What to Do After a Crypto Scam

    Reviewed and updated September 18, 2026 by the SmartCryptoEarnings editorial team · editorial policy

    Speed helps with containment, not with reversal. Confirmed blockchain transfers cannot be undone, so the goal in the first hour is to stop further loss and preserve evidence.

    Start with the branch below that matches what happened — an exposed recovery phrase, an unintended approval, a compromised account and a completed transfer all call for different first moves. The general checklist follows it.

    This page does not promise recovery and does not refer anyone to paid recovery services.

    First hour: what to do now

    Find the line that matches what happened and do that first. Detail for each situation follows below. Nothing here promises that funds can be recovered.

    • Recovery phrase or private key exposedTreat control of that wallet as lost. Create a new wallet on a device you trust and move whatever remains — highest value first. A phrase cannot be revoked or changed.
    • Approval or signature you did not intendInspect the address's approvals and revoke the permission where that is technically appropriate. Revoking prevents further use of that allowance; it does not reverse a transfer that has already happened.
    • Exchange or email account compromisedSecure the account through official channels only: your own bookmark or installed app. Email first, then the platform — change the password, sign out all sessions, re-enrol two-factor, delete unknown API keys.
    • Funds already transferred outStop sending anything further and preserve evidence: transaction hashes, addresses, domains, handles, message threads. Report promptly — speed is the only factor you control, and a confirmed transfer cannot be reversed.
    • Personal information exposedSecure the affected accounts and credentials: unique passwords, a strong second factor, a carrier port-out lock, and a review of active sessions.
    • Someone has contacted you offering recoveryDo not send additional funds, pay a fee, or grant access merely because someone promises recovery. That promise is itself the second attack.

    Then: what actually happened?

    The full response depends on what was exposed. Choose the branch that matches your situation — or read all six. Nothing here promises that funds can be recovered, and we never refer anyone to a paid recovery service.

    A. My recovery phrase or private key was exposed

    Every address derived from that phrase is compromised, including ones you have never used. Treat the whole wallet as lost and race the attacker to whatever is left.

    Do this first

    1. Create a brand-new wallet on a device you have reason to trust, and write the new phrase down offline.
    2. Move remaining assets to the new wallet, highest value first, native gas token last.
    3. Do not 'secure' the old wallet by changing a password — a phrase, once exposed, cannot be revoked.
    4. Assume any other account whose recovery details were stored alongside the phrase is also exposed.

    Then

    • Work out how the phrase was exposed — typed into a site, photographed, stored in cloud notes, or taken by device malware.
    • If device malware is possible, rebuild the device from a clean installation before using the new wallet on it.
    • Document transaction hashes and the site or message involved before anything disappears.

    B. I signed or approved something I did not intend

    An approval or signature can authorise transfers later, without your key ever leaving your wallet. The fix is removing the permission, not changing a password.

    Do this first

    1. Move remaining assets out of the affected address if anything of value is still there.
    2. Open your wallet's permissions or approvals screen and revoke the approval you granted.
    3. Revoke other stale approvals on that address while you are there, starting with unlimited ones.
    4. Disconnect the wallet from the site, and stop using that site.

    Then

    • Check whether the signature was an off-chain permit or an on-chain approval — permits can still be redeemed until the allowance is revoked on-chain.
    • Consider retiring the address entirely for anything of value, especially if you cannot identify what you signed.
    • Record the transaction hash, the contract address and the domain.

    C. My exchange or email account was compromised

    Custodial accounts have a support channel and internal controls, so there is more to do here than on-chain — and the email account behind them comes first.

    Do this first

    1. Work from a different device than the one you suspect.
    2. Change the email password first, sign out all sessions, and remove any forwarding or filter rules you did not create.
    3. Change the platform password, sign out all sessions, and re-enrol two-factor authentication from scratch.
    4. Delete every API key and remove withdrawal allowlist entries you did not add.

    Then

    • Contact the platform through its official site, from inside your account, and keep ticket numbers and timestamps.
    • Replace SMS two-factor authentication with an authenticator app or a hardware security key where supported.
    • Check whether your phone number was ported — sudden loss of mobile service is the tell.

    D. Funds have already been transferred out

    A confirmed transfer cannot be reversed by anyone. The remaining work is containment, evidence and reporting — not recovery.

    Do this first

    1. Stop sending anything further, including any payment described as a fee, tax or unlock.
    2. Stop communicating with the other party.
    3. Move whatever remains to a new wallet if the original one may still be exposed.

