Wallet safety
Recovering from a compromised wallet
What you do in the first few minutes after realizing a wallet is compromised determines whether the loss stays contained or spreads to everything else that wallet touches.
6 min readReviewed July 14, 2026Wallet safety
The short answer
If a seed phrase or private key has been exposed, the wallet itself is permanently compromised—there's no way to "clean" it. If it was a single malicious signature rather than a leaked key, the wallet may still be safe, but every delegate approval it ever granted needs review. Which situation you're in changes the entire response.
If the seed phrase or key was exposed
- Generate a brand-new wallet, with a new seed phrase, on a device you're confident is clean.
- Move any remaining assets to the new wallet immediately, starting with the highest-value holdings.
- Do not fund the compromised wallet again, ever, even briefly—an attacker monitoring it can drain new deposits as fast as they arrive.
- Update passwords and 2FA on any exchange or service where that seed phrase or a related password might have been reused.
If it was a bad signature, not a leaked key
- Check every token account for active delegates and revoke anything unfamiliar —see revoking approvals.
- Move remaining funds to a wallet that has never signed the malicious transaction, as a precaution, even if the wallet itself appears uncompromised.
- Review the specific site or link that led to the signature and avoid it going forward—see malicious links.
After the immediate response
- Record what happened in your journal while the details are fresh—what you clicked, what you signed, and what moved.
- Report the phishing domain or drainer address where you can—browser Safe Browsing reports and wallet-side scam databases both benefit from more reports, even if recovery isn't possible.
- Rebuild going forward with a compartmentalized structure so a future incident is contained to a burner wallet, not a savings wallet.
Primary and official sources
Turn the lesson into evidence
Document what happened while it's fresh.
Preflight the compromised wallet to build an evidence-backed record of what moved, when, and through which program.
Open wallet preflight