Digital Asset Recovery – Recoveris AG, Zug

How to Recover a Hacked Crypto Wallet (Drained or Phished)

Yes – a hacked or drained crypto wallet can sometimes be recovered. The stolen assets moved to addresses that stay visible on the public blockchain. When they reach an exchange or a token issuer, a freeze can be pursued. Speed decides most cases, and no honest firm guarantees the outcome.

Victims tell us "my wallet got drained" and "I didn't even get a notification". If that just happened to you, this was not your fault. Drainer kits are professional criminal tools built to fool careful people. Secure what is left first – this page shows how, and what recovery realistically looks like.

Tell us what happened, add the evidence you have, and leave your contact details. We will review your case and explain the next steps. Recovery is never guaranteed.

Former law enforcement & prosecutors  ·  EY technical partner  ·  Court-admissible reports Updated July 2026
The direct answer

My crypto wallet was drained – can I get it back?

Sometimes, yes. Every transfer out of your wallet was recorded on a public blockchain, so the stolen assets can be traced. Recoveris follows them to the exchange or service where they land and pursues a freeze there with forensic evidence. Recovery is never guaranteed – secure the wallet first, then preserve your records.

Why recovery is possible

  • The trail is permanent. Every movement of your stolen assets is publicly recorded and can be followed.
  • Cash-out is the chokepoint. To spend your crypto, the thief usually has to pass a regulated exchange.
  • Stablecoins can be frozen. Issuers like Tether can block stolen USDT at a specific address.

What to do now

  1. Move anything left to a brand-new wallet with a new seed phrase.
  2. Revoke the old wallet's token approvals so the drainer loses its grip.
  3. Save all transaction IDs, addresses and the phishing site, then request a free review.
Sources: FBI IC3; FTC consumer guidance; Etherscan and Solscan block explorers; Recoveris – How to Recover Stolen Cryptocurrency.

First 15 minutes: secure what's left

01

Protecting what remains comes before everything else, including reporting. Drainers often leave their permissions in place, so assets that arrive later can be swept too.

Do these four things now:

1

Create a brand-new wallet with a brand-new seed phrase

On a clean device if you can.

2

Move everything that is left into it

Starting with the most valuable assets.

3

Revoke the old wallet's token approvals

With a trusted tool such as revoke.cash.

4

Retire the old wallet completely

Treat it as burned, even if it looks quiet.

Then start preserving. Note the time you noticed the theft. Save the transaction IDs (TXIDs) of the outgoing transfers, the addresses they went to, and the site, app or message that started everything. Those records are the raw material of any trace.

Umberto Buonora, Head of Investigations at Recoveris
"You don't need to have handed over your seed phrase to be drained – one malicious 'approve' signature is enough. First move: get anything left into a brand-new wallet, then revoke approvals. And no wallet company or police force will EVER phone you and ask for your 24-word phrase."
Umberto BuonoraHead of Investigations, Recoveris AG · former Guardia di Finanza

Drained without your seed phrase: approvals and Permit signatures

02

Many victims describe the same shock: "someone hacked into my hot wallet and withdrew them – I didn't even get a notification". It feels impossible, because you never shared your seed phrase – the 12 or 24 words that act as your wallet's master key. The usual cause is a token approval.

An approval is a permission you sign that lets a smart contract move certain tokens for you. Legitimate apps use approvals every day, so wallets treat them as routine. Drainer sites abuse that trust. A cloned app, a fake claim page or a "support" link asks you to connect your wallet and sign. One signature – often a Permit, a gas-free variant – hands the drainer permission over your tokens. Automated scripts then empty the wallet in seconds, silently.

This pattern sits behind most "MetaMask hacked" cases we investigate. It also drives many Phantom wallet drained cases on Solana – one victim told us "I connected to the infected site by entering my Phantom Wallet password". In some of our files, scammers pushed victims to install a malicious app called "xtesepro" that forced transfers through.

