How to Recover Stolen Cryptocurrency: First Steps

If cryptocurrency has been taken from your wallet or exchange account, stop further access, secure accounts, notify the platform, preserve the transaction record and report the suspected crime. A confirmed blockchain transfer normally cannot be cancelled by a bank or victim. Recovery combines containment, tracing, platform action and, where justified, national legal procedures. The objective is to prevent a second loss and preserve options.

First Identify What Was Actually Stolen

“Stolen crypto” can mean an unauthorised exchange withdrawal, a wallet drained after a seed phrase was exposed, or a transfer made after an attacker controlled an email, phone or device. It can also mean social engineering that persuaded the victim to approve a transfer. A withdrawal freeze, fake dashboard balance or release-fee demand is different and should not be reported as on-chain theft without checking the facts.

Incident type Typical signs Immediate priority
Exchange or custodial account takeover Unknown login, changed security settings, new withdrawal address or unapproved withdrawal. Freeze withdrawals, terminate sessions, revoke API keys and contact the genuine security team.
Self-custody wallet compromise Assets leave after a phishing signature, malicious approval, exposed seed phrase or malware. Use a clean device, secure remaining assets and treat the old seed or key as compromised.
SIM swap or email takeover Password reset, lost mobile service, unfamiliar email rules or unrequested codes. Recover email and phone accounts, replace authentication and secure the exchange or wallet.
Induced transfer or impersonation A supposed support agent, adviser, partner or authority instructs a transfer. Stop contact, preserve the identity trail and report the payment and impersonation.
Platform restriction or fake balance A website shows profits but demands tax, insurance or verification money. Do not pay again; establish whether a real crypto balance existed.

Why the First Hours Matter

The blockchain entry is usually permanent, but surrounding evidence is fragile. A provider may flag an internal account, preserve login records or stop a pending withdrawal. A fake domain, profile, chat or payment page may disappear quickly. Early reporting reduces reconstruction from incomplete screenshots.

The Europol report on cryptocurrencies and criminal finances explains why public-ledger analysis can support tracing while cross-border structures, pseudonymous addresses and activity outside the blockchain still create investigative limits. A visible address is a lead, not automatically a person’s identity.

What to Do in the First 24 Hours

  1. Stop Communicating with the Suspected Attacker

    Do not negotiate, threaten or send a final payment. A tax, gas fee, bond, compliance deposit or “unlock” request is not proof that assets are recoverable. Save it and stop responding.

  2. Secure the Device and Primary Accounts

    From a trusted device, change the email password, terminate unknown sessions and replace compromised two-factor authentication. Contact the mobile operator if a SIM swap is possible. Do not use message links to log in.

  3. Contain a Self-Custody Wallet Compromise

    If a seed phrase or private key may have been exposed, assume all assets it controls are at risk. After checking for malware, create a new wallet with a new seed and move remaining assets. If remote access or malware is suspected, use a clean device or obtain technical help before signing anything.

  4. Freeze an Exchange or Custodial Account

    Use the provider’s genuine application or website. Request an urgent withdrawal freeze, session termination, review of the destination, preservation of access logs and a case number. Revoke API keys and unfamiliar permissions.

  5. Contact the Bank and Payment Provider

    If fiat was used, notify the card issuer, bank or payment institution immediately. Ask about recall, card-blocking, chargeback or fraud-review options. Give the payment reference, recipient, date, amount and connection to the crypto theft.

  6. Record the On-Chain Facts

    Copy the transaction hash, network, token, amount, sender, destination and confirmation status. Record UTC time and save the block-explorer page. State clearly if the transfer is still pending.

  7. Preserve the Surrounding Evidence

    Export messages and emails, save statements and exchange activity, capture the full URL and account context, and keep originals separate from working copies. Do not delete messages or suspicious files.

  8. Report to the Competent National Authority

    File a police, cybercrime or prosecutor report, normally starting with your country of residence. Include the transaction schedule and identify platforms or accounts that may hold records. Report to the platform and authority in parallel where urgent.

