Crypto Hack Incident Response
Wallet or exchange drained? Our crypto hack incident response contains the breach, traces stolen funds on-chain and preserves evidence. Start now.
If funds have just left your wallet, exchange account or treasury without your say-so, crypto hack incident response is about the next hour, not next week. Our European team moves to stop further loss, works out how the keys or access were taken, and traces the stolen assets across the blockchain while the trail is still warm.
What crypto hack incident response covers
A crypto theft is two incidents at once: a security breach of whatever held or authorised the funds, and a financial event that is now moving through public ledgers in real time. We handle both. That means securing the systems and keys the attacker touched, and following the money on-chain so there is a documented trail for exchanges, insurers and law enforcement to act on.
The situations we respond to
Blockchain incident response looks different depending on what was hit, so we scope fast around your specific loss.
Why the first hour counts
Unlike a bank transfer, an on-chain transaction cannot be reversed by calling support. What can still be done early is real: revoking the approvals a drainer relies on, moving any assets the attacker has not reached yet into safety, and getting freeze requests to centralised exchanges before the funds are cashed out. Every minute the attacker keeps access is another minute to move more.
On-chain tracing and attribution
Once the immediate bleeding is stopped, we follow the assets. Public blockchains are unforgiving to attackers in one respect: the movement of funds is permanently recorded, and with the right analysis it can be followed.
Following the funds
We trace stolen assets through the chain of addresses, flagging where they hit mixers, bridges, or centralised exchanges that respond to law-enforcement and compliance requests. Reaching a regulated off-ramp is the point where recovery becomes realistic, so identifying that hop quickly is a priority. We also flag when funds have been split across many wallets to muddy the trail, a common tactic, and keep following the significant branches rather than losing them in the noise. Where a transaction crosses a bridge to another chain, we pick the trail back up on the far side.
Building the evidence pack
We assemble transaction hashes, address clusters, timestamps and a written narrative into a report your lawyers, your insurer and the police can actually use. Chainalysis-style clustering and attribution underpin the analysis, presented so a non-technical reader understands where the money went and why we believe so.
An honest word on recovery
Be wary of anyone promising guaranteed recovery of stolen crypto. Most “stolen crypto recovery services” that make that promise are themselves a scam. We do not guarantee funds back, because no honest firm can. What we do is maximise the realistic paths: fast freezes at exchanges, a solid evidence trail, and the reports that let law enforcement and civil action proceed.
Our response process
The work follows a disciplined path so that under pressure nothing that could save funds or evidence gets missed.
Triage
We start within minutes of your call: what was taken, from where, and what access the attacker still holds. We identify assets still at risk and the fastest legitimate action to protect them.
Contain
We cut the attacker off. That can mean revoking malicious token approvals, rotating keys and moving remaining assets to fresh, secured wallets, locking down the exchange account, and killing the sessions or devices the intruder used to get in.
Eradicate
We find and remove the root cause, whether that was malware stealing clipboard addresses, a phished seed phrase, a leaked API key, or a poisoned dependency in your signing workflow. Moving funds to a new wallet is pointless if the same infostealer is still running on your machine.
Recover
We support the recovery effort: freeze requests to exchanges, coordination with your legal team and, where appropriate, law enforcement, and a clean rebuild of the wallet and custody setup so you can operate again safely.
Harden
We redesign how keys are stored and transactions are approved so a single mistake cannot drain everything again. For most clients that means hardware or multi-sig custody, strict approval hygiene, and monitoring that alerts on unexpected movement.
How they got in, and how we prove it
The address that received your funds is only half the story. The other half is how the attacker gained the ability to move them, and that is what stops it recurring.
Root-cause forensics
We examine the devices, exchange logs, and wallet history to reconstruct the intrusion. Common root causes we find are infostealer malware, a phishing site that captured a seed phrase, a blind-signed drainer transaction, an exposed API key, and account takeover via a compromised email or SIM.
Evidence handling
Everything is preserved to a defensible standard: device images, log exports, and on-chain records with hashes and timestamps, handled so the material holds up for insurers, regulators and any court proceedings that follow.
Want this tested on your own systems?
Free 20-minute scoping call, a fixed price with no hourly surprises, and a free retest once you fix what we find.
What you get
A clear picture of what happened, where the money went, and what to do next, in language your board and your lawyer both understand.
Prevention after the incident
Recovering from one theft is worthless if the next transaction is signed the same careless way. We fix the process, not just the wallet.
