PRE-RELEASEReal funds not accepted yet. Independent review pending.Know the limits
PREPARE. DON’T PANIC.

My wallet was drained.

What to do in the first hour, in order. This applies whether or not you use Bunker.

First: nobody can reverse it for a fee.

People will message you offering to recover your funds. They are the second scam. No one from Bunker, a wallet, or an exchange will ask for a seed phrase, a recovery kit, or an upfront payment.

1. Stop signing

Close the site that asked for the approval. Do not approve anything else from the affected wallet “to cancel” or “to verify”. If you typed a seed phrase into a page, treat that seed as public from this moment.

2. Make a new wallet on a device you trust

Create a wallet with a new seed phrase, not another account under the old one. If you suspect malware, do this on a different device. Write the new phrase on paper; do not screenshot it or store it in notes or cloud storage.

3. Move what is left, most valuable first

  • Send remaining tokens and NFTs to the new wallet. Start with what you would miss most.
  • Staked SOL takes time to unstake. Start now; if the attacker has your key they can do the same, and whoever moves first wins.
  • If SOL you send in for fees disappears within seconds, a bot is sweeping the wallet. Stop sending SOL to it.
  • If a token still shows but will not move, its account may have been reassigned to the attacker. It looks like yours and is not.

4. Check for approvals that are still open

Some drains leave a standing approval that lets the attacker take tokens again later. Check the wallet’s open token approvals, then revoke any you do not recognise from your wallet’s settings. Revoking does not help if the seed phrase itself leaked; in that case only moving assets to a new wallet does.

5. Work out how it happened

  • You approved a transaction on a site. The key may be safe, but assume it is not until you have moved everything.
  • You entered a seed phrase somewhere. Every wallet from that phrase, on every chain, is compromised.
  • Neither. Suspect malware, a fake wallet app or extension, or a seed phrase stored in photos, notes or a password manager that was breached. Clean or replace the device before using the new wallet on it.

6. Keep a record and report it

Save the transaction signatures, the attacker’s addresses, the site address, and screenshots. If funds went to an exchange deposit address, contact that exchange’s support with the transaction signatures immediately; it is the one case where a freeze is sometimes possible. Report the theft to your local police or national cybercrime unit. Recovery is rare, but a report is needed for tax, insurance and any later action.

If you have a Bunker

A Bunker is built so that the drained wallet’s key cannot authorize a withdrawal from it. What to do next depends on where your day key was.

If the day key was never on the compromised device, you have time. From a clean device, open your Bunker and withdraw to the new wallet, never back to the drained one. Any wallet can pay the network fee.

If the day key or its password was on that device, act now. Whoever has them can announce a withdrawal, and if your Bunker has no waiting period it leaves at once. The fastest stop is your cancel file: from any device, upload it on the recovery page. That kills the stolen day key and cancels a withdrawal that is still waiting, and it does not need your recovery kit. Afterwards, use the recovery kit in the offline tool to make a new day key. No cancel file? Use the recovery kit in the offline tool to make a recovery packet, which does the same. If the recovery kit itself was on that device, withdraw everything immediately instead.

Bunker is a pre-release and does not hold real funds yet. Read what it does and does not stop.