil claim tied to the loss, regardless of whether an investigator is assigned immediately.
Tracing where the funds went
Because blockchain activity is permanently recorded, it is often possible to trace exactly where stolen funds moved after the initial theft, even through multiple hops or across different blockchain networks. That tracing does not guarantee funds will be recovered, but it produces a documented account of the fund flow that can support a law enforcement referral or an exchange freeze request. A general explanation of how this process works is covered in our guide on how blockchain investigators trace stolen funds, and a more specific walkthrough for tracing bitcoin specifically is available in our guide on tracing stolen bitcoin.
Common mistakes that make things worse
- Publicly posting about the theft, including the transaction identifier or wallet address, on social media before reporting it to an exchange or investigator, since this can alert the attacker to speed up laundering the funds.
- Attempting to contact or negotiate directly with the attacker, whether through an on chain message or an email address left in a phishing site, which rarely produces a return of funds and sometimes exposes the victim to further targeting.
- Paying an upfront fee to a stranger who contacts the victim offering guaranteed fund recovery shortly after the theft becomes visible on chain, a pattern covered in depth in our guide on recovery scams.
- Continuing to use the same passwords, recovery phrases, or devices involved in the original compromise for any new wallet or account, on the assumption that the specific vulnerability has already been fixed.
- Waiting to gather every detail perfectly before filing any report at all, when an initial report can typically be amended or supplemented later as more information becomes available.
Avoiding the second scam
Victims of a wallet hack are frequently targeted again shortly afterward by someone claiming they can recover the stolen funds for an upfront fee, sometimes contacting the victim directly with details that make the offer seem credible. No legitimate investigator can guarantee a specific recovery outcome, since a blockchain transaction cannot be reversed by anyone, including law enforcement. Our guide on recovery scams covers the specific patterns to watch for. Firms that investigate this kind of theft, including Coin Trace, work on a documented, case based basis and are direct about the fact that recovery depends on where funds moved and whether a viable path exists, not on any guarantee made up front.
Frequently asked questions
It can occasionally help by alerting the wider community to a malicious address, but posting before reporting to an exchange or investigator risks tipping off the attacker to move or launder funds faster. Reporting through official channels first is generally the safer sequence.
Sometimes, though never guaranteed. Recovery generally depends on how quickly the theft was reported, whether the funds passed through a regulated exchange that can freeze them, and how well documented the transaction trail is. Many cases do not result in full recovery.
There is no need to delete wallet software itself, but the wallet's seed phrase and any keys derived from it should never be used again for any new funds. Treat the entire wallet structure as permanently retired.
As soon as possible. The window during which an exchange can flag or freeze incoming funds narrows quickly once those funds are withdrawn or converted, so reporting within hours, rather than days, meaningfully improves the odds of any intervention.
Yes. A formal report creates an official record of the theft, which can matter for insurance claims, tax reporting, and any future civil or criminal action, and it also contributes to broader law enforcement data used to identify repeat offenders and larger patterns.
Sources and further reading
- What To Know About Cryptocurrency and Scams · Federal Trade Commission
- New crypto payment scam alert · Federal Trade Commission
- Internet Crime Complaint Center · FBI Internet Crime Complaint Center (IC3)