Skip to content
Crypto Theft

Crypto wallet drained: trace it, report it, stop the bleeding

The balance is gone in transactions you never signed — or one you did sign, without understanding what it approved. Reversal is rare; tracing and freezing are not hopeless.

Crypto wallet drained: trace it, report it, stop the bleeding — Response Red advisory illustration

The essentials

  • Move whatever remains to a brand-new wallet — new seed phrase, created on a clean device — before anything else.
  • Record every transaction hash and destination address now; on-chain tracing is real, and exchanges can freeze funds that land with them.
  • Work out the how: a leaked seed phrase, a malicious token approval you signed, or malware on the device — each has a different cleanup.
  • Report to the exchanges on the fund path and to law enforcement with the hashes; speed improves the freeze odds.
  • Every "fund recovery expert" who contacts you or advertises to victims is a second scam.

Crypto theft has three main doors: your seed phrase got out (phishing site, cloud note, photo), you signed a malicious approval that let a contract spend your tokens, or the device holding the wallet was compromised. The response starts the same way regardless — protect what is left — and then splits by cause.

Transfers are final, which the thief is counting on. But finality is not invisibility: the ledger is public, tracing is routine work, and funds that touch a cooperative exchange can be frozen.

Do this now

  1. Evacuate the remainder. New wallet, new seed, generated on a device you trust — then move remaining assets to it. Never reuse the compromised seed, and never type it anywhere "to check it".
  2. Revoke token approvals. If a drainer approval is the suspect, use a reputable approval-revocation tool for each chain to cancel spending permissions the old wallet granted.
  3. Record the theft on-chain. Transaction hashes, destination addresses, timestamps, and amounts — from the block explorer, saved as files and screenshots.
  4. Report to the exchanges on the path. Follow the funds in the explorer; when they head toward a known exchange deposit address, report the theft to that exchange's security team with your hashes. Freezes happen — fast reports make them possible.
  5. File with law enforcement. IC3 or your national cybercrime unit, with the full hash list. Law-enforcement requests are what turn an exchange freeze into a recovery.
  6. Close the door you came in through. Seed leak: find where it was stored or typed. Approval drain: identify the site that got the signature. Malware: clean or replace the device before it touches the new wallet.

What not to do

  • Do not type the old seed phrase into anything, ever again — including "wallet checkers".
  • Do not set up the new wallet on the possibly-compromised device.
  • Do not hire recovery services that found you — payment upfront for recovery is the tell.
  • Do not keep signing transactions on the old wallet to "test" it.
  • Do not assume small remaining balances are safe; drainers sweep wallets on a schedule.

Preserve the evidence

Whatever else happens, these are the artifacts the investigation — and any insurance claim, dispute, or prosecution — will be built from:

  • Transaction hashes, addresses, and explorer screenshots of the theft path.
  • The dApp, site, or message that obtained the seed or signature, if known.
  • Browser extension list and recent downloads from the wallet device.
  • Exchange and law-enforcement report references.

Keep a clear head

The finality of a drained wallet lands hard — there is no fraud department to call, and that absence makes the loss feel total within minutes. Let the tracing work be the counterweight: it is concrete, it occasionally recovers funds at exchanges, and it is the only path that does.

The shame of having signed the transaction yourself is common and misplaced: drainer prompts are engineered to look like routine mints and connects, and they fool daily users of these systems.

Questions victims ask

Can blockchain analysis actually get funds back?

It finds where funds went; recovery happens when they land at an exchange that will freeze on a valid report or legal request. That is a real but time-sensitive path — which is why the hashes and fast reports matter, and why funds that go straight to a mixer are much harder.

What did the malicious approval actually do?

Token approvals let a contract spend a token on your behalf — a normal mechanism DeFi depends on. A drainer tricks you into granting an unlimited approval to their contract, which then empties that token whenever they choose. Revocation tools cancel those grants.

Will a hardware wallet prevent this next time?

It defeats seed-theft-by-malware, because keys never leave the device. It does not defeat a bad approval you physically confirm on it — so pair the hardware with reading every signature prompt, and keep long-term holdings in a wallet that signs nothing routinely.

When the first hour is over, we take it from there.

Scoping, containment, forensics, and recovery — expert-led and evidence-safe, with AI removing the waiting. Engage a responder or talk to us about readiness.