If your crypto was stolen in the last few hours, start here. Every minute counts.
What is a wallet drainer? What just happened to you
A wallet drainer is a type of malicious smart contract that, the moment you interact with it, transfers every token in your wallet to an attacker's address in seconds, often before you even realize anything is wrong.
You didn't make a mistake you should be ashamed of. These attacks are engineered by professional criminals. The fake sites look identical to the real ones. The links come from compromised official accounts on X, Discord, and Telegram. Victims include developers, crypto veterans, and security researchers, not just newcomers.
What matters now is not how it happened. It's what you do in the next 72 hours.
Why 72 hours is the critical window
Stolen crypto moves fast. Within minutes of a wallet drain, attackers typically begin routing funds through intermediary wallets, decentralized exchanges, bridges, and mixers, each hop making the trail harder to follow and the funds harder to freeze.
The 72-hour window matters for three specific reasons:
- Exchange freeze requests. If stolen funds land at a centralized exchange (Binance, Coinbase, Kraken, KuCoin, and others), that exchange can freeze the deposit account if notified quickly enough. Most exchanges have compliance teams that respond to documented theft reports. Once funds are withdrawn to a non-custodial wallet or converted to cash, that window closes permanently.
- Law enforcement response time. Investigators need a transaction hash, wallet addresses, and a documented timeline to open a case. The faster they have it, the more options they have, including emergency legal process to compel exchange cooperation.
- Blockchain evidence preservation. The blockchain record never disappears, but attacker wallets go dormant. A dormant wallet with funds sitting in it is a recovery opportunity. Identifying it early (and getting a law enforcement contact assigned to the case) keeps that option alive.
1Stop the bleedingFirst 30 minutes
Revoke all token approvals immediately.
A wallet drainer typically works by getting you to sign a transaction that grants unlimited token approval to a malicious contract. Even after the initial drain, that approval may still be active, meaning the attacker can return and pull additional funds later.
Go to one of these approval revocation tools and connect your wallet:
- Revoke.cash: works across most EVM chains
- Etherscan Token Approvals: for Ethereum specifically
- BscScan Token Approvals: for BNB Chain
Revoke every approval you don't recognize. Revoke approvals you do recognize too, if you're not actively using them. The cost is a small gas fee. The risk of not doing it is another drain.
Move remaining assets to a new wallet. If you have any tokens remaining in the compromised wallet, move them to a freshly created wallet: one that has never been used before and whose seed phrase was generated on a clean device. Do not reuse any wallet associated with the compromised address.
Do not interact with the compromised wallet again unless you are specifically documenting evidence with guidance from an investigator.
2Document everythingFirst hour
Before you do anything else, build your evidence file. You will need this for every step that follows: law enforcement reports, exchange freeze requests, and forensic tracing.
Collect and save the following:
- The theft transaction hash: the transaction ID (TxID) that shows the drain. Find it on the block explorer for the relevant chain (Etherscan for Ethereum, Arbiscan for Arbitrum, etc.) by searching your wallet address and looking for the outbound transaction you didn't authorize.
- Your wallet address: the address that was drained.
- The attacker's wallet address: the recipient address shown in the theft transaction.
- Screenshots of the fake site or link: if you still have the browser tab open, screenshot it. Note the URL exactly.
- The token amounts and types stolen: list each asset and the quantity.
- The approximate time of the theft: note the block timestamp shown on the explorer.
- Any communications: if you received a DM, email, or saw a post that led you to the malicious site, screenshot and preserve it.
Put all of this in a single document: a Google Doc, Notion page, or plain text file. Label it clearly. You will share it with multiple parties.
3Report to the FBI IC3Within 24 hours
File a report at ic3.gov, the FBI's Internet Crime Complaint Center. This is the primary federal intake point for cryptocurrency theft in the United States.
Filing a report does several things:
- Creates an official record of the theft with a case number
- Makes your case eligible to be linked to broader investigations already underway
- Gives investigators what they need to pursue subpoenas and asset freeze orders
- Puts you in the system for potential restitution if the attacker is prosecuted
When filling out the IC3 report, be specific. Include your wallet address, the theft transaction hash, the attacker's wallet address, the dollar value of the loss at the time of theft, and a timeline. A vague report gets deprioritized. A specific, documented report with blockchain evidence gets taken seriously.