You made one bad click on a professionally built trap. That is the entire story, and the theft it caused is traceable.

Seed-phrase phishing: the fake 'police + Ledger' calls

03

A crueler version arrives by phone. First, a "police officer" says your crypto appears in a fraud investigation. Then "Ledger support" calls to help you secure your device, backed by a spoofed email that looks official. You are guided to a fake website – our case files include ledgerensured.com – and told to enter your 24-word recovery phrase to protect your funds. Minutes later, the wallet is empty.

To be clear: Ledger is a real, legitimate company that scammers impersonate. The crime lives in the phone calls and the fake site. One victim was "persuaded to enter my 24-word recovery phrase into a phishing website" by exactly this two-step script. The fake police Ledger phone call scam works because each caller makes the next one believable.

One rule defeats it. Your seed phrase is the wallet, and anyone who holds it holds your funds. No police force, no wallet company and no exchange will ever ask you for it. Whoever asks is stealing. If your Ledger 24-word recovery phrase was stolen this way, do the first 15 minutes above, then preserve every number, email and URL.

NFT-mint, airdrop and event drains

04

"I thought I was minting an NFT – but it was a phishing scam." We hear this weekly. Fake mint pages, airdrop claims and event sign-ups are drainer sites wearing a costume.

Scammers impersonate real conferences and event platforms – invitations sent through services like Luma, "attendee NFT" mints tied to big-name events – so the button feels official. Clicking it signs a malicious contract, and the connected wallet is swept. An NFT minting drained wallet case follows the same approval mechanics as any other drainer, and the same first aid: revoke, secure, preserve.

The 'Celsius payout' phishing email

05

Scammers also impersonate real bankruptcy payouts. Victims waiting for a genuine Celsius distribution received emails with a "claim link". The link led to a page that harvested keys or triggered a wallet-draining signature. Because the payout itself was real, the email felt real too.

Treat every unexpected "claim your payout" email as phishing. Verify only through the official estate or court channel, and type the address into your browser yourself.

Address poisoning

06

Address poisoning targets your copy-paste habit. The scammer sends a tiny or zero-value transaction to your wallet from an address crafted to match the first and last characters of one you really use. Later you copy "your" address from transaction history – and the middle characters belong to the scammer. Clipboard malware performs the same swap invisibly.

Check the full address, character by character, before any large transfer. If you already paid a lookalike address, keep both addresses and the TXID. The trace works the same way.

Can drained crypto be recovered?

07

Sometimes, yes – and an honest firm will say only that before seeing your case. The trace itself is usually possible, because every movement of the stolen assets is publicly recorded. Reaching the funds is the harder part, and it depends on where they went.

Crypto phishing recovery follows three stages.

Stage 01

Trace

We follow the assets across wallets, chains and swap services – the same spine behind how we recover stolen cryptocurrency.

Stage 02

Intercept

When funds reach a regulated exchange – an "off-ramp", where crypto becomes ordinary money – we pursue a freeze with court-admissible evidence.

Stage 03

Recover

Frozen funds return through legal and law-enforcement channels.

Your odds rise when you act within hours, when funds land at an exchange that verifies identity (KYC), and when the thief took stablecoins – issuers like Tether can freeze stolen tokens / USDT at a specific address. If the drain included stolen Bitcoin, its trail is public too. Your odds fall when funds exit through non-KYC services, or when months pass before anyone looks. The assessment is free, and it tells you honestly where your case stands.

Umberto Buonora, Head of Investigations at Recoveris
Led by Umberto Buonora, Head of Investigations

Former Guardia di Finanza investigator specialising in financial crime. Leads Recoveris investigations across tracing, exchange freezes and court-ready evidence. LinkedIn

The intelligence team
Roman Bieda, Co-founder and Head of Product at Recoveris
Roman Bieda
Co-founder and Head of Product

Virtual assets expert for OSCE and Interpol; US court expert witness on the QuadrigaCX and DAO hack cases.

