You opened your wallet and the balance is wrong, or zero, or there’s an outgoing transaction you never made. Your heart rate is up and every search result is shouting at you. Slow down for three minutes — this page is ordered for exactly this moment: what to check first, what to do in the next ten minutes, and what will only make it worse.
I’ll be honest with you the whole way through, starting now: confirmed Bitcoin transactions cannot be reversed — by anyone. Most stolen Bitcoin is never recovered. What you do in the next hour can’t undo that, but it decides two things that matter enormously: whether the thief gets the rest of your coins, and whether you get robbed a second time by a fake “recovery service”.
TL;DR. First: verify on a public explorer that coins actually left — wallets lie, the chain doesn’t. Second: if anything remains on any address from the same seed, move it to a brand-new wallet with a brand-new seed now — the old seed is burned forever. Third: follow the coins on-chain, but do not pay anyone who promises to get them back; “recovery services” that contact you are scams, all of them. Fourth: report — police, the exchanges involved, and chainabuse.com — for the paper trail, not for miracles. Fifth: find the leak, fix the setup, and put an alarm on whatever cold storage you still have.
The first 60 seconds — confirm it’s really gone
Your wallet app’s balance is a claim. The blockchain is the fact. Before acting on panic, verify the claim.
- Get your addresses. Open the wallet’s receive history or transaction list and copy the affected address (or several). If the wallet is acting strangely, you can paste each one into our address validator to make sure you’re looking at a well-formed address and not a truncated or mangled string.
- Look them up on a public explorer. Paste each address into mempool.space. You are looking for an outgoing transaction you didn’t make: your address on the input side, someone else’s on the output side.
- Don’t confuse incoming with outgoing. A surprising number of “I’ve been hacked” moments are an unfamiliar incoming transaction (dust, a consolidation you forgot, an exchange withdrawal that finally confirmed) or a wallet resyncing and briefly showing a zero balance. If the explorer shows your coins still sitting on your addresses — they are not stolen. Breathe, then go read is your seed phrase compromised? anyway, because something made you nervous.
- Write down the facts. The txid of the theft transaction, the destination address(es), the amount, and the timestamp (block height is on the explorer). You will need all four for every report you file, and later memory is worse than you think.
If the explorer confirms an outgoing transaction you didn’t sign: it’s real. Keep moving.
Stop the bleeding — the next ten minutes
Here is the mistake that turns a partial theft into a total one: assuming the thief “only” got one address.
A modern wallet is an HD wallet — every address it has ever shown you comes from one seed phrase. Whoever signed that theft transaction has the seed, or has a device that holds it. That means every address in that wallet, including ones with coins still on them, including addresses it hasn’t generated yet, belongs to the thief now. Thieves often sweep the fat address first and leave crumbs, or wait to see if more arrives.
So, in order:
- Create a completely new wallet with a completely new seed. Generated fresh, on a device the attacker has no relationship with. The best available option is a hardware wallet, because the new seed is generated inside the device, protected by its secure element, and never touches a computer. If you have an unused one in a drawer, this is its moment.
- Send everything that remains to the new wallet. Pay a fee high enough to confirm in the next block or two — check the next-block rate on mempool.space and err upward. This is the one moment where overpaying the fee is obviously correct: you are literally racing the person who holds your seed.
- Verify the receive address on the new device’s screen before sending — not just in software. If the old computer or phone is compromised, its clipboard and its display are both suspect.
- Never use the old seed again. Not “later, for small amounts”. Not after a factory reset. A leaked seed is burned for eternity — the thief can watch it and drain it years from now, on any address it will ever derive.
If you don’t own a hardware wallet yet, the emergency fallback is a reputable open-source software wallet installed fresh on a device the old wallet never touched (a family member’s phone works). Move the coins there today, and move them again to a hardware wallet when it arrives. Verify the installer’s SHA-256 against the vendor’s published hash with our wallet verifier first — panicked people downloading wallets in a hurry are exactly who fake-wallet campaigns target.
Trace, don’t chase
Once the remaining funds are safe, you can look at where the stolen coins went. On mempool.space, open the theft txid and click through the outputs. Bitcoin is radically transparent: you can follow every hop, forever. Typical patterns you’ll see:
- Fan-out — the loot splits across dozens of fresh addresses to complicate the picture.
- Peel chains — a big balance moves repeatedly, shedding a small payment each hop.
- Consolidation into a busy address — often an exchange deposit address or a mixing service. This is the interesting one: if the coins hit a regulated exchange, that exchange knows whose account received them.
Knowing this, here are the realistic odds, stated plainly. Tracing is easy; recovery is rare. Your coins are recoverable in roughly two scenarios: (1) the thief deposits at a compliant exchange, and your police report reaches that exchange’s abuse desk while the coins are still there — freezes do happen, and speed matters; (2) the amount is large enough (think six figures and up) that a professional chain-analysis firm plus law enforcement plus lawyers can sustain a case for months. For a typical personal theft, neither is likely. I’m telling you this not to crush you but because the next section only makes sense once you’ve accepted it.
