If your bitcoin was stolen, start by preserving evidence, recording the transaction trail, and reporting the incident to the relevant exchange, wallet provider, and police at the same time.
What counts as stolen bitcoin
People use the phrase loosely, but the reporting path depends on what actually happened. Your exchange account may have been taken over. Your seed phrase may have been exposed. You may have sent BTC to a scammer after fake customer support, a fake investment group, or a phishing page pushed you into a transfer. In other cases, malware changed the address in your clipboard or gave someone remote access to your device.
This distinction matters because the evidence is different in each case. A custodial account breach usually leaves login alerts, withdrawal records, and account changes. A self-custody theft often turns on whether you entered a seed phrase, signed something you did not understand, or used a compromised device. The blockchain will usually show where the coins moved, but the report still needs context: how the address belonged to you, when you lost control, and what happened just before the transfer.
Bitcoin transactions are generally irreversible after confirmation. The network targets about 10 minutes per block, and confirmed transfers are written to a public ledger. That is why your first goal is not to argue online with the scammer or wipe your laptop out of panic. Your goal is to preserve proof and notify any service that may later receive the stolen BTC.
| Scenario | Common signs | What to emphasize in a report |
|---|---|---|
| Exchange account takeover | Unexpected login alert, withdrawal you did not authorize | Account ownership, time of withdrawal, destination address |
| Seed phrase or private key exposure | BTC leaves a self-custody wallet directly | Original wallet control, exposure path, transaction hash |
| Impersonation or social engineering | Urgent messages, fake support, pressure to transfer | Chat logs, receiving address, reason you were given |
| Malware or remote access | Clipboard replacement, strange pop-ups, system changes | Device used, timeline, suspicious software or logs |
What to do before you file reports
The biggest mistake after a theft is destroying your own evidence. People reinstall apps, reset devices, clear browser history, or delete chats because they want to feel back in control. Those actions can remove exactly the material an exchange compliance team or police investigator needs.
Start with the basics: save screenshots or exports of the transaction hash, sending and receiving addresses, exchange withdrawal notices, login alerts, email messages, text verification problems, chat histories, and any page that asked for your seed phrase or password. If the theft involved a self-custody wallet, note the wallet type, whether the seed phrase was photographed or uploaded anywhere, whether you connected the wallet to an unfamiliar site, and whether a browser extension was involved.
Build a timeline while events are still fresh. Write down when you last had normal control, when you first noticed the problem, what action you took just before that moment, and what you have already done to limit further damage. A short, clear timeline beats a long emotional account. The goal is to make the incident understandable to someone who has never seen your case before.
| Evidence type | Keep this | Frequent mistake |
|---|---|---|
| On-chain evidence | Transaction hash, addresses, confirmation status | Saying only that the coins are gone |
| Account evidence | Login alerts, withdrawal notices, changes to settings | Resetting the account before documenting the breach |
| Communication evidence | Chats, emails, support tickets, phone records | Deleting messages after the scammer blocks you |
| Device evidence | Suspicious apps, extensions, warnings, logs | Wiping the device too early |
Where to report stolen bitcoins
There is no single place that solves everything. You usually need to report the theft through several channels because each one serves a different purpose. Police can open a case and request records through proper process. Exchanges can review account activity, flag risky deposits, and respond to lawful inquiries. Wallet providers or security teams may help identify whether the loss came from phishing, a malicious extension, or unsafe signing behavior.
If the theft began on an exchange, contact that exchange first through its official support path. Provide proof of account ownership, the time of the unauthorized withdrawal, the transaction hash, and a concise incident summary. If the stolen BTC later appears to move into another exchange, report the destination address to that exchange as well. You should not expect a full investigation update from them, but an early alert may put the receiving account under closer review.
If the theft happened from a self-custody wallet, the wallet provider may not be able to reverse anything, yet it can still matter to report what happened. A serious report can help them identify fake domains, interface abuse, or patterns affecting other users. When you contact police, explain the asset type, how you controlled it, how the unauthorized transfer occurred, and what evidence you have preserved. A report that says only “my crypto was hacked” is much harder to act on than one that includes a clean chain of events.
| Who to report to | What they can do | What you should send |
|---|---|---|
| Police | Open a case, request records, coordinate investigation | Timeline, identity documents, loss description, evidence package |
| Exchange | Review abnormal activity, flag addresses, support legal requests | Account details, withdrawal records, transaction hash, case summary |
| Wallet provider or security team | Check product-side issues, gather technical clues | Wallet version, device details, suspicious steps |
| Blockchain explorer and analysis tools | Help map the movement of funds | Source address and related hashes |
How to write a report that is easier to process
Good reporting is specific, chronological, and verifiable. Start with ownership or control: which account or wallet was yours, and how you used it. Then describe the trigger event: a fake support message, a phishing site, an unexpected approval, an unauthorized login, or a withdrawal you did not request. After that, show the movement of funds and list the evidence you attached.
A practical structure is simple. First, state where the BTC was held. Second, explain what changed. Third, identify the on-chain transfer. Fourth, describe the damage control steps you took right after discovery. That structure works whether you are sending a report to police, an exchange compliance desk, or a wallet support team.
Be precise with units. Bitcoin has a hard cap of 21,000,000 BTC, and its smallest unit is 1 satoshi, equal to 0.00000001 BTC. If multiple small transfers occurred, using exact wallet records and correct units reduces confusion. If you mention amounts, copy them from the wallet or exchange record rather than typing from memory.
Be wary of “recovery agents” who promise to get stolen bitcoin back for an upfront fee. Some are just a second scam layered on top of the first loss. Helpful assistance can include tracing, evidence organization, and reporting support. A guaranteed reversal claim is a red flag because confirmed Bitcoin transfers are generally not reversible.
FAQ
Can stolen bitcoin actually be recovered
Sometimes, but it depends on where the funds go next. Public blockchain records can help track movement, and recovery becomes more realistic when the BTC reaches a service willing or required to cooperate with an investigation.
Is the transaction hash alone enough for a police report
No. The hash is essential, yet it does not explain ownership, the theft method, or the events that led to the transfer. A stronger report pairs on-chain data with account records, communications, and a timeline.
Should I contact an exchange if my self-custody wallet was drained
Yes, if you can see the funds moving into an address associated with that exchange. The exchange may not share details with you, though your report can still support internal risk review and later legal requests.
Should I move the remaining BTC before I report the theft
If the wallet or device still appears unsafe, secure the evidence first and then move any remaining funds with a clean device and a fresh wallet. Doing it in that order helps protect both your assets and your record of what happened.
What if I gave away my seed phrase by mistake
You should still report it clearly as unauthorized loss caused by deception or compromise. Include when and where you entered the phrase, what site or app was involved, and the exact transfers that followed.
After reporting, cut off any remaining exposure: change email passwords, review two-factor settings, remove suspicious browser extensions, stop using the compromised wallet or seed phrase, and rebuild access on a clean device. If you keep BTC on an exchange, review device management, withdrawal controls, and official alert settings before you do anything else.
Disclaimer: This article is for informational and educational purposes only and is not investment, financial, or legal advice. Crypto assets are highly volatile and you could lose your entire investment. Do your own research and decide carefully.

