Emergency response · self-custody

Your wallet was drained: seed phrase leak or malicious approval, and the seven steps that follow

Stop sending anything else to the address you suspect, then work out which of two very different problems you have: a private key or seed phrase that somebody else now holds, or a token approval you granted earlier to a contract that is spending on your behalf. Revoking an approval does not take a leaked key back, and topping up gas on an address that is being swept usually just funds the attacker's next transaction.

StableDesk self-custody and wallet security coverage

The 30-second version

  • Stop depositing to the address you suspect. If you think an automated sweeper is running on it, do not send ETH, TRX or any other gas asset to it.
  • Generate a completely new seed phrase on a clean device you trust. Adding another account under the same old seed does not isolate a seed phrase that has leaked.
  • Separate a key compromise from a malicious token approval, and both from a display fault. Revoking approvals cannot take back a private key the attacker already holds.
  • Keep the chain name, the addresses, the transaction hashes and the times. Contact support or your local police through an official entry point you have verified yourself, and never hand a seed phrase to a "rescuer" who approaches you in a direct message.

Leak, approval or display fault

The three look similar on the screen and call for different responses, so read each signal against what it can and cannot establish on its own.

What you can seeWhat to checkWhat it cannot prove on its own
Tokens left the address without your approvalWhether an approval event exists for that token, and which spender, chain and allowance it namesA single transfer does not prove the private key is out; it can come from a malicious approval you granted earlier
The balance in the wallet has droppedThe same address in a trusted block explorer, read-only, together with the network and the token contractA display or network problem is not evidence of theft
Native coin disappears shortly after it arrives, or outflows keep repeatingThe timing of each outflow against your own deposits, and whether the pattern is automatedSending more gas will not out-run it; bidding the fee up against the attacker widens the loss
You typed the seed phrase or private key into an unfamiliar page or sent it to someone, or the device or backup holding it was accessedTreat the key as compromised even if nothing has moved yetThe absence of an outflow does not make the key safe to keep using
Unfamiliar tokens arrived in the addressWhether this is dust, a phishing token or address poisoning — without clicking any URL the token carriesAn incoming transfer proves neither that the wallet is compromised nor that it is safe

A remote login to the device is a risk signal that needs further investigation rather than a verdict in itself. Do not copy a "frequently used" receiving address out of your transaction history; obtain the address through a communication channel you trust and check it in full.

The seven steps

Step 1: establish whether a key is actually out

Look at the address read-only in a block explorer you trust, without connecting the wallet to an unfamiliar site. Check the chain name, the token contract, the outgoing transfers and the approval events. A balance that looks lower may be an interface or network problem, and a transfer you did not authorise may come from a malicious approval granted at some earlier point, so one transfer is not enough to conclude that the private key has leaked.

Handle it as a key compromise if you have entered the seed phrase or private key on an unfamiliar web page or passed it to somebody else, or if the device or the backup holding it has been accessed. From that point the key cannot be treated as a safe credential, whether or not anything has moved.

Step 2: create a new wallet straight away

Build the new wallet on a clean device — not the one you suspect is infected. Trust Wallet on a phone, a freshly installed MetaMask or a Ledger hardware wallet all work for this. Generate a new 12 or 24-word seed phrase and write it on paper.

The point of the step is that the new seed phrase has to be entirely unrelated to the old one. Do not type the new phrase into the machine you suspect, do not photograph it, and do not put it anywhere in the cloud.

Step 3: let the sweeper evidence decide the migration route

MetaMask's own guidance is explicit: if you think a sweeper is running on the account, do not keep sending gas to it. The usual signals are native coin that is moved out without authorisation almost as soon as it lands, or outflows that keep appearing on their own. Repeated top-ups, and raising the fee to race the attacker, enlarge the loss rather than recovering it.

If there is no sign of automated sweeping, the old address already holds enough for fees, and you can verify what you are signing in an environment you trust, you can move the remaining assets to the new wallet — checking the full receiving address, the network you are actually on and the arrival of the funds. The risk of being front-run remains. Do not import the new seed phrase back into the suspect device, and stop putting fresh money in the moment anything looks wrong.

If there is no gas, the assets are still locked inside a protocol, or a sweeper is already active, preserve read-only evidence first and describe the chain, the assets and the transaction records to the wallet's official support. Some networks have elaborate coordinated-transaction rescue arrangements, but whether one applies, what happens if execution fails and what information you expose have to be weighed case by case; a private RPC endpoint is no guarantee of staying out of the attacker's view, and MEV-Boost is not a general rescue button for user wallets. Do not sign a bundle of transactions on the strength of a tutorial from someone you do not know.

A service that promises to get the funds back, asks for an "unfreezing fee" up front, or wants the seed phrase is a serious warning sign. Charging money establishes neither identity nor capability. In any support conversation, supply public on-chain material and the identity checks the provider genuinely needs — never the key.

