HostDeFi › Guides › Wallet drained
Your wallet was drained. Here's the first hour, in order.
It's a horrible moment, and what you do next actually matters — both for what can still be saved and for not being robbed a second time.
First, triage the honest reality: on-chain transfers are irreversible, and most drained funds are not recovered. What remains genuinely at stake in the first hour is everything the attacker hasn't taken yet — remaining balances, other accounts, and your future self, who scammers will now target specifically because you're on a victim list. Work the steps in order.
Step 1 — assume the environment is hostile
You don't yet know how they got in: phished seed, signed approval, malicious extension, or malware. So act from a device you have reason to trust — another computer or your phone if the drain happened on desktop. If malware is plausible (you installed something recently, or the drain needed no action from you), the compromised device touches nothing sensitive until it's wiped.
Step 2 — evacuate what's left
Create a brand-new wallet with a brand-new seed phrase on the clean device, and move remaining assets to it now. Never restore or reuse the compromised seed anywhere — a seed the attacker holds is compromised forever, on every chain, no matter what device it's typed into. If a drainer script is sweeping incoming funds, expect a race; move highest-value assets first.
Step 3 — cut the standing drain paths
If the theft came through a malicious token approval, that approval may still be live and able to take future deposits. Review and revoke everything granted from the compromised wallet — mechanics in approval drains and revoking. Then rotate the blast radius beyond the wallet: exchange account passwords, email, and 2FA, in case the compromise was device-level.
Step 4 — preserve evidence while it's fresh
Record the transaction IDs of the theft, the attacker's receiving address, timestamps, and the URL, message, or app that started it, with screenshots. This costs ten minutes and is the difference between a reportable case and a shrug — tracing firms and exchanges work from exactly these artifacts when stolen funds touch a platform that can freeze them.
Step 5 — report it properly
File with law enforcement — in the US that's the FBI's IC3 at ic3.gov — and notify any exchange whose platform the funds moved toward; freezes at cooperative exchanges are where the rare recoveries actually happen. Report the phishing site or extension where you found it, so the operation's next victim sees a warning instead.
The second scam is coming: "recovery agents" will find you — in DMs, in comment sections, even in search ads — offering to retrieve your funds for an upfront fee. Recovery-for-advance-payment is a scam category of its own, frequently run against fresh victims from lists. Nobody legitimate charges upfront to "hack back" your crypto. Our recovery-scams guide has the full anatomy.
Afterward — closing the door it came through
Do the honest post-mortem: which of the four entry paths was it? The answer decides the fix — password and approval hygiene, extension audit, or a full device wipe. Move meaningful funds behind a hardware wallet so a hot-wallet compromise is never total again. And if the drain traces to a copied lookalike address rather than a signature, read address poisoning — the defense is a different habit entirely.
Check before you sign — the drain usually starts with a token
Paste any token or claim-site contract before interacting; the scan reads it from the chain first.
Frequently asked
Can I get drained crypto back?
Usually no — on-chain transfers are irreversible. The realistic paths are freezes when stolen funds reach a cooperative exchange (why fast, well-evidenced reports matter) and law-enforcement action over time. Anyone promising recovery for an upfront fee is running the follow-up scam.
Should I move my remaining funds to a new wallet or just change passwords?
New wallet, new seed, created on a clean device — immediately. If the attacker has your seed phrase, no password change helps and the old wallet is compromised forever. Passwords and 2FA still get rotated afterward in case the compromise was device-level.
Do I need to revoke approvals if my seed was phished?
Revoking helps when the drain came through a malicious token approval; it does nothing against a stolen seed, which requires abandoning the wallet entirely. Since you often can't be sure of the entry path in hour one, do both: evacuate to a fresh wallet and revoke what the old one granted.
Where do I report a crypto theft?
In the US: the FBI's IC3 (ic3.gov), plus any exchange the funds moved toward, plus the platform hosting the phishing site or fake app. Include transaction IDs, the attacker's address, timestamps, and screenshots — reports with complete artifacts are the ones that lead to freezes.