After a wallet drainer or phishing attack, act in this order: move any remaining assets to a new wallet, revoke token approvals, record the drainer transactions, then trace the stolen tokens on-chain to the cash-out exchange. Speed limits the damage and preserves the evidence needed to trace.

Step 1: Contain the damage

If any funds remain, transfer them immediately to a brand-new wallet with a fresh seed phrase. If your seed phrase was exposed, the old wallet can never be trusted again.

Step 2: Revoke approvals

Wallet drainers often rely on malicious token approvals. Use a reputable approval-revocation tool to cut off the attacker's permission to move your tokens.

Step 3: Capture the drainer transactions

On a block explorer, open your address and find the unauthorized transfers — check the internal transactions and ERC-20 token transfer tabs. Record each TXID and the destination address.

Step 4: Trace the stolen tokens

Follow the transfers forward. Drainers commonly swap tokens on a DEX and then deposit to an exchange. That exchange deposit is the actionable endpoint for a freeze request.

Step 5: Report and get help

Report the phishing site and file a fraud report, then report the site here to protect others. For a full trace, open a free case review, and always verify links with our scam site checker before connecting your wallet.