Company Crypto Stolen: What to Do in the First 24 Hours
A step-by-step response plan after corporate cryptocurrency theft: stop the attack, preserve evidence, trace the funds, notify exchanges, and report the incident to law enforcement.
The first 24 hours after a cryptocurrency theft are not some magical “recovery window,” but this is usually when a company has the best chance to trace the assets, alert exchanges, and preserve critical digital evidence.
While the team is discussing who is to blame and whether the CEO should be informed, the attacker may already be splitting the funds, swapping tokens, moving assets across blockchains, and cashing out through various services. Response efforts should therefore begin as soon as an unauthorized transaction is confirmed, not after the internal investigation is complete.
Two extremes are equally dangerous: doing nothing and acting chaotically. Reinstalling a computer, deleting applications, and changing every possible setting can destroy evidence faster than it stops the attack.
During the first 24 hours, the company should run three workstreams in parallel: contain the technical compromise, trace and attempt to freeze the stolen assets, and preserve evidence for legal action.
Key Takeaways
Stop the ongoing compromise first and protect the remaining assets.
Do not destroy logs, devices, or other digital evidence.
Start the blockchain investigation at the same time as the internal technical investigation.
If an exchange, exchanger, or other VASP is identified, notify it immediately rather than waiting for the final report.
By the end of the first day, prepare an interim report covering the losses, fund flows, notifications already sent, and the next steps.
First 24-Hour Response Plan
Time Since Discovery;Main Task
First 15–60 minutes; Appoint an incident lead, restrict the attacker’s access, and secure the remaining assets
1–4 hours; Preserve evidence, collect addresses and TXIDs, and identify affected systems
2–8 hours; Start tracing, place addresses under monitoring, and identify exchanges and other exit points
4–12 hours; Notify VASPs and, where relevant, stablecoin issuers
By the end of the first day; File an initial report, coordinate communications, and prepare an interim incident reportёт
This approach is not limited to major crypto businesses with a 24/7 SOC. In a smaller company, one employee may be responsible for both finance and crypto wallets, with an external IT specialist brought in when needed. What matters is not the number of departments involved, but a clear division of responsibilities and a single decision-making center.
First Minutes: Appoint an Incident Lead
Every incident needs one coordinator. This does not have to be a CISO in an expensive suit sitting in a dedicated crisis room. In a smaller company, it may be the CEO, CFO, or the most technically competent employee available.
Their job is to maintain the timeline, assign tasks, and approve external communications. Without a single coordinator, IT starts changing access rights, the CFO writes to the exchange, the lawyer tells everyone not to touch anything, and someone else is already discussing the theft in an industry chat.
The company should immediately determine who is responsible for technical containment, who collects blockchain data, who communicates with exchanges and issuers, who prepares legal documents, and who is authorized to make public statements.
Other employees should not independently contact the attacker, exchanges, or suspected intermediaries.
Stop the Ongoing Attack
The first technical question is not “How exactly were we hacked?” but “Does the attacker still have access right now?”
The company needs to determine whether the compromise may involve private keys or seed phrases, devices used to sign transactions, wallet extensions, multisig permissions, corporate email, cloud storage, password managers, exchange accounts, API keys, automated withdrawal systems, or employee and contractor accounts.
If a seed phrase or private key has been stolen, changing the wallet application password will not solve the problem. It is roughly equivalent to changing the entry code to an apartment building after the attacker has already obtained the key to your front door.
For multisig wallets, check not only the list of signers but also any changes to signing thresholds, roles, and destination addresses. If corporate email has been compromised, assume the attacker may have seen security notifications, reset passwords, or monitored correspondence with exchanges and other platforms.
Move the Remaining Assets to Secure Infrastructure
If funds remain on potentially compromised wallets, they need to be secured. But signing a rescue transaction on the same device through which the theft may have occurred is not an ideal rescue strategy.
Use a pre-established backup wallet where possible, a clean device that is not connected to the suspected source of compromise, newly generated keys and seed phrases, and a verified destination address. For significant amounts, consider multisig or hardware-based storage.
The destination address should be independently checked by more than one person before funds are moved. Under pressure, companies sometimes become so enthusiastic about “saving” the remaining assets that they send them to the wrong network or the wrong address.
If the source of the compromise is still unknown, old devices, browser profiles, and wallets should not be considered safe simply because the password has been changed.
Isolate Systems Without Destroying Evidence
Compromised devices and accounts should be isolated from further use. But isolation does not mean performing a digital spring cleaning.
Before evidence has been preserved, avoid reinstalling the operating system, clearing browser history or system logs, deleting wallet extensions and applications, resetting devices, changing every setting at once, or shutting down equipment that may contain valuable volatile data.
Current NIST guidance treats incident response as a combination of analysis, containment, eradication, and recovery, and recognizes event logs as important for detection, investigation, and subsequent recovery. CISA also recommends preserving logs, memory, and other short-lived data before they are lost or altered.