LinkedIn
Sol Cinosi, Chief Government & Corporate Affairs Officer at Recoveris
Sol Cinosi
Chief Government & Corporate Affairs Officer

Attorney; co-created the crypto-asset task force at the Buenos Aires prosecutor's office.

LinkedIn
Dominik Konopacki, Blockchain Investigations Manager at Recoveris
Dominik Konopacki
Blockchain Investigations Manager

Source of Funds specialist; thousands of cases traced for corporations and banks.

LinkedIn
Dawid Koperski, Blockchain Investigations Manager at Recoveris
Dawid Koperski
Blockchain Investigations Manager

Former Global Investigations Lead at MoonPay; 1,000+ complex crypto investigations.

LinkedIn
Alessandro Rella, Blockchain Investigations Manager at Recoveris
Alessandro Rella
Blockchain Investigations Manager

OSINT and digital forensics, 25+ years; former Guardia di Finanza investigator.

LinkedIn

First steps

08
1

Secure what is left

New wallet, new seed phrase, approvals revoked (the first 15 minutes above).

2

Preserve everything

TXIDs, addresses, the phishing site or app, emails, caller numbers, screenshots.

3

Report it

To local police and the FBI's IC3 (ic3.gov), and to the real exchange if your funds passed one.

4

Expect the second scam

"Recovery agents" who contact drained victims claiming the funds are located, for a fee, run recovery scams. A legitimate firm never guarantees results, never asks for your seed phrase, and never demands a large upfront fee tied to a promise.

5

Start the trace early

Get a free case review while the freeze window is open.

Frequently asked questions

09
My wallet was drained – what do I do first?
Move anything that is left to a brand-new wallet with a new seed phrase, then revoke the old wallet's token approvals. Stop using the compromised wallet completely. Save the transaction IDs, addresses and the site or message that started it – those records make tracing possible.
How was my wallet drained without my seed phrase?
You most likely signed a malicious approval or Permit on a fake site. That signature gave a contract permission to move your tokens, and automated scripts swept them in seconds. A seed phrase is one way in; approvals are the quieter one. Revoke them on the old wallet now.
I got a call from 'police' and then 'Ledger' asking for my 24-word phrase – is it a scam?
Yes. This is a known two-step scam that impersonates a legitimate company. No real police force or wallet maker will ever phone you and ask for your 24-word recovery phrase. Hang up, keep the numbers and any emails, and check whether anything has already left the wallet.
I entered my 24-word recovery phrase on a website – what now?
Assume the wallet is fully compromised. Move any remaining assets to a brand-new wallet with a new phrase immediately. Then preserve the fake site's address, the emails and the transaction IDs – they are the evidence a trace is built on.
An NFT mint drained my wallet – can it be recovered?
Possibly. You signed a malicious contract, and the stolen assets left a public trail that can be followed to an off-ramp. Revoke your approvals, preserve the mint site and transaction hashes, and get a free assessment. Recovery is never guaranteed, but the trace usually is possible.
I got a Celsius payout email with a claim link – is it real?
Treat it as phishing. Scammers impersonate real bankruptcy payouts, and the "claim link" harvests keys or triggers a draining signature. Verify any payout only through the official estate channel, with the address typed in yourself.
What is address poisoning?
It is a lookalike address planted in your transaction history. The scammer's address copies the first and last characters of one you use, so you copy it by mistake later. Always check the full address before sending, and preserve both addresses if you already paid one.
Is it safe to keep using the wallet?
No. If the keys or approvals are compromised, the wallet stays dangerous – anything you add can be taken. Create a fresh wallet with a new seed phrase and use only that. Keep the old one untouched, as evidence.
Free Strategic Assessment

The drain took seconds. The trail is permanent.

Tell us what happened and get a free, honest assessment of whether your funds can still be reached.

Get a Free Case Assessment →

Recovery outcomes vary and are never guaranteed. This page is general information, not legal or financial advice.