How to Recover From a Hacked Crypto Wallet
Step-by-step actions to take immediately after a crypto wallet hack, from moving remaining funds to revoking approvals and rebuilding securely.
Recovering from a hacked crypto wallet means acting immediately to move any remaining, uncompromised funds to a new secure wallet, revoke any malicious token approvals, and identify how the compromise happened so it isn't repeated — since a stolen seed phrase or private key cannot be "changed" the way a password can.
Unlike a hacked email or bank account, there is no customer service line that can freeze or reverse a crypto wallet compromise. The moment you suspect your wallet's private key or seed phrase has been exposed, every asset controlled by that key should be considered at risk, and speed matters more than in almost any other kind of account recovery.
Immediate steps in the first few minutes
- Move remaining funds first, investigate later. If any assets remain in the compromised wallet, transfer them immediately to a brand-new wallet generated on a device you trust, using a freshly created seed phrase. Do not reuse the old seed phrase or private key in any form — if it was exposed once, it should be treated as permanently unsafe.
- Revoke active token approvals. Many DeFi hacks don't drain funds all at once — they rely on a standing approval that lets the attacker pull funds later, sometimes repeatedly, including newly deposited assets. Use an approval checker tool to review and revoke any approval you don't explicitly recognize and trust, on every chain the wallet has interacted with.
- Disconnect the wallet from all connected sites. Many wallets and browser extensions retain active connections to previously used dApps; disconnecting each one reduces the chance of a further automated drain through an existing session.
- Check for malware if the compromise may involve a device breach, not just an online phishing incident. Run a full anti-malware scan, and consider that any credentials typed or stored on that device — including exchange logins — may also be compromised.
Understanding what actually happened
Before rebuilding, it helps to determine the likely cause, since the fix differs:
| Likely cause | Typical evidence | Follow-up action |
|---|---|---|
| Phishing site or fake claim | Recently signed an unfamiliar transaction or connected wallet to a new site | Revoke approvals; review common DeFi scams patterns |
| Seed phrase entered somewhere | Recall typing seed phrase into any app, site, or "verification" form | Treat wallet as fully compromised; migrate everything |
| Clipboard hijacking malware | Pasted addresses don't match copied ones | Full device malware scan; new wallet on clean device |
| Malicious browser extension | Recently installed an unfamiliar or unofficial extension | Remove extension; scan device; new wallet |
| Exchange account breach | Unauthorized withdrawal from a custodial account | Contact exchange support directly, change password, enable stronger 2FA |
Rebuilding securely
Generate the new wallet's seed phrase on a device you're confident is clean — ideally a hardware wallet, which generates and stores keys in an isolated environment separate from your general-purpose computer or phone. Write the new seed phrase down physically and store it offline; never store it as a photo, cloud note, or password manager entry synced online, since digital storage of a seed phrase reintroduces the exact exposure risk that likely caused the original hack. Our DeFi wallet security guide covers secure storage practices in more depth.
Going forward, consider separating funds across multiple wallets by purpose — a small "hot" wallet for active DeFi use connected to various sites, and a separate, rarely connected wallet for long-term holdings. This limits how much is exposed if a hot wallet is compromised again in the future.
Should you try to trace or report the theft?
Reporting the incident can occasionally help, particularly if funds moved through a centralized exchange where investigators might freeze them, though outcomes vary widely and most reports do not result in fund recovery. See our guides on reporting a crypto scam and tracking stolen funds on-chain for realistic next steps, and read can stolen crypto be recovered for honest expectations about recovery odds. Be extremely cautious of anyone contacting you afterward offering paid "recovery services" — this is a well-documented secondary scam covered in our crypto recovery scams article.
Bottom line
There is no way to "reset" a compromised private key — the only real recovery path is moving remaining funds out immediately, revoking lingering approvals, and building a new wallet with better isolation and storage habits than before. Acting within minutes, not hours, meaningfully limits the damage, and understanding how the compromise happened is essential to avoiding a repeat with your new wallet.
Related articles
This article is for educational purposes only and is not financial advice. DeFi involves significant risk, including total loss of funds. Always do your own research.