If the transfer was recent, contact the sending bank or exchange and local police now. Do not wait for an analyst reply.
The first rule: stop the second loss
The first hour after a crypto loss feels like a race, but speed without control can create a second incident. Stop communicating with anyone who instructed you to transfer, pay a withdrawal fee, install remote-access software, reveal a recovery phrase, or move funds to a "safe" address. Do not send a test payment. Do not pay gas, tax, insurance, compliance, or verification charges to release a balance. A legitimate investigator, exchange, issuer, or government agency will not need your seed phrase or private key.
If the loss happened through an investment or relationship scam, the person may stay helpful after the withdrawal fails. They may introduce a supposed accountant, lawyer, regulator, or recovery desk. Treat every new contact and every link they supply as compromised. If the loss happened through a wallet drain, the attacker may still have access through the seed phrase, a malicious approval, a poisoned device, or a compromised email account. Assume the incident is continuing until the access path is understood.
Immediate danger, threats, extortion, or risk to another person should be reported to local emergency services. This guide addresses financial and digital containment. It does not replace emergency help, official reporting, incident-response support, or legal advice.
Never send more cryptocurrency to prove ownership, validate a wallet, pay recovery tax, or activate a freeze. Those are common second-loss scripts.
Minutes 0-10: separate the incident from the device you use to respond
Use a device you reasonably believe is clean. If you clicked an unknown link, installed remote-access software, entered credentials into a suspicious page, or approved a transaction from the affected computer or phone, do not use that device to reset every account. An attacker who still sees the screen or controls the session may capture the new credentials. Disconnect remote-access sessions and, where practical, isolate the suspected device from networks without wiping or discarding it. Preserving evidence and protecting accounts must happen together.
From the clean device, secure the email account connected to exchanges and wallets. Change the password to a unique one, review forwarding rules and recovery methods, sign out unknown sessions, and enable strong multi-factor authentication. Then secure the mobile carrier account if a SIM swap is possible, followed by exchange accounts and password managers. Save evidence of unfamiliar logins, recovery changes, API keys, withdrawal addresses, and support notifications before dismissing them.
Do not type a seed phrase into a website marketed as a security checker. Hardware-wallet support agents do not need it. If the seed phrase was exposed, the wallet should be treated as compromised, but moving remaining assets can be technically risky. Some attackers monitor the chain and automatically sweep deposits. Seek qualified wallet-security or incident-response help using a provider you verify independently, particularly when valuable tokens, NFTs, staking positions, or smart-contract permissions remain.
- Use a known-clean device and trusted network.
- Secure email, mobile carrier, password manager, and exchange access.
- Capture suspicious login and account-change alerts before clearing them.
- Isolate a suspect device, but do not wipe possible forensic evidence.
- Never enter a seed phrase into a recovery, validation, or tracing site.
Minutes 10-20: identify the exact transaction, chain, and token
Open the transaction record through a wallet or exchange you reach independently, not through the scammer's link. Record the complete transaction hash, blockchain network, token name and contract address, amount, timestamp, sending address, and destination address. A screenshot is useful, but copy the text identifiers as well. If several transactions occurred, place each on a separate line in chronological order. Include unauthorized token approvals and the later transfer that used them; they are distinct events.
Confirm the network carefully. Ethereum, BNB Smart Chain, Polygon, Arbitrum, Base, and other EVM-compatible networks can display similar address formats. USDT also exists on multiple networks, including Ethereum and TRON. A hash from one chain will not resolve on another. Do not rely on the ticker alone: fraudulent tokens can copy a familiar name and symbol, while a fake investment site may display a balance that has no on-chain counterpart.
For an exchange account takeover, the public withdrawal hash may be in the account's transaction history or confirmation email. Preserve the internal withdrawal ID, account identifier, destination, login records, and the platform's stated time. For a scam you authorized, record the real source of the crypto: bank transfer to an exchange, card purchase, peer-to-peer order, or transfer from your wallet. The purchase record may be as important as the final blockchain transaction.