For a smaller company without an in-house forensic team, bringing in an external specialist as early as possible is often sensible. Until they arrive, the company should at least document the current state of affected devices, active sessions, running processes, network connections, and the exact time the incident was discovered.
Document the Initial State of the Theft
At the same time, collect the minimum dataset required to start the blockchain investigation and prepare the initial report to law enforcement.
This should include the originating corporate addresses and suspected attacker addresses, TXIDs of all unauthorized transactions, blockchain networks and token types, amounts in cryptocurrency, fiat equivalents at the time of the theft, exact transaction times, screenshots from wallets and internal systems, withdrawal requests and approval logs, a list of employees and contractors with access, and relevant corporate correspondence and system notifications.
FBI/IC3 guidance identifies crypto addresses, the amount and type of cryptocurrency, transaction date and time, and the transaction hash as core information to provide when reporting crimes involving digital assets.
Do not try to write the definitive version of what happened during the first few hours. It is more useful to separate confirmed facts, working hypotheses, and unverified assumptions.
“There is evidence this laptop signed the transaction” and “the employee using this laptop stole the money” are two very different statements in evidentiary terms.
Start the Blockchain Investigation
The objective in the first few hours is not to identify the attacker by name. The immediate task is to determine where the assets are and where they are moving.
The analyst should confirm the originating addresses and the loss amount, build the first transaction routes, identify splitting and consolidation of funds, detect token swaps, follow cross-chain movements, identify bridges, DEXs and exchange services, locate deposits to centralized platforms, and flag addresses that require urgent monitoring.
The tracing process itself is covered in more detail in “How to Trace Cryptocurrency Stolen from a Company and Identify the Current Destination Addresses.”
During the first day, finding a point where intervention may still be possible is more important than producing a beautiful fifty-page graph. The detailed report can be expanded later. A deposit on an exchange may only remain actionable for a short time.
Put the Addresses Under Continuous Monitoring
A one-time check becomes outdated quickly. The attacker may leave the funds untouched and start moving them hours or days later, once they believe attention to the incident has decreased.
Monitoring should alert the team to new transactions, add newly discovered addresses to the case, track swaps and bridges, update the transaction map, and help identify new VASPs as soon as they appear.
The company should monitor not only the attacker’s initial address but also all major branches of the flow. Otherwise, the investigation starts to resemble watching the front door long after the person has already left through the fire exit.
Notify the Exchange or Other VASP
If stolen assets reach a centralized exchange, custodial exchanger, or another VASP, the platform should be notified immediately.
The notice should identify the affected company, explain the circumstances of the incident, provide originating addresses and TXIDs, specify the amount and type of assets, show the known transaction route and the platform’s deposit address, and include the contact details of the person responsible for the case. If a law-enforcement report number is already available, include it as well.
Major platforms have dedicated channels for official requests, while disclosure of customer information or long-term restrictions on assets may depend on the legal sufficiency of the request and a subsequent demand from an authorized authority. Exchanges publicly describe their cooperation with law enforcement and their ability to restrict suspected criminal funds, but the exact process varies by platform and jurisdiction.
It is therefore important to distinguish between an urgent notification to the platform, a temporary internal restriction, preservation of account data, and a legally formalized freeze or seizure.
Even if the exchange confirms receipt of the report, this does not mean that the assets have been permanently frozen. The detailed procedure is covered separately in “Stolen Company Cryptocurrency Reached an Exchange: How to Seek a Freeze and Report the Theft to Law Enforcement.”
Separately Assess Whether Stablecoins Can Be Frozen
If the stolen assets include USDT, USDC, or other centrally issued stablecoins, the company should separately assess whether contacting the issuer is appropriate.
However, the response plan should not assume that the issuer will automatically or immediately freeze the tokens. The outcome depends on the network, the tokens’ current location, the evidence supporting the incident, the issuer’s requirements, and the applicable legal process.
Tether states that address-freezing requests must be supported by appropriate legal documentation, while theft and hack cases are handled through the designated channel. Circle also reserves the ability to block addresses and freeze USDC associated with unlawful activity, including in response to valid orders from competent authorities.
An issuer should receive a structured evidence package rather than an emotional “our money was stolen” message. That package should include addresses, TXIDs, the transaction route, circumstances of the theft, company documentation, and law-enforcement contact information where available.
File an Initial Report Without Waiting for the Final Investigation
A blockchain investigation may continue for weeks. The company should not wait for it to be completed before contacting law enforcement.
The initial report can be filed using the facts already known and then supplemented with new addresses, an updated flow map, newly identified exchanges, analytical reports, revised loss estimates, and technical evidence relating to the compromise.
The exact procedure depends on the country and the circumstances of the case. However, when dealing with foreign exchanges and stablecoin issuers, a formally registered law-enforcement report often becomes an important part of the documentary trail.
