How to Recover a Hacked Crypto Wallet (Drained or Phished)
Yes – a hacked or drained crypto wallet can sometimes be recovered. The stolen assets moved to addresses that stay visible on the public blockchain. When they reach an exchange or a token issuer, a freeze can be pursued. Speed decides most cases, and no honest firm guarantees the outcome.
Victims tell us "my wallet got drained" and "I didn't even get a notification". If that just happened to you, this was not your fault. Drainer kits are professional criminal tools built to fool careful people. Secure what is left first – this page shows how, and what recovery realistically looks like.
Tell us what happened, add the evidence you have, and leave your contact details. We will review your case and explain the next steps. Recovery is never guaranteed.
My crypto wallet was drained – can I get it back?
Sometimes, yes. Every transfer out of your wallet was recorded on a public blockchain, so the stolen assets can be traced. Recoveris follows them to the exchange or service where they land and pursues a freeze there with forensic evidence. Recovery is never guaranteed – secure the wallet first, then preserve your records.
Why recovery is possible
- The trail is permanent. Every movement of your stolen assets is publicly recorded and can be followed.
- Cash-out is the chokepoint. To spend your crypto, the thief usually has to pass a regulated exchange.
- Stablecoins can be frozen. Issuers like Tether can block stolen USDT at a specific address.
What to do now
- Move anything left to a brand-new wallet with a new seed phrase.
- Revoke the old wallet's token approvals so the drainer loses its grip.
- Save all transaction IDs, addresses and the phishing site, then request a free review.
First 15 minutes: secure what's left
Protecting what remains comes before everything else, including reporting. Drainers often leave their permissions in place, so assets that arrive later can be swept too.
Do these four things now:
Create a brand-new wallet with a brand-new seed phrase
On a clean device if you can.
Move everything that is left into it
Starting with the most valuable assets.
Revoke the old wallet's token approvals
With a trusted tool such as revoke.cash.
Retire the old wallet completely
Treat it as burned, even if it looks quiet.
Then start preserving. Note the time you noticed the theft. Save the transaction IDs (TXIDs) of the outgoing transfers, the addresses they went to, and the site, app or message that started everything. Those records are the raw material of any trace.

"You don't need to have handed over your seed phrase to be drained – one malicious 'approve' signature is enough. First move: get anything left into a brand-new wallet, then revoke approvals. And no wallet company or police force will EVER phone you and ask for your 24-word phrase."
Drained without your seed phrase: approvals and Permit signatures
Many victims describe the same shock: "someone hacked into my hot wallet and withdrew them – I didn't even get a notification". It feels impossible, because you never shared your seed phrase – the 12 or 24 words that act as your wallet's master key. The usual cause is a token approval.
An approval is a permission you sign that lets a smart contract move certain tokens for you. Legitimate apps use approvals every day, so wallets treat them as routine. Drainer sites abuse that trust. A cloned app, a fake claim page or a "support" link asks you to connect your wallet and sign. One signature – often a Permit, a gas-free variant – hands the drainer permission over your tokens. Automated scripts then empty the wallet in seconds, silently.
This pattern sits behind most "MetaMask hacked" cases we investigate. It also drives many Phantom wallet drained cases on Solana – one victim told us "I connected to the infected site by entering my Phantom Wallet password". In some of our files, scammers pushed victims to install a malicious app called "xtesepro" that forced transfers through.
You made one bad click on a professionally built trap. That is the entire story, and the theft it caused is traceable.
Seed-phrase phishing: the fake 'police + Ledger' calls
A crueler version arrives by phone. First, a "police officer" says your crypto appears in a fraud investigation. Then "Ledger support" calls to help you secure your device, backed by a spoofed email that looks official. You are guided to a fake website – our case files include ledgerensured.com – and told to enter your 24-word recovery phrase to protect your funds. Minutes later, the wallet is empty.
To be clear: Ledger is a real, legitimate company that scammers impersonate. The crime lives in the phone calls and the fake site. One victim was "persuaded to enter my 24-word recovery phrase into a phishing website" by exactly this two-step script. The fake police Ledger phone call scam works because each caller makes the next one believable.
