What to Do After a Crypto Scam: The First 72 Hours, Hour by Hour
An hour-by-hour plan for the first 72 hours after a crypto scam: which payment routes can still be frozen, the evidence to record before you lose access, the reports that create a paper trail, and the mistakes that cost victims their second chance.
The First 72 Hours Decide Everything. Not the Next Six Months.
Why the hours before you have a lawyer matter more than the months after.
What this guide says in 5 lines
- The first 72 hours are the only window in which money can still be stopped. After that you are building a record, not chasing funds.
- Freeze the payment route first. Bank, card and exchange deadlines are measured in hours and days, not months.
- Record the evidence set before you lose access to any account, chat or email address.
- File at IC3.gov and ReportFraud.ftc.gov with a written trace attached, not described.
- Anyone who contacts you offering recovery is running the second scam. That is how most victims lose more.
If you have just realised you were scammed, the order of the next three days matters more than anything you do afterwards. Three things can still be stopped inside that window: a card payment, a bank transfer, and funds sitting at a regulated exchange. Everything else — the reports, the letters, the trace — exists to build a record that institutions will act on. This guide gives you the sequence, hour by hour, and says plainly which parts are urgent and which can wait until you have slept.
The emotional reality is that you will want to do everything at once, and the scammers know it. The same people who took the first payment often reappear within days as a “recovery agent”, a “blockchain investigator” or a “compliance officer” who can get it back for a fee. That approach is the single most common way victims lose a second time. Nothing in this guide requires you to pay anyone, and no legitimate step in it involves sending more crypto.
The first hour: stop the bleeding
Before you file anything, close the doors that are still open. A scam that took one payment often has continuing access — a connected wallet, an approved contract, a shared screen session, a password you reused. Each of those is a second withdrawal waiting to happen.
Work through this list in order. It takes about twenty minutes and it is the only part of the process where speed genuinely changes the outcome.
- 01Disconnect the wallet you used from any site you do not recognise, and revoke token approvals. An approval you granted weeks ago can still be used today.
- 02Move any remaining funds in that wallet to a fresh wallet with a new seed phrase, generated on a device that has never touched the compromised one.
- 03Change the password on the email address tied to the wallet, the exchange and the payment app — in that order, because email is the reset path for everything else.
- 04Turn on two-factor authentication using an authenticator app, not SMS. SIM-swap attacks are a standard follow-up move.
- 05Screenshot everything while it still exists: the site, the chat, the deposit page, the transaction confirmation, the “support” replies.
- 06Write down the transaction hash and the receiving address in a plain text file. Do not rely on screenshots for addresses — they must be copied exactly.
If anyone asks you to pay a “release fee”, a “gas fee”, a “tax clearance” or a “verification deposit” to unlock your own money, you are being scammed a second time. There is no such mechanism on any blockchain or at any exchange.
Hours 1–6: freeze every payment route you used
This is the part with real deadlines, and it is the part most victims do last. The route your money left by determines who can still act, and how long you have. A card payment and a self-custody wallet transfer are not the same problem, and treating them the same wastes the only hours that matter.
Contact every route you used, even the ones you think are hopeless. A refusal in writing is itself evidence, and it establishes that you acted promptly — which matters later when a bank or an insurer reviews your case.
| Route | Who to contact | Realistic deadline | What to say |
|---|---|---|---|
| Card payment | Card issuer, fraud line | Hours to a few days | Say “unauthorised card transaction” and ask for a chargeback. Do not say “I was scammed” first — that framing invites a refusal. |
| Bank transfer (wire, ACH, SEPA) | Your bank's fraud team, in writing | Same day, ideally within hours | Ask for a recall or indemnity claim and request the request in writing with a reference number. |
| Zelle, Cash App, Venmo | The app, then the linked bank | Days, and shrinking | Report in-app immediately, then escalate to the bank that funds the account. |
| PayPal | PayPal dispute centre | 180 days for most disputes | Open a dispute, not a “friends and family” message. Escalate to a claim if refused. |
| Crypto to an exchange deposit address | That exchange's compliance team | Days — the shortest window of all | Send the txid and receiving address and ask for a freeze under their compliance policy. |
| Crypto to a self-custody wallet | Nobody can freeze it | No deadline applies | Your only route is a trace plus a report. Do not pay anyone who claims otherwise. |
Ask every institution for a reference number and put the request in writing the same day. A phone call that leaves no trace is worth very little three weeks later.
Hours 6–24: record the evidence set
Investigators, bank fraud teams and exchange compliance desks all work from documents. None of them work from your recollection, and none of them will reconstruct a chat log you have already deleted. Extract the evidence set now, while the accounts are still open to you.
If you can only manage two items, manage the transaction hash and the receiving address. Everything else can be derived from those two later, but nothing can be derived without them.
- 01Transaction hash (txid) for every transfer, in order, with the amount and asset for each.
- 02Receiving address for each transfer, copied exactly — not retyped from a screenshot.