FATF has separately highlighted the challenges involved in recovering stolen virtual assets and the importance of international cooperation, freezing, and confiscation. This is another reason tracing and legal work should not be treated as consecutive stages. They need to run in parallel.
Do Not Publish the Full Route Without a Strategy
A company may feel an immediate urge to publish every identified address to the market, partners, and social media. Public disclosure can help warn others, but premature publication may also harm the investigation.
It may reveal to the attacker which addresses have already been identified, which routes are being monitored, which exchanges have received notifications, and how much the company already knows about the attack.
External communications should be coordinated by the incident lead together with legal counsel and investigators. A separate notice can be prepared for customers and partners without disclosing operational details of the tracing effort.
If the incident affects customer funds, personal data, or contractual obligations, the company should also assess any notification requirements under applicable law and its agreements with counterparties.
Do Not Negotiate With the Attacker on Your Own
The attacker may contact the company directly, offer to “return the funds for a reward,” or send a small amount back as proof that they still control the assets.
Without a proper risk assessment, the company should not follow links supplied by the attacker, connect a wallet to an unknown website, sign messages or transactions, disclose internal investigation details, send a “recovery fee,” or return incoming funds to a new address provided in a message.
The contact may be part of an extortion attempt, a way to gather additional information, or an attempt to obtain a malicious signature. Any decision to negotiate should be made jointly by legal counsel, investigators, and company management.
What Should Be Ready by the End of the First Day
After 24 hours, the investigation will probably not be finished. But the company should already have an interim report documenting the confirmed and preliminary loss amount, affected wallets, assets and systems, the likely compromise method, technical containment measures already taken, the current map of fund movements, identified exchanges, exchangers and bridges, notifications sent and their status, information about the law-enforcement filing, preserved evidence, and the action plan for the following days.
For a smaller company, this may be a well-structured document of only a few pages accompanied by a transaction table. There is no need to create a twelve-person corporate committee if the entire crypto infrastructure consists of two wallets and the CFO’s laptop. But addresses, decisions, timestamps, and responsible persons should still be documented with the same discipline.
Common Mistakes During the First 24 Hours
The most dangerous actions after a theft often feel perfectly reasonable in the moment.
Typical mistakes include reinstalling everything and destroying evidence, continuing to use the compromised wallet, waiting for the full investigation before notifying an exchange, contacting the suspected attacker independently, publicly disclosing the entire transaction route, assuming a blockchain transaction can simply be reversed, treating a support ticket as a guarantee that funds are frozen, or handling technical, financial, and legal work one after another instead of in parallel.
The sooner the company replaces improvisation with a controlled incident-response process, the more evidence and response options it is likely to preserve.
Conclusion
During the first 24 hours after a company’s cryptocurrency is stolen, the objective is not to answer every question immediately. The priority is to contain the compromise, protect the remaining assets, preserve evidence, and determine where the stolen funds are currently moving.
The technical investigation, blockchain tracing, and legal response should run in parallel. Exchanges and issuers receive urgent notifications, law enforcement receives an initial report, and management receives an interim assessment with a clear action plan.
The size of the company does not change this basic logic. Even if a single employee managed the wallet manually, the incident still requires discipline: one coordinator, clean infrastructure, preserved evidence, and continuous address monitoring.
For significant losses, AML Crypto can support urgent asset tracing, identify VASPs, prepare analytical evidence, and assist with the ongoing investigation and recovery process.
FAQ
Can Cryptocurrency Stolen From a Company Be Recovered?
Sometimes. Recovery is more realistic when the assets can be identified on a centralized platform or frozen with the involvement of an issuer. The outcome depends on the transaction route, speed of response, jurisdiction, and legal process.
Should the Company Finish Its Internal Investigation First?
No. Technical analysis, blockchain tracing, platform notifications, and preparation of the law-enforcement report should run in parallel.
Should a Compromised Computer Be Turned Off?
It depends on the circumstances. Shutting it down may stop some malicious activity, but it can also destroy volatile evidence stored in memory. Where possible, consult a specialist first and preserve the most time-sensitive digital evidence.
What Should Be Sent to an Exchange After a Theft?
Provide addresses, TXIDs, the amount, network, description of the incident, the identified transaction route, the platform’s deposit address, and the contact details of the responsible company representative. The request can later be supplemented with a police report and an official law-enforcement demand.
Should the Theft Be Disclosed Publicly?
Not automatically. Any publication should be coordinated with legal counsel and investigators so that it does not reveal the investigation strategy to the attacker or interfere with efforts to freeze the assets.
Want to learn more and get expert advice? Leave your email and we will contact you promptly!
Check blockchain address using Btrace
In seconds, determine the risk level of the counterparty’s address, find out the source of his funds and make an informed decision about interacting with him.