Save your IC3 complaint reference number. You will need it.
4Alert the exchangesWithin 24 hours
If your stolen funds landed at a centralized exchange (even partially), that exchange can freeze the receiving account. This is one of the most time-sensitive actions you can take.
To identify which exchanges received the funds, use a block explorer to follow the transaction trail from the attacker's wallet. Look for transactions going to addresses labeled as exchange deposits. Common exchange deposit address labels appear directly on Etherscan and similar explorers.
Once you've identified the exchange:
- Go to their support or compliance contact page
- Submit a detailed theft report including your wallet address, the theft transaction hash, the receiving address at their exchange, the amount received, and the timestamp
- Reference your IC3 complaint number
- Mark the subject line as URGENT · Theft Report · Fund Freeze Request
Most major exchanges have legal or compliance teams that handle these requests. Response times vary. Speed matters: the faster they receive a documented request, the more likely a freeze is possible before the funds move.
5Get a professional forensic traceAs soon as possible
A block explorer shows you where your funds went one hop at a time. A forensic trace follows the entire laundering path (across chains, through bridges, past mixers) and documents it in a format law enforcement can actually use.
This matters because:
- Most law enforcement agencies don't have the tools or the time to trace cross-chain transactions themselves
- An investigator-grade case file dramatically increases the likelihood your case gets worked rather than filed
- Forensic documentation of the full laundering path is required evidence for exchange freeze requests, civil litigation, and criminal prosecution
We trace your stolen funds, identify every exchange and wallet the funds touched, build a chain-of-custody forensic report, and deliver it directly to your law enforcement contact.
Request a case review6File with your local law enforcementWithin 72 hours
In addition to IC3, file a police report with your local department or sheriff's office. Even if your local department doesn't have a dedicated crypto investigator, the report:
- Creates a local case number, which some exchanges require before acting on freeze requests
- Opens the door for your case to be escalated to state or federal investigators
- Establishes documentation for insurance claims and tax loss reporting
When you file, bring your evidence document. The detective will likely have limited familiarity with blockchain; that's normal. A ChainWatch forensic case file is specifically designed to bridge that gap, giving your investigator everything they need in language they can work with.
More than 72 hours since the theft? What you can still do
If you missed the 72-hour window, don't stop. Recovery is harder but not impossible.
Attacker wallets sometimes go dormant with funds still sitting in them, waiting for attention to pass before moving. The dormant wallet from our co-founder's own case held funds for months. When law enforcement had a court order ready, the funds were still there.
The blockchain record is permanent. The forensic trail doesn't disappear. Cases that looked cold have been worked months and years later when the right investigator got involved.
File the reports. Get the forensic trace. Keep the case alive.
Your 72-hour checklist
After a wallet drain: common questions
My wallet was drained. Is it safe to keep using it?
No. Move anything left to a brand-new wallet whose seed phrase was created on a clean device, and don’t reuse the old one. An approval you signed may still be active, and if your seed phrase was exposed, the whole wallet is compromised.
How did they take my crypto if I never shared my seed phrase?
Most drainers don’t need it. You signed a transaction or approval that let a malicious contract move your tokens, often on a fake site that looked real. If you did type your seed phrase anywhere, assume every account in that wallet is exposed.
Will revoking approvals get my tokens back?
No. Revoking stops the attacker from taking more with the same approval. Getting stolen funds back depends on freezes, seizures or court action, which is why the reports and the trace matter. See can a scammer’s crypto be frozen?
It’s been more than 72 hours. Is it too late?
No. It’s harder, but the blockchain record doesn’t disappear, and attacker wallets sometimes sit with funds in them for months. File the reports and get the trace.
Someone offered to “hack back” or recover my funds for a fee. Should I trust them?
No. This is a common follow-up scam. The FBI says IC3 will never ask for payment to recover lost funds or refer you to a company that does. How recovery scams work.
ChainWatch provides forensic response and reporting services for cryptocurrency theft victims. We do not guarantee fund recovery. ChainWatch is not a law firm. All case data is kept strictly confidential.
If your theft occurred in the last few hours, contact us with subject line URGENT.
Sources
The information on this page was checked against the sources listed in September 2026. Laws, agency guidance, company policies and contact details change, so please verify the current information with the original source before you act.