Crypto Recovery Scams: The Second Hack

You just lost your life savings to a crypto scam. You are desperate. You post on Bitcointalk asking for help. Within hours, "recovery experts" flood your DMs promising to get your money back — for an upfront fee. They cannot. This is the second hack. Here is how to spot them.

Recovery scams, also called "second-chance scams" or "recovery room scams," specifically target people who have already been victims of a crypto hack or scam. The scammer monitors forums like Bitcointalk, Reddit (r/CryptoCurrency, r/Scams), and Telegram groups for people posting about being hacked. They then contact the victim posing as a recovery specialist, ethical hacker, law enforcement contact, or blockchain investigator. They claim they can recover the stolen funds — but they need an upfront "fee," "retainer," or "investigation deposit." The victim pays, the scammer disappears, and the victim has now been scammed twice. This is one of the most profitable niches in crypto scamming because victims are already in a vulnerable emotional state and desperate to believe recovery is possible. Legitimate steps to take after a hack →

Common Recovery Scam Tactics

"I can hack back the thief." The scammer claims they can access the hacker's wallet through a vulnerability and return your funds. This is impossible. Blockchain wallets cannot be "hacked back" — they are secured by private keys that no one possesses except the owner. If anyone tells you they can hack a wallet that has already received stolen funds, they are lying. The only way to move funds from a wallet is with the private key, which the hacker controls. There is no "backdoor" to any major blockchain.

"I have a contact at the exchange who can reverse the transaction." No exchange can reverse a confirmed blockchain transaction. Crypto transactions are final once confirmed. Exchanges can freeze funds that have been deposited to their platform, but they cannot reverse a transaction on the blockchain itself. Anyone claiming they can "reverse" a transaction is lying.

"I need a small fee to cover investigation costs." The scammer asks for $200-$5,000 as an "investigation fee," "retainer," or "gas fee for tracing." Once paid, they invent new fees: "legal fee," "court filing fee," "international transfer fee." Each fee is small enough to seem reasonable, but they add up quickly. Eventually, the scammer stops responding. The victim has now lost their original investment AND the recovery fees.

"Connect your wallet to verify ownership." The scammer sends a link to a site that looks like a legitimate blockchain explorer or recovery platform. It asks you to "connect your wallet to verify you are the owner of the stolen funds." This is a wallet drainer — connecting your wallet and signing a transaction gives the scammer approval to drain all remaining funds from that wallet. This tactic exploits victims who still have funds in other wallets they want to protect.

Fake testimonials and screenshots. Recovery scammers create fake Telegram channels and websites with testimonials from "satisfied clients" who supposedly recovered their funds. These are fake. The screenshots of recovered balances are photoshopped. The "before and after" transaction histories are fabricated. The "thank you" messages are from other scammers' accounts. If a recovery service has testimonials but you cannot verify the people independently, assume they are fake.

Real Recovery Services vs Scams

There are legitimate blockchain analytics firms, but they do not work with individual retail victims. Chainalysis, TRM Labs, CipherTrace, and Elliptic provide blockchain tracing services to governments, law enforcement, and large financial institutions — not to individuals posting on Bitcointalk. They charge six-figure retainers and work on major cases (multi-million dollar thefts, sanctions violations, terrorist financing). If a recovery service claims to be "partnered with Chainalysis" and offers to work for you for $500, they are lying.

Legitimate recovery is extremely rare. According to CipherTrace, less than 1% of stolen crypto is ever recovered. The only realistic recovery scenarios are: law enforcement seizes funds from an exchange where the hacker deposited (requires rapid reporting and a cooperative exchange), the hacker voluntarily returns funds (rare, but happened with Poly Network and Euler Finance where white hat hackers returned funds for bounty payments), or civil litigation against identifiable defendants (only possible if you know who hacked you and have legal resources). If a recovery service guarantees any level of recovery, they are lying. How to avoid crypto scams in the first place →

Red Flags Checklist

  • Contacted you via direct message (legitimate services do not cold-DM victims)
  • Requests upfront payment in any form (crypto, gift cards, wire transfer)
  • Claims they can "hack back" or "reverse" blockchain transactions
  • Asks you to connect your wallet to a website
  • Guarantees recovery (no one can guarantee recovery of stolen crypto)
  • Has fake-looking testimonials with no verifiable identities
  • Uses pressure tactics ("act now before the funds move")
  • Claims partnerships with well-known companies (Chainalysis, FBI, Interpol)
  • Communicates only via Telegram, WhatsApp, or Signal
  • Cannot provide a verifiable physical address or business registration

What to Do Instead

If you have been hacked, accept that recovery is unlikely and focus on damage control. Secure remaining funds on a hardware wallet created from a clean device. Report the hack to local police and the FBI IC3 (ic3.gov). If the stolen funds were deposited at an exchange, contact that exchange's compliance department immediately with the transaction IDs. Monitor the hacker's wallet addresses using a block explorer or service like Etherscan's address watchlist — if the funds move to an exchange, you have a brief window to alert that exchange. Take the tax loss deduction if applicable. Post about the hack to warn others — but ignore every DM you receive about recovery services. They are all scammers. Full post-hack recovery procedure →