Critical Action · Incident Response · Act from a clean device

Wallet drained, seed stolen, account taken over?
SEAL 911 provides free, 24/7 incident triage.

If a wallet or account may be compromised, stop using the affected device and preserve the transaction details. Do not pay unsolicited recovery offers, install software from a stranger, or share a seed phrase, private key, password, or remote-access code. PhishDestroy documents and reports malicious infrastructure; it does not provide recovery services.

SEAL · Security Alliance
Security Alliance
Recommended first action — SEAL 911

Free incident triage, 24/7. Published average response: under 30 minutes.

SEAL 911 is the war-room hotline of the Security Alliance — a coalition of top web3 security teams that triages live incidents, coordinates with exchanges, and helps trace funds. Free, volunteer-run, no recovery fees.

Open @seal_911_bot
<30 min
published average
24/7
on-call
$0
always free
Recovery scams target people after an initial loss. Treat unsolicited messages offering guaranteed recovery, transaction reversal, hacker negotiation, or a blockchain rollback as hostile. Do not reply, pay, install software, or approve a transaction. PhishDestroy does not contact victims to sell recovery. Verify any incident-response channel through a separately sourced official website.
01 · DO THIS NOW

5-step emergency sequence

follow in order · adapt to the incident · verify every link
100:00

Contact the official SEAL 911 incident-triage channel

Before anything else, message the SEAL 911 bot. Give them the basics (chain, drained wallet, drainer wallet, tx hash if known). SEAL reports an average response time under 30 minutes. Eligibility and response time depend on the incident.

tg → https://t.me/seal_911_bot · /start · paste your wallet + drainer + tx
  • If you suspect malware on your device → also open securityalliance.org/go/malware
  • Verify the bot link through securityalliance.org before sharing any incident details
202:00

Protect remaining assets using verified guidance

Treat a compromised seed phrase or private key as permanently exposed. Do not improvise transfers while an attacker may still control the wallet. From a clean device, use the wallet vendor's official documentation or a verified incident-response channel. Never reuse the compromised secret.

  • Verify every support URL independently; do not follow links sent in direct messages
  • Test instructions and transaction details before approving any action
  • Never install remote-access software or disclose a seed phrase, private key, or password
305:00

Revoke every approval — chain by chain

A malicious approval can authorize later transfers. Reach any permission-management tool through a separately verified official domain and inspect every transaction before signing. setApprovalForAll, Permit2, and unlimited allowances are the dangerous ones.

https://revoke.cash · verify the domain independently · review approvals · reject unrelated prompts
410:00

Report to the community — make the attack public

Report the drainer address and phishing URL through established channels such as Chainabuse. A factual public report can warn others and help analysts correlate infrastructure. Do not publish private victim data. Publish transaction identifiers and infrastructure evidence, not account credentials or identity documents.

  • Submit the drainer wallet to Chainabuse and retain the report reference
  • Post tx + drainer addr on Reddit r/CryptoScams and X with screenshots
  • Do not tag or message individual investigators unless their published intake guidance asks you to
  • Report the phishing URL to PhishDestroy so we can preserve evidence and submit it to relevant providers
520:00

File with law enforcement — preserve evidence

File through the official channel for your jurisdiction. A report does not guarantee recovery, but it creates a formal record that an exchange, insurer, or investigator may request. Preserve unedited screenshots, wallet addresses, transaction hashes, UTC timestamps, and relevant messages. If malware is suspected, avoid altering the affected device until a qualified responder advises you.

  • US: FBI IC3 at ic3.gov · UK: Action Fraud · EU: national CERT
  • Save evidence to clean USB or encrypted Proton Drive — not the affected machine
  • Share a case number only through a verified official channel and only when the receiving organization requests it
02 · DON'T LOSE TWICE

How recovery scammers find you

Unsolicited recovery offers are a common secondary scam

Treat unsolicited recovery offers as hostile4 patterns to recognize · verify through official channels

"I can reverse the transaction"

Public chains are immutable. No "white-hat hacker", flashbots service, or insider can reverse a confirmed tx. Anyone claiming this is selling you fiction.

DMs from "recovery agents"

Scammers monitor X, Reddit, Telegram for victim posts. Within hours of you posting, you'll get DMs from "MetaMask support", "USDT recovery", or "blockchain forensics". Do not reply or pay. Verify any organization through a separately sourced official website.

"Send 10% upfront / gas fee"

The classic. They take your fee, ghost you, or come back asking for more. PhishDestroy does not sell recovery services or accept recovery payments. Verify any third-party service's identity and terms independently.

