Securing what is left
If attackers had access to a wallet, assume they may still have it. Move any remaining assets to a new wallet created on a clean device, and revoke token approvals that a malicious contract may still be able to use. For exchange accounts, contact the exchange's security team, change credentials from a device you trust, and ask that the account be frozen. If a SIM swap was involved, contact your carrier right away to regain control of the number. Leave the compromised device as it is rather than wiping or resetting it, and disconnect it from the network so it can be examined later.
Reports and records
File reports with the FBI's Internet Crime Complaint Center and with local police, keeping the report numbers, since exchanges and courts often ask for them. Record the transaction hashes, the receiving addresses, and when you noticed the loss. Save emails and texts about password resets, login alerts, or carrier changes, because they help show how the attack happened. Exchange account statements and screenshots of the wallet's transaction history are worth saving before anything changes. Treat any unsolicited offer to recover stolen crypto for an upfront fee with suspicion, since such offers are a common second fraud aimed at people who have just lost assets.
Legal routes that may exist
Recovery usually depends on whether the stolen assets reached a place that can be compelled to act, most often a centralized exchange or a stablecoin issuer able to freeze tokens. Courts can sometimes issue orders freezing identified accounts, and a lawsuit against unknown defendants can be used to obtain records through subpoenas. If the theft passed through a carrier's or an exchange's security failure, there may be a claim against that company, although account agreements often require arbitration and limit liability. In a first review we look at the tracing picture, the realistic costs, and whether the amount involved justifies legal action. We are candid when the assets appear to have moved beyond reach.