← Back to Blog

    The First 24 Hours After Your Crypto Is Stolen: A Step-by-Step Guide

    Clock face over a blockchain transaction trail and an empty crypto wallet, illustrating the first 24 hours after cryptocurrency is stolen

    By Panayiotis Kattides · July 22, 2026

    If you have just discovered that your cryptocurrency is gone, read this page in order and work through it. The actions below are listed in the sequence that matters most. Do the first one now.

    The short version

    1. Move any remaining funds to a brand-new wallet with a fresh seed phrase. 2. Screenshot and save every piece of evidence before anything disappears. 3. Report to the Cyprus Police and to the exchange or platform involved. 4. Get a professional trace started while the funds are still traceable. 5. Ignore anyone who contacts you offering to "recover" your money for an upfront fee.

    Stolen crypto moves fast. In most incidents we see, the funds are split, swapped and pushed through bridges or exchanges within hours of the initial theft. That is the honest reason speed matters: not because panic helps, but because the window in which a transaction trail is clean, short and attributable is measured in hours, not weeks. What you do today shapes what is realistically possible later.

    This guide is written for individuals and small businesses in Cyprus and the wider EU. If you already know you need a trace, you can go straight to crypto asset recovery and come back to the rest afterwards.

    Step 1: Secure what is left (first 30 minutes)

    Assume the compromised wallet is permanently compromised. If an attacker has your seed phrase, your private key, or a signature-approval you granted to a malicious contract, changing your password does nothing. There is no way to "clean" a wallet whose key is known to someone else. The only safe move is to abandon it.

    1. Create a new wallet with a brand-new seed phrase. Ideally on a different device, and ideally a hardware wallet. Do not reuse the old seed, do not "derive a new account" from the same seed, and do not restore the old wallet anywhere.
    2. Move remaining assets out. Transfer whatever is left in the compromised wallet to the new one. Send the native gas token last, and be aware that some drainers automatically sweep incoming funds — if a small test transfer disappears instantly, stop and get help rather than feeding the attacker gas.
    3. Revoke token approvals. Many thefts do not involve a stolen key at all. They involve a token approval you signed, which lets a contract spend your tokens indefinitely. Revoke them using a reputable tool such as Revoke.cash or the Etherscan token approval checker. Do this for every chain you have used, not just the one where the loss occurred.
    4. Lock down the surrounding accounts. Change the password on the email address tied to your exchange accounts, enable app-based two-factor authentication (not SMS), and remove any browser extension you do not recognise. If a support agent, "wallet validator" or remote-desktop session was involved, treat the whole device as untrusted and stop using it for crypto.
    5. Freeze the account side. If the theft touched a centralised exchange account, log in and disable withdrawals, revoke API keys, and terminate all active sessions.

    Do not skip the approvals step because "the wallet is empty anyway". Approvals persist across chains and across new deposits, and victims are frequently drained a second time weeks later by the same open permission.

    Step 2: Preserve the evidence now, before it disappears

    This is the step victims most often get wrong, and it is the one that determines whether anything can be done later. Scam websites go offline. Telegram and WhatsApp accounts get deleted. "Support agents" block you. Exchanges retain records, but you need to ask for them while your account is still open. Capture everything today, even the parts that feel embarrassing or irrelevant.

    Collect and save, in one folder, with the date on each item:

    • Transaction hashes. The full hash of every unauthorised transaction, copied as text — not just a screenshot. These are the backbone of any trace.
    • Wallet addresses. Your address, the destination address the funds went to, and any intermediate address you can see on the block explorer.
    • Amounts, tokens, chains and timestamps. Record the value in EUR at the time of the transaction as well as the token amount.
    • Screenshots of the block explorer pages showing the transactions, taken while the pages are live.
    • The platform URL. The exact domain of the website, app or "investment platform" involved, including any variant spelling. Screenshot the homepage, your account dashboard and your supposed balance before it is taken down.
    • Full chat logs. Export, do not screenshot selectively — WhatsApp, Telegram, Signal, Instagram, LinkedIn, dating apps, Discord. Include usernames, phone numbers and profile photos.
    • Emails with full headers. Headers contain routing information that screenshots destroy.
    • Exchange statements. Download your full transaction and withdrawal history from every exchange involved, plus any deposit addresses you were given.
    • Bank records. If you sent fiat by card or transfer, save the statements, the beneficiary name, IBAN and reference.
    • A written timeline. Plain text, in order: when you were first contacted, what you were told, what you clicked or signed, when you noticed the loss. Write it today while your memory is accurate.

    Do not contact the thief. Do not tell them you are investigating, do not threaten legal action, and do not send a "test" payment to see whether they respond. Every warning you give them accelerates the laundering and costs you leverage.

    Step 3: Report it (same day)

    A police report is not optional paperwork. Exchanges will generally only freeze funds or disclose account holder information on the instruction of law enforcement or a court. Without a case number, a compliance team has no legal basis to act on your request, however sympathetic they are.

