Recently, users have publicly reported online that crypto assets in their accounts on a certain exchange were abnormally transferred out, amounting to approximately 1.7 million USDT.
The matter quickly evolved into a dispute where both the user and the exchange presented conflicting accounts: the user contended that, given the account was hosted on the exchange, the platform’s login alerts, large-withdrawal notifications, and risk-control intercepts should not have been so easily bypassed; the exchange typically reverted to issues such as account passwords, two-factor authentication, device environments, phishing links, and user authorizations, emphasizing the boundaries of liability.
Such disputes are hardly unfamiliar to us.
Every few days,Mankun attorneysencounter similar inquiries. When clients seek consultation, they rarely present a complete case narrative at the outset. More often, they simply state: “My coins were stolen; can you help me recover them?”
Further questioning reveals vastly different circumstances: in some cases, exchange accounts were accessed from unusual locations followed by withdrawals; in others, wallet users clicked on phishing authorization links; in yet others, seed phrases were viewed by acquaintances; some involved purported customer service representatives sending “unfreeze links”; and in other instances, an issue arose with a signer in a project’smulti-signature walletAn issue arose with a certain signatory therein.
Therefore, in such cases, one should not begin by asking, “Will the platform compensate? Can I report this to the police now? Can the public security organs recover the funds?” What is truly required is to clarify three matters within the shortest possible time: where the assets were originally held, how control was lost, and where the funds have flowed.
If these three points are not clearly established, subsequent steps—whether reporting to the police, requesting investigative assistance from the platform, conducting on-chain tracing, or negotiating liability with the exchange—will devolve into mutually inconsistent narratives.
First, secure the assets in the account
After crypto assets are stolen, the most time-wasting step is to ask in group chats, “Does anyone know someone inside the exchange?” or to search everywhere for so-called hacker teams. Many people are not unconcerned; rather, they are too anxious and end up spending their time on the most unstable avenues first.
The priority is to secure what you can still control.
If there is an anomaly with your exchange account, immediately freeze the account, change your password, revoke API access permissions, unbind unfamiliar devices, and check whether your email and mobile phone have also been compromised. At the same time, submit a support ticket to the platform requesting preservation of login logs, withdrawal records,device fingerprints, IP addresses, two-factor authentication (2FA) records, and risk management handling records.
If there is an anomaly with an on-chain wallet, do not continue to perform complex operations within the original wallet. First confirm whether there are any other assets under the same set of recovery phrases, on the same device, or within the same browser extension; migrate assets where appropriate and conduct offline checks where necessary. Meanwhile, preserve the original wallet address, transaction hashes of the theft, authorization records, suspicious contract addresses, and suspicious website domains.
Many users, after discovering the first transfer out, continue to log into the same phishing page, continue to enter verification codes, or even keep the remaining assets in the same wallet, thereby amplifying their losses. The portion of crypto assets already transferred may require subsequent tracing and coordinated investigation. For the portion not yet transferred, do not give the attacker a second chance.
If your exchange account is compromised, do not merely state, “I did not perform these operations.”
A compromised exchange account is not the same asa non-custodial walletbeing compromised.
Behind an exchange account lies an entire platform system: KYC identity verification, login devices, withdrawal whitelists, email and SMS notifications, identity verification, risk management rules, and customer support tickets. What the user sees is that the account balance is gone; what the platform may see is a login event, the addition of an address, or a 2FA Verification and single withdrawal confirmation. The dispute between the parties should not center on "whether the actions were performed by the account holder," but rather on whether there were any anomalies in this operational chain.
The user cannot merely claim, "I did not do it." It is necessary to reconstruct a timeline of key events: when the login alert was received, when a new withdrawal address was added, when the withdrawal was initiated, whether verification codes were received via email or SMS, whether two-factor confirmation was required prior to withdrawal, whether the platform intercepted the transaction, and whether the user clicked on any links purportedly related to customer service, claims processing, KYC upgrades, or risk control removal.
