7 Things to Do in the First 24 Hours After a Crypto Theft
Discover the essential things to do in the first 24 hours after a crypto theft to revoke malicious access, preserve forensic evidence, and support legal action.

Why This Immediate Response Window Matters

Discovering that your digital assets have been illicitly transferred from your wallet is a high-stress emergency. The actions you take immediately following an unauthorized transaction largely determine whether law enforcement and legal counsel can trace or freeze the assets. Executing the correct things to do in the first 24 hours after a crypto theft can prevent additional secondary drain, preserve volatile digital evidence, and establish a documented chain of custody necessary for potential legal remedies.
1. Revoke Active Smart Contract Approvals Immediately
Concrete Example: You interacted with a phishing site disguised as a decentralized finance (DeFi) staking platform. Without realizing it, you signed an ERC-20 setApprovalForAll or unlimited token allowance transaction. Hours later, your wallet is drained of ERC-20 tokens, but your non-fungible tokens (NFTs) or other tokens remain untouched for the moment.
What to do about it: Attackers often use persistent smart contract approvals to drain assets continuously over time. You must immediately terminate all active authorizations granted to unknown or suspicious addresses. Navigate to a reputable block explorer approval tool (such as Etherscan Token Approval Checker) or dedicated security interfaces like Revoke.cash. Connect your wallet safely, review all open allowances, and issue transaction revocations for every unverified contract. If your native gas tokens (such as ETH or SOL) are continuously automated-drained by a sweeper bot, abandon the public key entirely and refrain from depositing fresh funds for gas fees into that compromised address.
2. Isolate Compromised Devices and Secure Key Passphrases
Concrete Example: A malicious browser extension or keylogger infected your computer, compromising your private key or seed phrase while you logged into a web wallet.
What to do about it: Immediately disconnect the affected computer or mobile device from local Wi-Fi and cellular networks to prevent ongoing malware communication or remote access command execution. If your recovery seed or private key was exposed, consider the seed phrase permanently compromised. For assets stored across other derivative accounts generated by that same recovery seed, immediately establish an uncompromised wallet on an air-gapped device or clean hardware wallet. Securely transfer any remaining, uncompromised tokens to the new setup. To understand how wallet compromise vectors unfold in detail, review our guide on stolen seed phrase timeline responses.
3. Preserve Immutable On-Chain and Off-Chain Evidence
Concrete Example: A scammer operating through a fraudulent Telegram investment desk deletes their chat logs, removes their handle, and takes down the phishing website shortly after completing the unauthorized transfer.
What to do about it: Forensics and law enforcement investigations rely heavily on early evidence preservation before malicious actors erase their digital footprint. Take high-resolution, full-screen screenshots of all correspondence, transaction confirmations, web URLs, smart contract addresses, and wallet balances. Export complete email headers containing raw IP metadata if communication occurred over email. Extract raw transaction hashes (TxIDs) directly from the block explorer and record the exact timestamp and block numbers. Do not alter, rename, or manipulate raw log files. For a deeper breakdown of how forensic teams reconstruct stolen asset flows, examine our comprehensive guide on how to trace funds after a scam.
4. Issue Emergency Alerts to Target Exchanges and Custodians
Concrete Example: On-chain transaction routing shows that your stolen Bitcoin or Ethereum was transferred through intermediate deposit addresses and immediately deposited into a centralized cryptocurrency exchange (CEX) account.
What to do about it: Centralized exchanges maintain compliance desks capable of placing administrative holds on accounts receiving stolen property, provided they receive rapid notification backed by credible documentation. Contact the legal compliance or fraud response departments of the receiving exchanges immediately. Provide the exact transaction hashes, destination deposit addresses, and proof of your original ownership. While exchanges generally require law enforcement requests or court orders to initiate permanent asset freezes, early notice alerts their anti-money laundering (AML) teams to flag accounts for high-risk activity. Learn more about emergency intervention mechanisms in our article on USDT freeze requests and stablecoin issuer protocols.
5. File Formal Reports with Law Enforcement and Regulatory Bodies
Concrete Example: A resident experiencing significant financial loss needs official law enforcement documentation to support subpoenas or obtain judicial freezing orders.
