What to Do If Your Crypto Wallet Is Hacked

A hacked crypto wallet can't be fixed, only abandoned. Here's how to tell what happened, save what's left, report the theft and dodge the recovery scammers who follow.

Someone who can move your coins without you: that’s a hacked crypto wallet. Usually they got hold of your seed phrase, or they talked you into signing a permission you didn’t read closely. You won’t find a bank to ring or a chargeback to file, and in a self-custodial wallet (one where only you hold the keys) whatever leaves your address is gone unless whoever received it decides to send it back.

How you spend the first hour decides how much of the rest you keep. This guide sticks to what the wallet makers and the FBI publish: how these hacks happen, how to tell which one hit you, each wallet’s emergency steps, and how to report it without walking into a second scam.

An open padlock on a laptop keyboard, illustrating a crypto wallet that has been hacked
Photo: Yuri Samoilov, CC BY 2.0, via Wikimedia Commons

So What Counts as a Hacked Crypto Wallet?

Your wallet never holds coins, strange as that sounds. What it holds are the keys that move coins recorded against your wallet address on the blockchain, and a hack means someone else can use those keys now, or has your blessing to move particular tokens.

Some vocabulary helps here.

The seed phrase (MetaMask’s name for it is Secret Recovery Phrase) is the word list that can rebuild every key in the wallet. One account sits behind each private key. And a token approval, as Revoke.cash puts it, is permission “to a smart contract to spend your tokens on your behalf.”

Once coins start leaving, you’ll hear two more. A sweeper bot is a script parked on a compromised address that forwards whatever arrives straight to the attacker. Ledger describes blind signing as “approving a digital transaction without being able to verify its full details in a human-readable format.”

Before anything else, figure out which kind of hack you’ve got. Revoke.cash has a test we like because it’s so simple: look closely at what, exactly, was taken.

What’s missingWhat that usually points toWhat to do first
Lots of assets, spread over several networks or walletsSomeone has your seed phraseWalk away from the wallet and move whatever’s left to a new one with a fresh seed phrase
A batch of pre-approved assets, gone togetherYou signed a marketplace signature scamRevoke the approvals, then go back over everything else you’ve signed
Just one assetA token approval, or a straight transfer scamFind the approval behind it and revoke it
Each fresh deposit disappears within secondsA sweeper bot sitting on a leaked seed phraseStop funding it, gas too, and abandon the wallet

Coins on an exchange are another story, since the exchange holds those keys, not you. There the FTC’s advice is to get in touch with the exchange directly. We explain that split in custodial vs non-custodial wallets.

How a Crypto Wallet Gets Hacked in the First Place

Every theft the wallet makers and Revoke.cash describe goes down one of four roads, and which road you were on tells you whether the wallet’s salvageable.

  1. A private key or the seed phrase leaks out. The routes Revoke.cash lists are fake software downloads carrying hidden malware, phishing sites that ask you to type in your seed phrase, cloud backups sitting in Google Drive or iCloud, malicious terminal commands, and compromised AI tools that have access to your system.
  2. You approve something malicious. A phishing site asks for a token approval, and that approval lets its contract spend the token later on. With NFTs it’s worse, because a single “set approval for all” signature covers the entire collection.
  3. You sign something you can’t read. Ledger’s warning is that a blind-signed transaction may “grant a smart contract unlimited permission to move your assets.”
  4. Somebody poisons a tool you trusted. That’s what happened on December 14, 2023, when attackers phished the NPMJS account of a former Ledger employee and pushed malicious versions 1.1.5, 1.1.6 and 1.1.7 of Ledger Connect Kit, a library used by dApps (decentralized apps).

We find a building analogy useful. A leaked seed phrase is a thief with a copy of the master key; a bad approval is more like you handed one valet the key to one car.

Revoking the approval gets the valet’s key back. Nobody can un-copy a master key, though, so in that case you move out.

Things moved fast in the Ledger case. According to Ledger’s incident report, roughly 5 hours passed between the compromise and full resolution, with active draining “confined to less than two hours.” Anyone who signed the fake prompts during that stretch saw their wallet drained.

A laptop wrapped in a chain and padlock, a reminder to clean or wipe the computer after a crypto wallet hack
Photo: Santeri Viinamäki, CC BY-SA 4.0, via Wikimedia Commons

What Can Still Go Wrong After a Crypto Wallet Hack

Losing the first batch of coins often isn’t the end of it. Three things tend to follow, and any one of them can cost more than the original theft.

Anything you send in gets swept

In Revoke.cash’s words, sweeper bots “drain any incoming funds instantly, often within the same block.” That kills the rescue everyone thinks of first, which is topping the wallet up with a bit of ETH so you can pay gas and pull your tokens out. The ETH is gone before you can spend it.

