Minute 0–5: stop the bleed
Stop interacting with the suspicious message, app, browser extension, or site. Do not connect, sign, approve, install a “fix,” or send a test payment. Take note of what happened without sharing sensitive data publicly.
Minute 5–15: use a trusted path
Open the wallet or exchange only from a saved bookmark, manually typed address, or its known official app. Check the service’s verified status and support channels. Do not use links from search ads, replies, or direct messages.
Minute 15–30: secure accounts you control
- For an exchange: change the password from a trusted device, review sessions and withdrawal settings, and enable or re-check two-factor authentication.
- For email: secure the mailbox tied to the account; it is often the reset path attackers want.
- For a device: do not use a device you believe is compromised for sensitive actions. Use a known-clean device and remove unknown remote-access tools or extensions before signing in again.
- If a seed phrase or private key may have been exposed: assume that wallet is no longer safe. From a known-clean device, create a new wallet and follow its official guidance before moving any remaining assets; never reuse the exposed recovery phrase.
What not to do
Do not give a “helper” your seed phrase, private key, password, or recovery code. Do not pay a recovery fee to someone who contacted you first. Do not make a rushed transfer until you understand the destination and the risk.