Step 4: separate revoking an approval from replacing a key

If the problem is only a token approval granted to a malicious contract and the key itself is still trustworthy, open the approval manager your wallet provides, check the spender, the chain and the allowance, and revoke the relevant approvals. Disconnecting a site is not the same as revoking an on-chain approval: until the revocation transaction succeeds the original allowance can still be used, and revoking it does not bring back tokens that have already gone.

If the seed phrase or private key has leaked, the attacker can approve again or simply transfer. In that situation do not fund the old wallet merely to "revoke everything". After the migration, retire the affected key, check the other accounts and networks derived from the same seed phrase, and update your exchange withdrawal whitelists along with any old receiving address other people have saved.

Step 5: preserve the on-chain evidence

Write down the transaction hashes of the theft, the attacker's addresses and the timestamps. The chain keeps this permanently, but you are better off exporting a document as well, because you will need it if you later report the matter or pursue the funds.

Record the chain you were actually on, the token contract, the transaction hash, the from and to addresses, the amount, the time and the time zone, and keep the original chat logs, the phishing URLs, the device anomalies and any support ticket numbers alongside them. A destination address on chain does not by itself identify a person. If the funds appear to have reached a custodial platform, submit your material through that platform's formal channel together with the police documentation. Whether it can freeze, disclose or return anything depends on its own investigation and on the applicable legal process; a user report does not trigger recovery automatically.

Step 6: consider reporting it

If you suspect theft or fraud you can approach your local police or the official cybercrime reporting channel for advice, rather than deciding on the basis of some amount threshold this article invented. Set out the facts, the quantity of each asset and the basis on which you value it, and keep the acknowledgement you are given; whether a case is opened, and what happens after that, is for the local authority to determine under its own law.

Reporting helps document the timeline, but it does not guarantee recovery, an insurance payout or a tax deduction. Where insurance or tax is involved, check the policy wording, the applicable tax year and the local rules separately — an acknowledgement of a report is not an automatic deduction voucher.

Step 7: work out how the key got out

Find the route the private key took out of your control, or the new wallet will repeat the same story. Five paths are worth going through:

  1. An exposed backup: check whether the seed phrase was ever stored in cloud storage, in photos, in chat, in email or on a shared device; change the credentials of any affected account and end sessions you do not recognise.
  2. A fake wallet or a phishing page: note where you installed it from, the extension name and the malicious URL, and verify software against the developer's official entry point.
  3. A malicious approval or signature: distinguish an approval transaction from an ordinary transfer, and check what other tokens on the same chain have granted.
  4. A compromised device: isolate the machine you suspect, do not create new backups on it, and preserve the evidence before cleaning or reinstalling.
  5. Physical or shared access: check the paper backup, cameras, the people who share the device and any remote-control software installed on it.

These are items to check, not statistics about how often each one causes a loss. Compare them against your own situation, because the new wallet has to avoid whichever hole the old one fell into.

Frequently asked

My seed phrase is out — will revoking approvals fix it?

No. Revoking removes a contract's permission to spend; it does not take the key back from whoever now holds it. With the key, an attacker can grant a new approval or simply transfer the tokens. Do not fund the old wallet merely to revoke everything — move to a wallet built on a new, unrelated seed phrase instead.

Can I just create a new account inside the same wallet?

An extra account derived from the same seed phrase does not isolate a seed phrase that has leaked, because every account under it comes from the same secret. Generate a completely new 12 or 24-word phrase on a clean device, write it on paper, and keep it off the machine you suspect, out of screenshots and out of the cloud.

Should I send gas so I can move out what is left?

Only if there is no sign of automated sweeping, the old address already holds enough for fees, and you can verify the transaction in an environment you trust. MetaMask's guidance is not to keep sending gas to an account you believe is being swept, and raising the fee to race the attacker enlarges the loss. Even then, being front-run remains possible.

Someone has offered to recover my funds for a fee. Is that worth trying?

A promise to get the funds back, a request for an "unfreezing fee" up front or any request for the seed phrase is a serious warning sign, and being charged for the service establishes neither identity nor capability. Legitimate support needs public on-chain material and the identity checks it genuinely requires — never your key.

Further reading

Sources

Checked 2026-09-12: Revoke.cash; Etherscan Token Approvals; MetaMask guidance on compromised accounts and sweeper bots.

This site displays Binance referral code BN16188 and may receive a commission from qualifying referrals. Coverage of wallet compromise, self-custody practice and the wallet software named here is editorially independent. Full disclosure on the disclaimer page.

Referral codeBN16188Click to copy

Enter this code manually during sign-up. We may receive a commission from qualifying referrals; the actual fee discount is decided and displayed by Binance, not promised by us.