Last updated: August 12, 2026
- – The first 60 minutes matter most for tracing and freeze requests.
- – If a bank transfer was used, ask the bank what recall or fraud-reporting path exists.
- What changes: tracing becomes much harder, and exchange freezes may be less likely.
- What changes: the attacker may have seen passwords, seed phrases, or 2FA codes.
Quick Answer: Sent crypto to a scammer? Act within the first hour: save the transaction hash, contact the exchange or payment service, lock down accounts, and file reports. Sometimes that is enough to stop a second loss or freeze funds before they move again. This article explains what to do if you sent crypto to a scammer and when recovery is still possible.
Don’t wait and hope. Once you realize you sent crypto to a scammer, speed beats panic. Save everything, move quickly, and use the narrow recovery routes that sometimes still exist. In a few cases, you can stop a second loss, preserve evidence, or get an exchange to freeze funds while they are still moving through a regulated platform. Other times, the chain has already done its thing: the transfer is final, and you switch to damage control.
Key facts
– Confirmed on-chain transfers are usually irreversible.
– The first 60 minutes matter most for tracing and freeze requests.
– A transaction hash is the single most useful record.
– If a seed phrase was exposed, the wallet should be treated as compromised.
– Upfront-fee recovery offers are high-risk and should be checked carefully.
– The FBI IC3, FTC, and Action Fraud are common reporting channels.
This is information, not financial advice. Your own situation may involve tax, fraud, or legal issues that depend on your country and the exact facts, so a qualified adviser or lawyer can help with your case.
First: Figure Out What Kind of Crypto Loss This Is
Once the transfer is confirmed on-chain, the blockchain usually won’t reverse it. That changes the whole playbook. A wallet transfer to a scammer? Recovery gets hard fast. Still sitting at an exchange, bridge, or custodian? Then freezing or tracing the funds may be more realistic. And if you entered a seed phrase or fell for remote access, the damage may go beyond one transfer because the thief may still be able to drain other wallets.
Here is the simple split I would use, based on guidance from the FBI IC3 and FTC fraud reporting pages:
| Situation | Best Path | Why Other Options Fail |
|---|---|---|
| You sent crypto to a scammer’s wallet and the transfer is confirmed | Preserve evidence, trace the path, report to the right places | The chain is usually irreversible, so “asking the scammer nicely” or sending more money rarely helps |
| You sent from an exchange account | Contact the exchange’s fraud team immediately | A normal support ticket can be too slow; fraud teams may act faster if funds are still in-house |
| You gave away your seed phrase or remote access | Transfer any remaining assets from a safe device, then secure every account, and consult a qualified adviser or lawyer | Focusing only on the one transfer misses the bigger risk of repeated theft |
| You paid by bank card or bank transfer into crypto | Contact the bank and the exchange used for on-ramp/off-ramp | Crypto itself may be gone, but the fiat side sometimes still has a fraud path |
The first question I would ask is simple: did the scammer get access to your wallet, or only to one transaction? That answer decides whether you are stopping a single loss or a chain of them. For a situation like this, a lawyer or licensed fraud specialist can help you judge which recovery path is realistic.
Quick check: If you can still control any wallet or exchange account, you need both recovery steps and security steps right now. A qualified professional can help if you are unsure which one comes first.
The 5 Things to Do in the First Hour

If you only do one thing after realizing the scam, make it documentation. Time matters because coins can move quickly through multiple wallets and exchanges. Choose the wrong first move, and you may wipe out evidence or hand the scammer another opening.
Here is the order I would follow:
- Stop all contact with the scammer. Do not “verify,” do not negotiate, and do not send a second payment to unlock the first one. Recovery-by-conversation is a common trap.
- Save the transaction record. Copy the transaction hash, wallet addresses, timestamps, network used, screenshots, chat logs, emails, usernames, website URLs, and any payment references.
- Secure every account you still control. Change passwords for email, exchange, and wallet-related accounts from a clean device. Turn on app-based two-factor authentication where possible, and consider a cybersecurity professional if you think more than one account is exposed.
- Move any remaining assets to a safe wallet if you still control the keys. Use a device you trust. If you suspect a seed phrase leak, treat the old wallet as compromised and get professional help if you are not sure the device is clean.
