WORLD CRYPTOCURRENCY GUIDE
Respond calmly

What to do after a crypto security incident

Phishing, suspicious approvals and exposed recovery phrases call for different responses. First identify what was exposed.

Illustration of a safe response to a crypto incident
Educational illustration — Illustration of a safe response to a crypto incident
Short answer

Stop signing and document the incident. Secure accounts from a clean device. If a phrase was exposed, create fresh keys and move remaining assets after a test.

Exposed account

Secure access and sessions

Token approval

Inspect then revoke

Phrase or key

Fresh keys and transfer

01

Identify the exposure

Record the domain, signed messages, approvals and transactions. A website connection, spending permission and exposed phrase have different risks.

02

Secure account access

Through the official website, change passwords, end sessions and check multifactor settings. If the device may be infected, switch devices before sensitive actions.

03

Address keys and approvals

An exposed phrase requires new keys and an offline backup. Inspect and revoke suspicious token permissions on every affected network. Keep enough native asset for fees.

04

Preserve and report

Save URLs, screenshots, times and hashes. Inform the provider and relevant authorities. Ignore paid services promising guaranteed recovery.

05

Match the response to the exposed secret

A stolen password, a token approval and a compromised recovery phrase require different actions. Change platform credentials for account access, revoke a risky allowance, or move assets to a freshly generated wallet when the phrase is exposed.

  • Act from a trusted device and check destination addresses.
  • Do not pay a supposed recovery service that requests another secret or advance fee.
06

Practical case: decision and limits

If a recovery phrase was exposed, changing the app password does not change the keys. Treat affected derived accounts as compromised and prepare fresh custody in a clean environment. A dangerous token approval requires a different permissions diagnosis. Do not blindly add gas to an account possibly watched by an automated thief; preserve evidence and seek verifiable help.

07

A concrete verification

Arrange URLs, messages, network and hashes by time; exclude secrets from shared support reports.

Compare

Key points

StateMeaning
Exposed accountSecure access and sessions
Token approvalInspect then revoke
Phrase or keyFresh keys and transfer
Suspect deviceUse a clean device
FAQ

Frequently asked questions

Is disconnecting a site enough?

No. An on-chain approval may remain active.

Can a confirmed transfer be reversed?

Generally no. Pending operations depend on network and wallet rules.

Verifiable sources

Independent educational content reviewed against primary documentation. No personalized recommendation or promise of returns. Updated October 6, 2026