← Back to After Theft

Should You Communicate With an Unknown Attacker After a Crypto Theft?

The instinct to confront the person who stole from you is strong — and almost always wrong. A closer look at when silence serves you best, when communication helps, and how to do it without making the situation worse.

Every victim I work with eventually asks some version of the same question: can I just talk to this person? Sometimes it is about anger. Sometimes it is about wanting closure or an apology. Sometimes — and this is usually the most productive version of the question — it is about whether an on-chain message or a direct reply can actually recover funds. The answer depends on who the attacker is, what kind of attack it was, and what stage the investigation is in.

Before you type anything to anyone, understand the asymmetry: the attacker is working from a playbook. You are not. Anything you say gets filed into a script they have already run against hundreds of other victims. The ratio of downside-to-upside for unstructured victim-initiated communication is severe.

Attacker Profiles Shape the Answer

"The attacker" is not a single type of person. The correct communication strategy depends heavily on which profile you are dealing with.

Profile A: Organized Scam Ring (Pig-Butchering, Task Fraud, Fake Support)

These are industrial operations — typically based in SE Asia, often involving trafficked workers. They handle thousands of victims simultaneously, read from scripts, and have zero incentive to return funds. Contacting them typically achieves one thing: it confirms you are alive and motivated, making you a target for recovery-scam referrals within their network.

Recommendation: Do not engage. Preserve all past communications as evidence but send nothing new.

Profile B: Opportunistic Phisher

Single attacker or small group running approval-phishing kits, fake airdrops, seed-phrase harvesting. Once they have drained the funds, they disappear. There is usually no contact address for them at all, and any message into the void is unread.

Recommendation: On-chain communication is technically possible but nearly always useless. Focus on tracing and exchange reporting.

Profile C: DeFi Protocol Exploiter

This is the category where communication can work. Someone who exploits a vulnerability in a DeFi protocol — a reentrancy bug, a flash loan attack, an oracle manipulation — is often technically skilled, individually identifiable (at least to specialists), and sensitive to legal and reputational pressure. A well-crafted on-chain message offering a bounty in exchange for the return of funds has resulted in the return of hundreds of millions of dollars across documented cases.

Recommendation: Communication is viable, but should be drafted and sent by the protocol's team, security firm, or legal counsel — not the individual victim.

Profile D: Former Business Partner or Acquaintance

If the "attacker" is someone you know — a former employee, a business partner, a family member — this is not an anonymous crypto attack. It is a dispute between identifiable parties, and communication should go through attorneys, not directly.

Recommendation: Retain counsel immediately. Do not communicate directly.

Profile E: Insider at a Platform

Occasionally, the theft traces to an insider at an exchange, custody provider, or service. These cases almost always resolve through the platform's internal investigation and law enforcement, not through victim-to-insider contact.

Recommendation: Do not communicate. Work through the platform.

The Core Principle

Communication with an attacker is useful only when the attacker has something to lose from being identified and something to gain from cooperating. In most scam categories, neither condition is true.

The Specific Case for On-Chain Messaging

On-chain messaging — embedding a readable note in a tiny transaction sent to the attacker's wallet — has a narrow but real utility. Documented cases where it has produced recoveries generally share these features:

  • The attack was a protocol-level exploit, not a retail scam.
  • The attacker's on-chain activity suggests technical sophistication (DeFi use, bridging, etc.) rather than pure laundering.
  • The message offered a clear, credible bounty — typically 10% of the stolen funds — in exchange for the return of the rest.
  • The message was accompanied by credible public pressure: a published statement, a lawyer-signed letter, or an active law enforcement engagement.
  • The message was posted publicly enough that the return could be socially framed as "the right thing to do."

Notice what is not on the list: a grieving retail victim writing an angry DM to a drainer address has essentially no chance of working. The conditions for on-chain communication to succeed are institutional, not emotional.

What to Preserve From Pre-Existing Communication

Most victims already have some communication history with the attacker — in pig-butchering, often weeks or months of it. That existing communication is evidence. It should be preserved carefully:

  • Export full chat histories in their native format (Telegram export, WhatsApp chat export, iMessage screenshots). Exports are far more usable than screenshots for later forensic and legal work.
  • Do not delete accounts or block contacts until communication is fully exported. Blocking sometimes erases visible history.
  • Save metadata. Phone numbers, usernames, profile photos, any shared documents or voice messages.
  • Screenshot the scam platform's interface before you lose access. Scam sites disappear quickly once a victim stops responding.

Once everything is preserved, it is generally safe to block — but the preservation comes first.

If You Must Respond

Sometimes complete silence is not available — for example, if the scammer still has access to an account of yours, or is threatening to release private content obtained during grooming, or is continuing to demand additional payments. In those cases, handle communication with these rules:

  • Respond from a new channel and identity you have set up specifically for the purpose. Do not use your primary email or phone.
  • Keep replies factual, short, and emotion-free. Never appeal to their humanity, their family, or their conscience — this is interpreted as leverage, not persuasion.
  • Do not acknowledge the amount of your loss. Do not discuss remaining savings. Do not mention other accounts.
  • Do not agree to pay any additional amount under any framing — "release fee," "withdrawal tax," "decryption fee." These are always further scam vectors.
  • Route all responses through counsel or an investigator where one is involved. The words they choose are different from the words you would choose.

Law Enforcement Considerations

Self-initiated communication with an attacker can complicate ongoing investigations. Law enforcement sometimes monitors attacker accounts to identify infrastructure, or runs controlled communication through a cooperating victim. Ad hoc victim communication can spook the attacker into rotating infrastructure, burning evidence, or moving funds.

If any law enforcement agency is involved in your case, ask them directly what you should and should not say. If no law enforcement involvement exists yet but you are considering civil litigation, ask your attorney before sending anything.

The Emotional Part

Most of the time when a victim asks "can I message them?", the real question is "can I get closure?" The hard answer is that communication with the attacker almost never provides closure. What provides closure is time, completed reports, completed trace work, and — eventually — the decision to stop giving the incident daily mental space. Messaging the attacker tends to re-open the wound, not close it. If you are considering it for emotional reasons, the better move is usually the opposite: block, preserve, and redirect the energy into the structured steps of the case.