- Report the fraud to the exchange or platform involved. If the scam started on a known platform, use its fraud or abuse reporting process, not only general support.
- File reports with law enforcement and cybercrime channels in your country. In the U.S., that often means the FBI’s IC3 and the FTC; in the U.K., Action Fraud; in the EU, local police or cybercrime units. Other countries have their own equivalents.
- Write a clean timeline. What happened first, what you clicked, what you sent, where the scammer contacted you, and when you realized the fraud. Clear chronology helps investigators more than a long emotional story.
Panic drives a lot of victims toward random “crypto recovery” services. Some are legitimate investigators. Many are just another scam layer. If someone promises they can get your money back for an upfront fee, I would treat that claim very carefully and verify it with a lawyer or consumer-protection agency first. Sounds slick. Usually isn’t.
Quick check: If your phone, email, or seed phrase may also be compromised, don’t just chase the lost transfer; secure the whole account stack with help if needed.
When an Exchange, Bridge, or Custodian Is Involved
If the scammer’s wallet is not the end of the trail, your best shot is often at the exchange or service where the funds land next. That is why the transaction hash matters so much. It lets a fraud team or investigator follow the path. But once the crypto goes through a privacy tool, a chain of fresh wallets, or an offshore service with weak compliance, the trail gets murky in a hurry.
Report in parallel: to the exchange, to your bank if fiat was used, and to law enforcement. I would not pick one lane and sit on it. The people who can act fastest may not be the ones who investigate best.
Some useful references exist if you want to understand the process:
– FBI Internet Crime Complaint Center: https://www.ic3.gov/
– FTC fraud reporting: https://reportfraud.ftc.gov/
– Action Fraud (U.K.): https://www.actionfraud.police.uk/
– Chainalysis has public guidance on tracing and crypto compliance work, which can help explain why timing matters.
– U.S. Secret Service crypto fraud guidance: https://www.secretservice.gov/investigation/cryptocurrency
If the scam used a centralized exchange, ask for the fraud team, not just customer service. In your report, include:
– transaction hash
– sending and receiving addresses
– amount and network
– account names, emails, phone numbers, and profile links
– screenshots of the scam site or chat
– your own account identifiers with that platform
– the exact time you noticed the loss
The exchange may say it cannot reverse a blockchain transfer. That can be true and still not end the matter. Freezing a downstream account is different from reversing an on-chain transfer. The sooner you report, the better that option looks.
Quick check: If any part of the scam touched a regulated exchange or payment service, use that company’s fraud channel immediately.
If You Gave Away a Seed Phrase or Approved a Malicious Wallet Access

If you typed a seed phrase into a fake site, handed it to a “support” agent, or approved a malicious smart contract, the risk is broader than one transfer. The scammer may be able to empty the wallet later, even if the first theft already happened. In practice, I would treat the wallet as compromised.
Do this in order:
- From a clean device, create a new wallet. Do not reuse the compromised seed phrase.
- Transfer any remaining assets out of the old wallet immediately. If you hold multiple tokens, prioritize the ones that can be drained most easily.
- Revoke suspicious token approvals where the chain supports it. Tools such as Etherscan’s token approval checker, Revoke.cash, or the explorer tools for other networks can help you see what permissions exist.
- Check email, cloud storage, and password manager accounts. A lot of wallet theft starts with a broader account compromise.
- Scan the device for malware or remote-access tools. If you think the device itself is compromised, use a different one for every recovery step.
- Keep the old wallet only as evidence. Do not keep using it for new transfers.
A generic article often misses the point here by treating every scam as a one-time transfer problem. It is not. If the attacker has your seed phrase, they do not need your permission again. If the attacker tricked you into approving a contract, the permissions may survive after the first theft. And if you’re unsure whether approvals or a device compromise are involved, a security professional can help you check safely.
This is also where people make the painful mistake of “testing” the wallet by sending a tiny amount back into it. If it is compromised, that small test can become a second loss.
Quick check: If the scam involved your seed phrase, private key, or wallet approvals, assume the wallet itself is unsafe until proven otherwise.
