Stop signing and document the incident. Secure accounts from a clean device. If a phrase was exposed, create fresh keys and move remaining assets after a test.
Secure access and sessions
Inspect then revoke
Fresh keys and transfer
Identify the exposure
Record the domain, signed messages, approvals and transactions. A website connection, spending permission and exposed phrase have different risks.
Secure account access
Through the official website, change passwords, end sessions and check multifactor settings. If the device may be infected, switch devices before sensitive actions.
Address keys and approvals
An exposed phrase requires new keys and an offline backup. Inspect and revoke suspicious token permissions on every affected network. Keep enough native asset for fees.
Preserve and report
Save URLs, screenshots, times and hashes. Inform the provider and relevant authorities. Ignore paid services promising guaranteed recovery.
Match the response to the exposed secret
A stolen password, a token approval and a compromised recovery phrase require different actions. Change platform credentials for account access, revoke a risky allowance, or move assets to a freshly generated wallet when the phrase is exposed.
- Act from a trusted device and check destination addresses.
- Do not pay a supposed recovery service that requests another secret or advance fee.
Practical case: decision and limits
If a recovery phrase was exposed, changing the app password does not change the keys. Treat affected derived accounts as compromised and prepare fresh custody in a clean environment. A dangerous token approval requires a different permissions diagnosis. Do not blindly add gas to an account possibly watched by an automated thief; preserve evidence and seek verifiable help.
A concrete verification
Arrange URLs, messages, network and hashes by time; exclude secrets from shared support reports.
Key points
| State | Meaning |
|---|---|
| Exposed account | Secure access and sessions |
| Token approval | Inspect then revoke |
| Phrase or key | Fresh keys and transfer |
| Suspect device | Use a clean device |
Frequently asked questions
Is disconnecting a site enough?
No. An on-chain approval may remain active.
Can a confirmed transfer be reversed?
Generally no. Pending operations depend on network and wallet rules.
Verifiable sources
Independent educational content reviewed against primary documentation. No personalized recommendation or promise of returns. Updated October 6, 2026



