Who Should You Contact When Cryptocurrency Is Stolen?

The first place to report blockchain theft is the exchange, wallet provider, or financial institution that processed the transaction, followed by the relevant national fraud-reporting body and law enforcement. If the theft involved a known crypto business, report it to that platform’s security or compliance team and preserve the transaction hash, wallet address, exact amount, date, time, and time zone. In the United States, internet-enabled fraud can be reported through the FBI’s Internet Crime Complaint Center, while securities or investment-token fraud may also warrant a report to the SEC or CFTC. Local police can create an official case number, although a specialized cybercrime unit or prosecutor may ultimately be better equipped to request blockchain records.

Also worth reading: Can Stolen Crypto Be Recovered From DeFi After an Exploit in 2026? · How Does Crypto Bridge Forensics Trace Stolen Funds in 2026? · How Does AI Improve Blockchain Fraud Detection Without Creating False Positives?

Report the loss as soon as the theft is confirmed rather than waiting until every possible destination address has been investigated. Early reporting allows an exchange to freeze funds before they are withdrawn or transferred again, and it gives investigators time to link deposit addresses to accounts or to another hack. A report should distinguish facts from assumptions: include what the victim sent, which address received it, and any later addresses already identified, but do not label an unknown party a thief merely because the funds changed hands. The recipient of stolen crypto is not automatically the perpetrator; wallets can be controlled by malware operators, mixers, merchant processors, OTC traders, or victims whose accounts were compromised.

How Blockchain Tracing Actually Works

Blockchain tracing begins with public transaction data, not with magical access to a person’s identity. Investigators start from the compromised wallet’s transaction hash and follow outgoing transfers across the Bitcoin, Ethereum, or other relevant chain. They may identify the first receiving address, determine whether it is a personal wallet, an exchange deposit address, a merchant wallet, a bridge, or a mixing service, and then map subsequent hops. One hop is one transaction or transfer, but investigators often refer informally to a “hop” as movement from one controlled entity to another; a long chain of automated transactions can therefore obscure the practical route much faster than the transaction count suggests.

Public blockchains record addresses and transactions, but they do not normally record the real-world owner of an address. Attribution requires evidence such as exchange KYC records, subpoenaed account information, device data, IP logs, malware infrastructure, screenshots, victim communications, and cooperation from service providers. Investigators may use graph analysis, address clustering, timing correlations, and transaction-pattern analysis to determine whether several addresses probably belong to one entity. The conclusion should carry an appropriate confidence level because address clustering can produce false positives, especially when users share custodial wallets or custodial providers deposit many customers’ funds into pooled addresses.

Attribution becomes easier when stolen funds enter a centralized exchange, because the exchange can associate a deposit with a customer account. It becomes harder when the funds enter a mixer, privacy coin system, decentralized finance protocol, cross-chain bridge, or a service designed to reduce traceability. Mixers and privacy coins do not make every transaction impossible to investigate, but they can make analytical work slower, more expensive, and dependent on external evidence. A 2022 TRM Labs investigation of the Bitget hack illustrated this distinction: reporting initially focused on only 4 BTC being laundered through Wasabi CoinJoin, while most of the stolen assets remained dormant or had not yet been identified as laundered. Tracking is therefore not the same as automatic recovery.

The First 24 Hours: What to Do After Theft

The immediate priority is to stop additional access, not to argue with the suspected thief. If a wallet seed phrase or private key may have been exposed, transfer any remaining assets to a newly generated wallet created on a trusted device, revoke suspicious token approvals where appropriate, and change every related email and exchange password. For a compromised exchange account, contact support through the provider’s official website, disable withdrawals, and request account and device logs. Do not destroy the original device, browser profile, messages, emails, or compromised wallet records; they may contain useful forensic evidence and deleting them can also alert an attacker or prevent legitimate recovery work.

Next, document the incident with precision. Record the blockchain network, asset, contract address for tokens, transaction hashes, originating and receiving addresses, amounts, local time and UTC time, and the method of theft, such as phishing, malware, a compromised seed phrase, SIM swapping, or account takeover. Screenshots should include full URLs, domain names, wallet addresses, and visible timestamps, while saved messages should retain sender identifiers and message headers where possible. The original transaction hash is more useful than an address alone because it proves the exact transfer and allows another analyst to reproduce the path independently.

