TL;DR
- Look at where the damage is happening: an exchange balance moving means an account takeover, unexpected wallet transfers after something you signed mean a malicious approval, and wallet funds moving with no interaction at all mean a leaked key or phrase. Each has a different fix, so this diagnosis directs everything after it.
- Stop the bleeding by value: from a clean device, evacuate what remains to a fresh wallet, freeze the exchange account, lock the phone number if it was swapped, and secure the email behind everything, before any investigation, tweeting or grieving. Minutes are the currency; spend them on the largest balances first.
- Approvals get revoked, leaked keys get abandoned, and hijacked accounts get recovered through the platform: revocation cannot cure a leaked key, and migration is overkill for a bad approval, so match the surgery to the diagnosis. This section is the difference between fixed and fooled.
- Report to the platform immediately, to law enforcement always, IC3 in the US, Report Fraud in England, Wales and Northern Ireland, Police Scotland on 101, and set expectations honestly: freezes sometimes save what has not moved, traces sometimes lead to seizures, and most confirmed on-chain thefts are never recovered. Reporting is still worth doing, for reasons that include you.
In one block
Crypto incident response is the sequence of actions that limits damage after assets or access are compromised: diagnose the type of breach, evacuate remaining funds from a clean device, revoke or freeze what the attacker can still use, secure surrounding accounts, report to platforms and law enforcement, and rebuild in a safer structure.
How do you tell what kind of compromise you have?
Quick answer
Look at where the damage is happening: an exchange balance moving means an account takeover, unexpected wallet transfers after something you signed mean a malicious approval, and wallet funds moving with no interaction at all mean a leaked key or phrase. Each has a different fix, so this diagnosis directs everything after it.
Take three minutes for this even while panicking, because the wrong response burns the hour.
Signs of an exchange account takeover: login alerts or password reset emails you did not trigger, being locked out of the account, withdrawal confirmations arriving by email, and, often first, your phone losing service if a SIM swap opened the door, the attack anatomy covered in this academy's account security article. The battleground is accounts and logins; your self-custody wallet is untouched.
Signs of a malicious approval or signature: assets leaving a wallet you still control, usually after you interacted with a site, minted something, claimed something or "verified" something. You signed more than you thought, an approval, a permit, a delegation, and the drainer article in this academy explains the machinery. The key itself may still be private; what the attacker holds is a permission you granted.
Signs of a leaked key or seed phrase: transfers out of your wallet with no site interaction, sometimes sweeping everything in minutes, sometimes draining slowly over days; or you know the cause, because you typed the phrase into a page, read it to a caller, or found the backup missing. The attacker IS you, cryptographically, and every asset the key controls is exposed.
Mixed and unclear cases default to the harshest assumption on the list you cannot rule out. And one rule spans all three: from this moment, the compromised environment, the wallet, the account, and possibly the device it lived on, is treated as enemy territory. Response happens from a clean device wherever possible, because responding through the attacker's malware hands them your countermoves.
What are the first-hour moves, in order?
Quick answer
Stop the bleeding by value: from a clean device, evacuate what remains to a fresh wallet, freeze the exchange account, lock the phone number if it was swapped, and secure the email behind everything, before any investigation, tweeting or grieving. Minutes are the currency; spend them on the largest balances first.
The order below serves all three compromise types; the next section adds the type-specific surgery.
First, get clean ground. Use a device you have reason to trust, another computer, a family member's phone, and if the compromised device might carry malware, stop using it for anything financial immediately.
Second, evacuate by value. Whatever the attacker has not yet taken is the prize still on the table. For self-custody compromises, create a brand-new wallet on the clean device, new key material, never a restored copy of the old, and transfer remaining assets, largest first. Expect ugly company: leaked-key wallets are often watched by automated sweeper bots that instantly take anything arriving or remaining, so speed beats neatness, and a failed race on some assets does not mean abandoning the rest. For exchange compromises, evacuation means the freeze: contact the platform through its official emergency channel, report the takeover, and ask for an immediate lock on withdrawals; inside a custodial perimeter the operator genuinely can stop funds that have not left yet, which is the one reversibility crypto offers.
Third, close the doors that opened. If your phone lost service, call the carrier from another line and reclaim the number, the SIM swap playbook in the account security article. Change the email password from clean ground and check for forwarding rules and new recovery methods planted by the attacker; the email account is the master door to everything else.
Fourth, preserve evidence as you go: screenshots of transactions and addresses, timestamps, the phishing site's URL, the fake support handle. Thirty seconds of capture per item, in parallel with the moves above, feeds every later step, from platform freezes to police reports, and costs no meaningful time.
What does not belong in the first hour: buying "recovery software", replying to anyone who contacts you offering help, posting the full story publicly with your addresses, or reinstalling and restoring the old wallet from its seed phrase, which resurrects the compromised key and hands the attacker round two.
