Solana wallet hacked: what do I do first to stop further loss?
If you believe your Solana wallet has been compromised, the single most effective first step is to create a brand new wallet immediately and transfer any remaining funds that are still under your control. Do not pause to investigate. Do not try to "talk to support." Every second the compromised wallet remains connected to any dApp or has its private key exposed gives an attacker more time to drain it.
Step one: stop the bleeding
-
Disconnect the compromised wallet from the internet - Close your browser tab, unplug the computer from the network, or switch to airplane mode on your phone. This buys you a few seconds to think without new transactions arriving.
-
Open a fresh wallet - Install a wallet you have never used before on a different device if possible, or at least in a clean browser profile. Write down the seed phrase on paper. Do not photograph it, do not type it anywhere, do not paste it into any website.
-
Transfer your remaining SOL and tokens - As quickly as you can, send everything that is still in the compromised wallet to the new address. If you have staked SOL, you will need to deactivate the stake first - that takes several epochs (roughly two days). In that window the attacker may also be able to withdraw your stake rewards or unstake your SOL if they have access to your wallet. There is no faster fix for staked SOL; you must accept the risk and monitor the wallet constantly until the unstaking period ends.
-
Revoke token approvals - If you can still access the compromised wallet, use a token approval checker (many are available as free web tools) to revoke all permissions the wallet has given to dApps. This stops an attacker from using previously approved allowances to drain specific tokens without needing your seed phrase.
Step two: confirm the nature of the breach
Not every "my wallet was hacked" situation is the same. The correct next step depends on how the attacker gained access.
-
Seed phrase leaked - If you typed your seed phrase into a website, shared it with "support," or stored it in a cloud document, the attacker has full control. No amount of password changes or hardware wallet pairing will help. The wallet is permanently compromised.
-
Private key file stolen - If you used a hot wallet that stored the private key on your hard drive and malware copied it, the same applies. The wallet is burned.
-
Only a dApp approval was exploited - If you approved a malicious smart contract to spend your tokens (a common phishing method), the attacker may only be able to drain the specific tokens you approved. Your seed phrase may still be safe, and the wallet itself might be salvageable after revoking the approval. But if you are unsure, treat it as a full compromise anyway.
Step three: do not fall for recovery scams
After a hack, your wallet will receive fake "refund" or "recovery" NFTs and token airdrops. They link to websites that ask you to connect your wallet and "validate" your identity. These are second-phase attacks. Ignore them. Do not connect your new wallet to any site claiming to reverse the hack. No one can reverse Solana transactions.
Step four: change everything else
If your seed phrase was stolen because your computer or phone was compromised, assume the attacker also has access to:
- Browser passwords saved on that device
- Session cookies for exchanges and email accounts
- Any other cryptocurrency wallets installed in the same browser
Reset passwords for every exchange you use. Enable hardware-based two-factor authentication (not SMS). Move any remaining funds on exchanges to a fresh withdrawal address. Consider wiping and reinstalling your operating system if malware was the cause.
What you cannot do
-
Reverse transactions - Solana transactions are final within a few hundred milliseconds. There is no chargeback, no "cancel transaction" button, no central authority to call.
-
Contact "Solana support" - There is no official Solana customer support that can freeze wallets or recover funds. Anyone claiming to be Solana support who asks for your seed phrase is a scammer.
-
Use a hardware wallet with the same seed phrase - A hardware wallet does not fix a leaked seed. The attacker still holds the keys. You would just be putting your hardware wallet at risk.
After you have secured your new wallet
Once your remaining funds are safe in the new wallet and the old wallet is abandoned, you can investigate how the breach happened. Check your transaction history on a Solana explorer. Look for an unexpected "approve" transaction that gave a smart contract permission to spend tokens. Look for a transfer of SOL or tokens to an address you do not recognize. That address is the attacker's - reporting it to the relevant blockchain explorer may get it flagged, but it will not return your funds.
The honest summary: if your Solana wallet was truly hacked (not just a dApp approval), your funds are gone. The only thing you can do is protect what remains by moving it to a new wallet immediately. There is no recovery process, no appeal, and no support ticket that changes that.
Not financial advice. gokuofsolana.xyz publishes market data and general information about Goku super saiyan. Crypto assets are volatile and you can lose everything you put in. Nothing here is a recommendation to buy, sell or hold, and we make no price predictions.
Prices are sourced from third parties and may be delayed or wrong. Verify anything you intend to act on against a primary source.