Simple Base SwapSimple Base SwapOpen app
← All articles
Aug 22, 2026·5 min read

Your Wallet Was Compromised. Here Is What To Do Right Now

basesecurityself-custodyscams
base

Realizing your wallet has been compromised is one of the worst feelings in crypto. Tokens are missing, an approval you never remember signing shows up in your history, or a "support agent" somehow knew your balance. Self-custody puts you in charge of your funds, and that also means there is no company that can freeze a transaction or reverse it for you. What you do in the next few minutes and hours can still make a real difference, both for what is left in that wallet and for everything else connected to it.

This guide is a response plan, not a prevention guide. If you have not been through this and just want to avoid it, see avoiding wallet phishing and drainer scams and keeping your recovery phrase safe instead.

Figure out what is actually compromised

Before doing anything else, work out which secret was exposed, because that determines how far the damage reaches.

If you typed your recovery phrase into a fake site, app, or "support agent," every wallet ever generated from that phrase is compromised, on every network, not just the one where you noticed the theft. If you only signed a malicious approval or a signature request from a fake dapp, the exposure is usually limited to the specific tokens or contracts covered by that signature. If you are not sure which happened, treat it as the worse case. Assuming too little is how people get drained a second time.

Move what is left, immediately

If any funds remain in the affected wallet, get them out first and ask questions later.

  1. Create a brand new wallet with a freshly generated recovery phrase, on a device you trust, ideally one that was not involved in the incident at all.
  2. Send remaining ETH and tokens from the compromised wallet straight to the new one. Do this before spending time investigating or trying to revoke approvals, since a script or bot watching the wallet can move funds faster than you can click through a revocation tool.
  3. If gas is the problem because the attacker also drained your ETH, send a small amount of ETH into the compromised wallet from an exchange or another wallet, just enough to cover one transaction out.

Speed matters more than tidiness here. You can sort out approvals and records afterward.

Revoke approvals, from a safe wallet

Once funds are out, go through the compromised wallet's approval history on a block explorer or a revocation tool and cancel anything still active, even for tokens that are already gone. An open approval on an empty wallet still lets a contract move any new tokens that land there later, which matters if you expect an airdrop or refund to that address. For the full process, see how to check and revoke token approvals.

Do this from the new wallet's browser and device, not the compromised one, in case the compromise came from something installed locally, like a malicious browser extension or fake wallet app, rather than the phrase itself.

Retire the old wallet completely

Do not keep using the compromised address for anything, even for receiving funds you expect. Treat the recovery phrase behind it as permanently burned. Update any place that has that address saved, such as exchange withdrawal allowlists, recurring payment setups, or shared spreadsheets, so nothing gets sent there by mistake later.

If you used the same recovery phrase across multiple wallets through different derivation paths, assume all of them are exposed too. See same recovery phrase, different address for why that happens.

Watch for follow up scams

Once a wallet is known to be compromised, or even just active on a public block explorer, it can attract a second wave of scammers pretending to help. Common patterns include:

  • Someone messaging you claiming they can "recover" your stolen funds for an upfront fee.
  • A fake support account replying to a post where you mentioned the hack, asking you to share your recovery phrase "for verification."
  • Unsolicited tokens or NFTs airdropped to the compromised wallet with instructions to visit a site to "claim compensation."

No legitimate service asks for your recovery phrase to reverse a theft, because none of them can reverse it. See fake support and impersonation scams and unsolicited tokens and airdrop scams for what these attempts usually look like.

Document what happened

While it is fresh, write down the transaction hashes involved, the approximate time, what site or app you interacted with, and what you signed. A block explorer transaction history for the compromised address gives you most of this. This record is useful if you report the incident to a scam tracking service, warn others about a specific fake site, or need it later for tax purposes, since a theft may be relevant to how you report losses depending on your jurisdiction and local tax rules.

Build a plan before this happens again

Once the immediate response is done, it is worth setting up your new wallet so a repeat is less likely and less costly.

Consider spreading funds across a hot wallet for everyday use and a hardware wallet for anything you are not actively using, described in hot wallets and cold wallets, explained. A multisig wallet is worth considering for larger balances, since it means a single leaked phrase or single phishing click is no longer enough to lose everything. And periodically running a recovery test on your new wallet confirms your backup actually works, so the next incident, if there ever is one, is a lot less stressful to handle.

Ready to try it yourself?

Create a non-custodial wallet on Base in seconds. No account, no sign-up.

Open the web app