Which fix goes with which compromise?
Quick answer
Approvals get revoked, leaked keys get abandoned, and hijacked accounts get recovered through the platform: revocation cannot cure a leaked key, and migration is overkill for a bad approval, so match the surgery to the diagnosis. This section is the difference between fixed and fooled.
For a malicious approval or signature, the attacker holds permissions against your assets, and permissions can be cancelled. Use a reputable revocation tool to review every allowance your address has granted and revoke the hostile and the stale ones, paying attention to the exact wallet and chain involved. Two caveats from the drainer article's deeper anatomy: an off-chain permit signature is not undone by revoking old on-chain approvals, the asset it covers may need moving instead; and if what you signed was an account delegation, the newer EIP-7702 pattern, the delegation itself must be cleared. When in doubt about what you signed, treat the affected assets as needing evacuation, which cures everything a permission could do.
For a leaked key or seed phrase, there is no revocation, because the attacker does not hold a permission; they hold you. The key is unfixable, forever: not by changing wallet passwords, not by moving to a new device, not by revoking approvals. The entire remedy is migration, everything the key controls, on every chain it was used on, moved to the fresh wallet, and the old address treated as radioactive. Then find the leak before trusting anything: if the phrase was typed somewhere, that is the answer; if the backup was physical, consider who reached it; if nothing explains it, assume the old device is infected and rebuild it before it touches the new wallet.
For an exchange account takeover, the platform's process is the path: identity re-verification, password and two-factor reset on clean ground, removal of attacker devices and API keys from the account, and a review of linked withdrawal addresses, attackers add their own to allowlists. Once recovered, re-secure beyond what you had before, hardware key or passkey, no SMS anywhere, per the account security article, because takeover victims get retargeted.
Whatever the type, finish the surgery with the same closing sweep: rotate passwords on financial accounts from clean ground, check session lists and connected apps, and keep the evidence folder growing.

How do you report it, and what can realistically come back?
Quick answer
Report to the platform immediately, to law enforcement always, IC3 in the US, Report Fraud in England, Wales and Northern Ireland, Police Scotland on 101, and set expectations honestly: freezes sometimes save what has not moved, traces sometimes lead to seizures, and most confirmed on-chain thefts are never recovered. Reporting is still worth doing, for reasons that include you.
Start with why bother, since victims often skip it. Reports to exchanges can freeze stolen funds at the off-ramp, because launderers must eventually touch platforms that respond to fraud teams and court orders; speed decides these races, which is why the first-hour rule includes reporting. Reports to law enforcement build the case files behind the takedowns and seizures that do happen, and public statistics run on them: the FBI's Internet Crime Complaint Center logged 181,565 crypto-related complaints and 11.4 billion dollars in reported losses for 2025, numbers that shape enforcement budgets. And a police report is frequently required paperwork, for exchanges, insurers and, in many jurisdictions, tax treatment of the loss.
The channels, current as of this writing: in the US, file at ic3.gov with every address, transaction ID and screenshot you preserved. In England, Wales and Northern Ireland, use Report Fraud, which replaced Action Fraud in December 2025; in Scotland, call Police Scotland on 101. If a custodial platform was involved, its own fraud process runs in parallel, and if the theft crossed a regulated service in another country, that service's local regulator may take reports too.
Now the honest expectations. Base-layer transfers are, in general, final once confirmed: no ordinary mechanism reverses them. Real exceptions exist at the edges, and they reward speed: issuers of centrally administered stablecoins can freeze tokens, platforms can freeze funds inside their perimeter, some protocols and smart accounts carry administrative powers, and courts can order seizure and return. Alongside those sits tracing, the chain analysis this academy's privacy article describes, which follows funds to exchanges where legal process can sometimes freeze and eventually return them; recoveries of this kind happen, including some large ones, and they take months to years and favour large, fast-reported cases. Plan your finances around recovery of nothing, and let anything that returns be good news.
And one warning that earns its own paragraph: after the theft comes the second wave. "Recovery services" and "crypto lawyers" who contact victims, guarantee fund retrieval for an upfront fee, or ask for your remaining keys to "trace the hackers" are scammers targeting the newly desperate, a pattern documented in this academy's scam guides. Legitimate investigators do not cold-call victims, do not guarantee outcomes, and never need your keys. Everyone who approaches you unsolicited about your theft is selling round two.
How do you rebuild so this cannot happen again?
Quick answer
Run a short honest post-mortem, then rebuild the structure rather than just the vigilance: distributed custody with no single secret, hardened accounts with phishing-resistant factors, tiered balances, and a rehearsed recovery story. The best time to adopt this cluster's designs was before; the second-best time is now.
