Recovering From a Compromised Wallet: The First Hour
The order of operations decides how much you keep. Most people revoke first, which is the step that loses them the rest.
The order of operations decides how much you keep. Most people revoke first, which is the step that loses them the rest.
If a wallet is compromised, move remaining assets to a new wallet on a clean device before doing anything else — revoking takes a transaction that an attacker can outrun. Then determine whether the seed leaked or only an approval was signed, because a leaked seed means the wallet is permanently unsafe and no revocation helps. Secure connected accounts, revoke approvals from a safe wallet, document everything for tax and reporting, and treat the compromised address as burned.
There is no support line and no reversal. What you can control is the next twenty minutes, and the sequence matters more than any individual action.
The instinct is to revoke the malicious approval. That is the wrong first move. Revoking is itself a transaction; it needs gas, it needs to be mined, and an attacker watching the address will simply front-run it. Meanwhile everything else in the wallet stays exposed.
Move first. Send remaining assets to a wallet the attacker has no relationship with — ideally a fresh one created on a different device. Prioritise by what is easiest to take: liquid tokens with a live approval first, then NFTs, then staked or locked positions if they can be exited quickly.
If the wallet holds a native balance that funds gas, keep just enough to send the transfers, and expect that in a mass-drain scenario you may be racing a bot. Send the largest holdings first.
Do not create the new wallet on the same machine if there is any chance the compromise is malware rather than a signature. A device that leaked one seed will leak the next one.
Three very different situations, and they have different endings.
**A signature or approval was granted.** The attacker can move specific tokens they were approved for, and nothing else. Assets in the same wallet without an approval to that contract are safe once you have moved them. The address is contaminated but the seed is intact.
**The seed phrase or private key leaked.** Everything derived from that seed, on every chain, is permanently the attacker's. Revoking is pointless. There is no fix; the wallet is dead and any funds sent to it later will be swept, often within seconds by an automated bot. This is the case where people lose money twice.
**The account's control was changed.** On smart accounts and delegated accounts, ownership or execution can be reassigned. Treat this as equivalent to a leaked key.
Read the transaction history on a block explorer to tell them apart. A single `approve` or `permit` followed by transfers of one token points to the first case. Sweeps of unrelated assets across several chains at once point to the second.
Ask what else that device or that seed touched. Change passwords and re-enrol two-factor on every exchange account accessible from the affected machine, starting with email — email is the recovery path for everything else. Prefer passkeys or a hardware key over SMS, for the reasons set out in two-factor that actually works.
Revoke API keys on exchanges. Disconnect the wallet from applications. If malware is suspected, the device should be considered untrustworthy until it is wiped and rebuilt, not merely scanned.
Only now, from a safe wallet and with nothing left to lose in the old one, revoke the outstanding approvals on the compromised address using the revocation process. This is housekeeping, not rescue.
Be direct with yourself about this. On-chain transfers are final. There is no protocol-level reversal, no chargeback, and any service offering to recover stolen crypto for an upfront fee is a second theft aimed at people who have just experienced the first.
Two narrow exceptions exist. Funds that reach a centralised exchange can sometimes be frozen if you report quickly with the transaction hashes and the deposit address — exchanges do act on credible reports, and speed is everything. And centrally issued assets such as some stablecoins can be frozen by their issuer, who has a published contact route for law enforcement and, occasionally, for victims.
Both depend on reporting within hours, not days, so gather the transaction hashes, the destination addresses and the timestamps immediately and file with the exchange, the issuer and your national reporting body in parallel.
Export the transaction history of the compromised address while you still have the tooling connected. You will need it for a tax position — theft losses are treated differently across jurisdictions and require evidence of the disposal — and for any report you file.
Write down what happened while it is fresh: what you clicked, what you signed, which site, which device. The reconstruction is what stops it happening again, and it is the part people never do.
The replacement setup should differ structurally, not just in address. A hardware wallet for holdings, a separate connecting wallet for anything experimental, and a rule that the holding wallet never touches a site. That separation is the only defence that works regardless of what you sign next time.
If the cause was malware or a leaked seed, generate the new seed on the new device and never re-enter the old one anywhere. And leave the old address alone permanently — sweeper bots monitor compromised addresses indefinitely, and a deposit made a year later is still gone in the same block.

Moving funds off an exchange and into cold storage for the first time is simpler than it looks — provided you follow the sequence in the right order and don't skip the verification steps.

Most wallet losses are not stolen keys. They are approvals granted months ago to a contract that later turned hostile — and revoking them takes about a minute.

A plain-language breakdown of how crypto wallets actually work, and why the choice between hot and cold storage is the first real security decision every holder makes.