Contact the receiving exchange immediately if the funds have reached one. Many exchanges have a dedicated fraud or asset-recovery team and can review whether a freeze is legally and operationally possible. The victim should provide the transaction hash, incident report number, identity evidence requested by the exchange, a concise chronology, and proof of ownership. Avoid paying an unsolicited “recovery hacker” who promises a percentage of the funds; genuine investigators generally cannot guarantee success, and advance-fee recovery scams are common. If the theft appears to be an ongoing phishing operation, report the website and wallet details to the hosting provider or domain registrar as well, because that may prevent other users from becoming victims even if the stolen funds are not recovered.

Reporting, Freezes, and Cross-Border Cooperation

A report to law enforcement does not itself freeze a transaction. A freeze generally requires cooperation from a custodian or exchange that controls the relevant account and can act after receiving lawful instructions from the appropriate authority. The victim’s own police report may be useful, but a prosecutor, cybercrime unit, or agency familiar with digital assets may be better positioned to seek records rapidly. The time between theft and exchange action matters: under anti-money-laundering systems, an exchange may release funds or move them onward after identity checks and review periods, so delays of hours or days can materially reduce the chance of recovery.

International cases add another layer. A wallet in one country may deposit into an exchange operated by a company registered in another country, while the beneficiary withdraws through an OTC desk or payment network in a third jurisdiction. Investigators can use mutual-assistance processes, subpoenas, warrants, and direct compliance cooperation, but each step may require translation, identity checks, and formal legal requests. Publicly naming an address is not equivalent to serving a legal process, and an exchange cannot identify a suspect solely because an address appears on a public ledger. Cooperation between agencies can still be effective when evidence is packaged clearly, especially when transaction hashes and precise timestamps are supplied.

The FBI has seized cryptocurrency connected to North Korean fraud networks, including a reported USD 61 million action linked to a Pig Butchering operation announced in 2024, showing that large criminal networks can face asset seizures. Such actions are possible, but they are not a routine refund process for every victim. Public recoveries may also result from earlier investigations, information sharing, or a successful prosecution rather than from a single individual reporting a loss. A realistic report should state that the goal may be identification, evidence preservation, freezing, seizure, prosecution, or partial return of funds, with no outcome guaranteed.

What Tracing Can and Cannot Recover

Tracing is most useful when the funds remain on a transparent blockchain, the path contains identifiable exchange deposits, and investigators obtain timely legal cooperation. It is less effective after funds are converted into privacy-oriented assets, spread across many small transfers, routed through mixers, or moved through services that obscure the connection between blockchain and real-world identities. Wasabi CoinJoin, for example, can make Bitcoin transaction ownership more difficult to establish because multiple users contribute to a transaction intended to reduce linkability. That does not mean a stolen deposit becomes untraceable, but it changes the nature of the evidence required and may prevent a public address from being confidently assigned to a particular thief.

A tracing report may produce a graph, a list of addresses, an estimate of how much moved where, and a set of leads for investigators. It should not promise that an automated AI tool can “identify the hacker” from an address alone. Artificial intelligence can help flag transaction patterns, cluster large datasets, rank suspicious addresses, and reduce repetitive analyst work, but it can also generate false matches if trained or prompted with incomplete data. An AI Cryptocurrency Analyst should therefore explain its evidence, uncertainty, assumptions, and data sources rather than presenting a probabilistic lead as a confirmed identity.

Recovery prospects also depend on whether the victim can prove ownership and whether the funds are still in a reachable account. If a thief has already converted assets into cash through several regulated or unregulated channels, tracing may identify the network without producing a return. If a victim reports late, reports to the wrong institution, or sends funds to an alleged recovery agent, the remaining chance can decline substantially. The value of tracing is not limited to recovery: identifying infrastructure, preventing further transfers, documenting the incident, and supporting prosecution are legitimate outcomes.

Comparing Reporting and Tracing Options

The best option depends on the type of loss, the urgency, the suspected destination, and the victim’s location. A private recovery firm may be useful for technical investigation, but it is not a substitute for law enforcement and should be evaluated cautiously. A lawyer specializing in digital assets can coordinate civil claims and regulatory issues, while an exchange compliance team can stop a supported account only within its own operational and legal authority. The following comparison highlights the main differences.

