Stolen Crypto: Where You Actually File a Report and What Counts in the First Hours
After a theft most people google first and preserve the evidence last, when the right order is the other way round. What you have to record in the first hours, where private individuals actually turn, and where the limit of what is possible lies.




Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
The information provided in this article is for informational purposes only and does not constitute financial advice. Investing in cryptocurrencies carries a high level of risk.
After a theft the pattern is almost always the same: hours spent searching for what can be done, and eventually a police report that leaves out what matters most. The right order is the other way round.
What decides your chances is what you preserve in the first few hours. A transaction on the blockchain is permanently traceable, but only if someone knows which transaction is meant. Without addresses and transaction IDs, even the best cybercrime unit has nothing to work with.
Stolen crypto: the key points at a glance
- Preserve first, report second. Addresses, transaction IDs, timestamps and screenshots are the basis for everything that follows.
- Private individuals file a report with the online police portal of their federal state or at any police station.
- The Central Cybercrime Contact Points are explicitly not responsible for private individuals. They were set up for companies and public authorities. The police refer private individuals in so many words to the online portals of the state police forces.
- Recovery becomes realistic when the destination address leads to a regulated provider: there is a name behind the account, and investigators can reach it.
- If the funds settle on a self-custodied address with no onward route, the trail effectively ends.
- Anyone promising recovery against an upfront fee is the second fraud. These offers seek out their victims among reports of loss.
Stolen crypto: the first hours
Before you report anything, you preserve. Everything here is volatile the moment accounts are locked or sessions are ended.
- The transaction ID of every affected transfer. It is the key to everything that follows.
- Your address and the destination address, each copied in full, never typed out by hand.
- The time including the time zone and the chain involved.
- Screenshots of the wallet, of the history and, where there is one, of the message or page through which it happened. Including the full address of that page.
- For an exchange account: the session overview showing unfamiliar logins, while it is still visible.
Only then: have accounts locked, change passwords, move any remaining holdings to a newly created wallet. Where a seed phrase may have been compromised, moving the funds takes priority over everything else.
Stolen crypto: where the report belongs
Many guides get this wrong, so here it is set out cleanly:
| Affected party | Responsible body |
|---|---|
| Private individual | Online police portal of your own federal state, or any police station |
| Company, association, public authority, research institution | Central Cybercrime Contact Point (ZAC) of the state |
| Critical infrastructure, federal authorities | ZAC at the Federal Criminal Police Office |
The police put it unambiguously on their own overview page: "Private individuals should please contact the online portals of the state police forces." Such a portal exists in all sixteen federal states, though which offences can be recorded there differs. Any police station will take the report in any case.
The report should carry the five preserved details listed above, in plain order and without interpretation. Not "I was hacked", but: on this date, at this time, from my address to that address, transaction ID, amount, chain. Anything you suspect yourself belongs at the end and should be marked as a supposition.
Also worth doing: a notification to the exchange where the funds arrived, if the destination address can be attributed to one. Providers respond to tips, but they act only on an official order. The notification mainly ensures that the attribution is still documented at the time of the request.
Stolen crypto: what is realistically possible
Honesty belongs here, because it protects against the second loss.
There is a prospect when the trail leads to a regulated provider. Every account there is identified, and investigators can demand information and have balances frozen. That is exactly why addresses and transaction IDs matter so much: they are the bridge from an anonymous chain to a name.
It is practically hopeless when the funds stay on a self-custodied address or run through mixing services. There is then no body to which an order could be addressed.
With small amounts a report rarely leads to an investigation that produces a result. It still costs little, and it serves a second purpose: only reported cases appear in the statistics, and patterns across many reports are what allows investigation teams to come into being at all.
What happens to the loss for tax purposes is a separate question. A theft is something different from a loss through insolvency, and the two are treated differently. This article is no substitute for legal or tax advice.
Stolen crypto: the damage afterwards
The most common follow-up mistake is clutching at straws. Under every public post about a loss, offers appear within hours to retrieve the coins for an advance fee. There is no technology for it. Anyone able to reverse a confirmed transaction could reverse every other one as well, and the whole system would be worthless.
Two things noticeably lower the risk for next time, and both are dull: storage split by amount instead of everything in one place, and a backup that nobody finds but the right people can reach. What that looks like in practice is set out in our guide to storing your seed phrase safely.
And for the part held on an exchange, the choice of provider decides whether there is a supervisory authority to turn to if the worst happens. The licensed providers are listed in our overview of regulated crypto exchanges.
Stolen crypto: frequently asked questions
Is a police report worth it at all? With small amounts, rarely in the sense of a recovery. But it costs little, and it is the precondition for authorities being allowed to approach an exchange in the first place.
Can the police get my coins back? Not directly. They can demand information and, where the funds are held with a regulated provider, arrange for them to be secured. On a self-custodied address that ends.
Do I need a lawyer? With larger amounts, or where a provider is involved that does not respond, yes. For the report itself, no.
What about private investigation services? Analytics firms can retrace a trail and deliver usable reports. They cannot retrieve anything, though, and any offer promising exactly that against an upfront fee is fraud.
How much time do I have? For the report itself there is no short deadline. For the evidence there is: session logs and account data disappear as soon as accounts are locked or reset.
Sources
- Police: Central Cybercrime Contact Points of the police forces for businesses and public authorities (responsibilities, referral of private individuals to the online portals)
Transparency note: This article was produced with the assistance of artificial intelligence and reviewed by our editorial team before publication. All figures and claims were checked against the primary sources linked in the text. The feature image was generated with AI.
Related articles
Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
August 18, 2026 7:14 PM

