Why you should know this
An incident creates urgency, shame and conflicting advice. A written sequence lets us act on facts: protect the main identity account, stop additional authority, preserve evidence and reach genuine support.
Anyone can be targeted. The useful question is not “How could I fall for this?” but “What can I still protect now?”
Work in phases: contain, preserve, recover, learn
Contain means stopping additional access or authority. Preserve means keeping evidence before it disappears. Recover means restoring legitimate control through official processes. Learn means fixing the dependency that allowed the incident.
These phases overlap. Changing an email password can contain access while session records preserve evidence. The important point is not to chase the stolen asset so quickly that we expose another wallet, erase the timeline or obey a recovery scammer.
If there is immediate physical danger, coercion or a threat to personal safety, move to a safe place and contact appropriate local emergency services. Account steps come after personal safety.
First, identify the type of compromise

- Email or provider account: unknown login, password reset, changed recovery method or withdrawal.
- Device: malware, remote-access app, lost phone or suspicious browser extension.
- SIM: unexpected loss of service or carrier notice.
- Self-custody wallet: seed phrase, private key or unsafe signature may be exposed.
- Transaction only: an unintended transfer occurred, but login authority is uncertain.
The type determines which secret must change. A provider password can be reset; a phone number can be protected through the carrier; a disclosed seed phrase cannot be made unknown again. An incident may involve several types, so do not stop after the first obvious fix.
The first fifteen minutes

From a trusted device and network, open your written contact sheet—not a search advertisement. Secure the primary email, because it often controls resets. Contact the provider’s fraud or security channel and ask for the controls available for the account. If the phone number failed unexpectedly, contact the carrier. Note the time of every action.
Do not promise a caller that you will “cooperate” by reading an OTP. Do not install remote software. Do not move funds to a safe address supplied by support in a direct message. Genuine providers can open a case in their authenticated system.
The first-response sequence
- Use a clean, trusted device. Disconnect an obviously compromised device from sensitive activity. Do not erase it before preserving necessary evidence.
- Secure the primary email. Change its unique credential, remove unknown sessions, review recovery details and forwarding rules, and strengthen MFA.
- Contact the genuine crypto provider. Use the official app, bookmarked site or published number. Request the available security controls and obtain a case reference; a freeze or recovery is not guaranteed.
- Review connected authority. Remove unknown sessions, API keys, devices or third-party connections where the provider supports it.
- Contact the mobile carrier if SIM swap or number takeover is possible. Ask about account security and record the reference.
- Protect linked bank and payment accounts. Use each institution’s official fraud channel.
- Preserve evidence. Save messages, full URLs, email headers where practical, transaction hashes, addresses, times, amounts, screenshots and support references.
- Report through appropriate official channels. The correct route depends on the facts and jurisdiction.
Inspect the email takeover carefully

After changing the email credential, sign out other sessions and review recovery addresses, phone numbers, passkeys, app passwords, delegated accounts and connected applications. Inspect forwarding rules and filters for words such as “security,” “withdrawal,” “code” or the provider name. Attackers may hide or redirect alerts while leaving the inbox looking normal.
Check sent mail, deleted mail and recent account activity. Warn contacts if the account sent fraudulent requests. Secure the recovery email and platform account used to synchronize passkeys. A new password does not remove a malicious forwarding rule or an already-authorized session by itself.
Custodial and self-custody response are not the same
| Incident | Authority to protect | Possible first route |
|---|---|---|
| Custodial login stolen | Email, password/passkey, MFA, provider sessions | Provider security case and credential recovery |
| SIM swap | Mobile number and every SMS-linked account | Carrier plus affected providers |
| Wallet app compromised but phrase private | Device, app source and wallet connections | Clean device and official wallet guidance |
| Seed phrase/private key exposed | The remaining assets controlled by that secret | New independently verified wallet and carefully planned movement |
| Suspicious token approval | Contract permission, wallet and device | Official network/wallet tools to inspect and revoke where appropriate |
No row guarantees asset recovery. The table only points to the authority that still can be protected.
If a self-custody secret is exposed
A password reset does not change a disclosed private key or recovery phrase. Treat the wallet as compromised. From a clean device, consult the wallet’s official security guidance and assess creating a new wallet with a new secret before transferring any remaining assets.
Do not rush funds to an address supplied by a stranger. Confirm the network and destination independently. No helper can guarantee recovery.
Creating a new wallet means generating a new recovery secret in a clean environment and protecting it before moving anything. Restoring the old phrase into a new app does not create a new authority; the attacker may still have the same phrase. Consider network fees, exposed token approvals and the possibility that the attacker is monitoring the address.
Do not publish the compromised address together with identity data unless an official reporting process requires it. Public pleas often attract impersonators claiming to be investigators, validators or exchange employees.
If an unauthorized transfer already occurred
Record the transaction hash and destination. Contact the receiving provider or recipient through an official route if identifiable. Report promptly and truthfully. Some providers or authorities may investigate or preserve information; blockchain confirmation itself may still be irreversible.
Do not pay a “recovery hacker,” “blockchain agent” or unofficial tax to release funds. Recovery scams often target people immediately after the first loss.
Build an evidence package

