What to Do After a Crypto Scam
This guide is a sequence, not a menu — the order matters because early actions (moving remaining funds, revoking approvals) can still limit the damage, while later actions (reporting, documentation) mostly affect whether the incident is ever traceable or recoverable at all. Work through it in order rather than jumping straight to whichever step feels most urgent.
Direct answer: Disconnect from suspicious sites, stop communicating with the attacker, secure email and exchange accounts, and record transaction identifiers. The strongest approach contains the incident first, protects everything not yet touched, and only then moves to documentation, reporting, and expectation-setting.
Key Takeaways
- Treat every minute in the first hour as a chance to limit further loss, not as time to investigate exactly what happened.
- A seed phrase exposure and a malicious approval are different failure modes and call for different first actions — moving funds versus revoking access.
- Blockchain transactions can't be reversed by Swoopr, an exchange, or anyone else; realistic recovery paths are narrow (exchange freezes, law enforcement, rarely a protocol-level intervention).
- Evidence collected in the first day — screenshots, transaction hashes, attacker messages — is far more complete than anything reconstructed later.
- Reporting to platforms and authorities rarely returns funds directly but still feeds the data that flags addresses and connects related cases.
- No paid "recovery service" that contacts you first is legitimate; treat unsolicited recovery offers as a second scam.
First 15 Minutes
The first 15 minutes decide how much damage stops here versus keeps compounding. If a seed phrase, private key, or wallet-connect session was exposed, assume every asset reachable by that key is at risk until proven otherwise — don't wait to confirm the scam is "real" before acting. Prioritize in this order: disconnect the compromised device or browser tab from the malicious site, end any wallet connection to it, and stop replying to the attacker, since continued contact is often used to extract more information or stall you while remaining balances are drained.
Practical checklist
- Close the browser tab or app that triggered the compromise; don't submit any further transactions from it.
- Disconnect the affected wallet from WalletConnect or dApp sessions across every site it's paired with.
- If a seed phrase or private key was typed into a phishing site, treat that wallet as permanently compromised.
- Note the exact time the compromise was discovered; you'll need it for every report filed afterward.
- Do not respond further to the attacker, even to negotiate or ask for money back.
Common mistake
The common mistake in the first 15 minutes is spending them trying to understand exactly how the attacker got in. Diagnosing the exact phishing vector can wait; every extra minute spent investigating is a minute a still-connected approval or session can be used to drain additional funds.
Protect Unaffected Assets
Before moving anything, confirm the device you're using now is not the compromised one — malware or a malicious browser extension on the original device can capture a new seed phrase just as easily as the old one. Generate a brand-new wallet on a clean device, then transfer any surviving assets from wallets that were never connected to the incident, using addresses you type or scan fresh rather than a copied link from chat history or email.
Practical checklist
- Confirm the device and browser you're using now were never exposed to the phishing site or malicious download.
- Generate a new wallet with a freshly created seed phrase — never reuse or "recover" the compromised one.
- Move funds only from wallets that were not connected to the malicious site or contract.
- Double-check the destination address character-by-character before sending; clipboard-hijacking malware can swap addresses.
- Leave any remaining dust in the compromised wallet rather than risking a transaction that could expose further secrets.
Common mistake
The common mistake is rushing to "save" remaining funds by sending them from the same compromised device, which can hand the attacker the credentials for the new wallet too if active malware or a malicious extension is still installed.
Revoke Approvals
Many crypto scams work by tricking a wallet into approving a malicious smart contract to spend tokens, rather than by taking the seed phrase directly. Use a token-approval checker for the specific network the wallet operates on — approvals are per-chain, so a contract approved on one network won't show up when checking another — and revoke anything unrecognized or unlimited in scope, not just the approval tied to this incident.
