Wallet Compromised? Immediate Steps to Recover
Wallet compromised? Follow a practical response plan for exposed seed phrases, malicious approvals, stolen devices, sweepers, and asset migration.
Author: Damon Salvatore · Senior Content Marketer If a crypto wallet may be compromised, speed matters, but the first move should match the type of exposure. Revoking a token approval can stop one spender. It cannot make a leaked seed phrase private again. Moving funds can help after key exposure, but sending gas into an account watched by a sweeper may lose more money.
This guide separates those cases and gives a practical order of operations. Do not share the affected seed phrase, private key, screen, or remote access with anyone offering recovery help.
Quick Answer: What should you do if a wallet is compromised?
Stop signing, identify what was exposed, and use a clean environment. If the seed phrase or private key may be known to someone else, create a wallet from a brand-new seed and move remaining assets. If only a malicious token approval exists and the keys remain safe, revoke that approval. Do not add gas to an address that may have a sweeper, and do not trust unsolicited recovery services.
Key Takeaways
- Unauthorized transactions usually mean an attacker already has usable authority.
- A compromised seed phrase affects every account derived from it, including new accounts created under the same phrase.
- Revoking approvals helps with permission abuse but does not repair key exposure.
- A fresh wallet requires a fresh seed, created in a clean environment.
- Do not deposit gas into a wallet that immediately sweeps incoming funds.
- Preserve evidence and report the incident, but assume confirmed blockchain transactions cannot simply be reversed.
First identify what was compromised
| What may be compromised | Common signal | Is revoking enough? | Priority action |
|---|---|---|---|
| One token approval | A dApp can spend an approved token | Often, if the seed and device remain safe | Revoke the approval and review other permissions |
| One account private key | Unauthorized activity from one imported account | No | Move assets controlled by that key to a fresh account |
| Seed phrase or recovery secret | Several derived accounts are affected | No | Create a wallet from a new seed and migrate every asset |
| Computer or browser | Fake prompts, changed addresses, unknown extensions | No | Stop signing and rebuild on a clean environment |
| Hardware device only | Device lost or authenticity warning | Depends on PIN and backup exposure | Use a safe backup to migrate if the threat warrants it |
| Exchange login | Login alerts or withdrawals inside a custodial account | Not applicable | Contact the exchange through its official channel |
Do not collapse every warning into seed-phrase exposure. A malicious approval, stolen browser session, leaked private key, and lost hardware wallet are different incidents. The most destructive mistake is using a narrow fix for a wider compromise.
Step 1: Stop signing and disconnect suspicious sessions
Do not approve another transaction to test whether the wallet still works. Close suspicious sites, disconnect the wallet from dApps, and take the affected computer or phone offline if malware is plausible. A dApp disconnect removes a session from the interface; it does not revoke an on-chain token approval.
Step 2: Preserve evidence before cleaning everything
Record transaction hashes, affected addresses, timestamps, token contracts, destinations, phishing URLs, browser extensions, and any messages from the attacker. Screenshots can help, but never include a visible seed phrase or private key. Evidence supports exchange reports, explorer labels, insurer requests, and law-enforcement complaints.
Step 3: Create a clean destination when keys are exposed
Use a separate, trusted device or a rebuilt environment. Install wallet software from its official source and generate a brand-new recovery phrase. Do not import the compromised phrase into the new wallet, and do not create another account under the old phrase. Those accounts share the same compromised root.
MetaMask's compromised-wallet guidance also recommends a new wallet instance and a new recovery phrase, followed by moving any assets that remain.
Step 4: Prioritize what can still be moved
List native coins, tokens, NFTs, liquidity positions, staking positions, smart-account roles, and contract ownership. Move the assets with the highest value and simplest transfer path first. Some positions require an exit or claim before they can move.
Verify the clean destination address through a second channel. A compromised host may replace copied addresses.
When revoking approvals is the right fix
If the incident is limited to a token allowance or NFT operator approval and the seed remains secret, revocation can remove the attacker's contract permission. Use the network's recognized explorer or a well-established approval tool from a clean device.
Uniswap's approval guidance points users to explorer approval checkers and Revoke.Cash. Our token approval revocation guide explains the network fees and verification steps.
When revoking approvals is not enough
Move to a fresh wallet if a seed phrase, private key, keystore, or signing device unlock secret may be exposed. An attacker with the key does not need an old approval. They can sign a direct transfer or create a new approval.
Changing the wallet password, deleting the browser extension, or resetting transaction history does not rotate blockchain keys.
Sweeper bots change the rescue plan
A sweeper monitors a compromised account and automatically transfers incoming assets, often including gas sent for a rescue transaction. Do not keep funding the address to race the script. If valuable locked positions remain, seek help only through a verified incident-response channel that can explain private transaction or bundle options without asking for your seed phrase.
Be skeptical of direct messages. Attackers routinely target people who publicly ask for wallet-recovery help.
Review the device and account that caused the compromise
- Remove unknown browser extensions and applications.
- Scan or rebuild the host before using it for sensitive signing again.
- Change email, exchange, and cloud passwords from a clean device if they may be linked to the incident.
- Replace reused passwords and review multi-factor authentication.
- Check every chain used by the compromised address, not only the chain where theft was noticed.
- Review delegated roles, session keys, permits, and smart-account modules where applicable.
How to rebuild with fewer shared risks
Separate long-term holdings from daily dApp activity. Keep recovery backups offline, use a low-value wallet for unfamiliar contracts, and verify important actions on a trusted display. Learn the broader controls in How to Secure Your Crypto Assets.
A hardware wallet can reduce exposure to host malware, but it cannot repair a leaked seed or an approved malicious transaction. See how hardware-wallet attacks differ from wallet compromise.
Where UKey fits
UKey can support a rebuilt self-custody setup through device-side signing, official software, and offline recovery planning. Use the official UKey Help Center for setup and recovery instructions. Never enter an exposed recovery phrase into a new device and call that key rotation. A clean recovery root must be newly generated.
Related Resources
- How to Secure Your Crypto Assets
- How to Revoke Token Approvals
- Can a Hardware Wallet Be Hacked?
- What Is a Recovery Phrase?
- How to Set Up a Crypto Wallet Safely
- UKey Help Center
Authoritative Sources
This article provides general incident-response information, not legal, financial, or guaranteed recovery advice. Transactions may be irreversible, and rescue options depend on the network, asset, contract, and attacker behavior.