WORLDCRYPTOCURRENCY GUIDE
Respond calmly

What to do after a crypto security incident

Phishing, suspicious approvals and exposed recovery phrases call for different responses. First identify what was exposed.

Illustration of a safe response to a crypto incident
Illustration of a safe response to a crypto incident
Short answer

Stop signing and document the incident. Secure accounts from a clean device. If a phrase was exposed, create fresh keys and move remaining assets after a test.

Exposed account

Secure access and sessions

Token approval

Inspect then revoke

Phrase or key

Fresh keys and transfer

01

Identify the exposure

Record the domain, signed messages, approvals and transactions. A website connection, spending permission and exposed phrase have different risks.

02

Secure account access

Through the official website, change passwords, end sessions and check multifactor settings. If the device may be infected, switch devices before sensitive actions.

03

Address keys and approvals

An exposed phrase requires new keys and an offline backup. Inspect and revoke suspicious token permissions on every affected network. Keep enough native asset for fees.

04

Preserve and report

Save URLs, screenshots, times and hashes. Inform the provider and relevant authorities. Ignore paid services promising guaranteed recovery.

DATA

Key points

StateMeaning
Exposed accountSecure access and sessions
Token approvalInspect then revoke
Phrase or keyFresh keys and transfer
Suspect deviceUse a clean device
FAQ

Frequently asked questions

Is disconnecting a site enough?

No. An on-chain approval may remain active.

Can a confirmed transfer be reversed?

Generally no. Pending operations depend on network and wallet rules.

Verifiable sources

Independent educational content reviewed against primary documentation. No personalized recommendation or promise of returns. Reviewed September 23, 2026