Auditing approvals before there's an incident
Approval reviews are usually treated as something to do only after a compromise, but the same check on a routine schedule closes off an entire category of scam before it starts. Every dApp connection, NFT mint, or DeFi deposit that ever asked for token spending permission leaves a standing approval behind, and most wallets never surface those permissions unless someone goes looking. The distinction that matters most is unlimited versus capped allowances — many dApps request approval for an effectively infinite amount rather than the specific amount needed for that one interaction, and an unlimited approval to an abandoned or since-compromised contract is a standing liability with no expiration date. Reviewing and revoking these quarterly, independent of whether anything has gone wrong, is one of the few genuinely preventative habits in crypto security.
- Set a recurring reminder — quarterly is a reasonable cadence — to run an approval checker across every wallet and network in use.
- Prioritize revoking unlimited approvals over capped ones; an unlimited approval to an inactive contract has no upside left.
- Treat a surprise approval that wasn't knowingly granted as a signal worth investigating, separate from any active incident.
Practical checklist
- Check approvals separately on every network the wallet has ever used, not just the one the scam happened on.
- Revoke the specific malicious contract's approval first, then review the full list for anything unfamiliar.
- Confirm each revocation transaction on-chain before considering the wallet safe again.
- Budget for gas fees on revocation transactions — the attacker's approval doesn't disappear on its own.
- Repeat this check periodically; an old, forgotten approval can still be exploited later.
Common mistake
The common mistake is revoking only the one approval tied to the immediate incident and assuming the wallet is now safe, while other unrelated approvals granted months earlier stay active and exploitable.
Contact Platforms
Contact any exchange or custodian the stolen funds passed through, or that the compromised wallet is linked to, as soon as possible — some exchanges can freeze funds that land in an account before they're withdrawn or converted, but only within a narrow window. Lead with the transaction hash, sending and receiving addresses, and the approximate time of the transfer rather than a general description; support teams can act faster on specific identifiers than on a narrative.
Practical checklist
- Identify which exchange or platform, if any, the stolen funds moved to, using a block explorer if you don't recognize the destination.
- Open a fraud or security report with that platform's dedicated channel, not general customer support.
- Include the transaction hash, wallet addresses, and timestamp in the first message rather than waiting to be asked.
- If your own exchange or custodian credentials may have been exposed, secure that account (password, 2FA, API keys) in the same pass.
- Ask each platform directly whether a freeze is possible and what evidence they need to act on it.
Common mistake
The common mistake is contacting only the platform where the theft occurred and skipping the destination platform the funds moved to, which is often the only party with any actual ability to freeze or flag them.
Preserve Evidence
Evidence collected in the first day is far more complete than what you'll be able to reconstruct later — phishing sites get taken down, chat histories get deleted, and exact wording fades from memory. Capture full-page screenshots, not just crops, of the malicious site, wallet transaction confirmations, and any attacker messages, and export the raw transaction data from a block explorer rather than relying on a wallet app's summary view.
Organizing evidence so it holds up across multiple reports
The same evidence typically gets submitted to several recipients over the following weeks — a police report, an exchange fraud team, possibly a tax preparer — and each asks for it differently. Organize the raw material once into a single folder, with unedited originals kept separate from any cropped or annotated copies made for readability; some intake forms explicitly ask for unedited files because metadata can matter to their verification process. It's also worth keeping a dated log of every report filed, since the same evidence often needs resubmitting weeks later.
- Keep one folder per incident, with unedited originals separate from cropped or annotated copies made for readability.
- Export transaction data directly from a block explorer as a file or screenshot, rather than only recording the numbers by hand.
- Log every report filed — where, when, and any reference number returned — in the same folder as the evidence itself.
Practical checklist
- Screenshot the phishing site or malicious app, including its URL bar, before it's taken offline.
- Save every transaction hash involved, plus the block explorer link, not just the amounts.
- Save or screenshot the full conversation with the attacker, including usernames, handles, or contact details.
- Record the exact date and time, with timezone, the funds left your control.
- Keep the original files rather than only edited or cropped versions — some reports require unmodified evidence.
Common mistake
The common mistake is paraphrasing what happened from memory a few days later instead of preserving the original screenshots and transaction data, which weakens every report filed afterward and can't be reconstructed once a phishing site goes offline.