The platform cannot simply conclude the discussion with the statement that "users are responsible for safeguarding their own accounts." Given that the assets are held in exchange accounts, the platform must at least demonstrate whether its risk management mechanisms functioned properly: whether stricter verification was triggered by events such as logins from unusual locations, large-value withdrawals, withdrawals to new addresses, changes in devices, or multiple operations within a short period; whether customer service responses and asset-freezing actions were timely; and whether the disclaimer clauses in the platform agreement can cover the specific faults at issue.
This is why login logs, emails and SMS messages, device fingerprints, withdrawal records, and customer service tickets are critical in cases of account theft on exchanges. These are not mere technical details; they define the boundaries of liability.
Theft from On-Chain Wallets: Focus on Private Keys and Authorizations
If assets are transferred out of MetaMask, imToken, TokenPocket, hardware wallets, multi-signature wallets, or other non-custodial wallets, the issue reverts to wallet control.
The private key is the sole credential for a user to control virtual assets. Whoever obtains the private key, mnemonic phrase, or equivalent control information may initiate transfers.
Many users claim they did not disclose their mnemonic phrases to others. However, in practice, leakage is not always as straightforward as "telling someone." Some users save screenshots of their mnemonic phrases in their photo albums, which are then stolen through compromised cloud synchronization; some send them via WeChat's File Transfer Assistant, where they are read by trojans on their computers; some allow friends or so-called technicians to operate their wallets on their behalf, during which the other party notes down the mnemonic phrase; and others sign an authorization they do not understand on a phishing website.
Another scenario that is often overlooked is malicious authorization.
The user did not actively transfer coins out but merely clicked to authorize, stake, claim airdrops, upgrade contracts, or unfreeze accounts on a certain page. After obtaining the authorization, the attacker transfers away certain tokens. When reporting the incident, users often focus only on the final transfer, but the true entry point of risk may lie in an earlier token approval authorization, a contract interaction, or a phishing domain.
Therefore, in cases of on-chain wallet theft, do not merely screenshot the zero-balance status. It is essential to extract the complete sequence of on-chain actions before and after the theft: when the website was connected, what messages were signed, which contract was authorized, from which address to which address the assets were transferred, and whether there were subsequent splitting, cross-chain transfers, token swaps, or deposits into exchanges.
Cold Wallets Are Not Absolutely Secure
Upon hearing that a wallet has been compromised, many people immediately remark, “I should have used a cold wallet.” While cold wallets are indeed more suitable than hot wallets for the long-term storage of assets, they are not magical safes.
Theft of assets from cold wallets generally falls into three categories: improper custody by the user, risks inherent to the cold wallet service provider, and risks arising from the introduction of third-party services.
In practice, a portion of cold wallet theft cases are often perpetrated by acquaintances. This aligns closely with the consultations we observe: outsiders may not necessarily understand your asset situation, whereas those who truly know how many tokens you hold, where your wallet is stored, and how you typically operate may well be people close to you.
However, if the cold wallet product itself contains technical vulnerabilities, or if the service provider leaves backdoors during the generation, storage, or transmission of private keys, liability cannot be simply shifted to the user. If a cold wallet service provider holds or retains users’ private keys, and internal personnel use such information to transfer away client assets, such conduct may be evaluated as constituting the crime of theft.
There is also the risk associated with third-party services. Many hardware wallets or wallet software embed third-party entry points for buying tokens, swapping tokens, staking, cross-chain transfers, and other functions. Users may believe they are still operating within the official wallet environment, but in reality they have been redirected to another service provider’s page. In such circumstances, it is necessary to examine the user agreement, redirection notices, third-party terms, and whether the service provider has fulfilled its obligations to provide necessary warnings and ensure security safeguards.
The key reminder for ordinary users regarding cold wallets is not to equate “offline” with perpetual security. What truly matters is where the private key is generated, where it is stored, who has had access to it, who signs transactions, and whether any third-party services intervene in the usage process.
Two-Pronged Approach: Contact the Exchange and Report to the Police
When assets are lost within a platform’s ecosystem, users should simultaneously pursue two avenues: one involving criminal reporting and tracing, and the other addressing the platform’s liability and compensation arrangements.