Two-Factor Authentication on a Crypto Exchange: Why SMS Is the Weakest Option
SMS codes are the most common form of two-factor authentication on crypto exchanges, and the weakest. The problem is not only SIM swapping, which the FBI has recorded falling for three years. It is real-time phishing, and against that neither SMS nor an authenticator app helps.
October 12, 2018 2:48 PM

Savedroid website hacked or exit scam?
It’s panic in the crypto world as users scramble to figure out whether the recent downtime of Savedroid means that the site was hacked or the admins have performed an exit scam.
August 25, 2026 10:31 PM

Crypto Wallet Phishing by Letter: Why the QR Code From Your Postbox Wants Your Recovery Phrase
Letters carrying a QR code urge a supposedly urgent wallet update on grounds of quantum resistance and lead to a page that asks for the recovery phrase. The Federal Office for Cybersecurity reported the ploy on August 18, 2026.
August 23, 2026 1:16 PM

Address Poisoning: Why Seven of Forty Characters Were Enough to Divert $2 Million
A fake wallet address matched the real one in just seven of forty characters and still intercepted 2 million USDC. Our own count of the affected wallet shows that a third of all counterparties in its history belong to such look-alikes.
August 18, 2026 10:14 PM

Sent Crypto to the Wrong Address: What Still Works and What Is Gone for Good
A sent transaction cannot be recalled. That is true, but it is only half the story. Whether your money is gone depends on who holds the key to the destination address. Six cases, cleanly separated: four of them are recoverable.
October 13, 2018 10:22 PM

Duo Security Discloses Crypto Scam Botnet On Twitter
Duo Security, an Austin based cybersecurity company has disclosed a huge and sophisticated botnet crypto fraud scam On Twitter.
September 21, 2018 11:59 AM

Japanese Cryptocurrency Exchange Hacked, $60 Million Loss Reported
Japanese cryptocurrency exchange Zaif has been hacked, with an estimated loss of about $60 million worth of Bitcoin and two other digital currencies.
September 26, 2026 4:21 AM

Operation Herakles disconnects 13,888 phone numbers: what to check on crypto investment calls
Six authorities have disconnected 13,888 phone numbers used by investment fraudsters to call their victims in Operation Herakles, 9,304 of them in the past three months alone. What the Federal Network Agency now requires of telecoms providers and which three checks protect you from the scheme.
March 31, 2026 5:13 PM

Quantum Threat to Bitcoin? Google Research Sparks Urgent Crypto Security Debate
Google’s quantum breakthrough raises fears for Bitcoin security. Can crypto survive quantum attacks—or is an upgrade urgent?
May 27, 2024 11:56 AM

Wave of Crypto Hacks and Exploits Hits Influencers and Memecoins: WATCH OUT!
A series of hacks on crypto influencers, celebrities, and a major memecoin exploit have raised serious security concerns within the cryptocurrency community. Here is what you need to watch out for!
August 31, 2026 7:20 AM