One rule defeats it. Your seed phrase is the wallet, and anyone who holds it holds your funds. No police force, no wallet company and no exchange will ever ask you for it. Whoever asks is stealing. If your Ledger 24-word recovery phrase was stolen this way, do the first 15 minutes above, then preserve every number, email and URL.
NFT-mint, airdrop and event drains
"I thought I was minting an NFT – but it was a phishing scam." We hear this weekly. Fake mint pages, airdrop claims and event sign-ups are drainer sites wearing a costume.
Scammers impersonate real conferences and event platforms – invitations sent through services like Luma, "attendee NFT" mints tied to big-name events – so the button feels official. Clicking it signs a malicious contract, and the connected wallet is swept. An NFT minting drained wallet case follows the same approval mechanics as any other drainer, and the same first aid: revoke, secure, preserve.
The 'Celsius payout' phishing email
Scammers also impersonate real bankruptcy payouts. Victims waiting for a genuine Celsius distribution received emails with a "claim link". The link led to a page that harvested keys or triggered a wallet-draining signature. Because the payout itself was real, the email felt real too.
Treat every unexpected "claim your payout" email as phishing. Verify only through the official estate or court channel, and type the address into your browser yourself.
Address poisoning
Address poisoning targets your copy-paste habit. The scammer sends a tiny or zero-value transaction to your wallet from an address crafted to match the first and last characters of one you really use. Later you copy "your" address from transaction history – and the middle characters belong to the scammer. Clipboard malware performs the same swap invisibly.
Check the full address, character by character, before any large transfer. If you already paid a lookalike address, keep both addresses and the TXID. The trace works the same way.
Can drained crypto be recovered?
Sometimes, yes – and an honest firm will say only that before seeing your case. The trace itself is usually possible, because every movement of the stolen assets is publicly recorded. Reaching the funds is the harder part, and it depends on where they went.
Crypto phishing recovery follows three stages.
Trace
We follow the assets across wallets, chains and swap services – the same spine behind how we recover stolen cryptocurrency.
Intercept
When funds reach a regulated exchange – an "off-ramp", where crypto becomes ordinary money – we pursue a freeze with court-admissible evidence.
Recover
Frozen funds return through legal and law-enforcement channels.
Your odds rise when you act within hours, when funds land at an exchange that verifies identity (KYC), and when the thief took stablecoins – issuers like Tether can freeze stolen tokens / USDT at a specific address. If the drain included stolen Bitcoin, its trail is public too. Your odds fall when funds exit through non-KYC services, or when months pass before anyone looks. The assessment is free, and it tells you honestly where your case stands.

Virtual assets expert for OSCE and Interpol; US court expert witness on the QuadrigaCX and DAO hack cases.
LinkedIn
Attorney; co-created the crypto-asset task force at the Buenos Aires prosecutor's office.
LinkedIn
Source of Funds specialist; thousands of cases traced for corporations and banks.
LinkedIn
Former Global Investigations Lead at MoonPay; 1,000+ complex crypto investigations.
LinkedIn
OSINT and digital forensics, 25+ years; former Guardia di Finanza investigator.
LinkedInFirst steps
Secure what is left
New wallet, new seed phrase, approvals revoked (the first 15 minutes above).
Preserve everything
TXIDs, addresses, the phishing site or app, emails, caller numbers, screenshots.
Report it
To local police and the FBI's IC3 (ic3.gov), and to the real exchange if your funds passed one.
Expect the second scam
"Recovery agents" who contact drained victims claiming the funds are located, for a fee, run recovery scams. A legitimate firm never guarantees results, never asks for your seed phrase, and never demands a large upfront fee tied to a promise.
Frequently asked questions
My wallet was drained – what do I do first?
How was my wallet drained without my seed phrase?
I got a call from 'police' and then 'Ledger' asking for my 24-word phrase – is it a scam?
I entered my 24-word recovery phrase on a website – what now?
An NFT mint drained my wallet – can it be recovered?
I got a Celsius payout email with a claim link – is it real?
What is address poisoning?
Is it safe to keep using the wallet?
The drain took seconds. The trail is permanent.
Tell us what happened and get a free, honest assessment of whether your funds can still be reached.
Recovery outcomes vary and are never guaranteed. This page is general information, not legal or financial advice.