Wallet safety · International; wallet-specific instructions apply
Wallet drained? What to do before you reconnect
Separate a malicious approval from a stolen recovery phrase and protect remaining assets without making the loss worse.
By Stonebridge Resolution · Published 4 October 2026 · Updated 4 October 2026
AI-generated illustration; not a depiction of a real case.
The short answer
Stop using the suspicious site and determine whether the problem is an account credential, an approval or the wallet's signing keys. Disconnecting a site alone does not revoke existing token allowances.
Pause interactions, not evidence collection
Do not approve another transaction because a support account says it will reverse the theft. Close the suspect site, stop signing requests and save its address, messages and any transaction prompts you can still access safely.
Use a clean device to inspect trusted account records. If remote-access software or malware may be involved, changing a password on the affected device can expose the replacement password too.
Check whether the loss is actually on-chain
Look at your genuine wallet history and a reputable explorer without connecting to an unknown service. A missing token in an app could be a display or network-selection issue; an outgoing transfer is stronger evidence of a loss.
Record the asset, chain, outgoing hashes and timing. Note what happened just before the transfer: entering recovery words, signing a message, approving a token allowance or installing an app. This helps identify which access must be removed.
If the issue is a malicious approval
On networks and tokens using allowances, a contract may be authorised to spend tokens without asking you again each time. Revoking a relevant allowance can limit future spending by that contract; merely disconnecting the website does not erase it.
Use your wallet provider's official guidance or a well-established network tool reached independently. Revocation usually requires a transaction and a network fee. It does not retrieve tokens already transferred, and it does not repair exposed signing keys.
If a seed phrase or private key was exposed
Treat all accounts derived from that compromised phrase as unsafe. Changing the wallet application's password does not change the underlying keys. A new account under the same phrase is not a clean replacement.
Create a genuinely new wallet through trusted software on a clean device. Moving remaining assets may be urgent, but automated theft can take new deposits immediately. Do not repeatedly add network-fee tokens to an actively drained wallet or follow unsolicited rescue instructions. Seek independently verified technical help where necessary.
Report after securing the remaining access
Notify relevant exchanges and authorities with your transaction records and the suspected attack method. Do not send them your recovery phrase; they need evidence, not spending authority.
Also check email, exchange sessions and connected devices. A wallet loss may be part of a broader account compromise. Save support references and avoid publishing details that make you a target for another recovery scam.
Checklist
- Stop signing or connecting to the suspect site.
- Record outgoing transactions and recent approvals.
- Distinguish exposed keys from contract allowances.
- Secure remaining assets through trusted, verified tools.
Common questions
Does disconnecting the website stop a drainer?
Not necessarily. It removes the connection but may leave token allowances intact. Compromised keys require a different response entirely.
Can a hardware wallet prevent every drain?
No. It protects key handling but cannot make a malicious transaction or approval safe if you authorise it.