If you’re reading this because you installed a wallet that now looks wrong — stop and follow this plan in order. Fake wallet apps send your seed phrase to the attacker the moment you type it in. Some drain you instantly; others wait weeks until you’ve deposited meaningful money. Either way, the clock is ticking, and the order of your next moves determines how much you keep. First, find out how you got here with our guide to spotting fake wallets, then come back and execute.
Signs You Installed a Fake Wallet
| Sign | What it means |
|---|---|
| You found the app through a search ad, Telegram link, or third-party site | You’re almost certainly compromised |
| The developer name doesn’t match the official publisher | It’s a lookalike |
| The app asked for your seed phrase to “verify” or “restore” | Fake — real wallets never ask |
| The app’s website URL doesn’t match the official domain | Fake |
| A wallet you didn’t open prompted for your seed phrase | Drainer behaviour |
| The app requests phone contacts, SMS, or camera access | A wallet needs none of these |
Step 1: Determine Your Exposure
| Scenario | What you’ve lost |
|---|---|
| Installed but never entered a seed phrase | Nothing. Uninstall and reinstall the real app. |
| Created a new wallet in the fake app | The fake app has that seed phrase. Wallets generated there are compromised. |
| Imported an existing seed phrase | That seed phrase is in the attacker’s hands. Everything on it is at risk. |
Be honest about which scenario you’re in. If you created a wallet in the fake app and moved crypto into it — that’s the second scenario, even if the fake app “worked” like the real one.
Step 2: Move Remaining Funds Safely
The correct order matters. Create the new wallet before you touch anything else:
- Install the real wallet from its official website only (see our guide to verified vs unverified sources)
- Generate a new wallet with a new seed phrase, written down on paper — never screenshotted
- From the real app, transfer every balance out of any wallet connected to the fake app
- Transfer in small batches first if you’re unsure — confirm each arrives
- If you can’t reach the funds at all, the attacker already emptied them — skip ahead to Step 4
Step 3: Revoke Approvals
Fake apps and drainers often leave behind token approvals that let them spend your assets later. On a clean device, connect the compromised wallet address to a tool like Revoke.cash and revoke every approval you don’t recognise. Do this even after you’ve moved balances — leftover approvals can still target airdrops or new deposits.
Step 4: Freeze Compromised Accounts
The seed phrase may be tied to more than one wallet. Treat everything the phrase can unlock as compromised:
- Exchanges: contact support immediately and ask them to freeze the account and any linked deposits. Mention you’re reporting a theft.
- Passwords: change the password for your email first, then exchanges, then anything else — using a clean device.
- 2FA: reset authentication methods in case the attacker changed them.
Step 5: Clean the Device
- Uninstall the fake app or extension
- Run a full antivirus scan (Malwarebytes, Bitdefender, ESET) — fake wallets often ship keyloggers
- Remove any browser extension you didn’t intentionally install
- If you entered anything sensitive on that device, a factory reset or clean OS reinstall is the safest option
Step 6: Report It
| Where | Why |
|---|---|
| App store / Chrome Web Store listing | Get the fake taken down before others install it |
| Action Fraud (UK) / FBI IC3 (US) | Formal record for any follow-up |
| The exchange you use | They can freeze a receiving account if the attacker transfers there |
| BitcoinTalk Scam Accusations board | Warn the community |
Keep a record of the transaction hashes, the app’s name, the developer, and screenshots of the listing.
What NOT to Do
- Never pay a “recovery service”. No one can reverse a blockchain transaction. Everyone offering to “recover” your funds for a fee is a second scammer — many of them target the exact people this article is for. (More on recovery scams.)
- Never reuse the compromised seed phrase. A new wallet with the old phrase is still compromised.
- Never transfer funds to an “address” the scammer gives you to “protect” them — that address is theirs.
- Don’t reinstall the fake app to “check” — every launch is another chance for it to capture input.
- Don’t panic-post your wallet address alongside your story; it invites airdrop and phishing follow-ups.
- Don’t screenshot your new seed phrase — or anything else. Paper only.
Related: How to Spot a Fake Crypto Exchange | Common Phishing Attacks | Self-Custodial vs Custodial Wallets
Bottom Line
A fake wallet compromises every seed phrase it ever touched. Move fast and in the right order: create a fresh wallet on the real app first, transfer everything out, revoke approvals, freeze exchange accounts, clean the device, and report. And whatever the loss, never pay a “recovery service” — the only person who profits from that is the same person who already took your coins.