Skip to content

If your wallet is compromised

This page is written to be read quickly, by someone who is not calm. Start at the situation that matches yours.

This is the most serious case, because access cannot be taken back.

A phrase cannot be made secret again. Changing your password does nothing. Locking the wallet does nothing. Uninstalling does nothing. The only fix is to move everything to keys that person has never seen.

  1. Create a brand new wallet, from a new phrase. On a device you believe is clean. Write the new phrase down on paper.
  2. Move your plain currency first. It is the easiest to sweep and the most likely to be taken.
  3. Move your assets next, using the flow built for each asset type. If those flows are not available in your build, you cannot move assets from inside this wallet, and you should still move the currency. See Why an action is unavailable.
  4. Do not send anything back to the old wallet, ever, including change from an unrelated transaction.
  5. Assume anything left behind will be taken. Prioritise by value, not by convenience.

If your holdings are large and the exposure is recent, moving currency in a single high-fee transaction is usually worth it. An attacker who is watching will race you.

  1. Open Connected sites and disconnect the site. This stops further requests. It does not undo what you already signed.
  2. Check Activity for what actually happened.
  3. Work out what the signature was. A payment is done. A message signature moved nothing. A partial signature may still be outstanding and completable by someone else. See What a signature authorizes.
  4. If a partial signature is outstanding, the only certain revocation is to spend the committed coin yourself, into a transaction you control, so the offer can no longer be completed.
  1. Check whether it was really unauthorized. A change output returning to your own address looks like an outgoing transaction to a stranger. Check whether the destination is one of yours.
  2. If it genuinely was not you, your keys are compromised. Follow the phrase-exposed procedure above immediately. Do not investigate first.
  3. Record the transaction ids before you do anything else. They are the only evidence, and they are public.

You installed something that was not the real wallet

Section titled “You installed something that was not the real wallet”
  1. Remove it.
  2. If you entered your phrase into it, treat the phrase as fully exposed and follow the first procedure above.
  3. If you never entered a phrase into it, no key material was ever there and you are fine.
  • Reverse a confirmed transaction.
  • Freeze funds at another address.
  • Recover a lost phrase.
  • Identify who took the coins in a way that gets them back.
  • Review Security model and decide what you would do differently.
  • Consider hardware signing for long-term holdings.
  • Keep experimenting money in a separate wallet from savings.

If you believe the loss came from a flaw in the product rather than from an exposed phrase, report it to legal@bitcoinuniverse.io. See Support and reporting.