Skip to main content

Shepley Capital

WALLETS & SECURITY
Wallets and Security - Cryptopedia by Shepley Capital

How to Safely Recover a Compromised or Hacked Crypto Wallet

Discovering that your crypto wallet has been compromised is one of the most distressing experiences an investor can face. Whether you notice it through an unexpected transaction, an alert from your exchange, or simply by checking your balance, the instinct is often panic. The challenge is that panic-driven responses frequently make things worse: connecting a compromised device to a new wallet, using a compromised seed phrase to recover funds elsewhere, or delaying action while the attacker continues to drain assets are all common mistakes.

The correct response is systematic and prioritised. This guide walks through the exact sequence of actions to take when you suspect or confirm a wallet compromise, what can and cannot be recovered, and how to rebuild your security architecture from scratch. Time matters in a compromise situation, but accuracy matters more than speed: a methodical response protects what remains and limits further damage.

 

Step 1: Stop the Bleeding First

The first question when discovering a compromise is whether the attacker still has access and whether assets are still being drained. Check your wallet balance and recent transaction history immediately. If funds are actively moving out, your first priority is to move any remaining assets to an address the attacker does not control, faster than they can take them.

If the compromise is through a stolen seed phrase (the worst scenario), the attacker has full control of every asset in every address derived from that seed. Your only chance to save remaining assets is to transfer them to a completely new wallet with a new seed phrase before the attacker gets to them. This is a race, and you should prioritise the highest-value assets first.

If the compromise is through a malicious token approval (the more common DeFi scenario), the attacker can drain only the specific tokens they have approval to spend. Revoking those approvals immediately (using Revoke.cash or Etherscan’s token approval tool) stops the ongoing drain. The tokens already taken cannot be recovered through revocation, but stopping the approvals protects the remainder.

If the compromise is through a hacked exchange account (rather than a self-custody wallet), contact the exchange’s security team immediately and freeze your account. Most major exchanges including Swyftx, Independent Reserve, and CoinSpot have emergency security processes. Account freezing prevents further withdrawals while the situation is assessed.

 

Step 2: Isolate the Compromised Device

Once you have taken whatever immediate action is possible to stop further asset loss, the next step is to isolate the compromised device: the phone, computer, or hardware wallet that was involved in the compromise. Disconnect it from the internet. Do not use it to connect to any new wallets or to access any accounts until it has been fully investigated and cleaned.

Do not import your compromised seed phrase into a new wallet on the same device. If the device is infected with malware, the new wallet’s seed phrase will be compromised the moment it is generated or entered. A compromised device must be treated as untrusted until it has been factory reset and professionally scanned. The advanced crypto security guide covers malware types and detection approaches in detail.

For hardware wallet compromises, the situation depends on how the compromise occurred. If your seed phrase was physically exposed (written down and found, photographed, or disclosed to a phishing site), the hardware device itself may be clean, but the seed phrase it protects is not. You need to move funds and create an entirely new seed. If the hardware wallet itself is suspected to be a compromised device (counterfeit, tampered firmware), do not connect it to anything until you can verify its authenticity through the manufacturer’s process.

 

Step 3: Create a Clean New Wallet

Set up your replacement wallet on a verified clean device: ideally a brand new device that has never been online, or a trusted device that has been factory reset and had all software reinstalled from official sources. For hardware wallets, purchase directly from the manufacturer or an authorised retailer, and verify the device is genuine before generating a new seed phrase.

Generate a completely new seed phrase on the clean device. Never reuse any part of the old seed phrase or derive a new seed from any information associated with the compromised setup. The new seed phrase must be stored securely offline immediately: seed phrase storage best practices must be followed from the first moment. A rushed recovery that cuts corners on the new seed phrase storage creates the conditions for a repeat compromise.

Once the new wallet is set up, transfer any remaining assets from the compromised addresses to the new addresses. Use the compromised wallet only to sign outgoing transactions to the new wallet: do not interact with any protocols, DeFi applications, or unfamiliar addresses during this transfer process. Verify each receiving address carefully before signing any transaction, as attackers sometimes monitor compromised wallets and attempt address poisoning during the recovery window.

 

What Can and Cannot Be Recovered

Crypto transactions are irreversible by design: assets that have left your wallet to an attacker’s address cannot be recovered through any technical means. The blockchain does not have a “undo” function, and no legitimate service can reverse a confirmed on-chain transaction. Be wary of recovery scams: fraudulent services that claim to be able to recover stolen crypto in exchange for upfront fees or wallet access are themselves scams, and will compound your losses.