    • The Cyprus Police. File a report in person at your local station and ask that it be referred to the Office for Combating Cybercrime. Bring the evidence folder from Step 2 in printed and digital form, and ask for the case reference number in writing. Contact details are on the Cyprus Police website.
    • MOKAS, the Cyprus FIU. The Unit for Combating Money Laundering is the financial intelligence unit that handles suspicious transaction reporting and international asset-freezing cooperation. It is normally engaged through the police or through your lawyer or a regulated entity rather than by a direct victim complaint, but where laundering through Cypriot or EU accounts is involved, its involvement is what makes cross-border freezing possible. Ask the investigating officer explicitly whether the matter has been referred.
    • The exchange or platform. Open a support ticket immediately with the destination address, transaction hashes and your police reference. Use the words "unauthorised transaction" and "request for account freeze". Keep the ticket number.
    • Your bank or card issuer. If fiat left your account in the last days, call the fraud line rather than emailing. Some card payments can be charged back, and some SEPA transfers can be recalled, but only within tight windows.
    • CySEC, if the platform claimed to be a licensed Cyprus investment firm or crypto-asset service provider. You can check registers and file a complaint through the Cyprus Securities and Exchange Commission. A false claim of regulation is itself evidence.
    • Report abroad where relevant. If you are resident elsewhere in the EU, report to your national police as well — cross-border cases are routinely coordinated between member states.

    If the scam followed a pattern you recognise — a fake trading platform, a romance-led investment, a fake support agent, a giveaway or an airdrop drainer — our breakdown of the most common crypto scams in Cyprus and Greece may help you describe it accurately in the report.

    Step 4: Start a trace while the trail is short

    A police report on its own says "money was taken from me". A traced report says "the money moved through these seven addresses and 62% of it arrived at a named, regulated exchange at 04:11 on Tuesday". Those are very different documents. The second one gives an officer something to send, a specific counterparty to contact, and a legal target for a freezing request. This is the single biggest thing that changes the outcome of a case.

    Blockchain forensics works because the ledger is public and permanent. The transactions cannot be deleted. What a trace does is turn that raw data into attribution: clustering the addresses that belong to the same actor, following funds through swaps, bridges and chain hops, and identifying the point at which stolen value touches a regulated service that knows its customer.

    Be realistic about the odds

    Nobody honest can promise you your money back. Recovery is a genuine possibility in some situations and close to impossible in others, and you deserve to know which one you are in before you spend anything.

    Recovery is realistic when: the funds land at a regulated exchange with real KYC obligations; you act within hours or days rather than months; the amount is large enough to justify legal action; the destination sits in a jurisdiction whose authorities and service providers cooperate; or the platform that took your money still has identifiable corporate and banking infrastructure.

    Recovery is unlikely when: the funds were passed through mixers or converted into privacy coins; the trail ends in a jurisdiction that does not respond to mutual legal assistance requests; the theft happened months or years ago and the funds have already been cashed out; or the sums involved are too small to support cross-border litigation. In those cases a trace still has value — for insurance, for a tax loss position, for a criminal complaint, or to rule out throwing good money after bad — but it is not a route to getting the coins back, and we will say so.

    Warning: the second scam is aimed at you right now

    Within days of a theft — sometimes within hours — victims are approached by "recovery agents", "blockchain investigators" and "cyber units" who claim they can retrieve the stolen funds. They find victims through public complaint forums, social media comments, leaked victim lists sold between fraud groups, and search ads placed against phrases like "recover stolen crypto". Being scammed a second time is common enough that regulators treat it as its own category of fraud; see the general guidance on cryptocurrency fraud from the U.S. Federal Trade Commission.

    Treat all of the following as disqualifying:

    • An upfront fee paid in cryptocurrency, gift cards or to a personal account.
    • A guarantee of recovery, or a specific percentage promised before any analysis has been done.
    • A request for your seed phrase, private key, or remote access to your device. No legitimate investigator ever needs any of these.
    • Unsolicited contact — they messaged you, you did not go looking for them.
    • Claims of being able to "hack the blockchain", reverse a transaction, or work through a private contact inside an exchange or a police force.
    • "Release fees", "tax payments", "compliance deposits" or "unlocking costs" demanded after they claim to have found the money. This is the same structure as the original scam.
    • No verifiable legal entity, registration number, physical address or named professionals.

    A genuine firm will scope the work, quote for the analysis rather than for a promised outcome, tell you when the case is not worth pursuing, and produce a report you can hand to police or to a court.

    What a professional trace actually involves

    If you decide to take that route, this is what the work looks like at Ondology Labs, so you can judge it against anyone else you speak to.

    1. Intake and triage. We take your addresses, hashes and timeline and give you an early, blunt read on whether the funds are still traceable and whether the case is worth pursuing. If it is not, you hear that first.
    2. Tracing and clustering. We follow the funds across wallets, chains, swaps and bridges, and group addresses under common control to separate the thief's infrastructure from ordinary counterparties.
    3. Attribution. We identify where value reaches services that hold customer identity data — exchanges, payment processors, custodians — and flag the specific points where a freeze or a disclosure request can bite.
    4. Reporting. You get a written, court-ready report: methodology, evidence, exhibits and conclusions, structured so that police, a regulator, a bank compliance team or a lawyer can act on it without needing to redo the analysis.
    5. Support afterwards. We work alongside your lawyer and the investigating officers, respond to follow-up questions from exchanges, and can give expert evidence where proceedings require it.

    Ondology Labs is a blockchain forensics and auditing firm based in Cyprus, and our forensic work is built to the same evidentiary standard as our audit work — because a report that cannot survive scrutiny is worth nothing to you.

    How Ondology Labs can help: If your crypto has been stolen, start with our crypto asset recovery service for an honest assessment of whether the funds can still be traced, backed by blockchain forensics and court-ready reporting across Cyprus, Greece and the EU. Secure your remaining wallets and file your police report first — then bring us the evidence.

    Related reading: Common crypto scams and your rights in Cyprus and Greece · What blockchain forensics is and how it works.