- Thread starter
- #1
The moment you realize cryptocurrency has been stolen from your wallet, panic is a natural reaction. But the first hour is the most critical window for preventing further losses and preserving evidence that could lead to recovery. Professional investigators stress that acting methodically even under extreme stress can make the difference between a successful recovery and a case that goes cold.
This guide outlines the five essential steps to take immediately after a crypto hack, based on guidance from blockchain forensics experts and law enforcement resources.
Step 1: Stop the Bleeding Secure Your Remaining Assets
Drainers are automated. The moment you signed a malicious transaction or exposed your credentials, a bot likely swept your wallet. Your first priority is preventing additional losses.
Immediate actions:
Disconnect your wallet from every connected site. Not just the site you think caused the drain every site. Open your wallet's connected sites panel and revoke all connections. Individual site disconnects are insufficient if your browser session is still active.
Revoke all outstanding approvals. Do this from a clean device ideally one that has never accessed the compromised wallet or visited Web3 sites. Use tools like revoke.cash to revoke every outstanding token and NFT approval on the compromised address. If approvals remain active, a drainer can return for anything you receive into that address later.
Move remaining assets to a brand new wallet. Generate a new seed phrase on a clean device. Transfer anything remaining in the compromised wallet to this new address. Do not reuse the compromised seed phrase for anything, ever again.
Critical warning: If your seed phrase itself was exposed, the situation is more severe. Every wallet derivable from a compromised seed phrase is compromised including addresses you have never used. A drainer that obtained your seed phrase does not need to wait for you to use an address; it can sweep derivation paths proactively.
Step 2: Preserve Every Piece of Evidence
It can be tempting to delete messages, uninstall apps, or wipe devices as soon as you realize you have been targeted. However, all evidence should be preserved deleting messages or wiping devices risks destroying vital evidence that investigators and law enforcement need.
What to collect immediately:
The compromised wallet address
Every transaction hash associated with the drain (from Etherscan, Solscan, or the relevant chain explorer)
Screenshots of every phishing site, DM, or email that preceded the drain, with URLs visible
Timestamps of when you noticed each event
Any wallet addresses the stolen assets moved to
Any marketplace listings the stolen NFTs appeared in afterward
Communication logs with the scammer including usernames, profile pictures, wording and phraseology used in messages, claimed company names, and payment instructions
Important: If you suspect your device may be compromised, do not wipe, format, or reset it immediately. Compromised devices can contain important evidence showing whether malware was installed, whether remote access was obtained, or whether login credentials were intercepted. Best practice is to preserve and not use any suspected compromised devices until a forensic image can be taken.
Step 3: Begin On-Chain Tracing
Once your remaining assets are secure and evidence is preserved, start tracing where the stolen funds have gone. While professional forensics firms like Cryptera Chain Signals perform the most comprehensive analysis, you can begin the process yourself using free tools.
Self-service tracing tools:
Tool Purpose
Etherscan / Solscan / chain explorers Free, immediate visibility showing transaction paths
Arkham Intelligence Public labeled explorer; shows if funds touched known entities
MistTrack by SlowMist 400M+ labeled addresses, over 1,000 tracked entities; free lookups available; generates risk reports useful for filing
Breadcrumbs.app Visual fund flow graph; useful for presenting to investigators who are not chain-native
For more advanced users, open-source platforms like GraphSense provide secure, traceable frameworks for analyzing transaction networks across Bitcoin, Ethereum, and other major cryptocurrencies. The platform was developed through numerous research projects, combining scientific expertise with practical applicability for police, judiciary, and companies.
New tools are also emerging: AMLBot recently launched AI Tracer, a self-service blockchain analysis tool that maps visible fund movements from a transaction hash across blockchain networks. The tool traces through bridges that move assets cross-chain or when assets are split among multiple wallets. Its reports are intended as a starting point for investigations and do not replace professional audits or legal processes.
