Every investigator sees the same pattern: victims who moved in the first 24 hours had meaningful outcomes. Victims who waited a week had almost none. The blockchain doesn't give you infinite time — after funds move through a few hops, swaps, or bridges, the window for anything beyond documentation closes quickly.
Here is the sequence that matters, in the order it should happen.
Hour 0 – 1: Stop the bleeding
Preserve evidence before anything can be deleted or modified
Platforms can (and do) delete accounts, chats, and messages once they're reported. If the attacker realizes you're catching on, they can block you from the app. Capture everything first.
- Screenshot the full conversation with the scammer — every message, every profile page. Scroll the entire history.
- Export chat data if the platform allows (Telegram, WhatsApp, Discord all have export functions).
- Screenshot the scam website and note the exact URL (including any path or query string). Check the URL in Wayback Machine — saves often survive takedowns.
- Record transaction hashes of every transfer you made. Copy them as text, not just screenshots.
- Screenshot your wallet activity from MetaMask, Ledger Live, or the relevant app, showing the unauthorized transaction.
- Note account IDs, usernames, and display names on every platform involved. These change; capture the state today.
If the wallet is still under attack, move unswept assets
If the drainer or attacker hasn't yet taken everything — maybe they only got USDC but your staked ETH is still in a vault — move the survivors to a clean wallet from a separate wallet paying the gas. Never top up gas on the compromised address.
Hour 1 – 6: Report to everyone who can act
Stablecoin freeze requests (if applicable)
If the stolen funds are or include USDT or USDC, the issuers can blacklist specific addresses. They require legal process to do so — typically a law enforcement request or court order — but logging your case early starts the paper trail.
- Tether: report via the compliance contact form at tether.to and through law enforcement channels.
- Circle (USDC): compliance requests go through circle.com's law enforcement portal.
- Both prioritize cases where the funds haven't yet moved and where there's an active law enforcement case number.
Exchange reports
If your transaction hashes lead to a known centralized exchange deposit address (Binance, Coinbase, Kraken, OKX, Bybit, etc.), report immediately. Most have dedicated abuse or compliance contacts. They will not typically act on a victim report alone, but they will log the address — and when law enforcement or your forensic investigator follows up, the prior report strengthens the case.
Law enforcement
- Local police report. File within 24 hours. You'll need the report number for insurance, exchange compliance teams, and bank reversals. Most local departments don't investigate directly, but the report is the artifact other processes require.
- FBI IC3 (US victims): file at ic3.gov. See our guide on how to report a crypto scam to the FBI for the fields that matter.
- Action Fraud (UK), AFP / ReportCyber (Australia), local equivalents elsewhere. Every major jurisdiction has a cyber-fraud reporting portal.
- FTC (for civil recordkeeping) and Chainabuse (for community notice) — both help build the address's reputation across exchange compliance systems.
Bank and card reversals (if fiat was involved)
If you wired money to a scam platform or paid by card to buy crypto that was then stolen, the fiat leg may still be reversible. Chargeback windows for cards are typically 60–120 days, but the bank's internal fraud team can sometimes recall a wire within the first few days if it hasn't settled. Call — don't email — within the first 24 hours.
Hour 6 – 24: Lock down identity and related accounts
Assume the attacker has more than what they took
If the theft started with a SIM swap, phishing email, or device compromise, the attacker probably has credentials for more than just the drained wallet. Rotate.
- Change passwords on every exchange and wallet account — from a clean device, not the one that was compromised.
- Remove SMS-based 2FA everywhere; switch to authenticator apps or hardware keys. See our guide on SIM swap protection for specifics.
- Check email forwarding rules — attackers commonly set up a silent forward so they can see password resets.
- Revoke API keys from every exchange.
- Revoke outstanding wallet approvals via Revoke.cash or Etherscan Token Approvals.
Freeze your credit (if identity was exposed)
If the scam involved KYC documents or government ID, treat it as an identity breach. Freeze credit at all three US bureaus (Experian, Equifax, TransUnion) or the equivalent in your country.
Hour 24 – 72: Engage a forensic investigator
Tracing while the trail is warm
This is the window where a blockchain forensic investigator adds real value. Stolen funds typically move through 3–5 hops of intermediate wallets before being parked, swapped, or deposited to an exchange. Tracing those hops early — while the attribution is still clean — is what produces an actionable report.
A good investigator will:
- Confirm where the funds are right now, on what chain, at what address.
- Identify whether any portion has reached a centralized exchange, a bridge, a mixer, or another wallet with KYC ties.
- Provide a written tracing report that law enforcement and exchange compliance teams can act on.
- Tell you honestly whether the case is in one of the four scenarios where recovery is realistic, or whether the realistic outcome is documentation only.
What Not to Do in the First 72 Hours
- Don't confront the scammer on-chain or in-app. It tips them off to re-layer funds faster. Wait until a tracing plan is in place.
- Don't sell or move any unrelated holdings from the compromised wallet just to "be safe" — you're burning gas and creating noise in the on-chain record. Move through a rescue wallet if needed; otherwise leave it.
- Don't post your wallet address publicly asking for help. It attracts recovery scammers and can complicate evidence.
- Don't pay anyone who promises recovery. Legitimate investigators explain outcomes honestly and don't demand large upfront percentages.
- Don't delete the compromised wallet. Even if it's "burned," investigators may need signed messages from it later to verify ownership for claims or civil actions.
The 72-Hour Checklist
If you need a single condensed version:
- Screenshot and export all evidence before anything can be deleted.
- Record every transaction hash as text.
- Move unswept assets out of the compromised wallet (gas from a different wallet).
- Report to USDT and/or USDC issuers if stablecoins are involved.
- Report to any centralized exchange the funds may have reached.
- File a local police report and an IC3 (or equivalent) complaint.
- Recall any pending wire or initiate chargeback if fiat was in the chain.
- Rotate passwords, 2FA, API keys, and wallet approvals from a clean device.
- Freeze credit if identity documents were exposed.
- Engage a forensic investigator while the trail is still warm.
The Bottom Line
Recovery isn't about luck — it's about what was preserved, reported, and traced inside the first 72 hours. Most victims who lose the window lose it to inaction, not to bad options.
If you're still inside that window, move now. If you're already past it, the right moves shift — documentation becomes the priority, and long-tail opportunities like civil litigation or exchange freezes on re-appearing funds remain viable for months.