Crypto phishing response - Recoveris AG, Zug

Victim of a Crypto Phishing Scam? Act in This Order

If you entered an exchange password, shared a one-time code or seed phrase, or signed an unexpected wallet request, assume the affected account or wallet may be compromised. Use a clean device, secure the access route, preserve the phishing message and transaction evidence, and contact the real provider through its official website.

A phishing incident can be an account takeover, a malicious token approval, a deceptive signature, seed-phrase theft or malware. The correct response depends on which permission the attacker obtained, so avoid deleting evidence or sending money to anyone who promises an instant reversal.

Phishing evidence · Wallet analysis · On-chain tracingUpdated September 2026
The direct answer

What should I do after a crypto phishing attack?

Stop interacting with the message or site. From a clean device, open the exchange or wallet provider through a trusted bookmark or manually typed address, secure the relevant accounts, and record what you entered or signed. If a self-custody wallet may be exposed, review approvals and move remaining assets only after you understand whether the seed phrase, private key or a narrower smart-contract permission was compromised.

Primary guidance: The FBI advises crypto victims to report quickly and preserve wallet addresses, transaction hashes, amounts, dates, domains and communications. MetaMask explains that disconnecting a dapp does not revoke token approvals. FBI/IC3 · MetaMask · FTC

How crypto phishing compromises victims

01
01

Fake exchange login

A message claims that your account is locked or under attack and links to a copied login page. The attacker captures your password, one-time code or session information.

02

Seed-phrase request

A fake wallet-support page, airdrop or security check asks for 12 or 24 recovery words. Anyone with those words can control the wallet.

03

Malicious approval or signature

A fake mint, claim or verification flow asks you to approve token spending or sign a transaction whose effect is hidden or misrepresented.

04

Attachment or remote access

A file, browser extension or fake support agent may install malware, steal session data or obtain control of the device used for exchange and wallet access.

What to do immediately after crypto phishing

02
1

Stop the interaction

Do not revisit the link, reply to the sender, download another file or follow instructions from the same contact.

2

Use a clean device

If you opened an attachment, installed software or allowed remote access, stop using that device for passwords or transfers until it has been checked.

3

Secure email and exchange accounts

Open each service through its official site, change unique passwords, end active sessions, enable strong multi-factor authentication and contact official support.

4

Protect the wallet correctly

If the seed phrase or private key was exposed, create a new wallet on a clean device and plan a careful transfer. If you signed an approval, review and revoke the specific allowance. Disconnecting alone is insufficient.

5

Preserve the evidence

Save the original email or message, full headers where available, sender profile, domain, screenshots, wallet addresses, transaction hashes, timestamps and support case numbers.

6

Report and escalate

Notify the affected exchange or wallet provider through a verified channel and report the incident to local law enforcement. If funds moved, speed can matter when an exchange or stablecoin issuer appears in the trail.

Never pay to “validate”, “unlock” or “synchronise” a wallet

A legitimate investigator can begin with public wallet addresses and transaction hashes. Recoveris will never ask for your seed phrase or private key. Treat unsolicited recovery messages as a second phishing or recovery scam.

Identify what the attacker obtained

03
01

Credentials or one-time code

Change the affected password from a clean device, terminate sessions, secure the connected email account and ask the exchange to restrict withdrawals if the process is still active.

02

Seed phrase or private key

The entire wallet should be treated as compromised. Revoking approvals cannot make an exposed seed phrase safe; a new wallet is normally required.

03

Token approval

Review allowances on the correct chain and revoke the malicious permission. This is different from disconnecting the website from the wallet interface.

04

Signature or completed transfer

Record exactly what was signed and any resulting transaction. Blockchain analysis can trace assets that left, but it cannot cancel a confirmed blockchain transaction.

How Recoveris can support a phishing-loss case

04
01

Incident reconstruction

Connect the phishing message, domain, account events and wallet activity into a clear timeline, which helps establish how access was obtained.

02

Blockchain tracing

Trace stolen digital assets across wallets, bridges, swaps and services, then identify potential intervention points such as regulated exchanges.

03

Evidence and coordination

Prepare a documented investigation package and support communication with exchanges, counsel or law enforcement. Freezes and recovery depend on third parties and are never guaranteed.

Never pay to “validate”, “unlock” or “synchronise” a wallet

A legitimate investigator can begin with public wallet addresses and transaction hashes. Recoveris will never ask for your seed phrase or private key. Treat unsolicited recovery messages as a second phishing or recovery scam.

Evidence to preserve before it disappears

05
  • Original email, text, direct message or QR code
  • Full website address and screenshots of each page
  • Email headers, sender handles, phone numbers and profiles
  • What you entered, downloaded, approved or signed
  • Wallet addresses, networks, transaction hashes, assets and amounts
  • Exchange login alerts, withdrawal emails and support references
  • Exact timeline, including timezone
  • Device details and any remote-access software

What happens in a Recoveris review

06
  1. Stage 1
    Scope the compromise

    We review what was exposed, whether funds moved, the amount involved and the evidence available.

  2. Stage 2
    Trace and document

    Where appropriate, we reconstruct the on-chain flow and connect technical findings to the phishing timeline.

  3. Stage 3
    Support escalation

    We prepare actionable evidence for relevant exchanges, authorities or counsel. Their decisions and response times remain outside our control.

Frequently asked questions

08
I clicked a phishing link but entered nothing. Is my crypto safe?
Risk is lower, but it is not automatically zero. If the page downloaded a file, prompted a wallet connection or exploited the browser, further checks may be needed. Close the page, preserve the URL, scan the device and review account and wallet activity.
Can a crypto transfer caused by phishing be reversed?
A confirmed blockchain transaction usually cannot be cancelled. Recovery may still be pursued by tracing the assets and acting when they reach a service able and willing to restrict them, but no freeze or recovery is guaranteed.
Is disconnecting my wallet from the phishing site enough?
No. Disconnecting changes the site connection but does not necessarily revoke token approvals. Review allowances on the correct network and revoke any malicious permission. If the seed phrase was exposed, move to a new wallet created on a clean device.
Should I move my remaining crypto immediately?
If a seed phrase or private key was exposed, remaining assets are at risk, but rushed transfers can create more errors. Use a clean device, verify the destination carefully and consider a small test. If only a token approval was granted, first determine which assets and chain are affected.
What evidence matters most?
Keep the phishing message and URL, what you entered or signed, wallet addresses, transaction hashes, timestamps, exchange notices and the complete sequence of events. Do not rely only on cropped screenshots.
Can Recoveris guarantee recovery after phishing?
No. Recoveris can investigate the compromise, trace stolen assets and prepare evidence for exchanges, authorities or counsel. Whether assets can be frozen or recovered depends on the path of funds, timing, jurisdiction and third-party decisions.
Confidential case assessment

Phishing led to a crypto loss? Preserve the trail now.

Send the phishing URL or message, affected wallet or exchange, relevant transaction hashes and a short timeline. Never send a seed phrase, private key or password.

Request a Confidential Case Review →

Outcomes vary and are never guaranteed. Recoveris provides blockchain forensic analysis and investigative support; legal representation must be agreed separately with qualified counsel. This page is general information, not legal, cybersecurity or financial advice.