Wallet drained, seed stolen, account taken over?
SEAL 911 provides free, 24/7 incident triage.
If a wallet or account may be compromised, stop using the affected device and preserve the transaction details. Do not pay unsolicited recovery offers, install software from a stranger, or share a seed phrase, private key, password, or remote-access code. PhishDestroy documents and reports malicious infrastructure; it does not provide recovery services.
Free incident triage, 24/7. Published average response: under 30 minutes.
SEAL 911 is the war-room hotline of the Security Alliance — a coalition of top web3 security teams that triages live incidents, coordinates with exchanges, and helps trace funds. Free, volunteer-run, no recovery fees.
5-step emergency sequence
Contact the official SEAL 911 incident-triage channel
Before anything else, message the SEAL 911 bot. Give them the basics (chain, drained wallet, drainer wallet, tx hash if known). SEAL reports an average response time under 30 minutes. Eligibility and response time depend on the incident.
- If you suspect malware on your device → also open securityalliance.org/go/malware
- Verify the bot link through securityalliance.org before sharing any incident details
Protect remaining assets using verified guidance
Treat a compromised seed phrase or private key as permanently exposed. Do not improvise transfers while an attacker may still control the wallet. From a clean device, use the wallet vendor's official documentation or a verified incident-response channel. Never reuse the compromised secret.
- Verify every support URL independently; do not follow links sent in direct messages
- Test instructions and transaction details before approving any action
- Never install remote-access software or disclose a seed phrase, private key, or password
Revoke every approval — chain by chain
A malicious approval can authorize later transfers. Reach any permission-management tool through a separately verified official domain and inspect every transaction before signing. setApprovalForAll,
Permit2, and unlimited allowances are the dangerous ones.
Report to the community — make the attack public
Report the drainer address and phishing URL through established channels such as Chainabuse. A factual public report can warn others and help analysts correlate infrastructure. Do not publish private victim data. Publish transaction identifiers and infrastructure evidence, not account credentials or identity documents.
- Submit the drainer wallet to Chainabuse and retain the report reference
- Post tx + drainer addr on Reddit r/CryptoScams and X with screenshots
- Do not tag or message individual investigators unless their published intake guidance asks you to
- Report the phishing URL to PhishDestroy so we can preserve evidence and submit it to relevant providers
File with law enforcement — preserve evidence
File through the official channel for your jurisdiction. A report does not guarantee recovery, but it creates a formal record that an exchange, insurer, or investigator may request. Preserve unedited screenshots, wallet addresses, transaction hashes, UTC timestamps, and relevant messages. If malware is suspected, avoid altering the affected device until a qualified responder advises you.
- US: FBI IC3 at ic3.gov · UK: Action Fraud · EU: national CERT
- Save evidence to clean USB or encrypted Proton Drive — not the affected machine
- Share a case number only through a verified official channel and only when the receiving organization requests it
How recovery scammers find you
Treat unsolicited recovery offers as hostile4 patterns to recognize · verify through official channels
"I can reverse the transaction"
Public chains are immutable. No "white-hat hacker", flashbots service, or insider can reverse a confirmed tx. Anyone claiming this is selling you fiction.
DMs from "recovery agents"
Scammers monitor X, Reddit, Telegram for victim posts. Within hours of you posting, you'll get DMs from "MetaMask support", "USDT recovery", or "blockchain forensics". Do not reply or pay. Verify any organization through a separately sourced official website.
"Send 10% upfront / gas fee"
The classic. They take your fee, ghost you, or come back asking for more. PhishDestroy does not sell recovery services or accept recovery payments. Verify any third-party service's identity and terms independently.
Fake testimonials & screenshots
Their site has glowing 5-star reviews and "trustpilot" badges. Screenshots and badges are not proof. Check the legal entity, domain history, regulator records where applicable, and independent complaints before sharing data or money.
Report to community — break the silence
Multi-vendor abuse registry. Reports propagate to Trust Wallet, MetaMask, Coinbase, and 30+ partners.
Public on-chain investigation tool. Flag the wallet, visualize fund flow, share the case URL.
Post the phishing URL, drainer wallet, and tx hash. Subreddit indexes well in Google for future searches.
Publish a concise factual record with non-sensitive screenshots, addresses, transaction hashes, and UTC timestamps.
Submit the malicious URL so we can preserve evidence and send indicators to relevant abuse desks and security vendors. Enforcement decisions remain with those providers.