Fake testimonials & screenshots

Their site has glowing 5-star reviews and "trustpilot" badges. Screenshots and badges are not proof. Check the legal entity, domain history, regulator records where applicable, and independent complaints before sharing data or money.

03 · GO PUBLIC

Report to community — break the silence

public reports can connect indicators across cases
04 · RULES OF ENGAGEMENT

Do this · Don't do this

Do — every time

  • Verify the official SEAL 911 channel through securityalliance.org before sharing incident details.
  • Follow verified wallet-vendor guidance from a clean device before moving assets or creating a wallet.
  • Revoke approvals on every chain you've ever bridged to — not just the active one.
  • Capture evidence first — screenshots, tx hashes, browser state, drainer URL.
  • Report drainer wallet publicly on Chainabuse + Reddit + X. Public attribution matters.
  • Use the official reporting channel for your jurisdiction. Eligibility and reporting thresholds vary.

Don't — ever

  • Don't pay "recovery agents" who DM you offering to retrieve funds. Treat unsolicited offers as likely fraud and verify independently.
  • Don't import the compromised seed into anything new — even a hardware wallet.
  • Don't reset the affected machine until you've captured the extensions list and logs.
  • Don't trust "MetaMask support" / "Trezor support" DMs — official teams never DM first.
  • Don't reuse passwords tied to the wallet email — drainers harvest them in parallel.
  • Don't delete the phishing tab before screenshots — preserve the URL bar in evidence.
05 · WHO DOES WHAT

PhishDestroy and SEAL — different, independent roles

PhishDestroy

We document and report malicious infrastructure

PhishDestroy collects and publishes evidence, submits abuse reports, and shares indicators with relevant providers. Registrars, hosts, browsers, and security vendors decide enforcement. We do not provide incident response or recovery services.

+
SEAL 911

They respond to live incidents

SEAL 911 triages eligible active crypto incidents. Its published average response time is under 30 minutes; availability and outcomes vary. SEAL is independent from PhishDestroy.

06 · FAQ

Common questions, answered fast

Will I get my funds back?

PhishDestroy cannot assess or recover an individual loss. Outcomes are case-specific and may require the victim's direct involvement with law enforcement, an exchange, an insurer, or a verified incident responder. No report or service guarantees recovery.

An unsolicited message offering guaranteed recovery is a strong fraud warning. PhishDestroy does not provide or charge for recovery. Verify every other organization through its official site and review its published scope before sharing information.

What if I think there's malware on my device?

Open the SEAL malware playbook: securityalliance.org/go/malware. It walks you through isolating the device, capturing the infection, rotating credentials from a clean machine, and avoiding cross-contamination.

Common signs: clipboard-paste replaces your address with a different one; a wallet extension you don't remember installing; transactions you didn't initiate; "MFA" requests you didn't trigger.

Should I import my seed into a new wallet "just to check"?

No. Never. The seed is public to the attacker. Any wallet you import it into — including a hardware wallet — is already drained or scheduled to be. Sweep bots monitor known compromised seeds 24/7.

Why public reporting? Why not just file with police?

Official reports and public indicator reports serve different purposes. An official filing creates a case record. A public report can warn others and help analysts correlate addresses, domains, and transactions. Publish only non-sensitive facts and never expose seed phrases, private keys, identity documents, or private contact details.

What's the difference between PhishDestroy and SEAL 911?

PhishDestroy documents suspected phishing infrastructure, preserves public evidence, and submits reports to registrars, hosts, browsers, and security vendors. Those providers decide enforcement. We do not run incident response or recovery cases.

SEAL 911 is the war-room hotline of the Security Alliance — chain analysts, exchange contacts, malware experts, and protocol teams. If you're in an active incident, they're who you want on the phone. securityalliance.org

I see "pending" transactions. Can I cancel them?

Do not improvise a replacement transaction during an active compromise. Use the wallet vendor's official documentation from a clean device or ask a verified incident responder. Never share a seed phrase, private key, or remote-access code.

How long should I keep evidence?

Keep original, unedited evidence according to instructions from local law enforcement, counsel, an insurer, or the relevant exchange. Preserve transaction hashes, UTC timestamps, screenshots, and source files on protected media separate from the affected device.

SEAL · Security Alliance
Open the bot now
Active crypto incident · independent response resource

Contact SEAL 911 for active crypto incidents.

For an active crypto incident, contact SEAL 911 and provide only the minimum evidence needed for triage. Never share a seed phrase or private key. The service is free and available 24/7; its published average response time is under 30 minutes.

PhishDestroy · Critical Action playbook · independent guide referencing Security Alliance (SEAL) resources
phishdestroy.io · @seal_911_bot · malware playbook