The phone is gone. Taxi seat, festival crowd, snatched off a café table — the details vary, but the sequence that follows doesn’t: somewhere after “cancel the cards” arrives the colder thought that the Bitcoin wallet was on it.
Here’s the fact that makes the next hour navigable: your coins were never in the phone. Bitcoin lives on the chain; the phone held either keys to it or just a login. Which of those it held decides everything — one version of this story is a customer-service call, one is a genuine race, and one is a hard conversation with yourself. So the first ten minutes are for inventory, not action.
TL;DR. What was on the phone decides the playbook. Exchange app: the coins sit at the exchange, not the phone — from another device, change the password, confirm sessions were revoked, freeze withdrawals through support if locked out, and have the carrier kill the SIM. Hot wallet with a seed backup on paper: the thief may hold the same keys you do — restore the seed into a wallet on another device now, and send everything to a brand-new seed; that transaction is the only thing that ends the race. Hot wallet, no backup: honestly — if the seed exists nowhere but the phone and the phone never returns, the coins may be gone; the slim exceptions are below, and one of them means you should not remote-wipe. Everyone else: wipe, but after the money moves, not instead of it. Then rebuild so this class of problem retires — keys on a hardware wallet, the phone demoted to a watch-only window, and a movement alarm on the result.
The first ten minutes — inventory what was actually on it
Panic wants one dramatic action. The situation needs a sort. Three boxes, three different playbooks:
An exchange app. Coinbase, Kraken, Binance, your local exchange — custodial. The coins are in the exchange’s systems; what the thief holds is a logged-in window behind your phone’s lock. The real exposure isn’t the app — it’s that the same pocket held your email and your SMS, which together are the reset path to that account. From any other device: log in, change the password, and confirm in the security settings that other sessions were logged out and that withdrawals still require 2FA you control. Locked out? Contact support through their official website and request a freeze. Then call your carrier and deactivate the SIM: a thief receiving your text messages owns every account that trusts that number. Coins still on an exchange after a scare like this is its own lesson — moving them off properly is the follow-up read.
A hot wallet app, seed phrase written down somewhere. The app held real keys — but so does the paper in your drawer. The coins are on-chain, and right now two parties can potentially produce the keys to them: you, through the backup, and whoever holds the phone, if they can get past the lock. How real that “if” is gets an honest assessment in the next section — but notice the resolution doesn’t depend on it. You settle a race by moving the coins, and today you’re the only one who can.
A hot wallet app, no backup anywhere. I’ll say this straight, because vague hope burns hours that might matter: if the seed exists nowhere but that phone, and the phone never comes back, the coins are gone — not seized, not recoverable by a specialist, just permanently locked in plain sight on the chain. Nobody can regenerate keys that no longer exist — and the people who promise to, for an upfront fee, are the second scam that circles the first loss. The slim paths worth checking, in order: the wallet’s own cloud backup, if that app offered one and you turned it on — some mobile wallets push an encrypted copy of the seed to iCloud or Google Drive during setup. Sign into the same cloud account from another device, reinstall the app, look for a restore option. If that saves you, be honest about what just happened: a copy of your seed sat in a cloud account this whole time, a risk you were running without knowing it. Let it rescue you today, then move everything to a fresh seed and retire it. A full device backup is a longer shot — whether keys survive a restore onto a replacement phone depends entirely on how that wallet stored them, and many exclude key material from backups on purpose; try it before concluding anything. And if there’s any chance the phone itself resurfaces: do not remote-erase it. For everyone else, the wipe is a step below. For you, that phone is the last copy of your keys — lock it, put it in lost mode, and wait.
The race, honestly assessed
Most pages about this either promise doom or promise safety; the truth is more useful. Modern lock screens are genuinely strong: the PIN is enforced by dedicated secure hardware, failed attempts trigger escalating delays, and many phones can be set to erase themselves after ten misses (it’s off by default — worth knowing which yours is). A stranger who lifted a locked phone almost certainly cannot brute-force it — the overwhelmingly common fate of a randomly stolen phone is a factory wipe and resale. If that’s your situation, you will probably win this race at walking pace.
The exceptions are human, not technical, and both show up constantly in phone-theft reporting: the PIN was watched before the phone was taken — thieves loiter where people type passcodes, then steal the phone they already know how to open — and the phone was snatched unlocked, mid-use, out of your hand. If either could be true, or you honestly can’t rule them out, assume the person holding your phone can open it. The wallet app’s own PIN is software standing between a thief and money on a device they physically control — count it in minutes of friction, not days. You’re in a real race. Run it:
- Get the seed backup in hand and pick a clean device. Your computer, a spare phone, a family member’s tablet in a pinch.
- Install a reputable wallet from its official source. Urgency is exactly when people grab a fake installer from a search ad — on a computer, spend the extra ninety seconds to verify the download’s checksum before running it.
- Restore the seed. The balance appears. If it’s already zero with a withdrawal you didn’t make, this race is over — switch to the stolen-Bitcoin playbook and stop reading this page.
- Create a second wallet with a brand-new seed — and send everything to it. This is the step people skip, and it’s the entire point. Restoring only means you also have the keys again; the copy on the stolen phone still works. As long as coins sit on the old seed, nothing is settled — it’s an open bet that the thief’s patience runs out before their luck arrives. New seed, new address, checked character by character; if you had to retype an address by hand, our address validator at least confirms it’s well-formed.
- Pay a real fee. This is the one transaction where you want the next block, not a bargain — check the next-block rate on the fee estimator and pay it without flinching. Racing a thief is the wrong moment to save two dollars.
And if the lock would have held anyway? Then the move cost one fee and one evening — the cheapest outcome on the whole decision tree. Take it happily.
