LEGAL HELP
Emergency · Act now

My Crypto Was Stolen From My Wallet or My Exchange Account Was Hacked

“My crypto was stolen from my wallet or my exchange account was hacked”

This is potentially three things at once — a criminal offence to report to the police, a civil question about tracing assets and identifying whoever now holds them, and, where a licensed platform was involved, a regulatory question about that platform’s custody and client asset obligations.

If this has just happened, the next hour matters more than the next week, and the useful steps are practical rather than legal. This page sets out what to do first, who to tell, and what tracing can and cannot do. LEXNOVA is not a law firm. It does not investigate thefts, trace transactions, recover assets or give legal advice. It helps you explore lawyers who work on crypto theft and asset tracing.

LAST REVIEWED 22 SEPTEMBER 2026

WHERE THIS IS HANDLED

The police cybercrime unit is usually the first place to go, because a criminal report both starts an investigation and creates the official record other institutions ask for. The platform, if one was involved, comes immediately alongside it. Where the platform is licensed, the relevant regulator — VARA, the DFSA, the FSRA or the CMA — may take an interest in how the firm handled the incident. A civil claim goes to the DIFC Courts, the ADGM Courts or the onshore courts.

How the answer changes by jurisdiction

  • Dubai mainland

    VARA regulates virtual asset activity in Dubai, free zones included and the DIFC excluded, under Dubai Law No. 4 of 2022. If a VARA-licensed platform was involved, its obligations matter to you: licensed custody must sit in a separate legal entity, and client protections are in the Client Money Rules at Part IV and the Client Virtual Assets Rules at Part V of the Compliance and Risk Management Rulebook. VARA also publishes enforcement actions on a standing public register, worth checking for the platform involved.

  • DIFC

    The DIFC is a financial free zone with its own regulator, the DFSA, which supervises crypto token business principally through Chapter 3A of its General Module. One rule is directly relevant after a theft: under COB Rule 15.4.6, custodians report to the DFSA quarterly on unauthorised transfers, so a licensed DIFC custodian has its own reporting pathway for exactly this event. A firm here holds a licence for a financial service such as Providing Custody, and a civil claim is heard in the DIFC Courts.

  • Abu Dhabi mainland

    Abu Dhabi outside ADGM falls in the federal perimeter. Cabinet Resolution No. 111 of 2022 excludes the financial free zones at Article 3 and, at Article 6, covers virtual asset activity inside the UAE including the ordinary free zones. The CMA issued its virtual assets framework on 13 April 2026, comprising five core modules — one of them Anti-Money Laundering and Counter-Terrorist Financing — and eight regulated activities including Providing Custody and Arranging Custody. A criminal report goes to the police.

  • ADGM

    In ADGM the FSRA regulates virtual asset activities under the Financial Services and Markets Regulations 2015, with the operative rules in Chapter 17 of COBS, and a custodian holds a Financial Services Permission for Providing Custody. ADGM is where the traceability point is clearest: under COBS Rule 17.2.2 a firm must assess each virtual asset against seven criteria before using it, and those criteria expressly include traceability and on-chain monitoring capability, alongside security and private-key safeguarding.

STEP 01

In the first minutes, secure whatever is still yours

Work from a device you have reason to trust rather than the one you suspect. Move any remaining assets to a wallet whose keys have never been on a compromised machine, revoke outstanding token approvals, and disable any API keys attached to exchange accounts. Reset the linked email account first.

Do not re-enter an existing seed phrase anywhere to test whether it still works, and never enter one into a website, a form or a support chat. If it may have been exposed, treat that wallet as permanently compromised.

STEP 02

Tell the platform in writing, immediately

If an exchange or custodial account is involved, report the unauthorised access through the platform’s official channel and put it in writing. Ask expressly for the account to be secured, the withdrawal flagged, and login, device and withdrawal logs preserved.

Speed matters here in a practical rather than a legal sense. Where funds have moved to another account on the same platform, or on to an exchange that cooperates, the window in which anything can be held is short.

STEP 03

Report to the police cybercrime unit

Theft of virtual assets is capable of being a criminal matter, and a report to the relevant police cybercrime unit is usually the right early step. It also creates the official record platforms, banks and foreign authorities frequently require.

Take everything with you: wallet addresses, transaction hashes, timestamps, the chain or network involved, screenshots, and a plain chronological account of what happened and when you noticed. A clear timeline is worth more than a long narrative.

STEP 04

Capture the on-chain trail while it is fresh

Record the sending address, the receiving addresses, every transaction hash, the network each ran on, the amounts and the timestamps, and save all of it outside your wallet and outside the platform. Blockchain records do not vanish, but your access to the account that ties them to you sometimes does.

This trail matters more than people expect, because traceability is treated by regulators as a real property of an asset. In ADGM, the criteria a firm must assess before using a virtual asset expressly include traceability and on-chain monitoring capability.