Custody and signing hygiene
We move you to hardware wallets or multi-signature custody with clear approval rules, so no single compromised device or person can authorise a total loss. Blind-signing is retired in favour of verified, human-checked transactions.
Monitoring and alerting
We set up watch alerts on your addresses so an unexpected outflow triggers a warning in seconds, not the next time someone opens the app. For teams, we separate the machines used for signing from everyday browsing and email, where most drainers arrive.
Training the humans
Technology only goes so far when the attack targets people. We run your team through the specific tricks that led to the loss, from fake support agents and lookalike domains to malicious approval prompts, so the next attempt is recognised and refused rather than clicked. Most crypto thefts we investigate hinged on a single human decision made in a hurry, and a short, honest walkthrough of what that looked like does more than any policy document.
Reporting, regulation and GDPR duties
A theft can trigger obligations beyond getting your money back, and getting these right protects you from a second problem on top of the first.
When personal data is involved
If the attacker also accessed customer records, KYC documents or personal data alongside the funds, GDPR notification duties can apply. In many cases that means informing your supervisory authority within 72 hours of becoming aware, and telling affected people if they are at high risk. We help you judge whether the threshold is met and document the decision either way, so a reasonable choice is recorded rather than left to memory.
Law enforcement and financial reporting
For regulated firms across Europe, a crypto theft may also carry reporting duties to a financial regulator, and a criminal complaint is usually worth filing to unlock exchange cooperation. We prepare the technical evidence in the format investigators expect and can join calls with your legal counsel so nothing is lost in translation between the on-chain facts and the paperwork.
Timelines and common triggers
Crypto response is time-critical, so here is how the clock usually runs.
What to expect on the calendar
Containment and the first on-chain trace begin the same day, usually within the first hours. A full tracing and forensic report typically takes a few working days depending on how many hops and how many chains are involved, but freeze requests and protective moves never wait for the report. You get what we know as we learn it.
What usually brings people to us
An unexpected zero balance after opening a wallet app. A withdrawal from an exchange account that was not authorised. A “support agent” who turned out to be a scammer with your recovery phrase. A treasury signer who approved a transaction that was not what it appeared to be. If any of that just happened, act now rather than searching for reassurance that the funds will come back on their own.
Pricing
Crypto incident response is scoped by how the theft happened, how many assets and chains are involved, and how much tracing you need for insurance or legal action. We quote after a short call rather than guess blind.
| Package | What’s included | Response time | Price |
|---|---|---|---|
| Rapid response | Same-hour triage, containment of remaining assets and initial on-chain trace for a single incident | On call, same day | from €900 |
| Hourly investigation | Senior-led forensics and blockchain tracing billed by the hour for focused or evolving cases | Starts within hours | from €180/hr |
| Full tracing & forensics | End-to-end investigation: root cause, multi-hop tracing, exchange freeze pack and legal-ready report | 3–7 working days | scoped after a call |
| Custody rebuild | Hardening of key management, multi-sig or hardware custody, and monitoring after an incident | 2–5 working days | from €1,200 |
| Complex or protocol-level | Bridge, DeFi or multi-entity treasury incidents scoped to the case | On scoping | custom |
Every engagement is a fixed price agreed after a free scoping call, and a retest is included once you fix. Start emergency response
FAQ
How much does crypto hack incident response cost?
Can you get my stolen crypto back?
Can you tell me how they got in?
Is it worth acting if the money already left?
Do you handle exchange account takeovers as well as wallet drains?
Will you help with my insurance or legal case?
Is this confidential?
What should I do right now, before you start?
Related services
Individuals and businesses that just lost crypto to a hack, drainer or account takeover, treasuries and funds needing on-chain tracing and evidence for insurers or law enforcement, and teams that want their custody rebuilt so it cannot happen twice.
Security you can prove
The same standard on every engagement, big or small.
Evidence, not opinions
Every finding ships with a reproduction and proof of concept — no vague "maybe vulnerable".
Humans over scanners
Certified engineers find the logic flaws and chained attacks automated tools walk straight past.
Fixed price, free retest
You know the cost up front, and verifying the fix is part of the deal — not a second invoice.
Ready to lock this down?
Free scoping call, fixed price, free retest. Tell us what you're running and we'll take it from there — usually within one business day.
Tell us what you're running
Scoping is free. We reply within one business day, and under 30 minutes for active incidents.