Not financial, legal, or tax advice. Act quickly; this guide describes general steps, not a guarantee of fund recovery.
If your wallet is compromised, the priority is moving any remaining funds to a new, secure wallet immediately and cutting off the attacker's access. Recovery of funds already taken is unlikely, since transactions are irreversible, which is why prevention matters far more than recovery. Theft can be reported to law enforcement — in the US, through the FBI's Internet Crime Complaint Center.
Immediate steps
Stop using the compromised device or wallet app right away. If you suspect malware, disconnect the device from the internet before doing anything else, to prevent further data from being captured.
Speed matters more than certainty here, and that is worth stating clearly because the instinct is to first establish what happened. Attackers automate: many run scripts that watch a compromised address and move anything that arrives within seconds. If you are weighing whether you have really been compromised, act as though you have. Being wrong costs you an afternoon and a transaction fee. Being right and slow costs you everything remaining.
Move remaining funds
Using a separate, trusted device, create a brand-new wallet with a fresh seed phrase and transfer any remaining assets there immediately, before doing anything else. Speed matters more than caution here; every minute increases the chance of further loss.
The critical word is fresh. Changing a password, reinstalling the app, or generating a new address inside the same wallet accomplishes nothing, because if the seed phrase is known then every address it will ever derive is known too, forever. The compromise is at the root, not the branch. You need an entirely new phrase, generated on a device you trust, and you should assume anything reachable from the old one is already gone.
Prioritize by what is movable. Send the most valuable assets first, remembering that you need the chain's native coin to pay fees, and a wallet with tokens but no ETH or SOL cannot move any of them. If the attacker has already drained the gas, funding the compromised wallet to rescue tokens is a race you will usually lose, since bots sweep incoming coins on sight.
Revoke approvals
If you've interacted with decentralized apps, check and revoke any token approvals granted to smart contracts, since a compromised key can otherwise be used to drain assets through previously approved permissions.
Approvals deserve a moment because they are frequently the whole story rather than a footnote. If the compromise was a malicious approval rather than a stolen key, your seed phrase is still safe and the attacker's access is limited to the specific tokens you granted permission over. Revoking that approval genuinely closes it, and no new wallet is needed. If instead the phrase itself leaked, revoking is pointless, since the attacker can simply approve whatever they like.
Which makes the diagnosis the thing that determines the response. Ask what you actually did: signing something on a site is an approval problem, while typing your phrase into anything is a root compromise. When in doubt, treat it as the latter.
Prevent recurrence
Once secured, figure out how the compromise happened, whether a phishing link, a leaked seed phrase, or malware, and address that specific gap. Reviewing how these scams usually work is the best way to avoid a repeat.
This step is not optional housekeeping. Restoring a fresh wallet onto a device that still has malware on it simply repeats the exercise with extra steps, and people have been drained twice in a week doing exactly that. If malware is plausible, move to a different device entirely, and treat the old one as untrusted until it has been wiped.
Then be skeptical of everyone who appears afterward. Recovery services that guarantee they can retrieve stolen crypto are, without meaningful exception, a scam that finds its targets by watching people ask for help in public. On-chain transactions cannot be reversed by anyone, at any price. Reporting the theft to law enforcement is still worth doing for the record, and to exchanges if the funds moved to one, since those are the only places with any ability to freeze anything.
A checklist for the first hour
- Assume the worst and move. Do not spend time confirming the compromise. Transfer whatever is left, starting with the most valuable assets.
- Use a different device. If malware is even plausible, the device you are worried about is not the one to rescue funds from.
- Generate a genuinely new wallet. A fresh seed phrase, not a new address under the old one. Write it down on paper, offline, as you would have the first time.
- Revoke approvals for any contract you no longer use, if the compromise looks like an approval rather than a leaked phrase.
- Work out what happened before restoring anything to the old device, because the alternative is doing all of this again next week.
- Report it, to law enforcement for the record and to any exchange the funds reached.
The hardest part of this list is the first item, because everything in you will want to understand before acting, and understanding takes the time you do not have. It is also worth accepting what the list cannot do. Funds already gone are gone; on-chain transactions are final by design, and the same property that stops anyone from freezing your money stops anyone from returning it. What you are doing in this hour is limiting the damage, not undoing it, and that is a smaller job but a real one.