First, the post-mortem, three questions on paper. What exactly failed, a phrase typed, an approval signed, a number ported? What made it possible, a secret that existed where it could be phished, an account guarded by SMS, everything in one wallet? And what would have limited the damage, a delay, a second approval, a smaller hot balance? Answer without self-flagellation: these attacks are industrial, run by professionals against thousands of targets daily, and this academy's threat articles exist because intelligent, careful people get caught. Shame is a security risk; it delays response and prevents reporting.
Then rebuild structurally, using the map this cluster provides. If a single secret failed you, choose custody where no single secret exists: MPC share-based wallets or a multisignature quorum, as the custody spectrum and multisig articles detail, so the next phished sentence or burgled drawer is mathematically insufficient. If an account failed you, rebuild logins on passkeys or hardware keys with the phone number demoted everywhere, per the account security article. In every case, tier the balances, a small hot float whose loss would annoy, the majority behind quorums and delays, and rehearse the new recovery story with a trivial amount, because the incident just demonstrated what untested assumptions cost.
Finally, close the loop on the world: warn the community where the lure lives, report the phishing domain, and tell the people close to you what happened, both because they may be targeted through you and because every silent victim keeps the statistics lying. The incident ends when what you learned is built into what you hold, and someone else dodged the same hook because you spoke.
Frequently asked questions
Can a crypto transaction be reversed if I report it fast enough?
A confirmed base-layer transaction is, in general, final; that settlement design is how the system works, as this academy's transaction articles explain. What speed buys is the edges, and they are real: exchanges freezing stolen funds that land there, stablecoin issuers freezing centrally administered tokens, court-ordered seizures, and your own evacuation outrunning the attacker's next move. That is why the first hour matters so much.
The scammer's wallet is visible on the explorer with my money in it. Why can nobody just take it back?
Visibility is one of crypto's real virtues, and control belongs to whoever holds that wallet's key; police cannot sign for the thief any more than you can. What the visible trail enables is action at the edges: tracing toward regulated platforms where legal process can freeze funds, issuer freezes on centrally administered tokens, and eventual seizure in successful cases. Your report is what sets those wheels turning, which is why filing fast matters even though the base transfer itself stands.
Should I keep using my wallet after revoking the malicious approval?
If the compromise was genuinely limited to an approval and the key never left your custody, revocation plus caution can be sufficient, and many users continue safely. Any doubt about what was signed, or any sign the device or phrase was exposed, tips the answer to migration: a fresh wallet costs minutes, and the failed diagnosis costs everything. When in doubt, evacuate.
A firm contacted me saying they can recover my stolen crypto for a fee. Is it real?
Treat unsolicited recovery offers as the second attack, with near certainty: guarantees, upfront fees and requests for your keys or remaining funds are the fingerprints. Legitimate paths, platform fraud teams, law enforcement, and reputable investigation firms engaged by you or your lawyer, never cold-call victims and never guarantee outcomes. Being recently robbed puts you on scammers' hottest list; act accordingly.
Do I need to report if the amount was small?
Yes, briefly and without much cost to you. Small reports aggregate into the statistics that fund enforcement and the intelligence that takes down infrastructure, your address and domain details may complete someone else's case, and the report creates the paper trail if the loss matters for taxes or insurance. Silence is the only certainly wasted outcome.
Sources and further reading
Key references for this article, current as of July 2026. Volatile figures are re-checked at each quarterly review.
- FBI Internet Crime Complaint Center, 2025 Internet Crime Report: crypto complaint and loss figures. https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf
- FBI IC3, filing a complaint. https://www.ic3.gov
- Report Fraud (England, Wales and Northern Ireland; replaced Action Fraud in December 2025). https://www.reportfraud.police.uk
- Police Scotland, reporting fraud (101). https://www.scotland.police.uk/advice-and-information/scams-and-frauds/
- FBI IC3, public service announcement on cryptocurrency recovery schemes. https://www.ic3.gov/PSA/2023/PSA230811
- Chainalysis, 2026 Crypto Crime Report: theft, laundering and recovery context. https://www.chainalysis.com/blog/2026-crypto-crime-report-introduction/
- ScamSniffer, phishing and drainer loss reporting. https://drops.scamsniffer.io/
- Revoke.cash, token approval review and revocation documentation. https://revoke.cash/learn
- ethereum.org, token approvals and security basics. https://ethereum.org/en/guides/how-to-revoke-token-access/
- EIP-7702, Set EOA account code (delegation context). https://eips.ethereum.org/EIPS/eip-7702
- Investopedia, what to do if your cryptocurrency is stolen. https://www.investopedia.com/what-to-do-if-your-crypto-is-stolen-8605382
- FCA ScamSmart (UK, checking firms and reporting). https://www.fca.org.uk/scamsmart
Quick quiz: did it stick?
A few questions to check the fundamentals landed. Answers with explanations follow, and nobody is grading you except your future portfolio.
You have completed a quiz on “How to Respond If Your Crypto Is Hacked or Stolen”! Share your achievement on social media.




