Skip to content

Solana wallet drained? What to do in the first hour

Solana wallet drained? Move what is left to a new seed first, then find out what you signed, revoke what helps, report the attacker and avoid recovery scams.

Cover image for Solana wallet drained? What to do in the first hour
By 9 min read1946 words

Key takeaways

  • After a Solana wallet is drained, the first step is moving remaining assets to a wallet created from a new seed phrase, because a leaked seed or private key cannot be revoked or changed.
  • Revoking token delegates helps only when a Solana drain came from one malicious signature; if the seed phrase or private key is exposed, the attacker can sign anything and revoking does nothing.
  • Solana transactions are final, so stolen tokens cannot be reversed by a wallet, an explorer or a recovery service; only an exchange freezing a deposit or law enforcement can sometimes recover funds.
  • A Solana transaction signed with a durable nonce stays valid until its nonce is used, so a pre-signed malicious transaction can execute long after the signing prompt closed.
  • Anyone who contacts a Solana drain victim offering to recover stolen funds for an upfront fee is almost certainly running a recovery scam; the FBI's IC3 never charges to recover money.

The short answer#

If your Solana wallet was drained, create a new wallet with a new seed phrase on a device you trust and move everything still left to it, largest balances first. Do not revoke, reset passwords or investigate first. Once the remaining assets are safe, work out whether the key leaked or you signed one malicious transaction, deal with stake and token authorities, report the attacker, and ignore anyone offering to recover the funds for a fee.

This post assumes the loss has already happened. If you are reading before anything has gone wrong, the prevention side is in the Solana wallet security checklist.

What should you do in the first ten minutes?#

Move what is left before doing anything else, because a drainer that has your key is usually still running. The order below assumes the worst case, a leaked seed, since you cannot rule it out yet.

  1. Make a new wallet from a new seed phrase. Use your wallet app's "create new wallet" flow, or a hardware wallet if you own one. Adding another account under the old seed does not help; every account derived from a leaked seed is leaked.
  2. Use a device you trust. If you suspect malware or a fake extension, create the new wallet on a different device, such as your phone or a hardware wallet, not the same browser profile.
  3. Send the most valuable liquid assets first. SOL, stablecoins, then large token positions, then NFTs. A drainer usually takes in the same order, so whatever is left is what it has not reached yet.
  4. Do not top up the old wallet "for fees". If SOL vanishes the moment it arrives, a sweeper bot is watching the address. See the section on sweepers below before sending anything more to it.
  5. Write down signatures as you go. Every transfer you make and every theft transaction you see. You will need them for reports.

Why can't a compromised seed phrase be fixed?#

A compromised seed phrase cannot be fixed because on Solana the key is the account. There is no server holding your wallet, no "change password" that changes the key, and no way to revoke a key once someone else has a copy. The password in Phantom, Solflare or Backpack only encrypts the key stored on your device; an attacker with the seed restores the wallet on their own machine and never sees that password.

Phantom's own help center says the same thing: if the recovery phrase was shared, stop using the wallet and do not try to secure or fix it, because any funds sent to it can be taken at any time. The old addresses are burned for good.

How do you tell a leaked key from one bad signature?#

Read the theft transaction. Paste its signature into the free Transaction Decoder, which shows every instruction, including inner ones, and the balance change per account, with no wallet connection. Then match it to one of these patterns:

What you seeMost likely causeWhat it means for you
A plain transfer signed only by your key, at a time you approved nothingLeaked seed or private keyMigrate everything; revoking is pointless
Transfers inside a transaction you signed on a "claim", "mint" or "verify" siteMalicious signing requestSeed may be safe; migrate anyway if unsure
Tokens moved by another address, with an earlier Approve in your historyMalicious delegateRevoke the delegate, then migrate
SetAuthority on a token account, Assign on your wallet, or Authorize on a stake accountOwnership or authority hijackBalances may look intact but are no longer yours
A transaction you signed days ago executes now, starting with an advance-nonce instructionDurable-nonce pre-signed transactionMove assets so it has nothing left to take

Two of these deserve more detail.

Ownership hijacks. Some drainers do not move funds at all. In December 2025 the security firm SlowMist described a Solana victim who signed a transaction containing an Assign instruction, which changed the program that owns the wallet account. The simulation showed no balance change. Afterwards the victim could not transfer, revoke or manage several million dollars of assets. A token account's owner can be changed the same way with SetAuthority, and a stake account's withdraw authority with Authorize. If you see one of these, those balances cannot be moved by your key any more.

Durable nonces. A normal Solana transaction expires about a minute after it is built, because it carries a recent blockhash. A transaction that uses a durable nonce instead stays valid until that nonce is used. It is a legitimate feature for offline and multisig signing, and it is how the April 2026 Drift exploit worked: signers approved transactions that were executed weeks later. For an individual wallet the lesson is simple. If you signed something you did not understand, it may not have run yet, and you cannot cancel it if the attacker controls the nonce account. What you can do is move the assets, so that whenever it runs, it fails or takes nothing.

If you cannot tell which case you are in, assume the key leaked. Migrating when you did not need to costs a few transaction fees. Not migrating when you needed to costs the rest of the wallet.

