How to Check If Your Crypto Wallet Has Been Hacked
Not all wallet compromises are obvious. Attackers sometimes sit dormant inside a wallet for weeks before draining it. Here's how to check for compromise — before the damage is done.
Most people assume a hacked wallet announces itself immediately — balance goes to zero, funds vanish, panic follows. That's one scenario. But it's not the most common one.
In 2026, the more sophisticated attacks work silently. An attacker gains access to your seed phrase through a phishing site or malicious extension, then waits. They monitor the wallet, waiting for a significant deposit. Or they set a token approval that gives them the right to drain your funds at any moment they choose — while your balance sits untouched and your wallet appears completely normal.
By the time you notice something is wrong, it may already be too late. That's why checking your wallet proactively — not reactively — is a skill every crypto user needs.
This guide covers five concrete steps to check whether your wallet has been compromised, what warning signs to look for even when funds haven't moved, and exactly what to do if you find evidence of a breach.
Step 1: Check your transaction history on a blockchain explorer
The blockchain is a public ledger. Every transaction involving your wallet address is permanently recorded and visible to anyone. This is your first and most important diagnostic tool.
Go to the block explorer for the network your wallet uses:
- Ethereum and ERC-20 tokens (including USDT, USDC, LINK): use Etherscan.io
- BNB Smart Chain and BEP-20 tokens: use BscScan.com
- Polygon: use Polygonscan.com
- Bitcoin: use Mempool.space or Blockchain.com
- Tron and TRC-20 USDT: use Tronscan.org
- Solana: use Solscan.io
Enter your wallet address in the search bar and examine the full transaction history. Look specifically for:
- Any outgoing transactions you do not recognise — especially ones sending funds to an unfamiliar address
- Transactions that occurred at unusual hours, particularly if they happened while you were asleep
- "Approval" transactions — these show as Approve in the method column on Etherscan and grant a third party permission to move your tokens
- Small "test" transactions sending a tiny amount before a larger drain — a common attacker pattern to verify control of the wallet
If you see any transaction you didn't make, treat the wallet as compromised and move immediately to the emergency steps at the bottom of this article.
Step 2: Check active token approvals — this is critical
Token approvals are one of the most dangerous and least understood aspects of DeFi. When you interact with a decentralised protocol — swap tokens on Uniswap, deposit into a yield farm, claim an airdrop — you typically sign an "approval" transaction. This grants the protocol's smart contract the right to move a specified amount of your tokens on your behalf.
The problem: attackers have learned to exploit this mechanism. A malicious site will prompt you to sign an approval granting unlimited permissions to an address they control. Your funds look untouched — but at any point, the attacker can call that contract and sweep everything the approval covers.
Even legitimate approvals accumulate over time. Many people have dozens of old approvals sitting on their wallets from protocols they used years ago. If any of those protocols get exploited, those approvals become attack vectors.
How to check your token approvals:
- Go to revoke.cash and connect your wallet address (you don't need to sign anything — just paste the address)
- The tool will show every active approval across all tokens, who approved it, and what spending limit was granted
- For a more detailed view across multiple chains simultaneously, use Debank.com
- The Rabby wallet browser extension also has a built-in approval manager that flags risky approvals automatically
Free download
First 30 Minutes After Crypto Theft
PDF checklist: 6 steps to take immediately. Every hour of delay lowers your recovery chances.
Download free checklist →When reviewing approvals, pay attention to:
- Any approval with an unlimited spending limit — this should be revoked unless you actively use that protocol
- Approvals granted to addresses that aren't recognisable contract names (e.g., an address with no label instead of "Uniswap V3")
- Approvals you don't recall granting — especially ones dated around periods when you were exploring new platforms or clicking airdrop links
Revoking an approval costs a small amount of gas but is almost always worth it. If you find an approval you don't recognise, revoke it immediately — don't wait.
Step 3: Check for suspicious authorised apps in your wallet settings
Beyond on-chain approvals, some wallet software maintains its own list of connected sites and applications. These are separate from blockchain-level token approvals — they control which websites have a live connection to your wallet extension.
In MetaMask: Click the three-dot menu in the top right of the extension, go to Settings → Connected Sites. Review the full list. Remove any site you don't recognise or no longer use.
In Trust Wallet and other mobile wallets: Go to Settings → WalletConnect Sessions. Any active WalletConnect session represents a live bridge between your wallet and an external app. If you see sessions you don't remember establishing, disconnect them immediately.
In hardware wallets (Ledger, Trezor): The hardware device itself cannot be "connected" to a site — but the software companion (Ledger Live, Trezor Suite) can have accounts linked to third-party apps. Check the app's connected applications section and revoke any you don't recognise.
This step matters because a connected site can sometimes request transaction signatures without you having to navigate to it — especially if you have an older extension version with permissive settings.
Step 4: Check login activity on linked exchange accounts
Many people use the same email address across both their self-custody wallet and their exchange accounts. If an attacker obtained your email credentials through a phishing attack or data breach, they may have accessed your exchange separately from your wallet.
Check login history on every exchange you use:
- Binance: Account → Security → Login Activity
- Bybit: Account → Security → Login History
- OKX: Security → Login Log
- Coinbase: Settings → Activity → Login History
Look for logins from IP addresses you don't recognise, especially from different countries or at times when you weren't active. A single unfamiliar login should be treated as a breach — immediately change your password, enable 2FA if you haven't, and terminate all active sessions.
