Direct answer: after an unauthorized transfer or crypto scam, stop further payments and isolate the risk, preserve original evidence, then organize the transaction hashes, addresses, assets, amounts, and timeline. Do not pay a stranger an additional release fee, tax, deposit, or recovery charge.
Phase one: contain further loss
- Stop interacting with the suspicious party or platform. Do not add funds to satisfy a withdrawal, verification, tax, or release demand. The FTC identifies advance-fee recovery offers as a common second-stage scam pattern.
- Separate disconnection from revocation. Disconnecting a dapp does not revoke a token allowance. MetaMask explains that revocation is an on-chain transaction and normally requires gas.
- Assess whether unaffected assets should move. If a seed phrase, private key, or device may be compromised, create a clean wallet on a trusted device. First preserve balance, allowance, multisig, and suspicious-transaction snapshots so the evidence context is not lost.
- Notify relevant platforms. If a verified path reaches a centralized exchange, send the transaction hash and addresses to the exchange’s official support channel and the appropriate authorities. Account restriction or records preservation depends on evidence, jurisdiction, and platform policy; it is never guaranteed.
Phase two: preserve verifiable evidence
FBI/IC3 guidance asks victims to provide wallet addresses, cryptocurrency type and amount, transaction hashes, dates and times, plus communication channels, domains, applications, phone numbers, or social identifiers. Preserve:
- the affected address, transaction hash, explorer URL, asset, amount, network, and timestamp;
- original chat exports, full email headers, platform accounts, URLs, and application source;
- deposit and withdrawal receipts, bank or exchange records, order IDs, and support conversations;
- wallet balances, approvals, multisig permissions, device alerts, and security screenshots;
- a chronological narrative that separates memory from facts supported by files or chain records.
Facts, associations, and inference
Verified fact: a confirmed blockchain transaction can establish sender, recipient, asset, amount, time, and execution status. Association: an address label, shared counterparty, or time-and-amount overlap is an investigative lead, not automatic identity attribution. Inference: phishing approval, seed compromise, or a fake investment platform requires corroboration from approvals, contract calls, device evidence, and communications. Unknown: where evidence is absent, the report should say so.
Related cases
See the anonymized cases in the Case Library, including a liquidity-mining approval trap and a multi-chain wallet compromise.
Review and data scope
Data cutoff: 2 August 2026. Reviewed by the Crypto Forensics Lab Editorial Team for source traceability, evidence boundaries, operational safety, and bilingual consistency. This page is investigation-preparation information, not legal advice, a law-enforcement finding, or a recovery guarantee.