Wallet Hacked? Transfer Funds First, Then Revoke Approvals: Don’t Get the Order Wrong
Always transfer your remaining assets first, then revoke permissions. If you reverse the order, you might lose even the last bit of funds you can save.
When you realize your wallet has been compromised, your first instinct should be to "rescue movable assets," not "find out who did it." Revoking approvals requires an on-chain transaction, which costs gas and waits for block confirmation. In those few minutes, the hacker could have already swept everything out of the wallet.
Prerequisites
- A brand new, secure wallet address (private key never exposed online, preferably generated offline)
- Enough native tokens in the old wallet to cover gas fees (e.g., ETH, BNB, MATIC, TRX); don't count on topping up later—by the time you do, the assets could already be gone
- Tools to check approvals online (such as a block explorer or security platform)
Step 1: Transfer Remaining Assets from the Old Wallet
Immediately after discovering the breach, right away check what assets are still left in the old wallet. Focus on two types: native chain tokens (ETH/BNB, etc.) and major stablecoins (USDT/USDC). Hackers often sweep in bulk but may overlook small holdings or lesser-known tokens.
How to do it: Open the old wallet, initiate a transfer, and send all remaining assets—at once or in batches—to the new wallet address. Leave enough for gas: calculate the network fee needed for the transaction, then transfer everything else.
Completion criterion: All valuable tokens except a tiny amount reserved for gas have been moved out of the old wallet, with on-chain transaction records available.
High-Risk Warning
If the private key/seed phrase has been fully compromised, hacker bots may monitor wallet activity. When you initiate a transfer, they might front-run you with a higher gas price to steal the assets—this is known as a "front-running attack." As soon as you see assets still there, act immediately; every second of hesitation could let them be snatched. Also, avoid anyone online who claims they can "recover your funds." Phrases like "remove multi-sig authorization" are almost always secondary scams. The official team of a decentralized wallet has no authority and cannot freeze on-chain assets.
Step 2: Revoke Malicious Approvals on the Old Wallet
After the assets have been moved, the old wallet address itself is abandoned, but the approval records remain. If the hacker obtained "unlimited approval" (unlimited allowance), they could still drain any future tokens of that type you might later send to that address.
How to do it: Use an approval management tool to check and revoke approvals on the old wallet. Common tools include Revoke.cash, Debank, or built-in approval detection features in some wallets (e.g., TokenPocket's authorization checker).
Case A: Old wallet still has native tokens for gas Connect the old wallet directly in the tool, select the risky approval contract, click "Revoke," and pay the gas fee to complete the on-chain action.
Case B: Old wallet no longer has gas You cannot initiate a revocation from the old wallet. The correct approach is: abandon this address and never use it again. Focus on managing approvals for your new wallet. The old wallet approvals will remain because you can't pay gas to cancel them.
Completion criterion: In the approval management tool, all suspicious approvals under the old wallet address have been removed (or you have confirmed the address is abandoned and will not be used).
Verification After Completion
Use a block explorer (such as Etherscan, Tronscan) to search for the new wallet address, and verify that all asset balances and approval records are normal. This concludes all operations related to the old wallet.