Whether a platform is willing to compensate, the amount of compensation, and the rules governing compensation are not determined merely by emotional appeals. Instead, they depend on the platform agreement, the platform’s security safeguard obligations, the cause of the incident, the user’s own actions, the platform’s response speed, whether the assets remain controllable, and whether there is verifiable evidence of loss and fund flows.
A significant portion of stolen assets ultimately ends up on centralized exchanges. Attackers must eventually exchange, split, cash out, or continue laundering these assets. As long as the assets enter a platform with know-your-customer (KYC) identity verification, they may leave traces such as account details, device information, IP addresses, orders, withdrawal addresses, and identity documentation.
However, platforms will not freeze another person’s account simply because a user claims, “These are my tokens.” This is particularly true for overseas exchanges, which typically require users to first submit complete documentation for internal risk marking. To further freeze accounts or disclose KYC or login information, law enforcement authorities, lawyer’s letters, court documents, or compliance request procedures recognized by the platform are often required.
Time is also critical. Attackers are aware that centralized platforms implement real-name verification and risk controls, and therefore usually do not keep assets in a single account for an extended period. Funds may be quickly converted into other cryptocurrencies, transferred to new addresses, or continue to circulate through internal transfers, over-the-counter (OTC) trading, or cross-chain bridges. If users take several days to slowly compile their materials, even if the platform is willing to cooperate, it may only be able to confirm that the assets once passed through its system and are no longer controllable.
Many individuals file police reports with stacks of screenshots: balance screenshots, chat logs, browser captures, and customer service interactions. While the materials may appear voluminous, investigating officers often remain uncertain about where to begin after reviewing them.
More effective reporting materials should form a coherent chain.
First, establish the source of the assets. Specify whether the crypto assets were acquired through trading or investment purchases. Provide corresponding deposit records, purchase records, bank statements, exchange orders, and wallet history to demonstrate the original ownership of the assets.
Second, describe the process by which control was lost. Indicate when the anomaly was discovered, who originally maintained custody of the account or wallet, which transaction transferred the assets out, the transaction hash, the sending and receiving addresses, the type and quantity of the crypto assets, and the valuation method used to estimate the loss.
Third, present suspicious clues. Organize chronologically any anomalous login IP addresses, phishing website domains, chat logs involving impersonation of customer service, remote access software, email login records, newly added withdrawal addresses, authorized contract addresses, subsequent transfer addresses used by the attacker, and the exchanges or conversion platforms into which the funds were deposited.
Fourth, clearly explain actions already taken. Specify whether you contacted the exchange, submitted support tickets, requested asset freezes, submitted risk flags to on-chain security firms or blockchain explorers, and preserved webpages, emails, chat logs, and platform acknowledgments.
A practical reminder: do not rely solely on screenshots. Preserve original links, raw email files, screen recordings of webpages, ticket numbers, and transaction hashes wherever possible. Screenshots aid understanding, but original materials are more readily verifiable.
Legal counsel involves more than merely accompanying clients to file police reports
Following the theft of virtual assets, the value of legal counsel extends beyond accompanying clients to local police stations.
First, determine the appropriate legal characterization of the case. Assess whether the incident more closely resembles theft, fraud, illegal acquisition of data from computer information systems, a platform service dispute, misappropriation by insiders, an investment scam, or a security incident. The chosen characterization affects jurisdiction, evidentiary requirements, and the relevant counterparts for communication.
Second, restructure the evidence. Clients’ materials are often scattered across exchange screenshots, blockchain explorers, emails, chat logs, bank statements, wallet interfaces, support ticket responses, and community discussions. Lawyers must organize these materials into a factual chain that investigating authorities can readily understand, rather than leaving clients to repeatedly explain a disorganized collection of screenshots.
Third, facilitate cooperation with platforms. When dealing with exchanges, wallet providers, stablecoin issuers, on-chain analytics firms, domain registrars, cloud service providers, and email service providers, reliance on customer service chats alone is insufficient. Matters must be handled in tiers: determining which information users can submit directly, which requires a lawyer’s letter, which must be obtained through investigative powers exercised by public security organs, and which necessitates using law enforcement request channels for overseas platforms.