- 03The chain each transfer used. A trace on the wrong chain produces a report that is worse than no report.
- 04Your own sending address or account, which proves the funds were yours.
- 05Dates and times with the timezone, because institutions test credibility against chronology.
- 06Platform artefacts: the site URL, the chat, the deposit page, the “support” replies, the recruitment message.
- 07Any document the scammer sent you — contracts, statements, “profit” screenshots, ID images. These are often the most useful items for linking cases together.
Do not delete the chat, the email thread or the fake platform account, however much you want to. They are evidence, and they are frequently the only thing that connects an on-chain address to a real-world fraud.
Day 2: file the reports that create a paper trail
Filing is not about the chance that an agent personally takes your case. It is about creating a dated, verifiable record that a bank, an exchange or a lawyer can point to. Reports also cluster: when the same addresses appear across many complaints, they become a pattern, and patterns get resources.
File in this order. The first two take about forty minutes together and are the ones that matter most.
| Venue | What it is for | What to attach |
|---|---|---|
| IC3.gov (FBI) | Federal cybercrime intake and clustering | Written trace, txids, addresses, platform details, dollar amount |
| ReportFraud.ftc.gov (FTC) | Consumer protection data and pattern building | Same evidence set, plus the payment route used |
| Your state attorney general | Local consumer action and, sometimes, restitution funds | Complaint plus the IC3 confirmation number |
| The exchange that received funds | A freeze request under compliance policy | Txid, receiving address, your ID, a signed statement |
| Local police | A report number your bank may require | A one-page written statement, not a verbal account |
Attach the trace as a document. A complaint that says “I was scammed out of $40,000” is a statistic; a complaint that lists twelve hops with timestamps is a lead.
Day 3: the trace, and the freeze request
By day three you have stopped what could be stopped and created the record. Now you make the trace useful. A trace becomes leverage at exactly two points: a regulated intermediary holding the funds, and an official report detailed enough to be joined to others against the same addresses.
You do not need special software for the basics. A public block explorer, a text file and an hour of patience produce something an investigator can verify independently — which is the only standard that matters.
- 01Open a block explorer for the correct chain and search the receiving address you recorded.
- 02Find the transfer matching your amount and timestamp. That is your entry point; everything else is downstream of it.
- 03Walk forward one hop at a time, noting destination, amount and how long the funds sat before moving. Speed tells you whether the movement was automated or manual.
- 04Flag every destination that looks like a deposit into a centralised service. Those are the only points where a lawful freeze is technically possible.
- 05Write the result as a numbered list with dates, amounts and addresses, and send it to the exchange compliance desk with the txid.
One well-documented freeze request to the right compliance desk outperforms a hundred pages of tracing diagrams sent to nobody.
The five mistakes that cost victims their second chance
These are not hypothetical. They are the recurring patterns in published victim disclosures, and each one is avoidable.
- Paying a recovery fee. Any upfront payment, in crypto or by transfer, to someone promising to get your money back is a second fraud.
- Waiting for a perfect case before filing. The reports are the case. File today and refine later.
- Deleting the evidence because it is painful to look at. The chat log is often the only link between an address and a person.
- Telling the bank “I was scammed” before asking for a chargeback. The framing can convert a valid dispute into a refused one.
- Granting remote access to a “technician” who offers to “secure” the wallet. That is how the remaining funds leave.
What realistic progress looks like after 72 hours
By the end of three days, a well-organised victim has: frozen or attempted to freeze every payment route, recorded a complete evidence set, filed at IC3 and the FTC, sent a freeze request to any exchange the funds reached, and produced a written trace. That is a genuinely strong position, and it is achievable in a weekend.
What it does not produce is a promise. Most crypto losses are never recovered, and anyone who tells you otherwise is selling something. What the record does produce is a real chance in the minority of cases where funds are still reachable, and a documented basis for every institutional route that remains open afterwards — civil claims, tax treatment, and complaints against the platforms that enabled the fraud.
The goal of the first 72 hours is not to get the money back. It is to make sure that if it can be recovered, nothing you did in those hours is the reason it was not.
Common questions
Run the trace in your browser, free
Paste the receiving address into the tracer: it reads the public ledger, builds the hop record and exports a dated evidence file you can attach to a report.
Primary sources and further reading
- FBI IC3 — Internet Crime Report www.ic3.gov
- FTC — What To Know About Cryptocurrency and Scams consumer.ftc.gov
- CFPB — Submit a complaint www.consumerfinance.gov
- Chainalysis — Crypto Crime Report www.chainalysis.com
External links open in a new tab and are provided so you can verify the underlying material yourself. TrueMoneyTalk is not affiliated with these organisations.
Keep reading
Someone you know may be in this situation right now.
Disclaimer: this guide is general information, not legal, financial or recovery advice, and it is not a substitute for advice from a licensed professional in your jurisdiction. Individual outcomes vary and are never guaranteed.