Minutes 20-30: contact the sending platform and any clear destination service
Use the official fraud or security channel of the exchange, wallet provider, payment service, or bank that sent the value. Reach it by typing the known domain, using the verified app, or calling a number from an account statement. Do not use search advertisements or contact details supplied in a chat. State that the transfer was unauthorized or induced by fraud and ask for immediate security escalation, preservation of account records, and review of any available recall or restriction option.
Keep the notice compact. Provide the transaction hash, network, token, amount, timestamp, source account, destination, a one-sentence incident description, and your safe contact details. If an identifiable centralized exchange appears to receive the funds, notify its official compliance or fraud channel too. Ask it to preserve relevant records and advise what official process it requires. Do not claim certainty about a customer's identity based only on an address label.
A completed blockchain transfer is usually not subject to a conventional chargeback. That does not make the call pointless. The sending platform can protect your account and preserve access evidence. A receiving custodian may be able to restrict an internal account. A bank may be able to recall a recent wire or flag a beneficiary. A stablecoin issuer may have technical controls, but only the issuer can decide whether and how to use them under its policies and applicable law. A private analyst cannot order a freeze.
Ask for security escalation and record preservation. Do not ask a support agent to perform an impossible blockchain reversal or send accusations unsupported by the transaction data.
Minutes 30-40: file the official report that fits your location
Report promptly even if you do not yet have a full trace. In the United States, the FBI directs cryptocurrency investment-fraud victims to stop sending money and file with IC3, including addresses, token types, amounts, dates, times, and transaction IDs. Depending on the event, local police, an FBI or Secret Service office, the FTC, SEC, CFTC, or a state regulator may also be relevant. Preserve each confirmation and reference number. Duplicate reports should cross-reference earlier submissions rather than contradict them.
For England, Wales, and Northern Ireland, Report Fraud is the national reporting service; victims in Scotland should contact Police Scotland. Australian victims can use ReportCyber and notify their financial institution immediately, with Scamwatch and ASIC relevant to scam or investment misconduct reporting. Canadian guidance directs victims to local police and the Canadian Anti-Fraud Centre. In other countries, use the official national police, cybercrime, financial-intelligence, or securities-regulator channel. Verify the domain independently.
Do not wait for a consultant to file on your behalf if the loss is fresh. A private report may help organize or supplement the case, but it does not replace a victim's timely official report. Give known facts, label uncertainty, and add material later. If the destination platform asks for law-enforcement contact, give that requirement and the platform ticket number to the officer or reporting body. Whether they act is their decision.
Minutes 40-50: preserve evidence without turning it into a scrapbook
Create a master incident folder in a secured location the attacker cannot access. Save native conversation exports where available, original emails with headers, transaction confirmations, exchange statements, bank records, website URLs, domain names, social-profile links, usernames, phone numbers, QR codes, voice messages, and files received. Keep the originals untouched. Make separate copies for highlighting or redaction. A series of cropped screenshots can omit the time, sender, URL, and conversation sequence that gives evidence meaning.
Write a simple chronology while memory is fresh. Note how the contact began, each request or representation, what action you took, the exact time and time zone, which account or device was used, and when you discovered the problem. Distinguish what you observed from what another person told you. Record the fiat amount actually paid separately from a website's displayed profit. Include failed withdrawal demands, supposed taxes, and threats; they help explain the fraud pattern.
Start a contact log for every exchange, bank, police service, regulator, and adviser. Record the official channel, date, ticket number, person or unit if given, documents sent, and response. This prevents conflicting submissions and gives a later analyst or lawyer a reliable handover. Do not publish the entire case on social media. Public accusations can expose personal data, alert offenders, attract recovery scammers, and complicate a provider's review.