    Then

    • Record every transaction hash, address, domain, handle and message thread; export rather than photograph where possible.
    • If funds went to an address controlled by an exchange, contact that exchange's support with the hash — freezing is uncommon but only possible if you ask quickly.
    • File with the FBI's Internet Crime Complaint Center and the FTC if you are in the US.

    E. My personal information was exposed, but no funds moved

    Identity data feeds the next attack: SIM swaps, targeted impersonation and convincing 'support' contact that quotes real details back to you.

    Do this first

    1. Add a port-out PIN or account lock with your mobile carrier.
    2. Change passwords on the email address behind your financial accounts and enable a strong second factor.
    3. Review active sessions and trusted devices on exchanges and email.

    Then

    • Expect follow-up contact that quotes your real details. Knowing your data does not make a caller legitimate.
    • Be cautious with security questions whose answers are now known.
    • Keep the email used for exchanges separate from your public address.

    F. Someone has offered to recover my lost funds

    This is the second wave, and it targets people who have just been hit. No service can reverse a confirmed blockchain transaction.

    Do this first

    1. Do not pay an upfront fee, a percentage, a 'gas' cost or a 'tax'.
    2. Do not share a recovery phrase, private key or remote access with anyone offering to trace funds.
    3. Do not believe screenshots of a dashboard showing your funds 'located'.

    Then

    • Treat anyone claiming law-enforcement or government affiliation who contacted you first as unverified until you reach that agency yourself.
    • Report the approach as well as the original incident — it links cases together.

    First hour: contain

    1. Move any remaining funds in the affected wallet to a brand-new wallet created on a device you trust. If a recovery phrase may be exposed, every address derived from it is compromised.
    2. Disconnect the affected wallet from applications and revoke token approvals you can still reach.
    3. Change the passwords on your email and exchange accounts from a clean device, and revoke active sessions.
    4. Remove SMS two-factor authentication and re-enroll an authenticator app or security key.
    5. Stop communicating with the other party. Do not send anything further to 'release' or 'unlock' funds.

    If your recovery phrase was entered anywhere, treat the entire wallet as lost and migrate immediately. Nothing derived from that phrase is safe.

    Document everything, before it disappears

    • Transaction hashes, sending and receiving addresses, dates and times.
    • The website domains, app names and account handles involved.
    • Full message threads, emails and screenshots, exported rather than photographed where possible.
    • Any payment records for card, bank or wire transfers connected to the incident.

    Report it

    In the United States, file with the FBI's Internet Crime Complaint Center and report to the Federal Trade Commission. If funds were sent to an exchange-controlled address, contact that exchange's support with the transaction hash — occasionally funds can be frozen while an investigation proceeds.

    If a mobile carrier, bank or card issuer was involved in the chain of events, notify them too, since some non-crypto legs of a payment can sometimes be disputed.

    Do not become a second victim

    Fraud victims are routinely targeted again by 'recovery experts' who appear in comment replies, direct messages and search advertisements. They ask for an upfront fee, a percentage, or your recovery phrase 'to trace the funds', and they deliver nothing.

    • No legitimate service can reverse a confirmed blockchain transaction.
    • Never pay an upfront fee to recover stolen crypto.
    • Never share a recovery phrase or private key with anyone offering to help.
    • Be sceptical of anyone claiming law-enforcement or government affiliation who contacts you first.

    Rebuild safely

    1. Set up a new wallet on a clean device and record the recovery phrase offline, on paper or metal.
    2. Move long-term holdings to a hardware wallet kept separate from day-to-day activity.
    3. Re-secure email first, then exchange accounts, with app-based or hardware two-factor authentication.
    4. Review how the incident started so the same entry point is closed.

    Frequently Asked Questions

    Can the police get my crypto back?

    Sometimes funds are seized in larger investigations and later returned through a formal process, but this is uncommon and slow. Reporting is still worthwhile because it links cases together.

    Should I keep talking to the scammer to gather evidence?

    No. Preserve what you already have and stop engaging. Continued contact mainly creates more pressure to send additional funds.

    Is it safe to keep using the same wallet if only some funds were taken?

    Only if you are certain the cause was a single malicious approval and not an exposed recovery phrase. If there is any doubt, migrate to a new wallet.

    Sources

    Spotted something out of date? See our corrections policy and fact-checking policy.

    Continue reading

    Educational information only. Nothing here is financial, legal or tax advice.