UKey
English
简体中文
Small ivory porcelain shell holding an amber glass core on a teal-to-raspberry gradient background

Wallet Compromised? Immediate Steps to Recover

Wallet compromised? Follow a practical response plan for exposed seed phrases, malicious approvals, stolen devices, sweepers, and asset migration.

Damon Salvatore Author: Damon Salvatore · Senior Content Marketer

If a crypto wallet may be compromised, speed matters, but the first move should match the type of exposure. Revoking a token approval can stop one spender. It cannot make a leaked seed phrase private again. Moving funds can help after key exposure, but sending gas into an account watched by a sweeper may lose more money.

This guide separates those cases and gives a practical order of operations. Do not share the affected seed phrase, private key, screen, or remote access with anyone offering recovery help.

Quick Answer: What should you do if a wallet is compromised?

Stop signing, identify what was exposed, and use a clean environment. If the seed phrase or private key may be known to someone else, create a wallet from a brand-new seed and move remaining assets. If only a malicious token approval exists and the keys remain safe, revoke that approval. Do not add gas to an address that may have a sweeper, and do not trust unsolicited recovery services.

Key Takeaways

  • Unauthorized transactions usually mean an attacker already has usable authority.
  • A compromised seed phrase affects every account derived from it, including new accounts created under the same phrase.
  • Revoking approvals helps with permission abuse but does not repair key exposure.
  • A fresh wallet requires a fresh seed, created in a clean environment.
  • Do not deposit gas into a wallet that immediately sweeps incoming funds.
  • Preserve evidence and report the incident, but assume confirmed blockchain transactions cannot simply be reversed.

First identify what was compromised

Wallet-compromise signals and the response that matches each type of exposure.
What may be compromised Common signal Is revoking enough? Priority action
One token approval A dApp can spend an approved token Often, if the seed and device remain safe Revoke the approval and review other permissions
One account private key Unauthorized activity from one imported account No Move assets controlled by that key to a fresh account
Seed phrase or recovery secret Several derived accounts are affected No Create a wallet from a new seed and migrate every asset
Computer or browser Fake prompts, changed addresses, unknown extensions No Stop signing and rebuild on a clean environment
Hardware device only Device lost or authenticity warning Depends on PIN and backup exposure Use a safe backup to migrate if the threat warrants it
Exchange login Login alerts or withdrawals inside a custodial account Not applicable Contact the exchange through its official channel

Do not collapse every warning into seed-phrase exposure. A malicious approval, stolen browser session, leaked private key, and lost hardware wallet are different incidents. The most destructive mistake is using a narrow fix for a wider compromise.

Step 1: Stop signing and disconnect suspicious sessions

Do not approve another transaction to test whether the wallet still works. Close suspicious sites, disconnect the wallet from dApps, and take the affected computer or phone offline if malware is plausible. A dApp disconnect removes a session from the interface; it does not revoke an on-chain token approval.

Step 2: Preserve evidence before cleaning everything

Record transaction hashes, affected addresses, timestamps, token contracts, destinations, phishing URLs, browser extensions, and any messages from the attacker. Screenshots can help, but never include a visible seed phrase or private key. Evidence supports exchange reports, explorer labels, insurer requests, and law-enforcement complaints.

Step 3: Create a clean destination when keys are exposed

Use a separate, trusted device or a rebuilt environment. Install wallet software from its official source and generate a brand-new recovery phrase. Do not import the compromised phrase into the new wallet, and do not create another account under the old phrase. Those accounts share the same compromised root.

MetaMask's compromised-wallet guidance also recommends a new wallet instance and a new recovery phrase, followed by moving any assets that remain.

Step 4: Prioritize what can still be moved

List native coins, tokens, NFTs, liquidity positions, staking positions, smart-account roles, and contract ownership. Move the assets with the highest value and simplest transfer path first. Some positions require an exit or claim before they can move.

Verify the clean destination address through a second channel. A compromised host may replace copied addresses.

When revoking approvals is the right fix

If the incident is limited to a token allowance or NFT operator approval and the seed remains secret, revocation can remove the attacker's contract permission. Use the network's recognized explorer or a well-established approval tool from a clean device.

Uniswap's approval guidance points users to explorer approval checkers and Revoke.Cash. Our token approval revocation guide explains the network fees and verification steps.

When revoking approvals is not enough

Move to a fresh wallet if a seed phrase, private key, keystore, or signing device unlock secret may be exposed. An attacker with the key does not need an old approval. They can sign a direct transfer or create a new approval.

Changing the wallet password, deleting the browser extension, or resetting transaction history does not rotate blockchain keys.

Sweeper bots change the rescue plan

A sweeper monitors a compromised account and automatically transfers incoming assets, often including gas sent for a rescue transaction. Do not keep funding the address to race the script. If valuable locked positions remain, seek help only through a verified incident-response channel that can explain private transaction or bundle options without asking for your seed phrase.

Be skeptical of direct messages. Attackers routinely target people who publicly ask for wallet-recovery help.

Review the device and account that caused the compromise

  • Remove unknown browser extensions and applications.
  • Scan or rebuild the host before using it for sensitive signing again.
  • Change email, exchange, and cloud passwords from a clean device if they may be linked to the incident.
  • Replace reused passwords and review multi-factor authentication.
  • Check every chain used by the compromised address, not only the chain where theft was noticed.
  • Review delegated roles, session keys, permits, and smart-account modules where applicable.

How to rebuild with fewer shared risks

Separate long-term holdings from daily dApp activity. Keep recovery backups offline, use a low-value wallet for unfamiliar contracts, and verify important actions on a trusted display. Learn the broader controls in How to Secure Your Crypto Assets.

A hardware wallet can reduce exposure to host malware, but it cannot repair a leaked seed or an approved malicious transaction. See how hardware-wallet attacks differ from wallet compromise.

Where UKey fits

UKey can support a rebuilt self-custody setup through device-side signing, official software, and offline recovery planning. Use the official UKey Help Center for setup and recovery instructions. Never enter an exposed recovery phrase into a new device and call that key rotation. A clean recovery root must be newly generated.

Authoritative Sources

This article provides general incident-response information, not legal, financial, or guaranteed recovery advice. Transactions may be irreversible, and rescue options depend on the network, asset, contract, and attacker behavior.

FAQ

How do I know if my wallet is compromised?

Strong signals include unauthorized transactions, approvals you did not create, changed receiving addresses, repeated automatic transfers, or activity across several accounts derived from the same recovery phrase. A suspicious connection alone does not prove the seed was exposed, so review on-chain activity and device evidence.

Can I keep using a wallet after revoking malicious approvals?

Possibly, if the incident was limited to an approval and the seed, private keys, device, and host remain trustworthy. If any key material may be exposed, revoking approvals is not enough and the assets should move to a wallet created from a new seed.

Does changing my wallet password stop an attacker?

A wallet password usually protects local access on one device. It does not change the blockchain private keys or recovery phrase. Someone who has the seed or private key can still control the account.

Should I send gas to rescue tokens from a compromised wallet?

Not if a sweeper may be monitoring the address. The gas can be removed immediately. Standard rescue attempts may fail, so use only a verified response channel that does not ask for your recovery phrase.

Can a crypto wallet company reverse stolen transactions?

A self-custody wallet provider normally cannot reverse a confirmed blockchain transaction or reset a recovery phrase. Exchanges and issuers may be able to freeze assets in limited cases, but that is not guaranteed.

Should the new wallet use the old recovery phrase?

No. If the old phrase may be compromised, importing it into new software or hardware recreates the same vulnerable accounts. Generate a brand-new recovery phrase in a clean environment.

Official Verification, Downloads, and Help