Active Incident? 24/7 Response →
SleuthX

Beware of recovery scams

No legitimate service can guarantee it will get your money or account back for an up-front fee.

  • The FBI warns that “recovery scheme fraudsters charge an up-front fee and either cease communication with the victim after receiving an initial deposit or produce an incomplete or inaccurate tracing report and request additional fees to recover funds.” These schemes deliberately target people who have already been scammed once.
  • Never pay an up-front feeto a company that contacts you promising to recover lost funds, accounts, or cryptocurrency — especially if they ask for payment in gift cards, wire transfer, or cryptocurrency.

FBI sources: IC3 Public Service Announcement I-081123-PSA · FBI San Diego — Seizes Cryptocurrency Recovery Websites

For Individuals & Families

Coinbase or Crypto Exchange Account Hacked? Emergency Steps

Lock the account, contact the exchange, harden your login — in that order. Then the hard truth about what is recoverable, and the second scam already waiting for you.

All articles·7 min read·June 29, 2026

First, the emergency steps — you can still limit the damage

If you just learned someone is in your Coinbase or other exchange account, the warning above is for later. Right now, focus on shutting the attacker out. This is account-takeover, and the first minutes matter:

  1. Lock the account.Use the exchange's “my account was compromised” flow to disable it. Coinbase and the major exchanges have a dedicated path to freeze a compromised account and halt further withdrawals.
  2. Change the password from a clean device — one you are confident is not infected — and sign out all sessions.
  3. Harden two-factor. Move off SMS, which is the weakest second factor, to an authenticator app or a hardware security key. A SIM swap is a common way exchange accounts fall.
  4. Check the linked email. If your email was hacked first, the exchange break-in likely came through it — work the full account lock-down there too.

The hard truth about “getting it back”

Acting fast can stop more from leaving. But be clear-eyed about what is already gone: a confirmed on-chain transfer is final.Unlike a bank wire, there is no central operator who can claw a crypto transaction back, and no “recovery service” has a secret line to do it. An exchange can freeze youraccount and — rarely, and only with speed plus law enforcement — help where funds are still sitting on a regulated platform. It cannot reverse a transfer that has already left to the attacker's wallet.

Why the warning above matters

Here is the trap that catches takeover victims: within days of the hack, a “recovery expert,” a fake “blockchain investigator,” or a bogus “exchange compliance officer” reaches out promising to get your crypto back — for an up-front fee. The FBI has warned about exactly this and has seized websites built to pose as crypto-recovery firms and re-victimize people. The rule that protects you: no one legitimate recovers a sent crypto transfer for an up-front fee. Anyone who promises it is running the second scam.

What actually helps

If the loss is large or headed toward a dispute or court, crypto scam recovery explains what a credentialed forensic examiner can and cannot do — trace wallet infrastructure, preserve admissible evidence, support a filing — without ever promising to get it all back. For the broader pattern of recovery-fee fraud, see why crypto “recovery services” are usually a second scam.

Sources

  1. Coinbase Help, My account was compromised. https://help.coinbase.com/en/coinbase/privacy-and-security/account-compromised/my-account-was-compromised
  2. Federal Trade Commission, What To Know About Cryptocurrency and Scams. https://consumer.ftc.gov/articles/what-know-about-cryptocurrency-and-scams
  3. FBI Internet Crime Complaint Center (IC3), Public Service Announcement I-081123-PSA — fraudulent crypto-recovery schemes, 2023. https://www.ic3.gov/PSA/2023/PSA230811
  4. FBI San Diego Field Office, FBI San Diego — Seizes Cryptocurrency Recovery Websites. https://www.fbi.gov/contact-us/field-offices/sandiego/news/fbi-san-diego-seizes-cryptocurrency-recovery-websites
  5. FBI Internet Crime Complaint Center (IC3), File a Complaint. https://www.ic3.gov/

Related services

Meet Your Practitioner

Quinnlan Varcoe

Founder & CEO

GIAC-certified · 15 industry certifications

With operational experience across Fortune 50 security programs and the defense industrial base, Quinnlan founded SleuthX in 2022 to provide clients with the caliber of expertise typically reserved for the largest enterprises. Her work in threat intelligence and digital forensics has earned the trust of 26,000+ cybersecurity professionals who follow her analysis.

“26,000 professionals follow my work because I say what others won't — and I can back it up technically.”

Fortune 50 BackgroundDefense IndustryThreat IntelligenceDigital PrivacyIncident Response
Quinnlan Varcoe, Founder & CEO

Hacked crypto exchange account: quick answers

Certified Expertise

GIAC · AWS · Splunk · CompTIA

Transparent pricing

Trusted by partners across the practice

DAS Health
Exhibit A Cyber
Ally Security
KIRO Group
Black Mirage
Kalles Group
Gridware
CQR
Archstone Security
Cyvergence
Sentinel Cyber
Cloud Underground
Seron Security
Hexen
Koru Risk Management
DAS Health
Exhibit A Cyber
Ally Security
KIRO Group
Black Mirage
Kalles Group
Gridware
CQR
Archstone Security
Cyvergence
Sentinel Cyber
Cloud Underground
Seron Security
Hexen
Koru Risk Management