FeatureOption A: Exchange and platform reportOption B: Law enforcement and specialist investigation
SpeedOften fastest for a supported account or deposit addressFormal process may take longer, but can coordinate legal action
Best useFreezing funds and obtaining account-linked recordsCross-border tracing, subpoenas, seizure, and prosecution
Main limitationCannot reach wallets or services outside its controlNo guaranteed recovery; jurisdiction and evidence requirements matter
Typical costUsually no direct fee; may require identity verificationGovernment reporting is generally free; private counsel or analysts charge fees
Evidence neededTransaction hash, ownership proof, account detailsFull chronology, device records, communications, and chain evidence
Best forVictims who know the funds reached a custodial exchangeLarge, complex, international, or unresolved incidents
For an individual loss involving a transparent blockchain and a known exchange, beginning with the exchange and then filing an official report is often practical. For a large hack, a compromised business, or a cross-border network, a specialist investigator and experienced legal counsel can save time by organizing evidence and identifying which agency has jurisdiction. Free public tools such as block explorers are helpful for basic verification, but paid forensic platforms may provide deeper entity labeling, historical data, and faster collaboration. Pricing varies widely: some public blockchain tools are free, whereas professional investigations may be billed by the hour, by case complexity, or on a retainer.

Common Mistakes That Reduce the Chance of Recovery

One common mistake is assuming that every wallet address is a person. An address can belong to an exchange, a smart contract, a bridge, a merchant processor, or a group of users, so ownership must be demonstrated through corroborating records. Another mistake is sending suspicious funds to the suspected thief in an attempt to negotiate, which can expose the victim to further fraud and may complicate later reporting. Victims should not impersonate law enforcement, threaten an exchange publicly, or publish a suspect’s personal information without verified evidence; online amplification can create defamation, safety, and evidence-handling problems.

Another error is relying on a recovery company that guarantees success. No legitimate investigator can guarantee that stolen crypto will be returned, because privacy tools, cross-border transfers, time delays, and legal limits control the outcome. A reputable firm should explain its methodology, identify the regulated jurisdictions in which it operates, avoid asking for the victim’s seed phrase, and provide a contract and transparent fee structure. The victim should independently verify the company through official business records and established references. If a service asks for an advance fee equal to 10%, 20%, or more of the estimated recovery, that is not proof of expertise; it is a strong warning sign.

Finally, many victims fail to preserve the original evidence or fail to report the exact transaction. A screenshot of only the balance page may not identify the stolen transfer, while deleting a compromised device can remove malware samples and browser data. Keep original files, export conversation history, and record the UTC timestamp. Recovery is often a data-management problem before it is a technical problem.

When to Act and What It May Cost

Act within hours if a wallet is compromised, a large balance is at risk, or funds are moving through a centralized exchange. For a smaller incident with time to verify the transfer, the victim should still report promptly because exchanges may have internal review windows, but should avoid panic-driven payments to recovery agents. As of 29 September 2026, reporting channels and exchange policies can change, so the victim should confirm current procedures through official provider pages rather than relying on an old blog post or an unsolicited social-media message. The exact legal route depends on the victim’s country, the exchange’s location, the type of asset, and whether the event involved a business or an individual investment.

Public reporting is generally free, although exchanges may require identity verification and law-enforcement agencies may not guarantee an investigation. Private blockchain-forensics work can range from a modest fixed fee for a simple transaction review to several thousand dollars or more for a complex international case, depending on analyst time, data licensing, legal support, and the number of entities tracked. These figures are approximate rather than a published universal tariff. A legitimate engagement should define scope, deliverables, confidentiality, payment terms, and whether success fees are permitted before sensitive records are shared.

The practical sequence is to secure accounts, preserve evidence, report to the relevant platform, file with law enforcement, and commission a qualified analyst when the path is complex. The correct expectation is a documented investigative process, not a guaranteed refund. Blockchain records are durable, but rights over the assets are not automatically attached to the records; successful recovery requires a connection between the victim, the transaction, the receiving entity, and a legal authority able to act.