Skip to main content
We only call from +1 819-714-0789
LastResortyFraud recovery specialists
Menu

Phishing and hacked wallets

Funds drained after a fake site, a malicious link, or a compromised device or account.

Phishing sites, fake wallet apps, malicious browser extensions and SIM-swap attacks can drain a wallet in minutes.

First, secure what is left: move remaining funds to a new wallet created on a clean device, change passwords and enable app-based two-factor authentication. Then read on to understand what happened and what can be done.

Phishing and hacked wallets

Wallet theft rarely involves 'hacking' the blockchain. Almost always, the attacker gets you to reveal a secret (your recovery phrase or a password) or to sign a transaction you didn't understand.

The most common methods are fake websites that copy a wallet or exchange, 'wallet drainer' sites that ask you to connect and approve a transaction, fake support agents on social media, malicious apps and browser extensions, and SIM swaps that let attackers take over your phone number and reset accounts.

How it works, step by step

  1. 1
    Step 1

    The lure

    A search ad for your wallet brand, a message about a 'security issue', an airdrop or free NFT offer, or a 'support agent' who replies to your public complaint.

  2. 2
    Step 2

    The fake page or app

    A site that looks identical to the real one asks you to 'verify', 'sync' or 'restore' your wallet — which means typing your recovery phrase — or to connect your wallet and approve a request.

  3. 3
    Step 3

    The signature or the phrase

    Entering a recovery phrase gives full control of the wallet. Approving a malicious 'permit' or 'set approval' gives a contract permission to move your tokens later, sometimes days afterwards.

  4. 4
    Step 4

    The drain

    Automated scripts sweep every asset of value within seconds or minutes, often splitting it across many addresses at once.

  5. 5
    Step 5

    Laundering

    Funds are swapped into other tokens, bridged across blockchains, or sent through mixers, then routed toward exchanges or cash-out services.

Where the money goes

Drainer groups move fast, but their activity is very visible on public blockchains. Analysts can follow swaps and bridges, and many drainer wallets are already labelled from earlier incidents.

Recovery chances are best when stolen funds reach a centralized exchange or a stablecoin issuer that can freeze them. Funds sent through mixers or privacy coins are much harder to follow.

If an exchange or custodial service held your funds and its security failed (for example, an account takeover it should have prevented), there may also be a claim against that service.

What to watch out for

  • Anyone asking for your recovery phrase

    No wallet, exchange, support team or investigator ever needs it. Typing it into a website is giving the wallet away.

  • Support that contacts you first

    Real support teams don't DM you on social media or Telegram. Only use the help link inside the official app.

  • Urgent security warnings

    Messages that your wallet will be 'deactivated' or 'compromised' unless you act now.

  • Approval requests you don't understand

    A request to approve 'unlimited' spending or to sign a message with unreadable data. When in doubt, reject.

  • Sponsored search results

    Fake wallet sites often appear as ads above the real site. Type the address yourself or use a bookmark.

Things scammers say

  • “Your wallet has been flagged for suspicious activity. Validate it within 24 hours to avoid suspension.”
  • “Hi, I'm from support. Please fill in this form to sync your wallet.”
  • “You are eligible for an airdrop — connect your wallet to claim.”

What to do right now

  1. 1

    Secure what is left

    Create a brand-new wallet on a clean device and move any remaining funds. Assume the old recovery phrase is known to the attacker.

  2. 2

    Revoke approvals

    If you signed a malicious approval, revoke it using a trusted approvals checker, from a clean device.

  3. 3

    Lock your accounts

    Change passwords (email first), switch to app-based 2FA, and ask your mobile carrier to add a port-out or SIM-change lock.

  4. 4

    Write down the timeline

    Note when you clicked, signed or typed what, and keep the URL of the fake site. Then report to police and the CAFC.

What to gather for your case review

  • Your wallet address(es) and the transaction IDs of the theft
  • The fake website address, app name or social media account used
  • Screenshots or screen recordings of what you saw and approved
  • Exchange or mobile-carrier notices (password resets, SIM changes, login alerts)

Ask for your recovery phrase or private key — never.

How we can help

What we can do

  • Trace the stolen funds and identify exchanges where they land.
  • Contact those exchanges quickly with formal preservation requests.
  • Build a complaint against an exchange whose security failures contributed to the loss, and connect you with partner lawyers if a legal claim is warranted.

What we cannot do

  • We cannot restore access to a wallet or undo the transaction.
  • We cannot promise funds will be found at an exchange that cooperates.

Frequently asked questions

What information should I have ready?

Whatever you have: transaction IDs (hashes), wallet addresses you sent to, the name and website of the platform, screenshots of chats and of the platform, exchange statements, and your police or CAFC report number.

Never send us your recovery phrase, private keys or passwords. We do not need them.

Will you ever ask for my recovery phrase?

Never. Your recovery (seed) phrase and private keys give full control of your wallet. No legitimate recovery company, lawyer, exchange or police officer needs them. Our forms block them automatically.

Start your free case review