Hour one: stop the bleeding
- Make no further payments. Release fees, tax payments, verification deposits and insurance charges are all part of the same fraud, never a route out of it.
- If a wallet was compromised, create a brand new wallet with a fresh seed phrase and move any remaining assets there. Never reuse the old phrase.
- Revoke outstanding token approvals from the affected address if you are able to do so safely.
- Disconnect any remote access software you were asked to install, then remove it.
Hours one to three: preserve everything
Evidence is the one thing entirely within your control on day one. Capture it before the other side removes it.
- Export or screenshot every transaction: date, amount, asset, network, destination address and transaction hash.
- Save the full chat history — Telegram, WhatsApp, Instagram, dating apps — including profile pages and phone numbers, before accounts are deleted.
- Screenshot the platform dashboard, its URL, the account page and any support correspondence.
- Download exchange statements and withdrawal confirmations while your account is still accessible.
- Write a plain timeline: how contact began, each payment and its date, what you were told at each stage.
Hours three to twelve: notify
- Report to Action Fraud (actionfraud.police.uk or 0300 123 2040) if you are in England, Wales or Northern Ireland. In Scotland, call Police Scotland on 101 — Action Fraud does not cover Scotland.
- Tell your bank in writing if a card payment or bank transfer funded the purchase, and ask them to log the notification time.
- Report the destination address to the exchange it belongs to if you can identify one, quoting your crime reference.
- Change passwords and enable app-based two-factor authentication on your email and exchange accounts.
Day one, later: what not to do
- Do not respond to anyone who contacts you offering to recover the funds — approaches following a loss are common and usually a second fraud.
- Do not send your seed phrase, private keys or remote access to anyone, for any stated reason.
- Do not delete the fraudulent app or accounts before you have captured the evidence from them.
- Do not pay anyone in cryptocurrency for help with a cryptocurrency loss.
After day one
Once the record is preserved and reports are filed, the useful question becomes where the funds actually went. That is what a trace answers, and it is answerable weeks or months later — the ledger does not forget. What cannot be reconstructed later is the material you failed to save on day one.
If you are looking at your own case rather than reading generally, our cryptocurrency investigation service explains how a case is scoped and worked, the asset tracing hub covers the network-specific work, and our overview of cryptocurrency scam recovery in the UK sets out what is realistic. Asset pages: USDT tracing, Bitcoin tracing and Ethereum tracing. You can also contact the investigations team directly.
Common questions
- Is it too late if a few days have passed?
- No. The onchain record is permanent, so tracing remains possible long afterwards. Act now on preservation and reporting rather than assuming the window has closed.
- Should I contact the scammer to try to get funds back?
- No. It rarely helps and often leads to further demands. Preserve the conversation as evidence instead of continuing it.
- Will my bank refund me?
- That depends on how the payment was made and the bank's own assessment. Notify them promptly and in writing regardless — delay weakens any claim.
Have a case you want reviewed?
We scope at intake and tell you honestly whether the onchain data supports a traceable case.
Key terms in this guide
Plain-English definitions from the Wallsec glossary.