DeFi Intel

Safely Recover Funds from Compromised Wallet: Step-by-Step

Discovering that your crypto wallet has been compromised is one of the most stressful events in decentralized finance. Every second counts, but panic leads to costly mistakes. This guide provides a clear, step-by-step emergency protocol to safely recover funds from a compromised wallet — moving remaining assets, revoking dangerous approvals, and building a new secure vault. You will learn the exact sequence of actions to minimize losses and regain control, even if you have never dealt with a hack before.

We assume your private keys or seed phrase have been exposed, allowing an attacker to drain any funds they can reach. However, you may still have assets in accounts, layer-2 networks, or staked positions that the attacker hasn't yet accessed. By following this guide quickly and methodically, you can salvage what remains — and prevent future thefts by resetting your entire security posture.

Key takeaways
  • Act fast but calmly: stop using the compromised wallet immediately, disconnect from internet/malware, and create a clean wallet first.
  • Move all freely transferable assets (coins and tokens) to the new wallet, leaving only enough gas for one final transaction.
  • Revoke all smart contract approvals using Revoke.cash or Etherscan; this prevents attackers from draining leftover or future deposits.
  • Reset all linked passwords, API keys, and 2FA tokens for exchange, email, and dApp accounts to sever all possible access paths.
  • Analyze the attack vector to patch the weakness (phishing, malware, seed exposure) and adopt hardware wallet + multisig for long-term storage.
  • Never reuse the compromised wallet or its seed phrase for any purpose going forward — treat it as permanently burnt.

1. Immediate Triage: Stop, Disconnect, and Assess

Do not use your compromised wallet for anything yet. The attacker may have active sessions or scripts monitoring your every move. First, physically disconnect your internet if you suspect malware (then use a clean device). Otherwise, close all dApp tabs immediately. Open a fresh browser window or use a separate computer or mobile device you know is clean. Do not interact with any DeFi platform, approve any transaction, or even check your balance through the compromised wallet.

List all the assets and positions you had across all networks (Ethereum, Polygon, Arbitrum, etc.). Write them down manually. Assess: Which assets are in the wallet itself (easily stolen), which are staked or in liquidity pools (may need a transaction to withdraw), and which are idle in the wallet but have malicious token approvals (the attacker can sweep them using the approved contract). Understand that a compromised key works on every chain — an attacker can move assets from any chain where your address holds a balance and has gas for fees, whether or not you have ever used that chain before. Do not assume dormant chains are safe; the only practical friction is that a token balance with no native gas cannot be moved until someone (you or the attacker) funds gas. Prioritize your highest-value, most liquid holdings across all chains.

Your goal now: do not trigger any response from the attacker. Do not send messages to the address; do not try to argue or negotiate. Focus purely on moving what is salvageable to a brand new, uncompromised wallet.

2. Create a New, Isolated Wallet on a Clean Device

Before you do anything else, create a new wallet that is 100% disconnected from the compromised one. Use a hardware wallet if you own one — even a cheap one is better than a software wallet in an emergency. If not, generate a new software wallet on a trusted device that has never touched the compromised seed phrase. Choose a reputable wallet like MetaMask, Rabby, or Trust Wallet (consider a fresh browser profile or a dedicated computer). Write down the new seed phrase offline on paper only. No photos, no cloud, no typed files.

Use a strong, randomly generated wallet (do not use a “vanity” address you might have used elsewhere). Ensure this new wallet has a small amount of native gas token (ETH, MATIC, etc.) to cover transaction fees — you can buy a tiny amount from a centralized exchange and send to this new address. Do not connect this new wallet to any dApp until you have successfully rescued your assets. It is a temporary vault for the liquidation phase.

Once the new wallet is ready and verified (you can send a test transaction to yourself from an exchange), you now have a safe destination to move your remaining funds.