Report the Incident
Filing a report rarely returns funds directly, but it feeds databases that exchanges and investigators use to flag addresses and connect related cases — a report that seems to go nowhere can still matter months later if the same address resurfaces elsewhere. In the US this generally means a report to the FBI's Internet Crime Complaint Center (IC3) and, for larger losses, a local police report that some platforms require before they'll act.
What law enforcement and exchange fraud teams actually need
Reports that move fastest lead with structured identifiers instead of a narrative account of what happened. An intake officer or fraud analyst working through a queue of cases can act on a transaction hash, a pair of wallet addresses, and a timestamp far more quickly than on a paragraph describing the scam's backstory — the narrative still matters, but it belongs after the identifiers, not instead of them. Concretely, that means having the transaction hash and a block explorer link ready before starting the report; the sending and receiving addresses written out in full rather than truncated; the exact date and time with timezone, since blockchain timestamps are typically UTC; and the USD (or local currency) value of the loss at the time it occurred. A short, factual description of the scam mechanism — phishing site impersonating a known platform, fake customer support, a malicious airdrop — helps investigators recognize a pattern faster than a blow-by-blow account of the conversation that led up to it.
- Have the transaction hash and block explorer link ready before starting any report, not gathered partway through.
- Write out full wallet addresses (sender and receiver) rather than truncated or partial versions.
- State the USD or local-currency value of the loss at the time of the incident, since most forms ask for it directly.
Practical checklist
- File a report with your national cybercrime or fraud-reporting authority using the evidence already collected.
- File a local police report if the loss is significant — some exchanges and insurers require a police report number.
- Report the phishing site or malicious contract to the relevant platform, browser vendor, or blockchain explorer's scam-flagging tool.
- Report the incident to the exchange or wallet provider's own fraud team, separate from the destination-platform contact made earlier.
- Keep every report's reference number; a platform may later ask for proof the incident was reported.
Common mistake
The common mistake is skipping the report because the loss feels too small or recovery feels unlikely — reports are cumulative evidence, and an address linked to dozens of small reports is far more likely to get flagged than one linked to none.
Set Realistic Expectations
Blockchain transactions are designed to be irreversible — there is no equivalent of a card-network chargeback, and no company, including Swoopr, can reach into a wallet or contract and pull funds back. The realistic paths to recovery are narrow: an exchange freezing funds before withdrawal, a law-enforcement seizure following an investigation, or, rarely, a smart-contract exploit where the protocol itself can intervene. Most scam losses are never recovered, and that outcome doesn't mean the earlier steps were wasted effort.
Practical checklist
- Confirm whether the stolen funds are still sitting in an identifiable wallet or have already moved through a mixer or been swapped — this materially changes the odds.
- Ask each platform contacted whether a freeze occurred, rather than assuming silence means no action was taken.
- Track the case reference numbers from every report in one place so you can follow up without repeating the whole story each time.
- Set a realistic timeline with yourself; meaningful updates, if any, typically take weeks to months, not days.
- Move forward with securing remaining accounts and assets rather than pausing everything else to wait on an outcome.
Common mistake
The common mistake is treating "recovery is possible" as "recovery is likely" and delaying other steps — securing remaining accounts, revoking approvals, reporting to platforms — while waiting on a resolution that may never come.
Avoid Secondary Scams
Being the victim of a scam makes someone a target for a second one — "recovery agents" and "blockchain investigators" who contact victims directly, often within days of a loss becoming visible on-chain or after a public report, are overwhelmingly fraudulent. No legitimate recovery process requires an upfront fee, a seed phrase, or remote access to a device, and no legitimate law-enforcement or exchange contact reaches out first through social media or a comment on a forum post.
Practical checklist
- Treat any unsolicited message offering to recover funds — especially one that found you rather than the other way around — as a scam by default.
- Never provide a seed phrase, private key, or remote-desktop access to anyone claiming they need it to "trace" or "recover" funds.
- Refuse any request for an upfront fee, gas payment, or "unlocking" payment to release recovered funds.
- Verify a recovery contact's identity independently, through an official channel, before engaging further.
- Report the secondary scam attempt itself, the same way the original incident was reported.