  9. Secure Other Services

    If the same password, email or device was used elsewhere, change those credentials and review other exchanges, payment apps and cloud accounts.

For general EU consumer steps, see the European Commission guidance on online scams which advises consumers to contact their bank, secure accounts and report the matter to the relevant authority in their country.

Evidence That Makes a Recovery Review Possible

Send a structured evidence pack rather than unexplained screenshots. Establish the access event, actual loss, asset path and parties that may still hold records or funds.

Evidence What it establishes Preservation method
Transaction details The asset movement and whether it is pending or confirmed. Record the complete hash, network, token, amount, addresses, UTC time and explorer URL.
Wallet and exchange records The link between your account and outgoing transfer. Download CSV or PDF exports, statements, withdrawal history and security notices from the genuine service.
Access and security events How the attacker may have entered the account or device. Keep login alerts, password resets, 2FA notices, provider IP or device data and SIM-swap records.
Messages and impersonation material The instructions, promises, identities and timing behind the event. Export chats; preserve usernames, phone numbers, email headers, domains, profile links and attachments.
Malicious approvals or signatures Whether a token approval or signed transaction enabled the drain. Save the transaction data and contract address; do not sign a new transaction merely to “cancel” it.
Fiat payment trail The funding leg and the recipient of any bank or card payment. Save bank statements, receipts, payment references and the recipient details visible at the time.
Reports and responses What you asked providers or authorities to do and when. Keep ticket numbers, full replies, deadlines, acknowledgements and a submission log.

Use consistent file names such as 2026-09-10_exchange-withdrawal.csv or 2026-09-10_chat-export.zip. Keep a short index explaining what each file proves. For a company, preserve contracts, invoices, authorisation records and the responsible wallet or account holder.

Prepare a Transaction and Incident Timeline

A review should not depend on a reader guessing from screenshots. Prepare one chronology with a row for every material event. Include:

  • date and time in UTC, with local time where it helps explain an account alert;
  • first contact, suspected compromise and the moment the loss was discovered;
  • network, token, amount, source address, destination address and transaction hash;
  • the account, wallet, device or payment service involved;
  • the instruction or representation that caused an approved transfer, if any;
  • the provider, police or authority contacted, the channel used and the case number; and
  • what remains uncertain, such as the identity of the recipient or whether a device was infected.

Separate facts from inferences. “The exchange history shows a withdrawal at 14:02 UTC” is a fact; “the recipient is the scammer” remains a theory until additional evidence links the address to a person or service.

What to Write to a Platform or Authority

The first notice should be short and action-oriented. A useful opening is:

“I report an unauthorised transfer or suspected crypto theft discovered on [date]. The affected account or wallet is [identifier]. Transaction details: [network, asset, amount, hash and destination]. Please freeze or flag any account under your control, preserve relevant records, confirm the case number and tell me what evidence is required.”

Attach the transaction schedule, chronology and indexed files. Avoid presenting a suspected identity as a proven criminal. Clear wording helps the provider see an identifiable transaction rather than a general complaint.

Where EU and EEA Victims Should Report

No single EU victim portal can freeze a blockchain address. Use routes, each for the part of the incident it can affect:

  • Bank, card issuer or payment institution for the fiat funding payment, card compromise or account transfer.
  • Exchange, wallet provider or other crypto-asset service provider for the account, withdrawal, deposit address or internal transfer.
  • National police, cybercrime unit or prosecutor for suspected theft, fraud, unauthorised access and identity misuse.
  • The provider’s formal complaint channel and, where appropriate, the national competent authority if a regulated provider does not handle the complaint properly.

If the provider is an EU crypto-asset service provider within MiCA, use its complaint procedure after the urgent security notice where necessary. The procedure is not a promise of reimbursement, but it creates a clearer record of the provider’s response.

Article 71 of Regulation (EU) 2023/1114 MiCA requires in-scope providers to maintain effective and transparent complaint procedures, accept complaints free of charge, investigate them in a timely and fair manner and communicate the outcome within a reasonable period. National rules and the legal entity providing the service still determine the available escalation route.