Cross-chain tracing considerations: If funds have been bridged, you will need to:
Identify the bridge by the source-side contract address
Decode the source event—extract recipient, value, token, and unique sequence/nonce
Search the destination contract for the matching event using the sequence/nonce
Document both events—source TX hash, destination TX hash, value, token, sequence ID
Step 4: Report to Authorities and Exchanges
Reporting does not guarantee recovery. However, it creates the legal record necessary for any future action and contributes to aggregate data that funds enforcement priorities.
Where to report:
United States:
IC3.gov—the FBI's Internet Crime Complaint Center; primary federal filing point
FBI Field Office—for losses above approximately $10,000, direct contact is worth attempting alongside the IC3 filing
Local or state police—file for a report number; typically required for insurance claims and tax documentation
Chainabuse.com—community attribution platform; adds the attacker's addresses to a shared blocklist used by some exchanges and wallets
United Kingdom: Action Fraud (actionfraud.police.uk)
Canada: Canadian Anti-Fraud Centre (CAFC) and local police
Australia: Scamwatch and ReportCyber
European Union: Europol coordinates cross-border crypto crime; individuals report to their national agency, which can escalate
Exchange reporting: If traceable funds reach a centralized exchange with KYC requirements, report to that exchange's compliance team immediately with transaction hash documentation. The exchange may freeze the deposit pending investigation. Include your MistTrack or Arkham report links in every filing investigators familiar with these tools will know what they are looking at.
Step 5: Engage a Professional Forensics Firm
Self-service tools are valuable for initial visibility, but professional investigators provide capabilities that individuals cannot access, including:
Enterprise-grade tools like Chainalysis Reactor and Crystal Intelligence
Multi-layer attribution through sophisticated obfuscation
Court-admissible forensic reports
Coordination with exchanges and law enforcement
Direct partnerships with global exchanges for asset freezes
Cryptera Chain Signals specializes in these services, combining 28 years of digital investigation experience with proprietary AI-powered tools. The firm has completed over 426 documented recovery projects with 5 rating from verified clients.
For professional assistance with stolen crypto recovery, visit Cryptera Chain Signals – Advanced Crypto Fund Recovery & Forensics or contact [email protected].
This guide outlines the five essential steps to take immediately after a crypto hack, based on guidance from blockchain forensics experts and law enforcement resources.
Step 1: Stop the Bleeding Secure Your Remaining Assets
Drainers are automated. The moment you signed a malicious transaction or exposed your credentials, a bot likely swept your wallet. Your first priority is preventing additional losses.
Immediate actions:
Disconnect your wallet from every connected site. Not just the site you think caused the drain every site. Open your wallet's connected sites panel and revoke all connections. Individual site disconnects are insufficient if your browser session is still active.
Revoke all outstanding approvals. Do this from a clean device ideally one that has never accessed the compromised wallet or visited Web3 sites. Use tools like revoke.cash to revoke every outstanding token and NFT approval on the compromised address. If approvals remain active, a drainer can return for anything you receive into that address later.
Move remaining assets to a brand new wallet. Generate a new seed phrase on a clean device. Transfer anything remaining in the compromised wallet to this new address. Do not reuse the compromised seed phrase for anything, ever again.
Critical warning: If your seed phrase itself was exposed, the situation is more severe. Every wallet derivable from a compromised seed phrase is compromised including addresses you have never used. A drainer that obtained your seed phrase does not need to wait for you to use an address; it can sweep derivation paths proactively.
Step 2: Preserve Every Piece of Evidence
It can be tempting to delete messages, uninstall apps, or wipe devices as soon as you realize you have been targeted. However, all evidence should be preserved deleting messages or wiping devices risks destroying vital evidence that investigators and law enforcement need.
