Recovering From a Phishing Click: The First Ten Minutes
What you do in the first ten minutes decides how much is lost. A checklist in the order it needs to happen.
Priya Raman · 3 min read
If you have just signed something on a site you now think was fraudulent, stop reading everything else and work through this in order. Sequence matters more than thoroughness.
Minute 0 to 2: establish what you signed
There are three cases and they have different responses.
You entered a recovery phrase. Worst case. The wallet is compromised permanently. Go to the next section immediately.
You signed a transaction or an approval. The attacker has permission to move specific tokens. Recoverable if you act fast.
You only connected the wallet. Connecting alone grants nothing. Disconnect and audit approvals, but there is no immediate emergency.
Check your wallet’s activity log. It shows what was signed and when.
If you entered a recovery phrase
Do not try to secure the old wallet. You cannot. Anyone with the phrase has equal control and automated scripts will empty it within seconds to minutes.
- Create a brand new wallet, with a newly generated phrase, on a device you trust.
- Move everything from the compromised wallet to the new one, highest value first.
- If there are staked or locked positions that cannot move immediately, accept that they are likely lost and prioritise what can move.
- Do not send funds into the compromised wallet to pay for gas unless you are moving something worth more than the gas, because drain scripts frequently take incoming gas instantly.
Speed matters more than tidiness. Do not stop to organise.
If you signed an approval
- Open a block explorer’s token approval tool for your address.
- Sort by value at risk.
- Revoke the approval you just granted, and any others you do not recognise.
- Revocation is a transaction and needs gas. Have some available.
If tokens have already moved, revoking still matters, because a single approval can be used repeatedly.
Minute 2 to 10: contain the rest
Check every other wallet on the same device. If malware was involved rather than a website, other wallets on that machine are also suspect.
Check your exchange accounts. Change passwords, confirm two-factor is intact, review recent withdrawal addresses. If the phishing site collected credentials rather than a phrase, this is where the second theft happens.
Disconnect the wallet from all sites. Most wallets have a connected-sites list.
Do not install anything a helper recommends. People will appear offering assistance within minutes of any public post about a loss. All of them are the second scam.
After the first ten minutes
Document everything. Transaction hashes, timestamps, the URL, the wallet addresses involved, screenshots of the conversation if there was one. Do this while it is fresh.
Report it. To your national fraud reporting body, to the exchange if funds moved there, and to the chain analysis firms that maintain public scam address databases. Reports rarely recover funds and do contribute to cases that eventually do.
Do not engage with recovery services. Anyone who contacts you offering to trace or recover funds is running a follow-on scam that targets people the first one already found. There is no legitimate service that finds you.
What to do the next day
Assume the compromised address is permanently associated with you and with a successful attack. It will receive further phishing attempts, including fake airdrops designed to draw you into signing again.
Retire it. Move to a new address and do not use the old one for anything.
Then reconsider the structure: a separate wallet for interacting with unfamiliar sites, holding a small balance, with long-term funds in a wallet that has never connected to anything. A working balance at a regulated venue such as a licensed exchange with a published address is also a reasonable place for money you are actively using, because a compromised signature cannot reach it.
The hardest part
Most people lose the first ten minutes to disbelief, checking whether it really happened, or searching for reassurance.
There is no version of this where waiting helps. If you are unsure whether you were phished, act as though you were. The cost of an unnecessary wallet migration is an afternoon. The cost of a delayed one is everything.
Move any remaining funds to a wallet with a newly generated seed phrase before anything else. Then revoke token approvals, and report the incident to your local authorities and the exchange involved. Do not pay anyone who promises to "recover" your coins. That is a second scam, aimed at victims of the first.