Also check whether any withdrawal whitelist addresses have been added or modified, and whether your 2FA method has been changed. These are the first things an attacker changes to prepare a large withdrawal.
Free · no registration
Report the scam — we'll tell you exactly where to file
Fill in a short form and get a personalised filing guide: FBI IC3, FTC, Interpol or your exchange. Free.
Report a scam →Step 5: Check whether your email was in a data breach
Many wallet compromises start not with the wallet itself but with the email address associated with it. Data breaches at exchanges, DeFi platforms, and web services expose millions of email and password combinations every year. Attackers purchase these databases and use them in credential-stuffing attacks.
Check your email addresses at haveibeenpwned.com — the most comprehensive free database of known data breaches. If your email appears in any breach, assume those credentials are actively for sale on darknet markets.
Pay particular attention to breaches involving:
- Crypto exchanges or DeFi platforms you've used
- Password managers (a breach here exposes everything)
- Email providers themselves
- Any service where you used the same password as your exchange or wallet-linked email
If your email appears in a breach: change the password immediately on every platform where you used the same or similar credentials, enable 2FA everywhere, and audit your wallet permissions as described in Steps 1–3 above.
Warning signs your wallet may be compromised — even if funds haven't moved
The absence of missing funds does not mean your wallet is safe. Watch for these indicators of a dormant or pending compromise:
- New token approvals appeared that you didn't create — this is the clearest possible red flag. An approval transaction that you didn't sign means someone with access to your private key did.
- You received unexpected NFTs or tokens from unknown addresses — attackers sometimes "dust" wallets with malicious tokens designed to trigger approvals when you try to sell them.
- Your wallet suddenly requests you re-enter your seed phrase — legitimate software never does this. If this happened, your software may have been replaced with a malicious version.
- You connected your wallet to any site you found through an ad, social media post, or Telegram link in the past 30 days — even if that site looked legitimate, it may have extracted your wallet data.
- You installed a new browser extension that requested access to all websites — several popular-looking extensions have been found to be wallet stealers.
- Your MetaMask or wallet extension updated to a version you didn't recognise — particularly if this happened alongside a request to "re-verify" your wallet.
Any one of these should prompt an immediate full audit using Steps 1–5 above.
What to do if you find evidence of compromise
Speed matters. Every minute the attacker has active access to your wallet or approvals is a minute they can drain remaining funds.
Immediate actions — in this order:
- On a different device or a fresh browser with no extensions installed, create a completely new wallet and record the seed phrase physically, offline.
- Transfer all remaining funds from the compromised wallet to the new one immediately. Do this before revoking approvals — if the attacker is watching, revoking approvals may trigger an immediate drain of remaining funds.
- Only after funds are safe: go to revoke.cash and revoke all token approvals from the old wallet address. This prevents further damage if the attacker tries to return.
- Change all passwords linked to the compromised email, enable authenticator-based 2FA (not SMS), and terminate all active sessions on every exchange.
- Preserve all evidence: download full transaction history from every blockchain explorer, screenshot the suspicious approvals before revoking them, note the exact timestamps and addresses involved.
Do not use the compromised wallet again, even after revoking approvals. If the attacker has your seed phrase, they can regenerate the private key at any time from any device.
When to involve blockchain forensics
If funds have already moved out of your wallet, a blockchain forensics investigation becomes necessary — not optional. Here's what professional analysis can accomplish that self-investigation cannot:
- Tracing funds through multiple hop addresses, DEX swaps, and chain bridges to identify where they ultimately landed
- Determining whether the destination is a known exchange address (enabling a freeze request), a mixer, or a sanctioned address
- Preparing a formal evidence package for exchange compliance teams, law enforcement, and court proceedings
- Identifying patterns that link the attack to known threat actors or previous incidents
Professional tools like Chainalysis Reactor, TRM Labs, and Elliptic — the same platforms used by Interpol and FinCEN — can follow fund flows through paths that are effectively invisible to manual analysis. The earlier an investigation starts, the higher the probability of tracing funds before they're fully laundered.
Suspect your wallet is compromised?
Describe the situation — we'll review it for free within 15 minutes
The bottom line on wallet security checks
A compromised wallet doesn't always announce itself with a zero balance. The most dangerous compromises are the quiet ones — the ones where an attacker is positioned, patient, and waiting for the right moment.
Running the five checks in this article takes about 15 minutes. Done quarterly, they give you a clear picture of your wallet's security status and catch most forms of silent compromise before any funds are lost.
If you run through these checks and find something suspicious — or if you've already experienced a drain and need professional tracing — the team at KarCrypto handles exactly these cases. Our blockchain forensics process starts with a free assessment, and we work on a success-fee basis for large theft cases. Read more about what to do immediately after a crypto theft.
Frequently Asked Questions
How do I know if my MetaMask wallet has been compromised?
Can a crypto wallet be hacked without me knowing?
What is a malicious smart contract approval and how do I check for it?
Should I use the same wallet after detecting a hack?
What on-chain tools can I use to check my wallet for suspicious activity?
Get a free recovery assessment
Send your TX hash, address, or a description of the situation — within 15 minutes you'll get an honest answer: is recovery realistic in your case, and what it would take.