Home  ›  Guides  ›  Wallet Compromised? What to Do Next and How to Protect What’s Left
Simply Blockchain Guide

Wallet Compromised? What to Do Next and How to Protect What’s Left

Updated 31/08/2026 • Simply Blockchain
Crypto wallet compromised guide showing what to do next to protect your funds

Quick answer: what should you do if your crypto wallet is compromised?

Crypto wallet compromised? Acting quickly can make a major difference. This guide explains how to assess what happened, protect any remaining funds, revoke dangerous permissions and move safely to a fresh wallet.

If you believe you have a compromised crypto wallet, stop using suspicious websites or software, work out whether the problem is a malicious approval or exposed recovery credentials, and protect any remaining assets as quickly and carefully as you can. If your seed phrase or private key may be exposed, create a fresh wallet with new recovery credentials and move the assets you still control.

Do not waste time changing only the wallet app password if the underlying seed phrase or private key has been stolen. A new local password does not invalidate a key that an attacker can import elsewhere.

If you are currently watching unauthorised transactions happen, focus first on preventing additional loss. Investigation and reporting come after the immediate containment steps.

First: identify what “compromised” means

Not every wallet security incident has the same cause. Your response depends on what the attacker may have gained.

Possible seed phrase or private key exposure

This is the most serious category because the attacker may have direct signing control over the account. Examples include typing a seed phrase into a phishing site, storing it in compromised cloud storage or exposing a raw private key to malware.

Malicious token approval

You may have signed an allowance that lets a specific contract move certain tokens. In this case the underlying private key may still be secret, but the approval itself creates risk.

Malicious transaction or signature

You may have authorised a one-off transfer, permit, NFT operator permission or other smart-contract action.

Compromised device or browser

Malware, a fake wallet extension or remote-access software can affect more than one account. Do not assume moving funds from one browser wallet to another wallet on the same infected device solves the problem.

Signs your wallet may be compromised

  • outgoing transactions you do not recognise;
  • tokens or NFTs disappearing unexpectedly;
  • approvals to unknown spenders;
  • security alerts after using a suspicious site;
  • a seed phrase or private key was entered somewhere it should not have been;
  • a fake wallet extension or suspicious program was installed;
  • remote-access software was used during a support conversation;
  • multiple transactions occur soon after funds enter the wallet.

Remember that a missing token balance can also have innocent causes such as being on the wrong network or hiding the asset. Check the blockchain history before assuming theft.

If you discover your crypto wallet compromised after connecting to an unfamiliar website, disconnecting alone may not be enough.

Step 1: stop interacting with the suspected source

Close the suspicious site and do not sign further requests. If somebody is messaging you as “support”, stop the conversation until you independently verify the provider’s official support channel.

Do not follow recovery links sent by strangers. Scam victims are frequently targeted again by fake recovery services promising to reverse blockchain transactions.

Step 2: use a trusted device

If malware or a fake extension may be involved, use a different trusted device for emergency account actions where possible. Creating a fresh wallet on the same compromised environment can expose the new recovery phrase immediately.

Update the operating system, remove suspicious extensions or software and run appropriate security scans before trusting the original device again.

Step 3: create a genuinely fresh wallet when credentials are exposed

If the seed phrase or private key may have been copied, create a new wallet with a new recovery phrase. Do not simply import the compromised phrase into another wallet application and call it secure.

Record the new recovery information safely and keep it separate from the method that exposed the old one.

MetaMask’s account migration guide specifically recommends moving assets to a brand-new wallet derived from a fresh Secret Recovery Phrase when compromise or unauthorised transactions are suspected.

Step 4: prioritise the assets you still control

List what remains before moving things randomly. Depending on the wallet, you may hold:

  • native assets such as ETH;
  • ERC-20 or other fungible tokens;
  • NFTs;
  • liquidity positions;
  • staked assets;
  • claimable rewards;
  • smart-contract ownership roles.

High-value liquid assets are often the first priority because they are easiest for an attacker to transfer too. Complex DeFi positions may require additional transactions and gas.

Step 5: make sure you have gas for emergency transactions

Moving assets and revoking permissions requires network fees. A compromised wallet with no native gas token can be difficult to act from.

Be cautious when adding gas to an account that appears to be actively monitored by an attacker. Automated malicious systems may immediately sweep new funds. If you are dealing with a sophisticated active compromise, consider seeking qualified incident-response help rather than repeatedly funding the affected address.

Step 6: revoke suspicious approvals where appropriate

If the incident appears to involve a token allowance rather than leaked recovery credentials, inspect active approvals using a trusted approval checker and revoke permissions you do not recognise or no longer need.

MetaMask’s approval revocation guide explains that revoking is an on-chain action and is different from simply disconnecting a dapp.

If the private key itself is exposed, revoking approvals is not enough. The attacker can still sign new transactions directly.

Step 7: secure connected accounts

Wallet incidents can be part of a larger compromise. Review the accounts that may have been involved:

  • primary email;
  • crypto exchanges;
  • password manager;
  • Apple, Google or Microsoft account;
  • Telegram, Discord and social media;
  • mobile carrier account;
  • cloud storage.

Change reused passwords, terminate unknown sessions and strengthen two-factor authentication. Where available, use passkeys, security keys or authenticator apps rather than relying only on SMS.