What to do about it: Promptly report the theft to relevant municipal and federal investigative authorities. In the United States, file an immediate complaint with the FBI’s Internet Crime Complaint Center (IC3) and notify your local law enforcement agency's financial crimes unit. If you reside in specific state jurisdictions, tailored state reporting avenues exist; for instance, victims seeking regulatory guidance should review resources regarding crypto recovery in Illinois or consult local specialized white-collar crime task forces. Ensure your law enforcement report includes the complete ledger of transaction hashes, verified destination addresses, total fiat-equivalent loss value at the time of theft, and all suspect identifiers. Request a official police report number, as financial institutions and courts require this proof to take formal action.
6. Commission a Certified Blockchain Forensic Report
Concrete Example: Your legal counsel requires an court-admissible forensic document detailing asset movement across mixing protocols, cross-chain bridges, or nested OTC brokers to file an emergency ex parte freezing injunction.
What to do about it: On-chain transactions move rapidly across decentralized bridges and automated market makers. Standard block explorer screenshots are insufficient for formal legal proceedings. Engaging professional investigators allows for full mapping of multi-hop transactions, identification of exchange deposit attribution, and preparation of clear evidence packages. Utilizing our systematic forensic analysis methodology, certified analysts trace asset flows to identify recipient entities. These technical reports directly assist legal teams in applying for injunctive relief, as detailed in our guide on court-ordered crypto asset freezing orders.
7. Secure Audit Trails and Guard Against Secondary Recovery Scams
Concrete Example: Within hours of posting about your wallet drain on social media or public forums, direct messages flood your inbox from self-proclaimed "ethical hackers" or recovery agents promising guaranteed fund retrieval for an upfront fee.
What to do about it: Be acutely aware that recovery agent scams represent a major secondary threat to fraud victims. Blockchain transactions are cryptographically irreversible on the network layer; no private entity can magically hack a blockchain or reverse a confirmed transaction. Disengage immediately from any individual or service claiming a 100% success rate or demanding upfront fees via untraceable crypto transfers. Authentic recovery efforts rely strictly on rigorous forensic tracing, official law enforcement subpoenas, legal discovery, and formal court orders. For a realistic overview of investigative capabilities, read our analysis on how forensic reports support crypto recovery in court.
Critical Things to Do in the First 24 Hours After a Crypto Theft
When facing complex asset drains where multiple vectors overlap—such as compromised hardware, leaked seed phrases, and immediate cross-chain bridging—you must prioritize actions systematically. First, secure all uncompromised infrastructure to halt further financial exposure. Second, preserve every shred of digital evidence in its unedited, native state. Third, establish an official paper trail with legal entities and law enforcement agencies. Coordinating these initial steps swiftly ensures that investigators and legal counsel have the foundational evidence required to initiate formal tracing and escalation proceedings.
Frequently Asked Questions
Can stolen cryptocurrency be frozen within 24 hours of a theft?
Yes, under specific circumstances. Centralized stablecoin issuers (such as Tether or Circle) and centralized exchanges possess legal and technical capabilities to freeze specific addresses or custodial accounts. Achieving a freeze within 24 hours requires rapid reporting, verified proof of theft, and immediate communication with exchange compliance teams or emergency court relief.
Should I contact the police or a private forensic firm first?
You should initiate both actions concurrently. Filing a police report establishes an official law enforcement record necessary for legal proceedings, while a private forensic firm can immediately track high-velocity on-chain movements before assets pass through obfuscation services, providing actionable intelligence to law enforcement.
How do recovery scammers target victims in the first 24 hours?
Recovery scammers monitor public social media platforms, forums, and chat groups for posts from theft victims. They use automated bots and sock-puppet accounts to offer guaranteed asset retrieval services. They typically demand upfront retainers or access to remaining wallet keys, leading to secondary financial losses.
What to Do Next
If you have suffered a significant crypto asset loss and require authoritative on-chain analysis to support law enforcement intervention or legal proceedings, time is critical. Contact our forensic team for a confidential case assessment through our secure intake page at Aegis Financial Forensics Contact or review our full range of forensic accounting capabilities on our forensic services page.