Phantom doesn’t mince words: “Do not deposit additional funds or attempt to beat the bot.” MetaMask gives the same warning about ETH sent in for gas, and we’d add that it’s the most painful mistake to watch someone make.

Nobody’s going to reverse it

Don’t expect an undo. MetaMask’s help page says outright: “Transactions cannot be reversed, nor missing funds restored.” The FTC says something similar about crypto payments in general, that you can usually only get money back “if the person you paid sends it back.”

Your rescue transfers play by that rule too. Wrong network or wrong address means the funds are gone, and nobody can reverse it, so check the receiving address and the network twice before each transfer out of the hacked wallet.

Then the “recovery” people show up

Fake recovery firms go looking for people who’ve already been robbed, which is about as low as it gets. The FBI warned on August 11, 2023 that “private sector recovery companies cannot issue seizure orders to recover cryptocurrency.” Typically they take an up-front fee and then either disappear or hand over a tracing report that’s incomplete.

A newer warning came on July 20, 2026, about criminals pretending to be the IC3 itself. “IC3 will never ask for payment to recover lost funds,” it says, and IC3 doesn’t have a social media presence at all.

None of this is rare. The IC3 2025 report logged 181,565 complaints involving cryptocurrency and $11.366 billion in losses, which is 22% more in losses than 2024 and works out to an average loss of $62,604.

What MetaMask, Phantom, Trezor and Ledger Say to Do After a Wallet Hack

Each wallet maker publishes its own emergency routine. They all start from the same place: the old seed phrase is burned, and you begin again.

MetaMask’s steps

Start on a block explorer, MetaMask says, and confirm the theft is real by checking the date and time, the recipient address, the dApp involved and the value sent.

If it wasn’t you, install MetaMask on a different browser or browser profile, or on a second phone. Set up a new wallet there and write its new Secret Recovery Phrase down, and if the old wallet was created with a Google or Apple account, keep that account well away from the new one.

After that, send whatever funds are left to the new wallet and stop using the old one. MetaMask also warns: “Do not create additional accounts in your now-compromised Secret Recovery Phrase.” Pairing MetaMask with a device next time? Our roundup of hardware wallets for MetaMask goes through the choices.

Phantom’s steps

Phantom wants you off the wallet immediately, with a fresh one made on a new recovery phrase. It also asks for malware scans on every device you own, suspicious extensions removed and your software brought up to date.

Solscan and Chainabuse both take reports. Don’t expect Phantom to chase the funds, since it says flatly that it “does not offer fund recovery services.”

Trezor’s three routes

Trezor’s guide opens with a rule we agree with completely: “If you suspect your backup has been compromised, you should assume that is the case and move your funds elsewhere immediately.” After that come three routes.

Quickest is to send the coins to a compatible third-party wallet, then wipe the Trezor and set it up again with a new backup. Trezor itself warns this exposes the coins to “a potentially dangerous environment” and keeps it for emergencies only. Route two needs a second Trezor with its own new backup.

With just one device you can still do it, but it takes four wipe and restore cycles, which is tedious. Afterwards the old backup “can now be destroyed, or defaced,” in Trezor’s words. Check the new backup, and double-check it’s the old card you’re defacing, not the new one.

A Coinkite Coldcard hardware wallet, the kind of device that keeps a new crypto wallet's keys offline after a hack
Photo: Gareth Halfacree, CC BY-SA 2.0, via Wikimedia Commons

What Ledger took from Connect Kit

For Ledger, the Connect Kit incident came down to signing. The company said it would “double down on preventing Blind Signing” and pushed Clear Signing so users “verify what they see on a trusted display.”

Day to day, that means reading every prompt on the device screen before you approve it. If the screen can’t tell you what a transaction does, we’d walk away rather than sign. How each brand shows transaction details is covered in our Ledger vs Trezor comparison.

If the coins were on an exchange

The FTC’s advice for exchange accounts is to contact the exchange directly. When stolen funds landed in an exchange deposit address, let that exchange know as well and name it in your police and IC3 reports. Who holds the keys in each setup is explained in our crypto wallet vs exchange guide.

Hacked Crypto Wallet? The Order We’d Tackle Things In

Take these one at a time, in this order. Yes, speed matters, but rushing a transfer to the wrong address just hands you a second loss.