What to collect immediately:
The compromised wallet address
Every transaction hash associated with the drain (from Etherscan, Solscan, or the relevant chain explorer)
Screenshots of every phishing site, DM, or email that preceded the drain, with URLs visible
Timestamps of when you noticed each event
Any wallet addresses the stolen assets moved to
Any marketplace listings the stolen NFTs appeared in afterward
Communication logs with the scammer including usernames, profile pictures, wording and phraseology used in messages, claimed company names, and payment instructions
Important: If you suspect your device may be compromised, do not wipe, format, or reset it immediately. Compromised devices can contain important evidence showing whether malware was installed, whether remote access was obtained, or whether login credentials were intercepted. Best practice is to preserve and not use any suspected compromised devices until a forensic image can be taken.
Step 3: Begin On-Chain Tracing
Once your remaining assets are secure and evidence is preserved, start tracing where the stolen funds have gone. While professional forensics firms like Cryptera Chain Signals perform the most comprehensive analysis, you can begin the process yourself using free tools.
Self-service tracing tools:
Tool Purpose
Etherscan / Solscan / chain explorers Free, immediate visibility showing transaction paths
Arkham Intelligence Public labeled explorer; shows if funds touched known entities
MistTrack by SlowMist 400M+ labeled addresses, over 1,000 tracked entities; free lookups available; generates risk reports useful for filing
Breadcrumbs.app Visual fund flow graph; useful for presenting to investigators who are not chain-native
For more advanced users, open-source platforms like GraphSense provide secure, traceable frameworks for analyzing transaction networks across Bitcoin, Ethereum, and other major cryptocurrencies. The platform was developed through numerous research projects, combining scientific expertise with practical applicability for police, judiciary, and companies.
New tools are also emerging: AMLBot recently launched AI Tracer, a self-service blockchain analysis tool that maps visible fund movements from a transaction hash across blockchain networks. The tool traces through bridges that move assets cross-chain or when assets are split among multiple wallets. Its reports are intended as a starting point for investigations and do not replace professional audits or legal processes.
Cross-chain tracing considerations: If funds have been bridged, you will need to:
Identify the bridge by the source-side contract address
Decode the source event—extract recipient, value, token, and unique sequence/nonce
Search the destination contract for the matching event using the sequence/nonce
Document both events—source TX hash, destination TX hash, value, token, sequence ID
Step 4: Report to Authorities and Exchanges
Reporting does not guarantee recovery. However, it creates the legal record necessary for any future action and contributes to aggregate data that funds enforcement priorities.
Where to report:
United States:
IC3.gov—the FBI's Internet Crime Complaint Center; primary federal filing point
FBI Field Office—for losses above approximately $10,000, direct contact is worth attempting alongside the IC3 filing
Local or state police—file for a report number; typically required for insurance claims and tax documentation
Chainabuse.com—community attribution platform; adds the attacker's addresses to a shared blocklist used by some exchanges and wallets
United Kingdom: Action Fraud (actionfraud.police.uk)
Canada: Canadian Anti-Fraud Centre (CAFC) and local police
Australia: Scamwatch and ReportCyber
European Union: Europol coordinates cross-border crypto crime; individuals report to their national agency, which can escalate
Exchange reporting: If traceable funds reach a centralized exchange with KYC requirements, report to that exchange's compliance team immediately with transaction hash documentation. The exchange may freeze the deposit pending investigation. Include your MistTrack or Arkham report links in every filing investigators familiar with these tools will know what they are looking at.
Step 5: Engage a Professional Forensics Firm
Self-service tools are valuable for initial visibility, but professional investigators provide capabilities that individuals cannot access, including:
Enterprise-grade tools like Chainalysis Reactor and Crystal Intelligence
Multi-layer attribution through sophisticated obfuscation
Court-admissible forensic reports
Coordination with exchanges and law enforcement
Direct partnerships with global exchanges for asset freezes
Cryptera Chain Signals specializes in these services, combining 28 years of digital investigation experience with proprietary AI-powered tools. The firm has completed over 426 documented recovery projects with 5 rating from verified clients.
For professional assistance with stolen crypto recovery, visit Cryptera Chain Signals – Advanced Crypto Fund Recovery & Forensics or contact [email protected].