STEP 05

Work out which platform, and which regulator, is involved

If a licensed platform sat anywhere in the chain, there may be a regulatory dimension on top of the criminal and civil ones. Licensed firms carry obligations about client virtual assets, custody and their own reporting.

Establish the licensing position rather than assuming it. VARA covers Dubai outside the DIFC, the DFSA the DIFC, the FSRA ADGM, and the CMA onshore UAE and the ordinary free zones. Check the entity named in your terms of service.

STEP 06

Treat every recovery offer as a second attempt to defraud you

People who have lost crypto are targeted again, quickly and deliberately. Unsolicited offers to trace, unfreeze or retrieve stolen assets for an upfront payment are a well-documented second fraud, and so are messages claiming to come from the platform, a regulator or a lawyer.

Verify independently before paying anyone anything, and never through a contact detail supplied by the person approaching you. Be equally wary of anyone suggesting you can make back what you lost through another investment.

STEP 07

Take advice on the civil route, with realistic expectations

Where tracing identifies a real target — an exchange account, a named person, a company — a civil claim becomes possible, and the forum depends on where that target and any platform sit: the DIFC Courts, the ADGM Courts or the onshore courts.

Be honest with yourself about the range of outcomes. Some cases produce an identifiable defendant and a real claim; many do not, particularly where funds moved quickly through routes built to break the trail. Nobody can promise recovery.

START YOUR REQUEST

Tell Us About Your Situation.

The matter type is already set to Cybercrime & Digital Fraud, so the form begins with your location. LEXNOVA is a lawyer-matching service, not a law firm — any legal advice comes directly from the independent legal professional you are connected with.

Step 2 of 540%

Where is your matter located?

FAQ

Secure what is left first: move remaining assets to a wallet whose keys were never on a compromised device, revoke token approvals, disable API keys, and reset the password and two-factor authentication on the linked email.

Sometimes. Traceability is treated as a real characteristic of an asset rather than a theory — in ADGM it is one of the criteria a firm must assess before using a virtual asset. How far it gets depends on the route the funds took.

No, and this is the distinction that matters most. Tracing can show where value went; recovery needs a real, identifiable target holding reachable assets and a legal process able to compel them.

Generally yes, and early. Theft of virtual assets is capable of being a criminal matter, and a report to the relevant cybercrime unit creates the official record platforms, banks and foreign authorities often need.

That depends on the platform and how fast you reach it. Ask in writing for the account to be secured, the withdrawal flagged, and login, device and withdrawal logs preserved.

It can matter a great deal. A licensed firm carries obligations about client virtual assets, custody and its own reporting. In the DIFC, custodians report to the DFSA quarterly on unauthorised transfers under COB Rule 15.4.6.

It changes who is involved rather than whether you have options. There is no platform to freeze anything, so the criminal report and the on-chain record carry more weight. A regulatory angle appears only if the funds later pass through a licensed service.

Treat it as a second fraud attempt until you have independently verified otherwise. Targeting people who have just lost crypto is a well-documented pattern. Never verify anyone through a contact detail they supplied to you.

Be cautious. Public posts attract recovery scammers directly to you, and detailed disclosure of addresses, balances or security arrangements can create further exposure. Share what you need to with the police, the platform and your lawyer.

If there is any realistic chance a seed phrase or private key was exposed, yes. Continued access does not mean the keys are safe — it may only mean nothing further has been taken yet. Generate new keys on a device you trust.

That is common and not automatically a dead end, though it adds time and complexity. It can mean involving foreign authorities, foreign exchanges or legal processes in another country alongside the UAE steps.

Tracing generally becomes harder, sometimes much harder, and it is fair to expect that to affect the realistic prospects. It is still worth recording the full trail and reporting it, because assessing what can be followed is specialist work.

A regulator supervises firms; it is not a compensation scheme and should not be planned around as one. It may take an interest in how a licensed platform handled an incident, and VARA publishes enforcement actions on a standing public register.

Practically speaking, report immediately. The reason is not a formal deadline but that funds move, and options existing in the first hours often do not exist a week later. If time has passed, report anyway.

Wallet addresses, transaction hashes, timestamps and networks; your account details and terms of service with any platform; the police report reference; correspondence with the platform; and a short written timeline of what happened.

No. LEXNOVA is not a law firm, not a regulator and not an investigation or asset-tracing service. It does not investigate thefts, trace transactions, recover assets or give legal advice. It helps you explore lawyers who work on crypto theft and cybercrime.

LEXNOVA is not a law firm and does not provide legal advice, legal opinions, legal representation, or legal services. Any legal advice or representation is provided directly by the independent legal professional engaged by the client.

A connection or introduction does not constitute a guarantee, endorsement, or assurance of outcome. Users should independently confirm the professional's qualifications, authorization, fees, scope of engagement, and suitability.

NEED HELP WITH YOUR OWN SITUATION?

This page is general information — your situation is specific.

Find a Lawyer