Remote wipe — yes, but it comes second
Both platforms give you the button: Find My iPhone at icloud.com/find, and Google’s Find My Device. Use them in two stages — first lock the phone and mark it lost, which suspends Apple Pay (on Android, it locks the wallet cards behind the screen lock) and puts a contact message on the screen, then erase it once the money has moved. The order matters for a simple reason: the wipe protects your photos, messages, and sessions; the fund move protects the money — and only one of those has an opponent racing you. If someone’s with you, parallelize: they handle lost mode and the wipe while you restore the seed.
The one carve-out, repeated because it’s the expensive mistake: no seed backup means no erase. A locked phone in lost mode might come back with your keys still inside; an erased one never does.
Then the unglamorous, load-bearing call: the carrier, to deactivate the SIM. Your number receives 2FA codes and password-reset texts for half your digital life, and that stops being a problem the moment the number stops living in the thief’s pocket.
Rebuild — the phone was never the right place for the keys
Once the funds sit on a fresh seed and the adrenaline drains, resist the natural conclusion — “I need to be more careful with my phone.” You won’t be. Nobody is. Phones get handed to children, balanced on bar rails, left in seat pockets; being carried everywhere is what phones are for. The lesson isn’t a better phone habit. It’s that the phone was never the right place for the keys.
The durable fix is structural. Keys move to a hardware wallet — a device whose only job is holding them, which never leaves the house — and the phone gets demoted to what it should have been all along: a watch-only window. The companion app still shows balances and history, can still prepare a transaction; it just holds no keys, so nothing that runs on the phone can spend. Lose the next phone and you’ve lost a window, not a vault. The Trezor Safe 5 walkthrough goes from first boot to first receive; for larger sums, the cold storage guide maps the upgrade paths. And keeping a small phone wallet for actual spending is fine — funded like the cash in your pocket, an amount whose loss would annoy you rather than change your year.
Put the new setup on an alarm
You caught this incident because a missing phone is impossible not to notice. Cold storage fails in the opposite direction — silently. An address doesn’t announce that something moved, and phone-loss panics recur: next year’s version of this story shouldn’t depend on you happening to look.
So make the silence visible. Put the new wallet’s addresses on our Watchtower: it’s watch-only — addresses, never keys, so it couldn’t touch the coins even in principle — the free tier watches an address with no signup, and it emails you when anything moves, plus a weekly “still untouched” heartbeat. If the unthinkable happens to the new setup, you find out within the hour on the free tier, within minutes on paid — while a race is still a race, not a history lesson.
Prevention — the checklist for the next phone
Most of the defense fits in one paragraph, and none of it is clever. The seed lives on paper or steel, never in the phone — no screenshots, no photo of the recovery card, no note in a cloud app, because a camera roll that syncs turns a lost phone into a lost seed even when the lock holds — the copy in the cloud is reachable through account-recovery attacks (SMS resets via your own SIM, the well-documented post-theft phishing texts) that never need the phone unlocked. Cover your passcode in public like a card PIN at an ATM — the realistic attack on your lock screen was never brute force, it was a pair of eyes a week earlier — and give the wallet app a PIN that isn’t the phone’s PIN. I’ll also say what I skip: decoy-wallet tricks and hidden-app gimmicks mostly add complexity you’ll fumble under stress; the honest version of that idea is simply keeping only walking-around money on the phone at all, with the rest behind hardware. Two minutes on the self-custody score will tell you which of these layers your setup is actually missing — better to hear it from a quiz than from a taxi seat.
FAQ
Can a thief get my bitcoin through the lock screen?
Against a locked modern phone, very probably not — secure hardware, throttled attempts, optional auto-erase. The realistic dangers are a shoulder-surfed PIN before the theft or a phone snatched while unlocked. If either might apply, treat the wallet as open and move the funds from another device now.
Exchange app on the stolen phone — are my coins gone?
Almost certainly not; they’re at the exchange, not on the phone. The risk is account takeover via the email and SMS in the same pocket. Change the password from another device, verify sessions were revoked and 2FA holds, freeze via support if locked out, and kill the SIM at the carrier.
No seed backup and the phone is gone — are the coins gone?
If the seed truly exists nowhere else and the phone never returns: yes. Check the slim paths first — the wallet’s own cloud backup if it had one, a device backup restored to a replacement phone — and if the phone might resurface, lock it in lost mode instead of erasing it. Nobody can regenerate keys that no longer exist; whoever claims to, for a fee, is a recovery scam.
Does remote wipe delete my bitcoin?
No — coins live on the chain, and the wipe only deletes the phone’s copy of the keys. With a seed backup, you lose nothing. Without one, the wipe destroys the last copy of your keys in existence — in that one case, lock the phone instead of erasing it.
Should I move funds even if the thief probably can’t get in?
If there’s any doubt: yes. One side of the bet is a transaction fee; the other is everything, on an open-ended timer, because a working seed never expires. Moving is also the only outcome where you get to stop thinking about it.
Why does a hardware wallet fix this?
It takes the keys off the device you carry everywhere. Keys live in hardware that stays home; the phone becomes a watch-only window that can look but not spend. The next lost phone costs you a window, not a vault.
Related reading
- My Bitcoin was stolen — what now — the emergency companion, if the restored wallet shows a spend you didn’t make
- Is your seed phrase compromised? — judging exposure when a device that touched your keys leaves your control
- BIP-39 recovery phrase — the security bible — how the seed should live so a lost phone can’t take it
- Cold storage in 2026 — hardware vs multisig vs SeedQR, once the keys leave the phone for good
- Bitcoin Watchtower — the movement alarm: an email if a watched address moves, weekly proof of silence