Fourth, addressing disputes over liability. If assets are transferred out of an exchange or wallet service, subsequent issues may involve service contracts, security safeguard obligations, risk control rules, interception of anomalous transactions, and user security obligations. Lawyers should not simply ask whether “the platform must compensate” or whether “the user must bear the loss,” but rather identify specifically which link failed, who had the capacity to prevent it, and who failed to fulfill their due obligations.
Crypto asset theft cases do not necessarily involve only one charge
After virtual assets are stolen, many clients directly ask: “Does this constitute theft?”
This question cannot be answered solely based on everyday experience. In practice, there has been ongoing controversy over whether stealing digital currencies should be characterized as the crime of theft or the crime of illegally obtaining data from computer information systems.
The distinction behind these classifications is significant. The crime of theft protects property rights and interests, with higher monetary amounts leading to greater potential penalties; the crimes of illegally obtaining data from computer information systems and illegally controlling computer information systems focus more on protecting computer systems and data security, featuring different maximum penalty structures. For victims, the classification affects asset recovery, restitution, and loss assessment; for suspects, it affects whether the culpability and punishment are proportionate.
In today’s context of crypto asset theft, several different legal pathways may arise.
If an acquaintance obtains the mnemonic phrase and transfers coins from the wallet without authorization, the case more closely resembles the secret acquisition of another person’s proprietary interests. The key issues are who originally controlled the assets, how the mnemonic phrase was obtained, whether the transfer was authorized, and whether there was subsequent conversion into cash and intent to possess.
If a hacker obtains account passwords, private keys, or platform data through trojans, phishing websites, or system vulnerabilities, the case may involve both computer-related crimes and property crimes. It is insufficient to merely state “hacker attack”; one must examine whether the actor illegally obtained data or further controlled, transferred, split, exchanged, or converted the assets into cash.
If assets enter the accounts of USDT merchants, OTC acceptors, mixing services, cross-chain bridges, or exchanges, this may subsequently implicate issues such as concealing or disguising criminal proceeds, money laundering, and aiding information network criminal activities. The theft of crypto assets does not end at the moment of transfer; the subsequent flow of funds often determines whether asset recovery can proceed and who may become involved in the case.
This is why victims should not merely report “my coins were stolen” when filing a police report. They must articulate a investigable trail detailing how control was lost, how the assets moved, who might have received them, and where real-name verification might apply.
Friendly reminder: Do not fall victim to recovery scams again
After virtual assets are stolen, victims are prone to falling into a second trap: recovery scams.
Scammers exploit your urgency by impersonating on-chain security teams, exchange insiders, lawyers, public security investigators, or white-hat hackers. They promise “100% recovery,” “internal channel freezes,” “unfreeze first, pay later,” “wallet verification required,” or “import your seed phrase into a security tool.” While these pitches appear to address your immediate concerns, they often constitute a second wave of exploitation.
The bottom line is simple.
Exercise heightened caution whenever you are asked to provide your seed phrase, private keys, verification codes, or remote access to your phone or computer. Do not act hastily if you are instructed to transfer remaining assets to a so-called “secure wallet,” “verification wallet,” or “recovery wallet.” Genuine on-chain analysis and legal services typically proceed based on transaction hashes, addresses, platforms, evidence, and documentation, and will not require you to relinquish control over your assets.
Your crypto assets have already been stolen once; do not let urgency lead you to hand over your remaining assets and evidence to another stranger.
Mankun Lawyers’ Summary
In cases involving theft of crypto assets, first mitigate losses by securing your accounts and remaining assets; then preserve evidence by fixing transaction hashes, addresses, account details, logs, chat records, support tickets, emails, and device records; next, triage the matter to determine whether to report to the police, seek platform assistance, pursue civil remedies, hold internal parties accountable, or proceed along multiple paths in parallel.
Only after these foundational steps are solidly completed should you address asset recovery and liability.
(This article provides general legal risk analysis and shares practical experience; it does not constitute legal advice for any specific case. Handling of individual cases should be determined comprehensively based on specific platform rules, evidentiary materials, asset flows, judicial jurisdiction, and the latest laws and policies.)

