Wallet Compromise: The First 72 Hours That Decide Your Case
Your MetaMask, Ledger or exchange wallet was drained. Here is exactly what to do in the first three days to preserve evidence, contain the breach, and give a forensic investigation something to work with.

The moment you realize your wallet has been drained, two clocks start running: the containment clock, which determines whether any remaining assets survive, and the evidence clock, which determines whether a forensic investigator can later reconstruct what happened. Most victims lose the second one within an hour. This guide, drawn from the investigative methodology we apply to every wallet compromise engagement, walks through the first 72 hours in order.
Hour 0 to 1: contain what is left

- Move any surviving assets to a brand-new wallet generated on a different device you trust. Do not just "revoke approvals" on the compromised wallet — if the seed is exposed, revocation is theatre.
- Assume every connected account is compromised. Change passwords and rotate MFA on the email address tied to your exchanges, first. Email is the master key.
- Do not sign anything. Not a "recovery" transaction proposed by a stranger, not a support-desk signature request, nothing. Every drain we investigate includes at least one signature the victim later says they did not understand.
Hour 1 to 24: preserve the evidence trail
This is the window that most often gets destroyed accidentally. Do not reinstall the wallet app, factory reset the phone, or delete the browser profile. Everything on the compromised device is potential evidence: the exact extension version, the browser history the day of the drain, the clipboard history, and the specific approvals the wallet signed. Take screenshots of:
- The compromised wallet's transaction history, including timestamps and the exact recipient addresses.
- Any dApp connections listed in the wallet's "Connected sites" or WalletConnect sessions.
- Recent emails claiming to be from the wallet provider, exchange, or airdrop.
- Any Discord, Telegram, or Twitter DMs from the days before the drain — approval scams almost always start there.
Then photograph the physical device screen with a second camera. This becomes independent evidence that survives even if the device is later wiped.
Hour 24 to 72: file the report and open the tracing case
By day two, the drainer's wallet has usually consolidated funds and begun moving them toward an off-ramp. The window for actionable blockchain tracing is widest here. A properly scoped wallet compromise engagement produces:
- A forensic timeline of the drain — the malicious approval, the drainer contract, the hop pattern, and the endpoint custodian.
- Identification of the drainer service (many are branded infrastructure like Inferno, Angel, or Pink) which strengthens the case pattern.
- Compliance letters to the receiving exchanges before the funds are cashed out.
- A written incident summary suitable for insurance, HR, or exchange KYC re-verification.
How wallets actually get drained
Almost every compromise we see falls into one of five categories: a signed malicious approval from a fake mint or airdrop site, a seed phrase capture via a fake wallet installer or clipboard hijacker, a SIM swap unlocking an exchange account, a social engineering call impersonating "support," or a compromised browser extension that silently modified the transaction the user thought they were signing. Which category yours falls into changes what the tracing report has to prove — and what your counsel or your insurer needs to see.
What not to do
- Do not post the wallet address publicly asking "who drained me?" Drainers monitor those posts and target the victim again with fake "white-hat" DMs.
- Do not hire a "recovery hacker" from a comment section. There is no ethical hacker who can reverse a signed on-chain transaction. Read our FAQ for the full list of follow-up scam patterns.
- Do not delete the compromised wallet before an investigator has extracted the artefacts.
Realistic outcomes for wallet compromise cases
When funds reach a licensed exchange within the window, freeze rates are meaningfully higher than most victims expect — provided a properly formatted compliance letter, referencing the specific transaction hashes and a signed forensic exhibit, reaches the exchange's investigations team fast. When funds move directly to a mixer or a non-custodial DEX aggregator, the report becomes evidence for law enforcement referral and insurance treatment rather than direct recovery.
What to do next
If your wallet was drained in the last 72 hours, treat this as a live incident. Open a confidential intake with the compromised wallet address, the drainer's receiving address, and the approximate time of the drain. We will respond within one business day, and where the timeline warrants it, faster. Our engagement process is transparent, fixed-fee, and legally scoped from the first email.