When does revoking delegations help, and when is it pointless?#

Revoking helps only when the seed is safe and the loss came through an approval. A Solana delegate is an address you approved, with an Approve instruction, to move up to a set amount from one token account. If a drainer slipped an Approve into a transaction you signed, it can keep pulling from that account until you remove it.

The free Revoke Delegations tool scans any address read-only and lists every SPL Token and Token-2022 account with an active delegate. Revoking costs only the network fee, about 0.000005 SOL per transaction. The Solana CLI equivalent is spl-token revoke.

Its limits matter more than its features here:

  • A leaked key beats any revoke. The attacker can sign a new Approve, or skip delegates and transfer directly.
  • Revoke cannot undo SetAuthority or Assign. Those change ownership, not allowances.
  • A Token-2022 permanent delegate cannot be revoked by holders at all. It is set on the mint by the issuer.
  • A clean scan does not mean the key is safe. It only means no delegate is set right now.

So if you are unsure, migrate first and scan afterwards, as a cleanup step on the new picture rather than a fix.

How do you deal with a sweeper bot?#

A sweeper bot is a script that transfers any SOL arriving in a compromised wallet out within seconds, so the owner cannot pay fees to rescue the tokens still there. Sending more SOL "just for fees" usually feeds the bot.

The cleaner route is to make a different wallet pay the fee. A Solana transaction can name any signer as the fee payer, so a token transfer can be signed by the old key, which owns the tokens, while the fee comes from your new wallet. Wallet apps do not expose this, but the spl-token transfer command has a --fee-payer option, and --fund-recipient lets the payer cover the recipient's new token account. The trade-off: it means loading the compromised key into the CLI on a clean machine. If the tokens left behind are worth less than that risk, let them go.

What else does the old key control?#

The old key may control things that are not in the wallet's token list, and each needs moving or retiring.

  • Native stake. Stake accounts are separate accounts that the old key may control as stake and withdraw authority. The Stake Accounts tool lists them for any address. Deactivating is free, the stake becomes withdrawable at the next epoch boundary (an epoch is a little over two days), and withdrawing costs 0.002 SOL per account. Start early, and know that a key holder can race you to the withdrawal; withdrawing straight to the new wallet is the goal.
  • Token authorities. If you launched a token, the old key may be its mint, freeze or metadata update authority. Transfer or revoke them from the old key. The Update Metadata tool can hand the update authority to your new wallet for 0.02 SOL.

To keep an eye on old and new addresses without connecting anything, paste them into the Balance Checker, which is free and read-only.

How do drainers usually get in?#

Knowing the route tells you what to fix on your side. The common Solana patterns are:

  1. Fake airdrop and claim pages promoted through replies, Discord DMs, search ads and lookalike domains.
  2. Spam NFTs and tokens whose name or image advertises a URL. Holding them is harmless; visiting the site and signing is not. Cleanup is covered in what to do with spam NFTs on Solana.
  3. Malicious signing requests that bundle transfers, Approve, SetAuthority or Assign into one prompt, sometimes built so the wallet simulation fails or shows nothing.
  4. Seed phishing through fake wallet updates, fake support agents, counterfeit extensions or a seed stored in cloud notes, screenshots or a synced file.
  5. Malware on the device: clipboard swappers, infostealers and rogue extensions.

If it was 4 or 5, clean or replace the device before trusting it with the new wallet.

Who should you report a Solana wallet drain to?#

Report to the places that can act on it, with signatures and addresses, the same day if you can.

  • The receiving exchange. Follow the stolen funds forward in an explorer. If they reach a centralized exchange deposit address, contact that exchange's support with the signatures. Exchanges can freeze accounts; nobody else in this list can.
  • Chainabuse. A public scam-reporting database used by investigators, exchanges and wallets. Phantom's help center points victims there.
  • Law enforcement. In the US, the FBI's Internet Crime Complaint Center at ic3.gov; elsewhere, your national cybercrime unit or local police. A report number also helps when an exchange asks for one.
  • Your wallet. Report the drainer domain to your wallet provider. Phantom maintains a public blocklist of malicious domains, and a report protects the next person.

Be realistic: most stolen crypto is not returned. Report anyway; freezes only happen when someone has filed.

What should you not do after a drain?#

The days after a drain are when victims are most likely to lose more. Avoid these:

  • Do not pay a "recovery service". Accounts that reply to your post offering to trace and return funds for a fee are running recovery scams. The FBI has issued repeated warnings about fake recovery firms and people impersonating IC3, which does not charge fees or message victims on social apps.
  • Do not share your seed with anyone "to help". Not support staff, not a friend of a friend, not a tool. No legitimate party needs it, including SOLTidy.
  • Do not reuse the old seed for a new account, an airdrop wallet or a "test" wallet.
  • Do not sign anything from the drainer site to "undo" or "cancel" the theft. There is no such transaction.

Bottom line#

A drained Solana wallet is an emergency for the first ten minutes and an investigation after that. Move what is left to a wallet with a brand-new seed, assume the key leaked until a transaction proves otherwise, and read what you signed before deciding whether revoking delegates is worth anything. Retire the old key's stake and authorities, report with signatures to the exchange, Chainabuse and law enforcement, and treat every unsolicited offer of recovery as the next scam. The old address is gone for good; the goal now is that nothing else follows it.

Questions & answers