That structure matters for a case. It means the addresses involved are usually part of a larger pattern rather than a one-off, and it means the proceeds follow a laundering routine that has been used before — which is exactly what makes them traceable.
The uncomfortable part. Nothing was hacked. The signature was valid, the transaction was valid, and the blockchain did what it is supposed to do. That is also why nobody — not us, not a developer, not an exchange — can reverse it. What can be done happens afterwards, to the money, not to the transaction.
| What you approved | What it actually allows | Visible in your wallet history? |
|---|---|---|
| Token approval an on-chain allowance | A named contract may move a token on your behalf, frequently for an unlimited amount and with no expiry. Granted once, usable indefinitely | Yes — it is a transaction you paid gas for |
| Off-chain permission a gasless signature | The same power to move tokens, granted by signing a message rather than sending a transaction. The attacker submits it later, at a moment of their choosing | No — nothing is recorded until it is used |
| Collection-wide approval typical for NFTs | Permission over an entire collection at once, rather than a single item. One signature, everything of that kind in the wallet | Yes, but the wording rarely conveys the scope |
| Blind signature an opaque transaction | A request whose contents cannot be displayed in readable form. It may bundle several transfers into one call, so the wallet empties in a single confirmation | Yes — after the fact |
This is also why a drain sometimes happens long after the interaction that caused it. An approval does not expire on its own, and an unused off-chain permission sits with the attacker until they decide it is worth spending gas on.
A reward is waiting, and claiming it requires connecting and signing. The reward does not exist; the signature does.
Reached through a paid search result, a link in a chat, or a spelling that differs by one character.
A project's own account posts a mint link because the account itself was taken over. The source looked right, because it was.
A person appears after you post a problem publicly, offers to fix it, and directs you to a wallet-connect page or a QR code.
Pages offering to check or revoke your approvals, which ask you to sign in order to do it.
The one rule that holds across all of them. If the flow ends in a signature you cannot read in plain language, stop there. A request that cannot be explained by the site asking for it is not a formality — it is the payload.
We investigate on Ethereum, Bitcoin, Tron, BSC, Polygon and Solana, where each of those steps is permanently visible and can be followed across the bridge that was meant to hide it. We do not work with Monero, because it cannot be traced, and we say so at the first call instead of billing the attempt.
In your favour. The proceeds are ordinary transferable assets that have to be laundered before they are worth anything, and the routine used to launder them is often shared across campaigns run by the same kit. Both facts make the money followable. We flag stolen transactions to AML providers within four hours of intake, so the marker is waiting at the services the funds are heading towards; a freeze request to an exchange takes 2–4 days once filed, and the formal block that follows a police report adds 2–3 days.
Against you. Speed. A drain is executed and dispersed in minutes, while an investigation begins whenever the victim gets in touch. Cases that reach us the same day are a different proposition from cases that reach us a month later, and no amount of skill compensates for funds that were cashed out three weeks ago.
What recovery looks like when it works: the assets are traced through the swaps and bridges, flagged, and stopped where they touch a service with a compliance team and a customer behind the account. Return then follows the ordinary timetable — 6–9 months from an exchange, 6–36 months for complex or multi-jurisdictional cases. A freeze is measured in days; being repaid is not. Full timings are on our data page.
A cold-wallet theft we handled, documented on our cases page: $200,000 taken, $18,000 frozen on Solana in a cross-chain trace. We publish that case for the same reason we publish the difficult answers here — most of that money was already gone by the time the case reached us, and a page that only shows the recoveries would be telling you about our marketing rather than about your odds.
Our published figure is 68% success rate on accepted cases · measured over the past 24 months. The word accepted carries the weight: we decline cases where we see no realistic prospect of recovery, and drainer cases that arrive weeks late are frequently among them.
The FBI's Internet Crime Complaint Center has issued repeated advisories about fictitious law firms contacting crypto scam victims and offering to recover funds for an up-front fee. Between February 2023 and February 2024 alone, victims re-targeted this way reported losses of more than $9.9 million. Both advisories are public: PSA240624 and PSA250813.
This applies to us too. We do not cold-message victims, we are not affiliated with any government agency, and no agency refers cases to us. If someone approaches you in our name, it is not us — report it to IC3. Before engaging anyone, including us, run the ten-point check on our verification page; our registry entries are published in full on credentials.
Nobody can. What exists is a freeze after the funds reach a service with an operator, and a return after that.
The phrase cannot be un-shared; the wallet is finished and the case becomes about the money, not the wallet.
It cannot be traced, so we decline rather than bill the attempt.
Outside what we can work effectively.
Non-negotiable.
Declined on the first call.
Forensics and the evidence base are ours; police reports, freeze filings and court applications are carried out by partner law firms in the relevant jurisdiction.
Recovery is decided by courts, exchanges and token issuers.
Related: all six types of crypto theft and their recoverability · fake exchanges and platforms · how a recovery case runs end to end · what happens in the first four hours.
A wallet drainer is malicious code that persuades you to sign something — an approval, an off-chain permission, or a transaction whose real contents sit behind a friendly button — and then uses that signature to move everything it can reach out of your wallet. Your keys are not stolen and your recovery phrase is usually never seen: the wallet does exactly what a signature you gave told it to do. Most drainers today are rented kits, so the people who wrote the code and the people who built the site that got you to sign are frequently not the same.
Response within two business hours. Confidential. Success-fee terms on recovery work.