3. Transfer Remaining Assets – Fast, But Deliberately

Now, carefully transfer every asset you can from the compromised wallet to your new one. Speed is important, but errors — like sending to the wrong address — are irreversible. Work network by network:

Triple-check each address. Consider using a test transaction with a tiny amount. After sending, verify receipt on a block explorer. Once all free assets are moved, you can breathe a little.

4. Revoke All Smart Contract Approvals (Token Allowances)

Even after moving your assets, your compromised wallet may still have active approvals that allow attackers to sweep tokens from other networks or from accounts that you might later deposit into. More critically, if you left any token in the wallet (e.g., a small balance or a forgotten airdrop), an approval could let the attacker drain it without your seed phrase. You must remove these approvals.

Use a revoke tool like Revoke.cash or Etherscan's token approval checker. Connect your compromised wallet (do not connect your new wallet to any dApp yet). The tool will list all contracts that have permission to spend your tokens. For each one, you have two options:

Revoking costs gas, but it is essential. If you have many approvals, prioritize the ones with high allowance amounts and on networks where you still hold tokens. After revoking, you can also consider “revoke all” option if you never plan to use that wallet again. Important: after revoking, do not interact with any dApp again using that wallet.

If you had any dApps connected (e.g., Uniswap, OpenSea), disconnect those sessions from within the compromised wallet’s settings (e.g., in MetaMask: Settings > Connected Sites > click trash icon). This prevents the dApp from initiating future transactions without explicit user approval.

5. Rotate All Linked Credentials and Reset 2FA

Attackers often compromise more than just your wallet seed. If your email, phone, or cloud backups are exposed, they may also have access to passwords for exchanges, dApp logins, and social accounts. Immediately change passwords for:

Use a password manager to generate and store new strong passwords. Ensure you have a second factor (hardware key or authenticator) on critical accounts. If you used biometric authentication elsewhere, consider re-enrolling after changing passwords.

Do not reuse any password from before the compromise. The attacker may have scraped your browser's saved passwords if they had malware access.

6. (Optional but Valuable) Analyze the Attack Vector

After the dust settles, you should understand how your wallet was compromised to prevent recurrence. Common vectors include:

If you can identify the root cause, you can take targeted action — like switching to a hardware wallet permanently, or never using that browser again. Even if you can't, commit to a clean slate.

7. Long-Term Prevention: Build Your Fortress

Now that you have a new wallet and have evacuated the compromised one, it's time to secure the future. Follow these best practices religiously:

This incident is a painful lesson — but it can be the catalyst for adopting the strictest security that protects you for years.

Frequently asked questions

Can I recover funds that have already been stolen from my compromised wallet?

Unfortunately, once funds leave your wallet to the attacker's address, recovery is extremely difficult unless you can trace to a centralized exchange (KYC) and report to law enforcement. This guide focuses on saving what you still control, not recovering lost funds.

How do I know if my wallet has been compromised?

Warning signs include unrecognized outgoing transactions, drained balances, or dApp interactions you did not initiate. If you suspect your seed phrase or private key has been exposed (e.g., entered in a phishing site, stored in a compromised cloud), assume the wallet is compromised even if nothing has been stolen yet.

Should I contact the attacker or pay a ransom to get my wallet back?

Never. Engaging with attackers validates their method and may encourage further extortion. There is no guarantee they will return anything. Focus on securing remaining assets and follow the steps here.

What if I have staked or locked tokens in the compromised wallet?

If the staking contract does not allow immediate withdrawal, you might consider contacting the protocol's support or governance to see if they can migrate your position to a new address. In many cases, you may have to wait, but do not use the compromised wallet to interact further without revoking approvals first.

Can I just create a new wallet and leave the old one alone?

No. The old wallet still has active approvals that can drain any future tokens you might accidentally send to it (e.g., airdrops). You must revoke approvals and ideally never use that address again. Also, moving your assets out is only the first step — revoking approvals is equally critical.

Track the entities behind the concepts

DeFi Intel maps 11,000+ protocols, tokens and companies to a typed knowledge graph — with live data, incidents and regulation.

Entities mentioned