Step 8: investigate how the compromise happened

Once the immediate funds are protected, reconstruct the sequence of events. Look at:

  • browser history;
  • recent wallet connections;
  • token approvals;
  • transaction and signature history;
  • new browser extensions;
  • downloaded applications;
  • support conversations;
  • emails and social messages containing links.

MetaMask’s unauthorised transaction guidance lists common causes including malware, phishing websites, exposed recovery information, malicious token permissions and fake wallet extensions.

Can stolen crypto transactions be reversed?

Confirmed blockchain transfers generally cannot be reversed by a wallet provider in the way a card payment might be charged back. Self-custody wallet providers do not have central control over your account balance.

This is why fast containment matters. Be very cautious with anyone claiming they can “reverse the blockchain” for an upfront fee or by asking for your recovery phrase.

What if only one token was stolen?

If one approved token was taken while other assets remain untouched, the cause may be a token-specific allowance. Inspect approvals and transaction history before deciding whether the whole wallet credential set is exposed.

However, do not assume the wallet is safe solely because only one token moved. An attacker may be selective or waiting for additional funds.

What if funds disappear every time you add gas?

This can indicate that the account is actively monitored or controlled by automated malicious software. Repeatedly adding gas may simply provide more funds for the attacker to take.

At that point, avoid improvising complicated rescue transactions unless you understand the risk. Specialist recovery techniques exist for some circumstances, but they are highly situation-specific and can themselves attract scammers.

What if an NFT or DeFi position is stuck?

Some assets cannot be moved with a simple token transfer. Staking contracts, vesting positions, liquidity pools and smart-contract ownership may require specific exit or migration steps.

Use only the official protocol documentation from a trusted device. If the old wallet controls a critical contract role, investigate whether ownership can be transferred to the new address.

Do not reuse the compromised recovery phrase

Once a seed phrase is believed to be exposed, treat every account derived from it as potentially compromised. Creating another account inside the same recovery phrase does not create a new security boundary.

A fresh wallet means a genuinely fresh recovery phrase generated securely.

Having your crypto wallet compromised does not necessarily mean your recovery phrase has been exposed.

Reporting a crypto scam in the UK

If the incident involved phishing or fraud, keep transaction hashes, wallet addresses, screenshots, messages and relevant URLs. Do not delete evidence simply because you have moved funds.

The NCSC provides guidance for people who have shared sensitive information through phishing and a service for reporting suspicious websites. If money has been lost through fraud in England, Wales or Northern Ireland, current NCSC guidance directs victims to Report Fraud; in Scotland, contact Police Scotland.

See the NCSC phishing response guidance for the latest UK instructions.

How to reduce the chance of another compromise

  • keep seed phrases and private keys offline where practical;
  • use a hardware wallet for higher-value long-term funds;
  • separate long-term storage from experimental dapp activity;
  • verify websites and contracts before connecting;
  • read wallet prompts before signing;
  • limit token approvals when possible;
  • review approvals periodically;
  • keep devices and wallet software updated;
  • use strong account security on email and exchanges.

Our Crypto Security Guide, scam prevention guide and hardware wallet setup guide cover these preventative layers in more detail.

Compromised wallet response checklist

  • I stopped signing requests from the suspicious site or person.
  • I identified whether this is likely a key compromise, malicious approval or isolated transaction.
  • I moved to a trusted device if the original device may be infected.
  • I created a fresh wallet with a new recovery phrase if credentials were exposed.
  • I prioritised the remaining assets and accounted for gas.
  • I reviewed and revoked suspicious approvals where relevant.
  • I secured email, exchange and cloud accounts connected to the incident.
  • I preserved transaction hashes, URLs and messages as evidence.
  • I stopped using the old recovery phrase when it was potentially exposed.

Frequently asked questions

Should I delete the compromised wallet?

Removing the wallet app does not change blockchain permissions or invalidate an exposed private key. First secure the assets and credentials, then retire the compromised wallet from future use.

Will changing my MetaMask password stop an attacker?

Not if the attacker has the seed phrase or private key. A local password and the underlying blockchain credentials are different.

Can revoking approvals make the wallet safe again?

If the only issue was a specific malicious allowance, revoking it may remove that permission. If recovery credentials are exposed, migrate to fresh keys.

Should I pay a recovery service?

Be extremely cautious. Scam victims are commonly targeted by fake recovery services. Never give a recovery service your seed phrase or private key.

Can a wallet provider freeze the attacker’s address?

Self-custody wallet providers generally cannot freeze arbitrary blockchain addresses or reverse confirmed transfers. Centralised services may have separate controls if funds enter their platforms.

Final thoughts

A compromised wallet is stressful, but the response becomes clearer when you separate containment from investigation. Stop the suspicious interaction, protect what remains, move to fresh credentials when keys are exposed, then secure the wider accounts and work out how the incident happened.

The best time to build an incident plan is before you need it. Know where your backups are, know how to create a fresh wallet and know which official support links you would use during an emergency.

If you find your crypto wallet compromised, prioritise protecting remaining funds before investigating what caused the incident.

This guide is educational and cannot account for every blockchain, smart contract or active theft scenario. For significant losses or complex on-chain positions, consider qualified professional incident-response advice and be alert to recovery scams.

Related Crypto Security Guides

Continue through the Simply Blockchain security library with the guides most relevant to this topic.

Ready to keep learning?

Explore more written guides, tools and structured learning from Simply Blockchain.

Explore More Guides