Safely Recover Funds from Compromised Wallet: Step-by-Step
Discovering that your crypto wallet has been compromised is one of the most stressful events in decentralized finance. Every second counts, but panic leads to costly mistakes. This guide provides a clear, step-by-step emergency protocol to safely recover funds from a compromised wallet — moving remaining assets, revoking dangerous approvals, and building a new secure vault. You will learn the exact sequence of actions to minimize losses and regain control, even if you have never dealt with a hack before.
We assume your private keys or seed phrase have been exposed, allowing an attacker to drain any funds they can reach. However, you may still have assets in accounts, layer-2 networks, or staked positions that the attacker hasn't yet accessed. By following this guide quickly and methodically, you can salvage what remains — and prevent future thefts by resetting your entire security posture.
- Act fast but calmly: stop using the compromised wallet immediately, disconnect from internet/malware, and create a clean wallet first.
- Move all freely transferable assets (coins and tokens) to the new wallet, leaving only enough gas for one final transaction.
- Revoke all smart contract approvals using Revoke.cash or Etherscan; this prevents attackers from draining leftover or future deposits.
- Reset all linked passwords, API keys, and 2FA tokens for exchange, email, and dApp accounts to sever all possible access paths.
- Analyze the attack vector to patch the weakness (phishing, malware, seed exposure) and adopt hardware wallet + multisig for long-term storage.
- Never reuse the compromised wallet or its seed phrase for any purpose going forward — treat it as permanently burnt.
1. Immediate Triage: Stop, Disconnect, and Assess
Do not use your compromised wallet for anything yet. The attacker may have active sessions or scripts monitoring your every move. First, physically disconnect your internet if you suspect malware (then use a clean device). Otherwise, close all dApp tabs immediately. Open a fresh browser window or use a separate computer or mobile device you know is clean. Do not interact with any DeFi platform, approve any transaction, or even check your balance through the compromised wallet.
List all the assets and positions you had across all networks (Ethereum, Polygon, Arbitrum, etc.). Write them down manually. Assess: Which assets are in the wallet itself (easily stolen), which are staked or in liquidity pools (may need a transaction to withdraw), and which are idle in the wallet but have malicious token approvals (the attacker can sweep them using the approved contract). Understand that a compromised key works on every chain — an attacker can move assets from any chain where your address holds a balance and has gas for fees, whether or not you have ever used that chain before. Do not assume dormant chains are safe; the only practical friction is that a token balance with no native gas cannot be moved until someone (you or the attacker) funds gas. Prioritize your highest-value, most liquid holdings across all chains.
Your goal now: do not trigger any response from the attacker. Do not send messages to the address; do not try to argue or negotiate. Focus purely on moving what is salvageable to a brand new, uncompromised wallet.
2. Create a New, Isolated Wallet on a Clean Device
Before you do anything else, create a new wallet that is 100% disconnected from the compromised one. Use a hardware wallet if you own one — even a cheap one is better than a software wallet in an emergency. If not, generate a new software wallet on a trusted device that has never touched the compromised seed phrase. Choose a reputable wallet like MetaMask, Rabby, or Trust Wallet (consider a fresh browser profile or a dedicated computer). Write down the new seed phrase offline on paper only. No photos, no cloud, no typed files.
Use a strong, randomly generated wallet (do not use a “vanity” address you might have used elsewhere). Ensure this new wallet has a small amount of native gas token (ETH, MATIC, etc.) to cover transaction fees — you can buy a tiny amount from a centralized exchange and send to this new address. Do not connect this new wallet to any dApp until you have successfully rescued your assets. It is a temporary vault for the liquidation phase.
Once the new wallet is ready and verified (you can send a test transaction to yourself from an exchange), you now have a safe destination to move your remaining funds.
3. Transfer Remaining Assets – Fast, But Deliberately
Now, carefully transfer every asset you can from the compromised wallet to your new one. Speed is important, but errors — like sending to the wrong address — are irreversible. Work network by network:
- Native coins: Send ETH, BNB, MATIC etc. first. Leave a little gas for further transactions (even after compromise, you need gas to move the rest). Estimate: if you have 5 ETH, send 4.9 and keep 0.1 ETH for fees. You can send the remainder in a final cleanup transaction.
- Tokens (ERC-20, BEP-20, etc.): Use the same procedure. Do not batch send; single token transactions per network to keep it simple. If you have multiple tokens on the same network, use the wallet's “send” feature for each.
- Staked / LP tokens: Unless you have a very specific reason, do not try to unstake or withdraw liquidity now. Attacker may be monitoring for withdrawal transactions, which require approvals. If you must unstake, you may need to first revoke dangerous approvals (next section). Better to leave staked assets if they are time-locked; some vaults can be migrated via governance — but that is advanced. For this emergency, focus only on freely transferable assets.
Triple-check each address. Consider using a test transaction with a tiny amount. After sending, verify receipt on a block explorer. Once all free assets are moved, you can breathe a little.
4. Revoke All Smart Contract Approvals (Token Allowances)
Even after moving your assets, your compromised wallet may still have active approvals that allow attackers to sweep tokens from other networks or from accounts that you might later deposit into. More critically, if you left any token in the wallet (e.g., a small balance or a forgotten airdrop), an approval could let the attacker drain it without your seed phrase. You must remove these approvals.