The second theft — “recovery services”
Within hours of posting about a theft anywhere public — Reddit, X, a Telegram group, an exchange’s support forum — you will receive replies and DMs from “recovery experts”, “certified crypto forensic investigators”, “ethical hackers”, and helpful strangers who “know a guy who got his funds back”. Some will have polished websites, testimonials, and fake registration numbers. Some will impersonate real firms like Chainalysis or real exchanges.
Every single one of these is a scam. Not most — all. The mechanics vary: an upfront “case fee”, a “recovery dashboard” showing your coins ready to release once you pay “gas”, a request for your seed phrase to “synchronize the recovery”, or a remote-access session to “trace the hack” that drains whatever you have left. The underlying tell never varies: they promise a thing that is not possible. Nobody — not the FBI, not Binance, not a hacker — can reverse a confirmed Bitcoin transaction. Anyone who says otherwise is describing the impossible, which means they are describing a lie. Victims of a first theft are the single most profitable audience for a second one, and these people work that audience full-time.
Legitimate forensic firms exist. They work large cases, through law enforcement and counsel, and they do not contact victims out of the blue. If you engage one, it’s because you found them, verified the company’s legal existence, and understood you’re paying for tracing evidence — not for your coins back.
Report it — what a report actually achieves
File the reports even though they probably won’t bring the coins home. Here’s the honest value of each:
- Local police / cybercrime unit. Gets you a case number. That number is what exchange compliance desks, courts, insurers, and tax authorities act on. In the US that’s IC3; in Thailand, thaipoliceonline.go.th; most countries have an equivalent online portal. Bring the txid, addresses, amounts, timestamps.
- Exchange abuse desks. If the trace shows the coins landing at an identifiable exchange, email that exchange’s abuse/compliance contact with the case number and txids. This is the one lever that sometimes actually freezes funds — and it’s time-sensitive.
- chainabuse.com. The industry-shared reporting database (free, run by TRM Labs). Your report tags the thief’s addresses for every exchange and analytics firm that subscribes — it makes cashing out incrementally harder and helps the next victim’s case connect to yours.
- If your wallet was drained via approvals or a drainer kit — see the revocation and documentation steps in my wallet drainer guide.
What a report will not do: recover coins on its own, move quickly, or generate updates. Treat it as archiving evidence, not as a rescue in progress.
Never again — close the hole, then set an alarm
Bitcoin theft is almost never broken cryptography. The seed leaked, somewhere, and if you don’t find the where, you’ll rebuild on the same rot. Run this checklist honestly:
- Was the seed ever typed into a website or app — a “validation”, an airdrop claim, a fake support chat, a wallet you sideloaded? (The classic. See the drainer red flags.)
- Does a photo of it exist — phone camera roll, cloud backup, a scan in your email?
- Did it live in a note app, password manager, or spreadsheet?
- Was the wallet a hot wallet on a daily-use computer or phone (malware territory)?
- Did anyone physically access the paper — visitors, workers, family?
- Did you install the wallet from a search ad or unofficial source?
Walk through the full self-assessment with our self-custody score — two minutes, eight questions, and it names your weakest layer and the one change that fixes it fastest. Then rebuild: hardware wallet, seed on steel, seed never photographed, never typed, bought direct from the vendor.
And then the part almost everyone skips. The thief in your story had a quiet head start — coins move in silence, and most people discover a drain days or months later, exactly like you just did. You can’t watch the chain 24/7 — but an alarm can. If you still have any bitcoin in cold storage, put a tripwire on it: our Watchtower watches your address and emails you the minute anything moves, plus a weekly “still untouched” heartbeat so silence becomes information. It’s watch-only (it never sees keys, so it can’t move coins), the free tier watches one address with no signup, and if this article had a single practical souvenir, this is it: the next incident, you find out in minutes — while a fee-bump race or an exchange freeze is still winnable — not in months.
FAQ
Can I get my stolen Bitcoin back?
Usually no — transactions are irreversible by design. The realistic exceptions are an exchange freeze (thief deposits at a regulated exchange and your report gets there first) or a large-sum case worth professional chain analysis and lawyers. Plan around not recovering it; spend your energy protecting what’s left.
Can the police actually do anything?
They produce the case number that everything else runs on — exchange freezes, prosecution, insurance, taxes. They will almost never trace and seize coins for a small personal theft. File the report for the paper trail.
Are recovery services legit?
The ones that contact you: no, universally. They monetize desperation with upfront fees, fake dashboards, and seed-phrase requests. Nobody can reverse a confirmed transaction; a promise to do so is the scam identifying itself.
Should I pay a tracing firm?
Only for large amounts, only one you sought out and verified yourself, and only knowing that tracing produces evidence, not coins. For typical personal thefts the math doesn’t work.
How do thieves get seed phrases?
Phishing sites and fake apps the seed was typed into, cloud photos, note apps, fake “support”, hot-wallet malware, and plain physical discovery of the paper. The words leak; the math doesn’t break.
Related reading
- Is your seed phrase compromised? — the companion guide: how to judge whether your words leaked before the sweep happens
- Wallet drainer red flags 2026 — the attack pipeline that causes most of these thefts, and the five-second habit that stops it
- Bitcoin Watchtower — the cold-storage tripwire: email the minute a watched address moves
- Self-custody score — eight questions that find the weakest layer in your setup
- Move Bitcoin off an exchange to a hardware wallet — the safe-withdrawal walkthrough for the rebuild