What can be done is report the theft to Australian authorities (the Australian Cyber Security Centre and local police), the exchange if the attacker is known to use specific platforms, and blockchain analytics firms if the amounts involved justify the cost. While recovery is unlikely, reporting creates a record and contributes to the body of information that may eventually lead to law enforcement action against organised crypto theft operations.

In some circumstances, particularly where the compromise occurred through an exchange hack or a protocol exploit where the protocol itself holds insurance or a recovery fund, partial restitution may be available. Documenting your losses fully and promptly, including screenshots of balances before and after, transaction records of stolen funds, and all communications related to the incident, preserves your ability to make any available claim.

 

Rebuilding Your Security Architecture

After completing the immediate response and establishing the new wallet, the recovery process involves a critical review of how the compromise occurred and implementing changes to prevent recurrence. Was the seed phrase inadequately stored? Was a malicious dApp approved? Was the device insecure? Was the exchange account login credentials reused from another service?

The wallet security audit guide provides a framework for reviewing your full security setup. Key upgrades commonly identified after a compromise include: migrating SMS 2FA to authenticator apps or hardware security keys across all accounts, implementing a multi-signature wallet strategy for significant holdings, separating funds into a cold storage wallet for long-term holdings and a hot wallet for active use (with only minimal funds in the hot wallet), and reviewing email security to ensure the email accounts linked to crypto services are protected with the highest available security.

The experience of a compromise, as damaging as it is, often produces the security awareness that prevents significantly larger future losses. The self-custody security guide and the crypto wallet hygiene guide provide comprehensive frameworks for the security approach that should be in place going forward.

Frequently Asked Questions

How do you recover a compromised crypto wallet?

Discovering that your crypto wallet has been compromised is one of the most distressing experiences an investor can face. Whether you notice it through an unexpected transaction, an alert from your exchange, or simply by checking your balance, the instinct is often panic. The challenge is that panic-driven responses frequently make things worse: connecting a compromised device to a new wallet, using a compromised seed phrase to recover funds elsewhere, or delaying action while the attacker continues to drain assets are all common mistakes.

What should you do first when a wallet is compromised?

The first question when discovering a compromise is whether the attacker still has access and whether assets are still being drained. Check your wallet balance and recent transaction history immediately. If funds are actively moving out, your first priority is to move any remaining assets to an address the attacker does not control, faster than they can take them.

How do you isolate the compromised device?

Once you have taken whatever immediate action is possible to stop further asset loss, the next step is to isolate the compromised device: the phone, computer, or hardware wallet that was involved in the compromise. Disconnect it from the internet. Do not use it to connect to any new wallets or to access any accounts until it has been fully investigated and cleaned.

How do you set up a clean replacement wallet?

Set up your replacement wallet on a verified clean device: ideally a brand new device that has never been online, or a trusted device that has been factory reset and had all software reinstalled from official sources. For hardware wallets, purchase directly from the manufacturer or an authorised retailer, and verify the device is genuine before generating a new seed phrase.

What Can and Cannot Be Recovered?

Crypto transactions are irreversible by design: assets that have left your wallet to an attacker's address cannot be recovered through any technical means. The blockchain does not have a "undo" function, and no legitimate service can reverse a confirmed on-chain transaction. Be wary of recovery scams: fraudulent services that claim to be able to recover stolen crypto in exchange for upfront fees or wallet access are themselves scams, and will compound your losses.

How do you rebuild your security after a compromise?

After completing the immediate response and establishing the new wallet, the recovery process involves a critical review of how the compromise occurred and implementing changes to prevent recurrence. Was the seed phrase inadequately stored? Was a malicious dApp approved?

What are the risks during wallet compromise recovery?

The recovery process itself introduces risk. Moving remaining assets from a compromised wallet can fail if the attacker has automated sweeping, and restoring a seed phrase onto the same infected device simply hands over the new wallet as well. Panic decisions are the other danger, since recovery scams target people immediately after a loss, promising to retrieve funds for an upfront fee. No legitimate service can reverse a blockchain transaction.

What should Australians do after crypto is stolen?

Stolen crypto is almost never recoverable, so the practical steps are containment and documentation. Move any remaining assets to a wallet created on a clean device, revoke outstanding approvals, and secure the email and exchange accounts connected to the wallet. Report the theft to the platform and through ReportCyber, and retain the transaction records, since a genuine theft may support a capital loss claim in your Australian return, calculated against the original cost base.

WRITTEN & REVIEWED BY Chris Shepley

UPDATED: AUGUST 2026

Choose your next topic from our Cryptopedia​

Grow your crypto portfolio with the latest insights, straight to your inbox!

Join 10,150+ CEOs, Business Owners, Parents, Students, & more receiving actionable crypto insights to grow their portfolios.