Stop signing and document the incident. Secure accounts from a clean device. If a phrase was exposed, create fresh keys and move remaining assets after a test.
Secure access and sessions
Inspect then revoke
Fresh keys and transfer
Identify the exposure
Record the domain, signed messages, approvals and transactions. A website connection, spending permission and exposed phrase have different risks.
Secure account access
Through the official website, change passwords, end sessions and check multifactor settings. If the device may be infected, switch devices before sensitive actions.
Address keys and approvals
An exposed phrase requires new keys and an offline backup. Inspect and revoke suspicious token permissions on every affected network. Keep enough native asset for fees.
Preserve and report
Save URLs, screenshots, times and hashes. Inform the provider and relevant authorities. Ignore paid services promising guaranteed recovery.
Key points
| State | Meaning |
|---|---|
| Exposed account | Secure access and sessions |
| Token approval | Inspect then revoke |
| Phrase or key | Fresh keys and transfer |
| Suspect device | Use a clean device |
Frequently asked questions
Is disconnecting a site enough?
No. An on-chain approval may remain active.
Can a confirmed transfer be reversed?
Generally no. Pending operations depend on network and wallet rules.
Verifiable sources
Independent educational content reviewed against primary documentation. No personalized recommendation or promise of returns. Reviewed September 23, 2026



