The first hour after a crypto scam is about containment and evidence, not embarrassment or chasing the thief. Fast, organised action may reduce further loss and gives banks, exchanges and law enforcement better information to work with.
If you are in India and the incident is happening now, the National Cyber Crime Reporting Portal directs financial cyber-fraud victims to call 1930 or report at cybercrime.gov.in. Use the official website typed into the address bar; do not follow a reporting link sent by the suspected scammer.
Minute 0–10: stop new access
End contact with the scammer. Do not announce what you are doing, argue, send a “small final fee” or follow instructions to recover the money. Recovery-fee demands are often a continuation of the fraud.
From a clean device where possible:
- lock or freeze affected bank cards and payment accounts;
- contact the bank’s official fraud channel;
- change the email password if it may be exposed;
- end unknown email and exchange sessions;
- enable strong two-factor authentication that does not rely only on SMS where supported; and
- remove remote-access software installed at the scammer’s request.
If the attacker has your seed phrase or private key, that wallet must be treated as compromised. No password change can make the old secret private again. Create a new wallet through verified software or hardware and move remaining assets carefully. Never enter the exposed phrase into a “recovery” website.
If only a suspicious token approval was signed, review and revoke the allowance through a verified block explorer or approval tool. Do not confuse disconnecting a website with cancelling an on-chain permission.
Minute 10–25: preserve evidence
Do not delete chats, emails or apps before preserving the record. Capture:
- phone numbers, usernames, profile links and email addresses;
- full website domains and app names;
- wallet addresses and transaction hashes;
- bank, UPI, card or exchange transaction IDs;
- dates, times, amounts and the sequence of payments;
- screenshots of promises, threats and payment instructions; and
- support-ticket numbers and names of financial providers contacted.
Export original chat or email data where the service allows it. Keep screenshots uncropped when possible so time, account and domain context remains visible. Write a short timeline while memory is fresh.
Do not continue interacting merely to collect more evidence. Safety and containment come first.
Minute 25–40: contact every financial intermediary
Call the bank, card issuer, UPI provider or exchange through contact details shown in its official app or website. State clearly that this is suspected financial cyber fraud and ask for the relevant account, transfer or withdrawal to be flagged.
Provide precise transaction identifiers. If funds moved from a bank to an exchange and then on-chain, contact both. An exchange may be able to identify its own deposit address, preserve account records or review a destination connected to its platform. It cannot reverse an unrelated blockchain transaction, and it may require a police or legal request before restricting another account.
Do not pay anyone who claims to have an inside contact at an exchange. Legitimate support does not ask for a seed phrase or private key.
Minute 40–60: report through 1930 and the portal
Call 1930 as soon as possible or file at https://cybercrime.gov.in/. The official reporting instructions ask for details such as the complainant’s mobile number, bank or wallet information, transaction ID, transaction date and available screenshots.
If you report by phone, keep the acknowledgement or login details sent to you and follow the portal instructions to complete the complaint. Save the complaint number with your evidence package.
For immediate danger, threats or identity misuse, contact local police as well. The cybercrime report does not replace emergency assistance.
What not to do
Avoid the actions that turn one loss into two:
- Do not send tax, gas, verification or unlocking fees to withdraw fake profits.
- Do not share one-time passwords, screen access, seed phrases or private keys.
- Do not trust a direct message from a supposed police officer, lawyer or recovery hacker.
- Do not move clean funds into a “safe wallet” chosen by a stranger.
- Do not delete evidence in an attempt to forget the incident.
- Do not publicly post full identity documents, account numbers or recovery phrases.
The Indian Cyber Crime Coordination Centre has specifically warned about relationship and matrimonial contacts that build emotional trust before introducing fraudulent investments or crypto opportunities. A convincing relationship does not make an unsolicited investment platform genuine.
After the first hour
Continue with a structured account review. Check email forwarding rules, connected devices, SIM changes, API keys, withdrawal addresses and identity documents that may have been shared. Inform trusted contacts if the attacker can impersonate you.
Monitor bank and exchange activity, preserve each new development and respond through official complaint channels. Consider professional legal advice for large losses or complex identity theft, but verify the professional independently.
Finally, expect follow-up scammers. Victim lists can circulate, and a person claiming to trace or recover crypto may know details of the original event. Knowledge of the case is not proof of authority.
Keep this response card
- Stop contact and freeze exposed accounts.
- Secure email, devices and authentication.
- Move remaining assets only if a wallet secret is compromised.
- Preserve addresses, hashes, transaction IDs and communications.
- Contact banks, payment providers and exchanges through official channels.
- Call 1930 or report at cybercrime.gov.in.
- Save acknowledgements and reject recovery-fee demands.
This guide provides general incident-response information, not legal advice or a guarantee that funds can be recovered.
Advertisement
Sources and review
This article was checked against the primary or authoritative sources below on .
- National Cyber Crime Reporting Portal advisories — Indian Cyber Crime Coordination Centre
- Citizen Financial Cyber Frauds Reporting and Management System instructions — National Cyber Crime Reporting Portal
- Misuse of Matrimonial Platforms for Investment/Crypto Frauds — Indian Cyber Crime Coordination Centre
- Ethereum security and scam prevention — ethereum.org
Frequently asked questions
The National Cyber Crime Reporting Portal directs financial cyber-fraud victims to call 1930 or report at cybercrime.gov.in.
Be extremely cautious. Anyone demanding a seed phrase, private key, remote access or an upfront crypto payment may be running a second scam.
A confirmed blockchain transfer generally cannot be reversed by a bank or wallet provider, but rapid reporting may still help trace funds or stop related bank and exchange movements.
Advertisement