Losing cryptocurrency through suspected fraud, phishing, an account takeover, or a wallet compromise can be financially and emotionally overwhelming. Once a loss is discovered, it is important to act promptly but carefully. No security measure can eliminate every risk, but understanding how the incident may have occurred and addressing the suspected vulnerability can help reduce the likelihood of another loss. Learning about the different types of cryptocurrency scams may also help users recognize similar warning signs.
Stop sending money or cryptocurrency to the person or platform involved until its legitimacy and any payment demand can be independently verified. The Federal Trade Commission warns that fraudulent investment websites may display fictitious account balances and demand additional fees when users attempt to withdraw. Requests for purported taxes, withdrawal charges, verification deposits, or blockchain fees should not be assumed to be legitimate or to provide access to the displayed funds. Additional payments may result in further loss.
The appropriate security response depends on whether the incident involved a payment made under false pretenses, an exposed seed phrase, a compromised exchange account, a phishing website, malicious wallet permissions, or a potentially compromised device. If a seed phrase or private key was disclosed, wallet providers such as MetaMask and Coinbase recommend transferring remaining assets to a newly created wallet and discontinuing use of the compromised recovery phrase. If an exchange account may have been accessed, contact the exchange through a verified official channel and ask whether it can restrict the account or stop any pending transfer. The exchange may not be able to reverse a completed transaction or recover transferred assets.
Users should also review the security of any connected email, financial, mobile-provider, and cryptocurrency accounts. Consider changing compromised or reused passwords, reviewing active sessions and account-recovery settings, and enabling strong multi-factor authentication. The Cybersecurity and Infrastructure Security Agency recommends phishing-resistant MFA, such as FIDO/WebAuthn authentication, when available. Our MFA recommendations provide additional information about common authentication methods and their limitations.
Preserve available transaction records and communications without taking actions that could place additional funds or accounts at risk. Potentially useful information includes transaction hashes, wallet addresses, cryptocurrency amounts, dates, account statements, messages, usernames, phone numbers, and relevant websites. The FBI’s cryptocurrency guidance asks victims to include these details when filing an IC3 complaint. Reporting information to an exchange, financial institution, or law-enforcement agency may assist its review, but it does not guarantee that an investigation will be opened, funds will be frozen, or a recovery will occur. Our guide explains how to gather blockchain transaction data and evidence.
Be particularly cautious of anyone offering cryptocurrency recovery services. The FBI has warned that fraudulent recovery businesses target people who have already lost cryptocurrency. Warning signs may include unsolicited contact, guaranteed recovery claims, demands for sensitive credentials, unverifiable government or exchange affiliations, and substantial upfront payments accompanied by vague explanations. Before engaging an investigator, attorney, or recovery provider, independently evaluate the provider’s identity, credentials, written scope, fees, and representations. Verification may reduce risk, but it cannot establish that a provider will successfully trace, freeze, or recover funds.
For future transactions, independently verify the recipient, website, and complete wallet address; avoid relying on links or telephone numbers supplied through unsolicited messages; and consider beginning with a small test transaction. The FBI advises users who receive purported exchange-security alerts to contact the exchange through a known official channel. These precautions may reduce risk but cannot guarantee protection against every scam, theft, or technical compromise.