Browser Extensions as Wallet Thieves: How a Sports App Became a Seed Phrase Collector
In August 2026 the security firm Socket disclosed two separate campaigns: 40 confirmed malicious Firefox extensions and 19 for Chrome and Edge, all of them from the official marketplaces. Nine of them were harmless sports apps that only turned into wallet thieves through an update.
January 31, 2025 11:45 AM

What Happens If Sam Bankman-Fried Gets a Pardon From TRUMP?
The parents of Sam Bankman-Fried are reportedly exploring a presidential pardon from Donald Trump for their son. What would a pardon mean for the crypto industry?
September 20, 2026 4:15 PM

Crypto Phishing After a Data Breach: The Warning Signs in a Fake Exchange Email
After every major data breach, the number of phishing emails sent in the name of crypto exchanges and wallet manufacturers rises. This article shows you how to recognise such a message, which data a reputable provider never requests by email, and what to do in the first hour after a click.
September 1, 2026 7:27 AM

Clipboard Attack: How Malware Swaps the Wallet Address You Copied
A clipper replaces the receiving address between copying and pasting with the attacker’s, and your wallet’s checksum notices nothing. What Microsoft and the Federal Office for Cybersecurity have documented, and which check really makes the attack come to nothing.
August 31, 2026 10:12 AM

Fake AML Checks for Crypto Wallets: How to Spot the Scam Sites
Fraudulent websites pose as money-laundering screening services for crypto addresses and ask you to connect your wallet. A genuine check needs only the public address, and three of the domains named by Malwarebytes still respond twelve days later.
August 13, 2026 4:59 PM

Trezor Data Breach: First 13,689 Customers, Then Roughly 67,000 More Exposed
A breach at Trezor shipping partner ShipMonk exposed names, phone numbers and home addresses of 13,689 customers in August; in September Trezor reported roughly 67,000 more in the US. Devices are safe, phishing risk is not.
April 27, 2026 10:30 AM

Win $5,000 in BTC: Tangem Launches Exclusive 2026 Prize Draw
Tangem announces a massive prize draw with $5,000 in BTC and iPhone 17s up for grabs. Secure your crypto and enter today using our exclusive link.
July 1, 2024 8:35 AM

Floki Inu Issues Major Scam Alert: A New Crypto Hack?
Floki Inu issues a major scam alert, urging investors to stay vigilant against fraudulent token schemes and the importance of security in the crypto space. What is it about?
December 22, 2020 3:49 PM

Crypto Wallet Provider Ledger Hacked: Data Leak Results in Phishing Scams
Ledger, a cryptocurrency wallet provider has encountered a data breach. The official Twitter account of the hardware wallet tweeted that they have been alerted to the dump of a client database.
May 4, 2019 5:44 PM

Microsoft Hackers Stole Crypto Using Victims Emails
Another batch of crypto users have lost money recently through an unlikely breach. Recently, Microsoft services such as Hotmail, MSN, and Outlook have been hit by a breach. It was later learned that the breach was due to an employee’s […]
September 29, 2026 1:15 AM

BaFin warns over nova-c-solutions.com: What is behind a genuine registration number
The BaFin has warned about a website offering crypto-asset services without authorisation and speaks of a presumed identity theft at the expense of a real US company. The case shows why the advice to look a provider up in the register does not carry on its own.
September 8, 2026 7:23 AM

Compensation After an Exchange Hack: What Twelve Crypto Providers Really Promise German Customers
After $322 million in losses in a single September week, the question is who replaces stolen coins. On September 8, 2026 we retrieved the security and legal pages of twelve providers and evaluated what is promised there.
February 21, 2025 9:55 PM

Bybit Hack Revealed: Here's the Mastermind Behind the $1.46 Billion Theft
The Bybit hack has been traced back by the blockchain investigator ZachXBT, with conclusive evidence linking the hackers to the $1.46 billion theft. Full details revealed...
September 26, 2026 7:29 PM

Coins Stolen in an Exchange Hack: What the German Tax Office Accepts as a Loss
After the attack on Bitget on September 24, a question the reports leave out arises for those affected in Germany: can a stolen balance be written off against tax? The answer hangs on a single term in the Income Tax Act, and it is decided by your records.
September 17, 2026 4:14 PM

D'CENT App Wallet: How to Tell If Your Recovery Phrase Has to Move Now
Manufacturer IoTrust reports suspicious asset transfers in the D'CENT app wallet and asks users to move their holdings. One question decides the matter: has your recovery phrase ever been entered into the app?
More from CryptoTicker