Create a timeline with timezone and include only relevant facts:
- first suspicious alert and how it arrived;
- email, device, SIM and provider session activity;
- asset, network, amount, complete addresses and transaction hashes;
- full message sender, URL and app or account names;
- actions taken, case numbers and official responses;
- documents or identity information that may have been exposed.
Keep original files and headers where practical. Screenshots are helpful but may omit metadata. Do not edit evidence to make it clearer; add a separate note explaining what it shows. Store it privately and share through the official investigator, provider or complaint route.
Philippine scenario: email rules changed

Nico notices a withdrawal alert he did not initiate. On a clean device, he secures his email and finds a forwarding rule sending security messages elsewhere. He removes the rule, signs out unknown sessions, contacts the crypto provider and bank, then records the transaction hash and case numbers.
He reports through official channels rather than posting his ID and evidence publicly.
During the next day, Nico reviews bank and e-wallet links, warns contacts about messages from his email, checks whether identity documents were taken and follows the provider case. If his evidence suggests a cybercrime, he can use the appropriate Philippine law-enforcement channel; if personal data was mishandled, the National Privacy Commission has information and complaint routes.
If the issue concerns a BSP-supervised provider, he begins with the provider’s formal complaint process and keeps the reference for any available regulatory escalation. Reporting creates a record; it does not promise reimbursement.
What not to do
- Do not continue using a suspect device for every recovery step.
- Do not delete all messages before saving evidence.
- Do not reuse the compromised password or wallet secret.
- Do not reveal seed phrases, OTPs or IDs to commenters offering help.
Also do not reuse the old recovery setup immediately. If the attacker changed a phone number or added a passkey, remove that authority. If a device may contain malware, changing every password on that same device can hand the new credentials back to the attacker.
After containment

Review the timeline and entry point. Replace reused passwords, update devices, strengthen recovery, warn affected contacts and monitor for identity misuse.
Turn the incident into one control improvement at a time. Perhaps the entry point was a reused email password; the amplification was SMS-only recovery; and the delayed response came from not knowing the official support route. Fix all three, then rehearse the new sequence.
Avoid shame as a security policy. Families and teams report faster when people expect care and facts instead of blame. Early reporting can protect other accounts and community members even when the original loss cannot be reversed.
How this connects to market mastery
Incident response follows the same discipline as trading survival: stop uncontrolled exposure, preserve decision-quality information, use predefined escalation and review the failure after the immediate danger passes.
Key takeaways and check
- Secure email and recovery channels, not only the crypto password.
- Separate custodial-account recovery from self-custody key compromise.
- Preserve transaction and communication evidence before cleanup.
- Use official support and reporting routes; recovery is never guaranteed.
Security check: Write an emergency contact sheet for email, carrier, crypto provider and linked bank without including passwords, OTPs or seed phrases.
This lesson prioritizes containment, trusted-device checks and evidence preservation during a stressful incident.
*Cryptocurrency and virtual asset transactions are highly volatile and irreversible, may result in significant losses, and do not guarantee returns; customers should trade only after understanding the risks involved.