You got drained. Here is what to do now
Take a breath. Work in order. Some of this is fixable, some is not, and this page is honest about which is which. The most important thing right now is to not make a second mistake while you are panicking.
In the first minutes
- 1
Move what is left, from a wallet the attacker does not control
If any funds remain, send them to a brand new wallet, created on a device you trust, from a seed phrase you have never typed into any website. Do not send from the drained wallet using a link anyone gave you. Speed matters, but a wrong move here loses the rest.
- 2
Revoke delegate approvals
A drain can leave a delegate approval that lets an address keep moving a token. Revoking clears it. This is the one lingering permission you can still shut off.
- 3
Treat the seed phrase as burned
If you signed on a fake site or entered your seed anywhere, assume the whole wallet is compromised. Stop using it. Never re-fund it: attackers watch drained wallets and sweep new deposits in seconds.
- 4
Write down the evidence
Save the transaction signatures, the exact site or link, the wallet addresses involved, and the timestamps. You will need these to report it, and it helps others get the domain blocked.
What is and is not recoverable
Delegate approvals can be revoked. If a drain set a delegate on one of your token accounts, revoking removes it and stops further transfers by that delegate.
A transfer that already executed is final. And if an attacker reassigned ownership of an account with SetAuthority on AccountOwner or the System assign instruction, only the new owner can sign for it now. That cannot be undone on-chain. Be wary of anyone who says otherwise.
Report it, and avoid the second scam
Report the domain and the addresses so others get protected: label the address on a Solana explorer, file a report on Chainabuse, and flag the phishing site to Scam Sniffer and to the project's real channels. If a specific project was impersonated, tell the real team so they can warn their community.
No legitimate service can reverse a Solana transaction. Anyone in your DMs offering to recover your funds for a fee, or asking you to connect a wallet or sign a transaction to "get your money back", is the second scam. Do not pay, do not sign. Drained victims are targeted again within hours.
How the lure works, so you spot the next one
Almost every drain starts the same way: a fake claim or airdrop site, a spoofed Jupiter or Raydium frontend, a Blink in a social post, or a hijacked X, Discord, or Telegram account posting a link. The site shows a normal wallet connect, then asks you to sign a transaction that quietly bundles the drain.
The one rule that stops most of it: no real project ever needs you to sign a transaction to verify, claim, or connect. Connecting a wallet is a signature-free action. The moment a "verify" or "claim" button pops a transaction to sign, close the tab. When in doubt, paste the transaction into the scanner first.