Common mistake
The common mistake is that someone already stressed about losing money is primed to accept an offer that demands acting fast and paying a fee "to unlock the recovery" — that urgency-plus-fee combination is the reliable tell of a fraudulent recovery scheme, not a sign it's legitimate.
Worked Decision Example
Hypothetical example — for education only.
Assume a reader controls three wallets and discovers Wallet A was compromised through a phishing site that captured its seed phrase.
Situation
- Wallet A (compromised): assorted tokens, seed phrase exposed.
- Wallet B (unaffected): never interacted with the phishing site.
- Wallet C (unaffected): connected to the same phishing site via WalletConnect, but its seed phrase was not exposed.
Reasoning
Wallet A's seed phrase is exposed, so any asset still sitting in it should be assumed reachable by the attacker at any moment — moving what's left is urgent, but only from a known-clean device. Wallet C's seed phrase was never exposed; its risk is a malicious contract approval, not a compromised key, so the priority there is revoking the approval, not migrating to a new wallet. Wallet B was never connected to the incident at all and needs no action beyond normal security hygiene.
Resulting priority order
- Revoke Wallet C's approval to the malicious contract — lowest effort, closes an active risk.
- Move any remaining balance out of Wallet A from a known-clean device — highest urgency, the seed phrase is burned.
- Leave Wallet B alone; monitor it as part of normal account hygiene.
The example shows why "protect unaffected assets" and "revoke approvals" are treated as parallel first steps rather than a single instruction — the correct action depends on which failure mode, an exposed key or a malicious approval, applies to each wallet.
Misconceptions Versus Reality
| Misconception | Reality |
|---|---|
| A paid "recovery service" can reliably get stolen crypto back | Nearly all unsolicited recovery services are secondary scams; legitimate recovery happens through exchange freezes or law enforcement, not a paid third party |
| Reporting to police is pointless because crypto is anonymous | Reports are cumulative evidence used to flag addresses and connect cases; many transactions are traceable on a public blockchain even when identities aren't obvious |
| If the transaction already confirmed, nothing more can be done | Confirmed transactions can't be reversed, but funds sitting in an identifiable destination wallet can sometimes still be frozen before they're moved again |
| Only large losses are worth reporting | Small reports still contribute to the pattern data that gets an address or scam operation flagged |
| Revoking one malicious approval makes the wallet safe again | Other unrelated approvals granted earlier can remain active and exploitable; a full review across every network is needed |
| A hardware wallet makes this guide unnecessary | Hardware wallets block remote seed-phrase theft, but still sign a malicious approval if the owner confirms without reading what it authorizes |
| The incident is over once the wallet is secured | Being visibly victimized can make someone a repeat target; staying alert to unsolicited "recovery" contact matters for weeks afterward, not just the first day |
Risks, Limitations, and Exceptions
- Blockchain transactions are irreversible by design; no platform, including Swoopr, can undo a confirmed transfer.
- Exchange freezes only work within a narrow window before funds are withdrawn or converted, and only if the destination platform cooperates with such requests.
- Law-enforcement investigations of crypto theft can take months and frequently close without recovering funds, especially in cross-border cases.
- Funds routed through a mixer or swapped across multiple chains become significantly harder to trace, sometimes effectively untraceable.
- Some approval-checker and "recovery" tools are themselves malicious; verify a tool's reputation before connecting a wallet to it.
- Reporting requirements and consumer-protection options vary by country and by platform.
- A wallet can be re-compromised after the initial incident if any exposed credential or approval is missed during cleanup.
- A successful exchange freeze usually still requires a subpoena or formal law-enforcement request before funds are released; an individual generally can't obtain that release alone.
- Reports should stick to what the evidence supports; exaggerating the loss amount or the certainty of who was responsible can create problems later.
- None of the steps in this guide guarantee a favorable outcome; they reduce further loss and preserve the best realistic chance of recovery.
Practical Implementation Checklist
- Disconnect the compromised device or wallet session immediately.
- Move any funds still reachable by the compromised key to a new wallet from a clean device.
