Skip to main content
Don't invest unless you're prepared to lose all the money you invest. This is a high-risk investment, and you should not expect to be protected if something goes wrong. Take 2 min to learn more.

What to Do if Your Crypto Is Stolen: The First-Hour Drill

The honest incident drill for stolen crypto: stop the second loss, keep the evidence, report to the right places and dodge the scammers who circle victims.

beginner5 min readWritten by Dan Clarke
Hero image for what-to-do-if-your-crypto-is-stolen

TL;DR

  • On-chain transfers do not reverse; the drill below is about preventing a second loss
  • Hour one: new wallet if your seed was exposed, revoke token approvals, rotate exchange and email logins
  • Save hashes, addresses and timestamps, then report to IC3, Action Fraud or your local police and keep the crime reference number
  • Anyone promising recovery for an upfront fee is the follow-up scam; the FBI has warned about these schemes
  • Educational guide only, not financial or legal advice

You open the wallet app with your morning coffee and the balance is a row of zeros. One outgoing transfer sits at the top, timestamped 3.47am, headed to an address you have never seen, and your stomach drops. The first question everyone asks is the same one: who do I call to reverse this?

Nobody. Blockchain transfers are irreversible by design, no chargeback layer, no fraud desk, no dispute window. This is an incident drill, not financial or legal advice, and because recovery of retail thefts is genuinely rare, almost everything below is about stopping the second loss.

The first hour, in order

Three moves, and do them before you tell a single soul what happened.

If your seed phrase or private key was exposed anywhere, typed into a website, an app or a so-called support tool, or kept on a device you suspect is compromised, that wallet is burnt for good. Do not tidy it, create a brand-new wallet with a fresh set of 12 or 24 words on a clean device, and move whatever remains to it immediately. Restoring the old seed onto a new phone changes nothing, because the words themselves are the key and someone else now holds a copy.

Revoke standing token approvals: drainers often hold approvals that keep working after the first hit, so yesterday's theft can repeat next week. Block explorers such as Etherscan carry approval checkers for ethereum wallets. Open one, review the list, revoke anything you do not recognise.

Lock down everything around the wallet: rotate the passwords and 2FA on your exchange accounts and, above all, on the email behind them. Kill any API keys you have ever created, and if the theft hit an exchange account rather than your own wallet, contact that exchange's support team in the same hour and ask for a freeze on the account.

None of this brings the stolen coins back. It stops the next theft, and in the first hour that is the achievable goal.

Write everything down while it is fresh

Next, the boring part that matters in month six. Record every transaction hash, the long ID each transfer carries, 64 characters of letters and numbers on bitcoin and much the same elsewhere. Add destination addresses, timestamps, amounts, and screenshots of anything you clicked, signed or received. Chains are public, anyone can follow the money on a block explorer, and investigators will want that trail with your notes attached, not your memory of it. Police forms and exchange compliance teams ask for the same fields, so collect everything once and paste it everywhere. Doing this at hour two beats reconstructing it at week six, when the browser history is gone and the panic has blurred the order of events.

Report it where reporting does something

Thieves have a weakness you can use: at some point they want real money, and the paths to real money run through exchanges. If stolen funds land at a major venue, its compliance team can freeze deposits arriving in accounts with completed KYC. This does happen, though nobody should promise you it will.

To make that machinery move, file a police report first. In the US that means IC3, the FBI's Internet Crime Complaint Center, in the UK Action Fraud, and elsewhere whatever your national cybercrime channel is called. The crime reference number you get back is the item exchanges and investigators actually ask for, so get it early and quote it in every message you send. File even if the amount feels embarrassing: small complaints get aggregated, and they feed the pattern files that larger cases get built from.

What recovery honestly looks like

Slow, when it happens at all. Analytics firms such as Chainalysis and Elliptic trace stolen funds for law enforcement, and stolen coins often sit dormant for years before they move. Money has been recovered and returned in major cases, on timescales measured in years rather than weeks. Keep your evidence pack backed up for exactly that reason, and check the destination addresses every few months rather than staring at them nightly.

For scale: in February 2025 the exchange Bybit lost roughly $1.5bn, the largest crypto theft on record, which the FBI attributed to North Korea's Lazarus Group. The biggest custodians on earth get hit, so there is no embarrassment in a personal wallet losing a four-figure sum to a phishing page.

The second scam comes looking for you

Post about a theft anywhere public and the self-described recovery agents find you within hours, in direct messages, on polished websites, sometimes in paid ads. Some pose as investigators, some as lawyers, a few as the very exchange you just reported to. They promise to trace and retrieve your coins for an upfront fee, and collecting that fee is the whole of the business. The FBI has issued repeated public warnings about recovery schemes. The rule has no exceptions: legitimate investigators never require upfront crypto payment and never ask for your seed phrase. Anyone doing either is running the second scam, whatever their website looks like.

Afterwards

Rebuild deliberately: new seed, clean device, and an unsentimental look at how the thief got in, because the same route gets tried twice. The guide on protecting crypto from hackers covers the hardening order. And if your loss was a platform going down rather than a wallet being emptied, FTX in November 2022 being the canonical case, that is an insolvency queue rather than a theft drill, and proof-of-reserves is the topic to read up on before you pick the next venue. Tax and insurance treatment of losses sits outside this guide.

One last thing: run this drill in your head before you ever need it, the way you clock the fire exits in a hotel. On the day it matters, people who already know their first three moves make them in minutes, while everyone else spends the hour searching for a phone number that does not exist.

Frequently Asked Questions

Rarely, for individuals. Exchanges can freeze stolen funds that land in KYC'd accounts, and law enforcement has clawed money back in major cases, but on multi-year timescales. Assume it is gone, and do the reporting anyway, because freezes only happen for people who filed.

No. Once coins move on-chain the transfer is final, and there is no chargeback layer on a blockchain. Your bank can help with card fraud on the buying side, but the on-chain movement itself does not come back.

Police first: IC3 in the US, Action Fraud in the UK, your national cybercrime channel elsewhere. Then any exchange the funds moved through, quoting your crime reference number. That number is what makes compliance teams take the case up.

Treat every one that approaches you as a scam, because nearly all of them are. The FBI has warned about recovery schemes repeatedly. Nobody legitimate charges an upfront crypto fee or asks for your seed phrase, ever.

No. Treat the wallet as burnt from the moment the seed left your head or your paper. Make a new wallet with a new seed on a clean device and move everything now. This is one of the few crypto emergencies where minutes genuinely matter.

You can. Block explorers are public, and stolen funds oddly often sit still for years. Log anything that moves and pass it to investigators. Do not contact the thief, and do not pay anyone who claims they can negotiate.

About the author — Dan Clarke
Dan Clarke

Dan Clarke is the author of Bitcoin: The Complete Guide and a former content lead at Binance Academy, where he wrote crypto education for readers arriving with no background in the subject. He has worked in the cryptocurrency industry since 2017. His rule for these guides: plain language first, precision where it matters, no cheerleading.