Safety
The first thing to establish is which of two things happened: your seed phrase or private key was compromised, or you signed an approval that let a contract move one token. If the native gas token also left, or assets moved on several chains at once, the key itself is compromised, the wallet can never be used again, and sending gas to it will be taken by an automated sweeper. If only specific tokens left after you signed something on a website, it was an approval, the wallet can be saved, and revoking is the right next step.
Three things, before anything else
Do not accept help from anybody who contacts you. Not on Discord, not in a reply, not by email. Recovery scams follow drains within minutes because the victims are public and upset.
Do not type your seed phrase anywhere at all, including into anything calling itself a recovery tool, a validator, or a support page.
Which one happened to you
Everything else on this page depends on this answer, so work it out before you act. Open the address on a block explorer and look at the transactions that took the money.
| What you can see | What it means |
|---|---|
| The native gas token left as well. ETH from an Ethereum wallet, SOL from a Solana wallet. | The key is compromised. An approval cannot move the gas token, only tokens. This is the serious case. |
| Assets left from the same address on more than one chain. | The key is compromised. One approval only ever covers one token on one chain. |
| Anything new you send to the address disappears within seconds. | The key is compromised and a sweeper bot is running on it. Stop sending. |
| One token left, or one NFT collection, and the gas token is untouched. | An approval was used. The wallet itself is still yours. |
| It happened shortly after you connected to a site and signed something. | Most likely an approval or a permit signature. Check whether the gas token is still there. |
| The outgoing transaction was sent by a different address, not yours. | An approval. A third party contract pulled the tokens using permission you granted. |
If the key is compromised
There is no undoing this. Whoever has the key has exactly the same power over that wallet as you do, permanently. The wallet is finished, and so is every account derived from that recovery phrase, on every chain, including ones you have never used.
Create a new wallet on a device you trust
A different machine if you can, and a hardware wallet if the amount justifies it. If the compromise came from malware, generating a new phrase on the same computer hands it straight over.
Move what is left, in order of value
Highest value asset first. You may only get one transaction through before the bot reacts. Do not tidy up, do not consolidate, do not move small things first.
If a sweeper takes your gas, stop and get help
A sweeper bot spends the gas the moment it lands, so an ordinary rescue is impossible. The fix is a bundle that funds and rescues in the same block. The Flashbots Whitehat Hotline does this for Ethereum and asks that the remaining assets exceed $1,000. Their published intake is whitehat.flashbots.net, and they say plainly that they can only try to save what is still there.
Assume everything from that phrase is gone
Every address, every chain, every account index. Do not keep using account 2 because only account 1 was emptied. They came from the same words.
Work out how it leaked, before you use the new wallet
A photo of the words, a cloud backup, a phrase typed into a website, a fake wallet app, or malware on the machine. If you do not find it, the new wallet is at the same risk. Scan the device, and consider a clean install.
If an approval was used
Better news. The key is still yours, the wallet still works, and the attacker only has permission to move a specific token. That permission can be taken away.
Revoke the approval that was used
Find the spender address from the draining transaction on the explorer, then revoke that approval. Revoking is an onchain transaction and costs gas.
Revoke everything else you do not use
While you are there. See token approvals for the full pass.
Repeat on every chain
Approvals are per network. Ethereum, Base, Arbitrum and Polygon are four separate reviews.
Move the remaining assets anyway
Some drains use a signed permit rather than an onchain approval. Revoking does not cancel a signature that has already been given, so a permit signed earlier can still be used until it expires. If you signed anything you did not understand, move the assets to a fresh wallet and treat the old one as untrusted.
Find the site you connected to
Check your history for what you opened just before. Whatever it was, it is still live and still taking people.
Reporting it
Be realistic. Reporting rarely returns funds. It is still worth doing, because it is required for any insurance or tax claim, because exchanges can freeze funds that arrive with them, and because the pattern data occasionally does lead somewhere.
| Where | Why it is worth the fifteen minutes |
|---|---|
| The exchange the funds moved to, if you can see one on the explorer | This is the only route with a real chance. Exchanges can freeze an account, and they act faster on a documented report with transaction hashes than on anything else. |
| Your national cybercrime reporting body. In the United States that is the FBI Internet Crime Complaint Center, at ic3.gov. | Creates the official record, and clusters your case with others against the same addresses. |
| The Federal Trade Commission at reportfraud.ftc.gov, if you are in the United States | Feeds the fraud database that law enforcement and researchers use. |
| Local police | Usually cannot act, but the report number is what an insurer or an accountant will ask for. |
Have the transaction hashes, the addresses involved, the amounts, the dates and any link or message that started it, written down before you file. Every form asks for the same things.
The second attack, which is coming
Within hours of a drain, people will contact you. They found you because the transaction is public, or because you posted about it. They will be confident, technical, and sympathetic.
| What they say | What is actually true |
|---|---|
| They can trace and recover your funds for a fee | A confirmed transaction cannot be reversed by anybody. The fee is the scam, and there is often a second fee after the first. |
| They need your seed phrase to validate or restore the wallet | No legitimate person or tool ever needs it. This request alone identifies a thief, with no exceptions. |
| They are from the wallet or exchange support team | Support never contacts you first. Reach support only from your own bookmark, inside your own account. |
| They can freeze the attacker’s address | No individual can freeze anything. Only the issuer of a centralized token, or an exchange holding the funds, has that power, and neither will negotiate through a stranger. |
| They have a recovery tool that needs your private key | Handing over the key to somebody who found you after a drain is how the remaining balance goes. |
Rebuilding
Separate what you hold from what you use
A hardware wallet that never connects to a site, and a small hot wallet that does. A drain of the second one is then an annoyance rather than an event. See self custody.
Use a wallet that shows you what you are signing
Wallets that simulate a transaction and tell you what will leave your account stop a large share of these before they happen.
Bookmark every site and use only the bookmarks
Search results and advertisements are one of the two main delivery routes. The other is a direct message.
Review approvals quarterly
Twenty minutes. How to do it.
Run the full pass once
The security checklist covers the rest of it in one sitting.
Common questions
Can I get my money back?
Usually not. The realistic chance is when the funds land at an exchange that can freeze them, which is why reporting quickly with transaction hashes is worth doing. Anyone promising recovery for a fee is running the follow up scam.
Should I send gas to the drained wallet to rescue what is left?
Not until you know a sweeper bot is not running. If the private key is compromised, the gas is taken the moment it arrives. If assets remain and are worth over $1,000, a whitehat bundle that funds and rescues in one block is the route.
Is my wallet safe again after I revoke the approval?
Only if it was an approval. If the seed phrase or private key leaked, revoking changes nothing at all and the wallet can never be used again.
They took an NFT collection but nothing else. What was that?
A setApprovalForAll signature, which grants control of every item in one collection at once. Revoke it, then check every other collection you have ever listed for sale.
Can I still use the same wallet software?
Yes, if the software was not the problem. Create a new recovery phrase inside it, ideally on a clean device. If you installed the wallet from a search advertisement or an unofficial store listing, remove it and install from the official site.
How did they get my seed phrase?
The usual routes are a photo in a cloud backup, the words typed into a website that looked official, a fake wallet application, a support impersonator, or malware reading the clipboard. Find yours before you set up the replacement.
Where to go next
Get a second pair of eyes on your setup
A security session reviews what you hold, where it sits, what approvals are open and what would happen if your laptop were compromised tomorrow. Most people find at least one thing worth fixing.