What To Do About Banks, Taxes, and Recordkeeping
Used a bank card, bank transfer, or centralized exchange to buy the crypto before sending it? Then the fiat side may still matter. Banks sometimes have fraud, card-dispute, or authorized-payment complaint processes, depending on your country and the payment rail. I cannot tell you which one applies everywhere because the rules vary by jurisdiction and change often. A bank or qualified adviser can help with your specific case.
Separate the crypto loss from the fiat trail:
– If a card was used, call the card issuer’s fraud or dispute team.
– If a bank transfer was used, ask the bank what recall or fraud-reporting path exists.
– If the scammer persuaded you to move money through an exchange, save the exchange records too.
– If you need a formal complaint, keep your language factual and brief.
For taxes, the loss may or may not be deductible or reportable in your country. That depends on local tax law, how the asset was held, and whether the loss is treated as theft, fraud, or something else. I would not assume the answer from a forum post. A tax professional is the right person to ask.
Keep a file with:
– transaction hashes
– dates and times
– wallet addresses
– screenshots
– platform messages
– bank or card statements
– police or fraud report numbers
– names of anyone you spoke with and when
That file does two things: it helps investigators, and it stops you from retelling the story differently every time someone asks. Consistency matters.
Quick check: If money came from a bank or card before crypto was sent, the crypto loss is only one part of the case.
Edge Cases Where the Normal Advice Breaks Down
If your situation falls into one of these, the standard playbook changes.
-
The scammer used a privacy coin or mixer.
What changes: tracing becomes much harder, and exchange freezes may be less likely.
What to do instead: focus on the on-ramp, the off-ramp, and the scammer’s identity clues rather than the middle of the chain. -
You were tricked into a remote-access session.
What changes: the attacker may have seen passwords, seed phrases, or 2FA codes.
What to do instead: treat every related account as exposed, change credentials from a clean device, and check for new logins or forwarding rules. -
The scam was a fake investment platform showing fake profits.
What changes: the screen may show balances that never existed on-chain.
What to do instead: ignore the fake dashboard, preserve the records, and trace actual transfers out of your wallet or exchange. -
The payment went through a crypto ATM or P2P platform.
What changes: the intermediary may have stronger identity records or quicker compliance tools than a pure wallet-to-wallet transfer.
What to do instead: report both the platform and law enforcement fast, because identity records can matter more here. -
The scam involved a romance, job, or “support” impersonation.
What changes: you may have a longer message trail and more identity evidence than usual.
What to do instead: save the whole conversation, not just the final payment request. That context can be useful. -
The wallet is on a chain with low-cost, fast transfers.
What changes: the funds can move far before anyone wakes up.
What to do instead: report immediately and include the exact network, because speed is part of the evidence.
Quick check: If the scam used a fake platform, a privacy tool, or remote access, the usual “call the exchange and wait” advice is not enough.
What Recovery Claims I Would Be Skeptical Of
If someone contacts you claiming they can “recover” your crypto, slow down. That does not mean every recovery professional is fake. It means the incentives are skewed. Scammers know victims are desperate and more likely to pay a second fee.
Red flags:
– they ask for an upfront “unlock” fee
– they guarantee recovery
– they claim special access to blockchain investigators or regulators
– they tell you to move funds to a new wallet they control
– they pressure you to act before you compare options
A real investigator or lawyer should be able to explain the process, the limits, and the costs without promising a result. If they cannot explain why they are the right fit, I would walk away.
I would also be cautious of:
– fake law firms
– fake “crypto tracing” firms
– social media accounts claiming insider recovery
– Telegram groups offering fund retrieval
– anyone who asks for your seed phrase to “verify ownership”
Quick check: If the recovery pitch sounds urgent, secretive, or guaranteed, treat it like a second scam until proven otherwise.
FAQ
Can I reverse a crypto transaction?
Usually no, not once it is confirmed on-chain. That is why speed, tracing, and reporting matter so much.
Should I file a police report if the scam was online?
Yes. Even if local police cannot recover the funds, the report can help establish fraud, support exchange requests, and create a record for banks or tax professionals.
If I sent crypto from an exchange, can the exchange undo it?
Usually not by reversing the blockchain transfer. But the exchange may still be able to help with freezing, tracing, and account review if you report quickly.