- Revoke malicious and unfamiliar contract approvals across every network the wallet has used.
- Secure email, exchange, and any other accounts that share credentials with the compromised wallet.
- Preserve screenshots, transaction hashes, and attacker communications before they disappear.
- Identify the destination platform the funds moved to, if any, and contact its fraud team.
- File reports with the relevant cybercrime authority and local police.
- Report the phishing site or malicious contract so it can be flagged for others.
- Treat any unsolicited recovery offer as a scam and verify independently before engaging with one.
- Set a realistic timeline for any follow-up and continue securing unaffected assets in the meantime.
Tool Opportunity
A dedicated Swoopr tool should convert this framework into a guided incident-response workflow.
Recommended inputs: which wallets and accounts were affected, whether a seed phrase or only an approval was exposed, transaction hashes, the platform funds moved to if known, and the date and time discovered.
Expected outputs: a prioritized action checklist (contain, protect, revoke, report), a pre-filled evidence summary formatted for platform and law-enforcement reports, and links to the relevant per-network approval checkers.
Validation requirements: never claim a transaction can be reversed, never recommend a named third-party recovery service, distinguish confirmed on-chain data from user-supplied claims, and flag unsolicited recovery contacts as high-risk by default.
Frequently Asked Questions
What should a beginner understand about what to do after a crypto scam?
Speed matters more than completeness in the first hour: securing what wasn't taken — unaffected wallets, connected accounts, remaining balances — comes before documenting exactly how the scam happened. A beginner's biggest risk is freezing up trying to understand the attack instead of containing it; the order in this guide (contain, protect, revoke, document, report) works even without a full picture of what went wrong.
What are the largest risks after a crypto scam?
The two largest risks are continued exposure — an active malicious approval or a compromised seed phrase left unaddressed while attention shifts to reporting — and secondary scams from people posing as recovery agents who contact victims directly. Both are more damaging than the original incident because they're preventable and often overlooked while attention is on documentation.
Which detail matters most when deciding what to do first?
Whether a seed phrase or private key was exposed versus only a contract approval determines almost everything that follows: an exposed key means the wallet is permanently compromised and should be abandoned, while an exposed approval means the wallet can stay in use once the approval is revoked. Getting this distinction right early avoids overreacting to a wallet that's actually fine or underreacting by continuing to use a burned one.
Is this a process to repeat, like reviewing a portfolio?
This isn't a recurring review the way a portfolio strategy is — it's a one-time sequence to work through immediately after an incident. The one habit worth repeating afterward is periodically checking token approvals across all wallets and networks, since a forgotten approval from an unrelated incident can resurface as a new compromise later.
Which Swoopr tool supports this process?
A planned incident-response workflow tool is intended to turn this page's checklist into a guided process — capturing the exposure type, generating a pre-filled evidence summary for reports, and surfacing the right per-network approval checkers, rather than requiring the reader to reconstruct each step manually while under stress.
Does owning a hardware wallet make this guide unnecessary?
No. A hardware wallet substantially reduces the risk of a stolen seed phrase, since private keys never leave the device, but it doesn't prevent a malicious approval — the device still signs whatever transaction the owner confirms, and a rushed or unread confirmation can approve a draining contract just as easily as a software wallet can. The revoke-approvals and audit-approvals steps apply regardless of wallet type; only the seed-phrase steps are specific to software or custodial wallets.
Conclusion
Disconnect from suspicious sites, stop communicating with the attacker, secure email and exchange accounts, and record transaction identifiers. Use this page as part of the larger Swoopr learning architecture. Move to the parent hub when broader orientation is needed and to a supporting guide or tool when a specific calculation, comparison, or workflow is required.
Related Reading
- Crypto Security and Scam Center — the parent hub for prevention and incident-response guidance.
- Common crypto scam types — how the phishing sites, fake support, and malicious contracts behind most incidents actually work.
- Wallet security score — check remaining wallets and accounts for the same weaknesses before they're exploited.
- Contact Swoopr — for account-related questions on your own Swoopr login; Swoopr cannot recover funds from an external wallet or exchange.