- Original messages and email files, not only screenshots
- Transaction hashes and explorer links for the correct chain
- Exchange, card, bank, and peer-to-peer purchase records
- Login, device, API, whitelist, and withdrawal notifications
- One chronology and one contact-reference log
Minutes 50-60: make a controlled decision about remaining assets
If unaffected assets remain, determine whether the risk is account-specific, device-specific, approval-specific, or seed-level before moving them. Revoking a malicious token approval may stop a contract from spending additional tokens, but it does not undo transfers already confirmed and it will not cure an exposed seed phrase. Moving assets to a fresh wallet may be sensible when the controlling secret is compromised, yet doing so from an infected device or through a monitored wallet can reveal or lose the destination. High-value or technically complex positions justify specialist help.
For centralized accounts, disable unknown API keys, reset withdrawal controls, review authorized devices, and ask the platform whether a temporary account lock is appropriate. For identity compromise, follow your country's identity-theft guidance and notify relevant financial institutions or credit bureaus. For business incidents, involve internal security, legal, finance, and insurance contacts under the organization's response plan. Do not let a well-meaning employee erase logs or negotiate privately with the attacker.
At the end of the hour, write the next three actions and assign an owner. Typical priorities are: follow up on the destination-service ticket; provide the official report number to the sending platform; and obtain an evidence-led preliminary trace. Avoid opening ten overlapping engagements. One coherent case record is more useful than several vendors sending inconsistent wallet maps.
What not to do after the first hour
Do not assume that the first person who names the destination exchange can recover the money. Address labels vary in reliability, and a deposit into an omnibus wallet does not reveal the customer publicly. Do not pay for a fabricated court order, police stamp, AML certificate, or tax clearance. Courts and government agencies do not receive evidence fees at anonymous crypto addresses. Verify any official contact through the agency's published directory and quote the reference number you already hold.
Do not delete embarrassing messages. Fraud often works through trust, urgency, romantic grooming, authority, or shame. Those communications explain why transfers occurred and can link your case to other victims. Investigators need the pattern, not a sanitized story. Do not describe an authorized payment induced by deception as a hacked wallet if that is not what happened; the inaccurate account can send the case down the wrong route.
Do not interpret a freeze as a completed recovery. A platform hold may be temporary, affect only part of the value, and require formal legal process. Seizure, forfeiture, and return are later stages. Likewise, do not abandon evidence because the first platform declines to disclose information to you. That response may simply mean it requires a valid request from law enforcement or a court.
Accurate language protects the case: traced, identified, reported, preserved, restricted, seized, forfeited, and returned are not interchangeable words.
The minimum package for an analyst
A preliminary analyst does not need wallet secrets. Provide the network, token and contract if known, transaction hashes, public source and destination addresses, amount, dates, sending platform, official report and support references, and a short incident chronology. Add account statements or communication exports through an agreed secure channel only when relevant. Redact passwords, seed phrases, private keys, one-time codes, full card numbers, and unrelated identity data.
The analyst should first verify that the transaction exists and matches the narrative. The next questions are whether the value can be followed, whether an identifiable service or issuer control appears, what confidence supports each label, what evidence is missing, and whether further tracing is proportionate. The deliverable should distinguish direct observations from inferred attribution and should state what another actor would need to decide.
If you submit a request to MoneyBack Legalix, an analyst will review the non-secret facts and explain the realistic next step for that specific case. We may help structure material for a platform, authority, or independently retained local lawyer and, with your consent, coordinate a handoff. We cannot guarantee recovery, compel disclosure, freeze a wallet, or replace an urgent official report.
Sources and fact check
- FBI - Cryptocurrency Investment Fraud: what victims should report↗
- FBI - Operation Level Up victim guidance↗
- Federal Trade Commission - What to know about cryptocurrency and scams↗
- Federal Trade Commission - Refund and recovery scams↗
- Report Fraud UK - Reporting cybercrime and fraud↗
- Australian Cyber Security Centre - Report and recover from scams↗
- Australian Cyber Security Centre - Police impersonation and seed-wallet theft alert↗
- Canadian Anti-Fraud Centre - Payment methods and reporting guidance↗
- Canadian Anti-Fraud Centre - Recovery-fraud and impersonation warning↗
Sources link to the closest available primary record. If a status changes, the article should be updated rather than silently rewritten.