The distinction everything else hangs on. A freeze is an exchange or issuer stopping the funds moving — that can happen in days. A recovery is money arriving back with you, which needs a court order or an issuer's payout process: 6–9 months from an exchange, longer for stablecoins, 6–36 months for complex cases. Every dishonest recovery site works by quoting the first number to answer the second question.
A token or project raises money, then the people behind it drain the liquidity and disappear. Because the funds move through decentralised exchanges and bridges by design, and because the operators are pseudonymous from the start, this is the hardest category in this list to recover from — and the one most likely to be misrepresented to you by firms that need the case. How a rug pull works, and the narrow conditions under which anything is recoverable →
A relationship is built over weeks or months — romantic, friendly or professional — and then an investment opportunity appears inside it. The victim funds an account that looks real, sees returns that are not, and is asked for more. Losses here are among the largest of any category because the victim sends the money themselves, repeatedly. How the money moves, and when it can still be caught →
A malicious contract or fake site obtains a signature or an approval, and empties the wallet in one transaction — often for assets the victim never intended to touch. The theft is instant, but the funds still have to be laundered and cashed out afterwards, which is where the opportunity to intervene lies. Which permission was abused, and what to do in the first hour →
A trading site, app or broker that looks entirely ordinary, takes deposits, shows a growing balance, and blocks withdrawals — usually by demanding a tax, fee or verification payment first. The balance was never real; the deposits were. How the platform is built, and where the deposits went →
The attacker takes control of the phone number, defeats SMS-based two-factor authentication, and withdraws from the victim's own exchange account. Distinctive because the theft leaves a clear trail on the exchange's own systems — the account is the crime scene, and it belongs to the victim.
Malware or a spoofed address causes a transfer to go to the wrong destination — frequently an address that differs from the intended one only at the beginning and end. It rarely appears on lists of scams because it feels like the victim's own mistake. It is not: it is an attack, and it is one we have handled — a $40,000 USDT transfer to Kraken sent to a manipulated address is among the cases documented on our cases page.
No percentages here — they would be invented. What follows is which conditions have to hold for a case in each category to be worth opening at all.
| Category | Recovery is realistic when… | Typical difficulty |
|---|---|---|
| Rug pull | The proceeds were consolidated and moved to a centralised exchange, and it is early enough that they are still there | Hardest |
| Romance / investment | Deposits went to accounts at real exchanges, and the case is opened while the funds remain in the chain of accounts | Moderate |
| Wallet drainer | The drained assets are traced and reach a screening service before cash-out | Moderate |
| Fake exchange | Deposits are traced out of the platform to identifiable accounts elsewhere | Moderate |
| SIM swap | Usually the strongest position — the withdrawal is documented by the victim's own exchange, and there is a counterparty on both ends | Best odds |
| Address manipulation | The receiving address is at, or routes into, an exchange | Varies sharply |
Why we publish the difficult answers. Our figure is 68% success rate on accepted cases · measured over the past 24 months. The word accepted is doing real work: we decline cases where we see no realistic prospect of recovery. That is a strange thing to advertise — and in a sector whose principal business model is charging desperate people for hope, it is the most informative thing we can tell you about ourselves.
The FBI's Internet Crime Complaint Center has issued repeated advisories about fictitious law firms contacting crypto scam victims and offering to recover funds for an up-front fee. Between February 2023 and February 2024 alone, victims re-targeted this way reported losses of more than $9.9 million. The advisories are public: PSA240624 and PSA250813.
This applies to us too. We do not cold-message victims, we are not affiliated with any government agency, and no agency refers cases to us. If someone approaches you in our name, it is not us — report it to IC3. Before engaging anyone, including us, run the checklist on our verification page; our registry entries are published in full on credentials.
It cannot be traced. We decline rather than bill the attempt.
Outside what we can work effectively.
Non-negotiable.
Not our field.
Declined at the first call.
We stop, at whatever stage we find out.
Forensics and the evidence base are ours; police reports, freeze filings and court applications are carried out by partner law firms in the relevant jurisdiction.
Recovery is decided by courts, exchanges and token issuers. Anyone promising the outcome is promising something they do not control.
The ones where the money reaches a centralised exchange and is still sitting there. An exchange has an operator, a compliance team and an account holder behind the address, so there is somebody who can be asked to stop the funds and somebody a court can order to return them. Thefts where the funds stay on-chain — swapped through decentralised exchanges, bridged between networks, pushed through a mixer — have no such party. That distinction matters far more than what the scheme was called.
Response within two business hours. Confidential. Success-fee terms on recovery work.