Skip to content

Wallet compromise

When signing keys are no longer yours alone

Wallet hacks combine device intrusion, social engineering, or leaked seeds with automated draining scripts.

Wallet hack matters

Losses occur when attackers obtain signing capability—seed, private key, or session—not merely view access.

Investigation correlates device indicators with sweep transactions.

Compromise vectors

  1. 01

    Malware

    Clipboard hijackers or remote access trojans.

  2. 02

    Seed exposure

    Phishing forms, cloud photo leaks, or support impersonation.

  3. 03

    SIM swap

    SMS 2FA bypass for exchange accounts linked to self-custody workflows.

Indicators

  • Unknown device approvals in exchange emails
  • Wallet emptied minutes after importing seed online
  • Battery drain from suspicious APKs

Sweep behavior

Bots monitor compromised addresses and sweep on deposit.

  • — Native token gas funded by operator
  • — NFT and token batch transfers
  • — Quick routing to master drain wallet

Preserve

  • Device images or logs
  • Antivirus detections
  • All sweep TXIDs
  • Timeline of seed entry if applicable

Investigation

01

Forensics

Identify malware family and C2 if artifacts exist.

02

Tracing

Follow sweeps to off-ramps.

Now

  • 01Rotate all credentials on clean devices
  • 02Never reuse compromised seed
  • 03Report to exchange if funds hit custodial platforms

Never provide a seed phrase, private key, or authentication code to anyone claiming they can recover funds—including parties who contact you unsolicited. Legitimate investigators do not need wallet secrets to begin a case review.

Frequently asked questions

Should I reuse the wallet after hack?

No—create new wallets with fresh seeds on clean hardware.

Investigate wallet compromise

Share sweep hashes and device context.