What Legitimate Recovery Work Can and Cannot Do

A credible review normally follows five stages:

  1. Containment review. Check whether a wallet, exchange, email, device or payment account remains exposed and whether a platform can act on a pending or internal transfer.
  2. Transaction mapping. Organise hashes and addresses into a documented flow. Treat bridges, decentralised applications, mixers and service labels as leads, not conclusions.
  3. Counterparty identification. Look for a custodial exchange, payment provider or company where records may connect an address to a real entity. A blockchain label alone is not proof of ownership.
  4. Legal and provider escalation. Use the evidence for preservation requests, complaints, police reporting or a civil route where jurisdiction, value and evidence justify the cost.
  5. Cost and outcome review. Keep tracing, identification, freezing and restitution separate. Reassess the likely reachable amount before paying for further work.

No legitimate professional can hack an exchange, calculate a private key from a public address, secretly reverse a confirmed transaction or guarantee seizure and return. A useful result may be a platform freeze, stronger report, service identification, civil claim or restitution. None is automatic.

When Specialist Support May Be Proportionate

Consider legal or forensic assistance when the loss is material, several countries or providers are involved, the recipient may be identifiable, a provider rejects a complete report or a deadline is approaching. A specialist can separate technical facts from legal conclusions and choose a realistic escalation route.

A Get a Free Case Assessment from P&P can be useful before extensive work. Ask for a written scope, required evidence, first deliverable, fees and the point at which further work needs approval. Treat guaranteed recovery or an unexplained “release” payment as a warning sign.

Get a Free Case Assessment

Common Mistakes After a Crypto Theft

Mistake Better approach
Sending a second payment to recover the first Stop, preserve the demand and report the new request as possible recovery fraud.
Using the compromised wallet or device again Secure the device and move remaining assets only through a clean, controlled environment.
Contacting only the police or only the exchange Notify the platform, the bank or payment provider and the national authority in parallel where each has relevant information.
Treating a blockchain label as an identified criminal Use it as a lead and support it with provider records, messages or other attribution evidence.
Deleting messages or changing files after the incident Keep originals, make working copies and record any later changes in the evidence log.
Posting wallet addresses and the full story publicly Use verified reporting channels; public posts can alert a suspect and attract a second scam.

Frequently Asked Questions

Can stolen cryptocurrency actually be recovered?

Sometimes, but there is no standard reversal mechanism. The route may involve an exchange freeze, payment dispute, criminal seizure, civil order or voluntary repayment. The result depends on timing, asset location, identification evidence and the law of the relevant countries.

What if the transaction is already confirmed?

Record and report it anyway. Confirmation usually means the blockchain will not undo the transfer, but the address may later touch a regulated service or account that can be flagged or frozen. Confirmed does not mean impossible to investigate.

Should I hire a blockchain tracing company immediately?

Secure accounts, notify providers and preserve evidence first. Then compare the proposed scope and cost with the actual loss and legal route. Tracing without a plan for using the result may not improve recovery prospects.

What if a hardware wallet was used?

A hardware wallet does not protect a seed phrase entered into a phishing site or exposed elsewhere, and it cannot prevent a malicious signature. Treat the phrase and suspicious approvals as compromised, secure remaining assets and preserve the transaction data.

Do I need a lawyer for a small loss?

Not necessarily. Report the incident yourself and ask for a case number. Legal assistance becomes more proportionate when the loss is significant, cross-border, a provider is unresponsive or a formal claim or deadline is involved.

What if the first recovery service also took money?

Treat that as a second suspected fraud. Preserve the agreement, invoices, messages, wallet addresses and payment records, notify your bank and report the additional loss to the platform and authority.

Confidential preliminary assessment

Get a Clear View of Your Options

Tell us what happened. We aim to respond in English within one business day.

  • Evidence-led first review
  • EU/EEA and cross-border support
  • No seed phrases or private keys required