HostDeFiGuides › Wallet drained

Your wallet was drained. Here's the first hour, in order.

It's a horrible moment, and what you do next actually matters — both for what can still be saved and for not being robbed a second time.

Educational guide · written September 2026 · not financial advice

First, triage the honest reality: on-chain transfers are irreversible, and most drained funds are not recovered. What remains genuinely at stake in the first hour is everything the attacker hasn't taken yet — remaining balances, other accounts, and your future self, who scammers will now target specifically because you're on a victim list. Work the steps in order.

Step 1 — assume the environment is hostile

You don't yet know how they got in: phished seed, signed approval, malicious extension, or malware. So act from a device you have reason to trust — another computer or your phone if the drain happened on desktop. If malware is plausible (you installed something recently, or the drain needed no action from you), the compromised device touches nothing sensitive until it's wiped.

Step 2 — evacuate what's left

Create a brand-new wallet with a brand-new seed phrase on the clean device, and move remaining assets to it now. Never restore or reuse the compromised seed anywhere — a seed the attacker holds is compromised forever, on every chain, no matter what device it's typed into. If a drainer script is sweeping incoming funds, expect a race; move highest-value assets first.

Step 3 — cut the standing drain paths

If the theft came through a malicious token approval, that approval may still be live and able to take future deposits. Review and revoke everything granted from the compromised wallet — mechanics in approval drains and revoking. Then rotate the blast radius beyond the wallet: exchange account passwords, email, and 2FA, in case the compromise was device-level.

Step 4 — preserve evidence while it's fresh

Record the transaction IDs of the theft, the attacker's receiving address, timestamps, and the URL, message, or app that started it, with screenshots. This costs ten minutes and is the difference between a reportable case and a shrug — tracing firms and exchanges work from exactly these artifacts when stolen funds touch a platform that can freeze them.

Step 5 — report it properly

File with law enforcement — in the US that's the FBI's IC3 at ic3.gov — and notify any exchange whose platform the funds moved toward; freezes at cooperative exchanges are where the rare recoveries actually happen. Report the phishing site or extension where you found it, so the operation's next victim sees a warning instead.

The second scam is coming: "recovery agents" will find you — in DMs, in comment sections, even in search ads — offering to retrieve your funds for an upfront fee. Recovery-for-advance-payment is a scam category of its own, frequently run against fresh victims from lists. Nobody legitimate charges upfront to "hack back" your crypto. Our recovery-scams guide has the full anatomy.

Afterward — closing the door it came through

Do the honest post-mortem: which of the four entry paths was it? The answer decides the fix — password and approval hygiene, extension audit, or a full device wipe. Move meaningful funds behind a hardware wallet so a hot-wallet compromise is never total again. And if the drain traces to a copied lookalike address rather than a signature, read address poisoning — the defense is a different habit entirely.

Check before you sign — the drain usually starts with a token

Paste any token or claim-site contract before interacting; the scan reads it from the chain first.

Frequently asked

Can I get drained crypto back?

Usually no — on-chain transfers are irreversible. The realistic paths are freezes when stolen funds reach a cooperative exchange (why fast, well-evidenced reports matter) and law-enforcement action over time. Anyone promising recovery for an upfront fee is running the follow-up scam.

Should I move my remaining funds to a new wallet or just change passwords?

New wallet, new seed, created on a clean device — immediately. If the attacker has your seed phrase, no password change helps and the old wallet is compromised forever. Passwords and 2FA still get rotated afterward in case the compromise was device-level.

Do I need to revoke approvals if my seed was phished?

Revoking helps when the drain came through a malicious token approval; it does nothing against a stolen seed, which requires abandoning the wallet entirely. Since you often can't be sure of the entry path in hour one, do both: evacuate to a fresh wallet and revoke what the old one granted.

Where do I report a crypto theft?

In the US: the FBI's IC3 (ic3.gov), plus any exchange the funds moved toward, plus the platform hosting the phishing site or fake app. Include transaction IDs, the attacker's address, timestamps, and screenshots — reports with complete artifacts are the ones that lead to freezes.

HostDeFi is an educational risk tool, not financial advice. On-chain data can be incomplete or manipulated; a clean check is a dated snapshot, not a guarantee. Always do your own research. Free · no signup · a HostDeFi product