Official US cybercrime complaint channel. Keep the confirmation and any case reference with your evidence; filing does not guarantee asset recovery or an exchange freeze.
Separate monitoring services maintain their own intake rules and coverage. Verify the current submission page before providing data.
Review the account's published guidance and research. Do not assume that a public account accepts individual recovery cases.
Do this · Don't do this
✓Do — every time
- Verify the official SEAL 911 channel through securityalliance.org before sharing incident details.
- Follow verified wallet-vendor guidance from a clean device before moving assets or creating a wallet.
- Revoke approvals on every chain you've ever bridged to — not just the active one.
- Capture evidence first — screenshots, tx hashes, browser state, drainer URL.
- Report drainer wallet publicly on Chainabuse + Reddit + X. Public attribution matters.
- Use the official reporting channel for your jurisdiction. Eligibility and reporting thresholds vary.
✕Don't — ever
- Don't pay "recovery agents" who DM you offering to retrieve funds. Treat unsolicited offers as likely fraud and verify independently.
- Don't import the compromised seed into anything new — even a hardware wallet.
- Don't reset the affected machine until you've captured the extensions list and logs.
- Don't trust "MetaMask support" / "Trezor support" DMs — official teams never DM first.
- Don't reuse passwords tied to the wallet email — drainers harvest them in parallel.
- Don't delete the phishing tab before screenshots — preserve the URL bar in evidence.
PhishDestroy and SEAL — different, independent roles
We document and report malicious infrastructure
PhishDestroy collects and publishes evidence, submits abuse reports, and shares indicators with relevant providers. Registrars, hosts, browsers, and security vendors decide enforcement. We do not provide incident response or recovery services.
They respond to live incidents
SEAL 911 triages eligible active crypto incidents. Its published average response time is under 30 minutes; availability and outcomes vary. SEAL is independent from PhishDestroy.
Common questions, answered fast
Will I get my funds back?
PhishDestroy cannot assess or recover an individual loss. Outcomes are case-specific and may require the victim's direct involvement with law enforcement, an exchange, an insurer, or a verified incident responder. No report or service guarantees recovery.
An unsolicited message offering guaranteed recovery is a strong fraud warning. PhishDestroy does not provide or charge for recovery. Verify every other organization through its official site and review its published scope before sharing information.
What if I think there's malware on my device?
Open the SEAL malware playbook: securityalliance.org/go/malware. It walks you through isolating the device, capturing the infection, rotating credentials from a clean machine, and avoiding cross-contamination.
Common signs: clipboard-paste replaces your address with a different one; a wallet extension you don't remember installing; transactions you didn't initiate; "MFA" requests you didn't trigger.
Should I import my seed into a new wallet "just to check"?
No. Never. The seed is public to the attacker. Any wallet you import it into — including a hardware wallet — is already drained or scheduled to be. Sweep bots monitor known compromised seeds 24/7.
Why public reporting? Why not just file with police?
Official reports and public indicator reports serve different purposes. An official filing creates a case record. A public report can warn others and help analysts correlate addresses, domains, and transactions. Publish only non-sensitive facts and never expose seed phrases, private keys, identity documents, or private contact details.
What's the difference between PhishDestroy and SEAL 911?
PhishDestroy documents suspected phishing infrastructure, preserves public evidence, and submits reports to registrars, hosts, browsers, and security vendors. Those providers decide enforcement. We do not run incident response or recovery cases.
SEAL 911 is the war-room hotline of the Security Alliance — chain analysts, exchange contacts, malware experts, and protocol teams. If you're in an active incident, they're who you want on the phone. securityalliance.org
I see "pending" transactions. Can I cancel them?
Do not improvise a replacement transaction during an active compromise. Use the wallet vendor's official documentation from a clean device or ask a verified incident responder. Never share a seed phrase, private key, or remote-access code.
How long should I keep evidence?
Keep original, unedited evidence according to instructions from local law enforcement, counsel, an insurer, or the relevant exchange. Preserve transaction hashes, UTC timestamps, screenshots, and source files on protected media separate from the affected device.
Contact SEAL 911 for active crypto incidents.
For an active crypto incident, contact SEAL 911 and provide only the minimum evidence needed for triage. Never share a seed phrase or private key. The service is free and available 24/7; its published average response time is under 30 minutes.