Use a revoke tool like Revoke.cash or Etherscan's token approval checker. Connect your compromised wallet (do not connect your new wallet to any dApp yet). The tool will list all contracts that have permission to spend your tokens. For each one, you have two options:
- Revoke (set to 0) – removes the approval. Safe, recommended for all unknown or unused contracts.
- Set to a specific amount – only do this if you trust the contract and intend to use it again (unlikely in an emergency). For almost all approvals, choose Revoke.
If you had any dApps connected (e.g., Uniswap, OpenSea), disconnect those sessions from within the compromised wallet’s settings (e.g., in MetaMask: Settings > Connected Sites > click trash icon). This prevents the dApp from initiating future transactions without explicit user approval.
5. Rotate All Linked Credentials and Reset 2FA
Attackers often compromise more than just your wallet seed. If your email, phone, or cloud backups are exposed, they may also have access to passwords for exchanges, dApp logins, and social accounts. Immediately change passwords for:
- Email accounts linked to the wallet (especially the one used for exchange or NFT platform registrations).
- Centralized exchange accounts – force logout all sessions, enable or reset 2FA with a new authenticator app (not SMS). Revoke API keys.
- Social media – attackers sometimes impersonate or use them to phish further.
- Any DeFi or dApp account where you connected using the compromised wallet (e.g., Magic.link, Torus, etc.). Change those login methods.
Use a password manager to generate and store new strong passwords. Ensure you have a second factor (hardware key or authenticator) on critical accounts. If you used biometric authentication elsewhere, consider re-enrolling after changing passwords.
Do not reuse any password from before the compromise. The attacker may have scraped your browser's saved passwords if they had malware access.
6. (Optional but Valuable) Analyze the Attack Vector
After the dust settles, you should understand how your wallet was compromised to prevent recurrence. Common vectors include:
- Phishing websites: Did you connect your wallet to a fake dApp? Check your browser history for suspicious URLs (e.g., uniswap-xyz.com).
- Seed phrase exposure: Did you type your seed into a website, take a photo, or store in a cloud note? Treat that environment as burned.
- Malware / keyloggers: Run a full antivirus scan on all devices that ever had the wallet installed.
- Social engineering: Were you tricked into revealing private keys via a fake support call? Report to relevant authorities (e.g., FBI IC3 for large losses).
- Browser extension compromise: Did you have any suspicious browser extensions with wallet-read permissions?
If you can identify the root cause, you can take targeted action — like switching to a hardware wallet permanently, or never using that browser again. Even if you can't, commit to a clean slate.
7. Long-Term Prevention: Build Your Fortress
Now that you have a new wallet and have evacuated the compromised one, it's time to secure the future. Follow these best practices religiously:
- Hardware wallet mandatory: For any meaningful amount (e.g., above what you are willing to lose), use a Ledger, Trezor, or similar. Seed phrase generated offline, never touches a computer except via signed transactions.
- Multiple wallets: Keep your 'vault' wallet (cold storage) separate from a 'hot' wallet for daily DeFi interactions. Keep minimal funds in the hot wallet. If the hot wallet gets compromised, the vault remains safe. Wait 24 hours before moving funds to vault after a dApp interaction.
- Revoke regularly: Use tools like Revoke.cash or DeBank to review and revoke unused approvals monthly. Set reminders.
- Never connect to unknown dApps: Bookmark official URLs, use Etherscan to verify contracts, and use a secondary check (e.g., RugDoc) for new protocols.
- Simulate transactions: Before signing anything, use a transaction-simulation tool or check the transaction simulation in your wallet (e.g., MetaMask's 'Simulate' feature for some chains, or Rabby's built-in simulation).
This incident is a painful lesson — but it can be the catalyst for adopting the strictest security that protects you for years.
Frequently asked questions
Can I recover funds that have already been stolen from my compromised wallet?
Unfortunately, once funds leave your wallet to the attacker's address, recovery is extremely difficult unless you can trace to a centralized exchange (KYC) and report to law enforcement. This guide focuses on saving what you still control, not recovering lost funds.
How do I know if my wallet has been compromised?
Warning signs include unrecognized outgoing transactions, drained balances, or dApp interactions you did not initiate. If you suspect your seed phrase or private key has been exposed (e.g., entered in a phishing site, stored in a compromised cloud), assume the wallet is compromised even if nothing has been stolen yet.
Should I contact the attacker or pay a ransom to get my wallet back?
Never. Engaging with attackers validates their method and may encourage further extortion. There is no guarantee they will return anything. Focus on securing remaining assets and follow the steps here.
What if I have staked or locked tokens in the compromised wallet?
If the staking contract does not allow immediate withdrawal, you might consider contacting the protocol's support or governance to see if they can migrate your position to a new address. In many cases, you may have to wait, but do not use the compromised wallet to interact further without revoking approvals first.
Can I just create a new wallet and leave the old one alone?
No. The old wallet still has active approvals that can drain any future tokens you might accidentally send to it (e.g., airdrops). You must revoke approvals and ideally never use that address again. Also, moving your assets out is only the first step — revoking approvals is equally critical.
Related reading
Track the entities behind the concepts
DeFi Intel maps 11,000+ protocols, tokens and companies to a typed knowledge graph — with live data, incidents and regulation.