  1. Figure out what’s been taken, using the table near the top. A leaked seed phrase and a bad approval call for different fixes.
  2. Leave the hacked wallet alone. Don’t deposit anything into it, and don’t send ETH or SOL in to cover fees either.
  3. Assume the computer or phone is infected. Revoke.cash recommends malware checks, a full computer reset if it comes to that, and fresh passwords on your important accounts.
  4. Make a new wallet, with a new seed phrase, on a clean device. We’d use a hardware wallet here because it keeps the new keys offline, and our best crypto hardware wallets list compares the current models.
  5. Shift what’s left into the new wallet. Copy the receiving address from the new wallet itself, confirm it on the hardware wallet’s screen if you’ve got one, and make sure the network matches before you hit send.
  6. Revoke the approval if that’s how they got in. Revoke.cash works on over 100 networks: type in your address, choose the network, sort by “Newest to Oldest” and click “Revoke.” You’ll pay the network’s gas fee for each revoke, while a batch revoke costs $1.50 for free users.
  7. Keep the evidence and report the theft. IC3 wants the cryptocurrency addresses, the amounts and types, the transaction hashes, and the dates and times; file with ReportFraud.ftc.gov too.
  8. Got more than $1,000 still stuck in the hacked wallet? Reach the Flashbots Whitehat Hotline, and only through whitehat.flashbots.net, bearing in mind MetaMask says the service keeps a 5-10% cut of whatever it recovers.

Ethereum users have a second place to check approvals, Etherscan’s Token Approval Checker. It shows which contracts you’ve approved and the value at risk, and gives you “Connect Wallet” and “Revoke Selected” buttons.

Anyone 60 or older can phone the National Elder Fraud Hotline on 833-372-8311. File a complaint even if nothing was lost; the FBI asks for that too.

Mistakes People Make Right After a Wallet Hack

  • Topping up a swept wallet with gas money. The bot takes it within seconds, you lose the gas, and your tokens don’t budge.
  • Adding another account on the same seed phrase. Every account that phrase generates is exposed, so make a brand-new phrase.
  • Revoking approvals and calling it fixed. Revoke.cash is clear that revoking won’t help once the seed phrase is out; that wallet has to be abandoned, which is hard to accept, but there it is.
  • Paying anyone who promises recovery. According to the FBI, private recovery companies can’t seize crypto, and law enforcement doesn’t charge a fee to investigate.
  • Building the new wallet on the infected machine. Whatever malware took the old phrase can take the new one, so clean or reset that device first.
  • Signing into the new MetaMask wallet with the same Google or Apple account. MetaMask warns those accounts could be compromised too.
  • Defacing the wrong backup card. Trezor asks you to make sure it’s the old backup you’re destroying and not the new one.

Quick Answers on Hacked Crypto Wallets

Is there any way to recover a hacked crypto wallet?

No, not once the seed phrase has leaked. According to Revoke.cash nothing will re-secure it, so you leave it behind and move what’s left into a new wallet built on a new seed phrase.

Will MetaMask or Phantom reverse the stolen transaction?

No. MetaMask says transactions can’t be reversed; Phantom doesn’t offer fund recovery.

If I revoke my token approvals, do I get the stolen crypto back?

Sadly, no. Revoke.cash says it can’t recover stolen funds, and revoking just stops that approval from being used a second time.

A company says it can trace and recover my crypto. Should I pay?

Don’t. The FBI says private recovery companies can’t issue seizure orders, and IC3 will never ask you to pay to get lost funds back.

Where should I report a crypto wallet hack in the US?

Start with a complaint at ic3.gov, then report it at ReportFraud.ftc.gov. The FTC also points to the CFTC and the SEC, and suggests contacting whichever exchange was involved.

What’s a sweeper bot?

It’s a script that watches a compromised wallet and passes every new deposit to the attacker, often inside the same block. If you’ve got one, your seed phrase is out.

Is my hardware wallet still usable after a hack?

Yes, the device is. The old backup isn’t, though: Trezor’s guide has you move the funds, wipe the device and set it up again with a new backup.

Our Take on Surviving a Crypto Wallet Hack

There’s no repairing a hacked crypto wallet. If the seed phrase leaked, leave it, move what’s left to a new wallet on a clean device, and don’t ever send gas into an address that’s being swept; if a bad approval did the damage, revoke it straight away.

After that, report it to IC3 and the FTC with your transaction hashes and ignore anyone selling recovery for a fee.

Next time round, we’d put the new seed phrase on a hardware wallet with a readable screen, which keeps it off your computer where malware goes looking.

Picking a wallet to start over with? Best Crypto Hardware Wallets →
Devices we rank for keeping a fresh set of keys offline.

This article is for general information only and is not financial, legal, or investment advice. Prices and features change; check the vendor’s official page before buying.

Andrei B.
Andrei B.

Andrei B. is a long-time crypto enthusiast. With over eight years of experience exploring blockchain technology and digital asset security, he focuses on helping users find trustworthy wallets through clear, unbiased, and practical reviews.

His background spans years of hands-on testing with both hardware and software wallets, combining personal experience with a passion for simplifying crypto security for everyone.

Articles: 143