A stolen phone or compromised computer containing cryptocurrency is an immediate crisis. Unlike a traditional bank account, where a call to customer service can freeze transactions and initiate recovery, a non-custodial wallet leaves the user as the sole custodian of their assets. If the device vanishes, the critical question becomes whether you retained a usable backup of your seed phrase—the 12 or 24-word recovery code that controls access to your funds. Without it, recovery is mathematically impossible. With it, recovery is urgent but achievable, provided you follow the correct sequence and avoid the traps that make the situation worse.
The distinction between having a seed phrase backup and using it safely is not academic. An attacker who gains access to a stolen device still needs the seed phrase to move funds. A user who panics and enters the seed phrase into the first recovery interface they find might be typing it into a phishing site, a malware application, or a legitimate-looking fake wallet designed to capture exactly this scenario. The recovery process therefore requires three parallel actions: isolating the compromised device, securing access to a new one, and verifying that the wallet application itself is authentic before revealing the recovery code. This article covers the practical sequence that minimizes loss and avoids compounding the initial theft.
The first 24 hours: assume the device is permanently compromised
The moment you realize a device containing cryptocurrency is missing, the operating assumption must be that it is no longer under your control. Do not assume that a PIN, fingerprint lock, or encrypted hard drive will prevent a determined attacker from accessing the wallet application. Modern smartphones and computers have demonstrated vulnerabilities in their unlock mechanisms. A thief with technical skill may attempt to extract private keys, examine backup files, or use forensic tools. If the stolen device still has the wallet application installed and cached data, the attacker may have a direct path to your funds.
The practical first action is to document what you know: which device was stolen, what time it went missing, which wallets were installed, and approximately how much was at risk. If you remember the receiving addresses of major holdings, write those down separately from your seed phrase. This information will be useful for tracking whether funds move without your authorization and for later coordination with law enforcement or exchanges if any coins surface. Do not spend time searching for the device or hoping it will be returned; time is the enemy in a theft scenario.
Next, change any passwords associated with cryptocurrency services, email accounts, hardware wallet providers, or exchanges that might be linked to the stolen device. An attacker with access to your email account can request password resets for other platforms. This is true even if you never used the stolen device to log into those accounts; the attacker can use the device’s IP address, browser fingerprint, and device identifiers to strengthen the appearance of authenticity during a password recovery request. A fresh password created from a different device and network makes unauthorized account takeover measurably harder.
If the stolen device was a hardware wallet such as a Ledger or Trezor, the risk profile is different and potentially lower. Hardware wallets store private keys in a secure element that is extremely difficult to extract even if the device is disassembled. However, if you were using a pin code that was weak or predictable, change the pin on a backup hardware wallet immediately. If you do not own a backup, consider this a sign that your recovery process was incomplete—a lesson for after the current crisis is resolved.
Accessing a clean device and verifying the wallet application
Before entering a seed phrase into any new device, that device must be treated as potentially hostile until proven otherwise. Use a computer or phone that was not present when the original device was stolen. Ideally, use a device that has been powered off since before the theft and has received no new network connections related to the incident. Borrow a device from a trusted family member if necessary; the temporary inconvenience is worth the security benefit.
The next step is to independently verify the correct application. Do not click a link in an email or follow a search result that appears after searching for “Bitget Wallet recovery.” Instead, navigate directly to the official source. Open the official app store on the new device—Apple App Store or Google Play Store—and search for the wallet application by exact name. Cross-check the developer name, look for official verification badges, read reviews carefully for mentions of recent version updates, and inspect the permission requests the app makes. A legitimate wallet should request network access, camera access for QR codes, and secure storage permissions; it should not request SMS message access, contact lists, or call logs.
After installing, open the application and look for any prompts or notifications. A legitimate non-custodial wallet will not ask for a username or email during initial setup. It will present an option to create a new wallet or recover an existing one. Do not create a new wallet unless you intend to set up a fresh account; recovering an existing wallet is your goal. At this stage, you can learn more about the authentication and security practices of the wallet by visiting the official documentation or support portal, but avoid entering your seed phrase on any page that is not the recovery interface within the application itself.
Entering the seed phrase safely and securing the new device
Once you have installed and verified the wallet application on a clean device, the recovery process begins. Most wallets will present a recovery option during setup, usually labeled “Recover Existing Wallet” or similar. Tap or click this option. The application should then display a field or series of fields requesting the seed phrase. Before entering anything, ensure that:
No one else is watching the screen. Close other applications and windows. If you are in a public space, use a privacy screen or position the device so that only you can see the display. Do not enter the seed phrase if you feel hurried or observed; move to a private location. The seed phrase entry field should be part of the installed application itself, not a web page or external link. Check the address bar of your browser if you are using a web interface; it should show the official domain, with an HTTPS connection and a lock icon indicating encryption. If you are using the wallet application, confirm that it is still the application you just installed.
Type or paste the seed phrase word by word. Most applications will offer autocomplete suggestions as you type each word; this is a legitimate feature that reduces typing errors. If the application does not recognize a word you enter, stop and re-examine the seed phrase. A single incorrect word will generate a different wallet with zero balance—a critical failure that will become obvious when you see the result. After entering all words, the application should show a confirmation screen with your wallet address, balance, and list of holdings. This is the moment of truth: do the assets shown match what you expect to see?
If the balance is correct and the addresses are familiar, you have successfully recovered the wallet. Immediately take several additional security steps. First, change the wallet’s PIN or authentication method if the original device allowed access through a weak biometric or simple pin. Second, confirm that two-factor authentication is enabled for any linked accounts such as email or exchanges. Third, review the wallet’s transaction history for any unauthorized outflows since the device was stolen. If transactions appear that you did not authorize, the attacker may have gained access to the compromised device faster than you recovered on the new one.
What to do if the recovered balance is zero or partially depleted
If you access the recovered wallet and find that funds are missing, the attacker has successfully moved your assets. This is a devastating but recoverable situation in one critical sense: you now have proof of exactly what was taken and when. Blockchain transactions are immutable and publicly visible. Use a blockchain explorer to examine the transaction history from your wallet address. Identify the outgoing transactions and follow the address trail to see where the funds were sent.
In many cases, stolen cryptocurrency will be moved through a series of addresses before reaching an exchange or mixing service. Law enforcement agencies, blockchain analysis firms, and exchange compliance teams have tools to track these movements. If the amount is substantial—above a certain threshold that varies by jurisdiction—contact local law enforcement and file a report. Provide them with the blockchain evidence of the transaction. While recovery is far from guaranteed, a police report creates a record that may assist if the coins surface on a regulated exchange later.
Simultaneously, begin monitoring for any exchange deposits. If you know the addresses where your funds were sent, you can use tools such as blockchain explorers or exchange deposit tracking services to watch for activity. Major exchanges require identity verification before allowing withdrawals. If a stolen wallet’s coins arrive at an exchange, that exchange may be able to freeze the deposit or assist law enforcement. This is not a reliable recovery mechanism, but it is part of the documentation process.
If only some of the balance is missing, examine which assets were taken and which remain. This can indicate whether the attacker had access to the wallet for an extended period or found the seed phrase but not the PIN code. Some wallets offer features such as private key control that allow you to manage individual token holdings. If your wallet supports this—if you can, for instance, transfer assets to new addresses under your direct control—do so immediately for the remaining balance. This isolates funds from any residual compromise of the current recovery environment.
Preventing this situation in the next recovery cycle: seed phrase storage
The lesson from a stolen device is not that seed phrases are too risky; it is that seed phrase backup practices were inadequate. A seed phrase written in a notebook and stored in a safe deposit box, split across multiple locations, or committed to memory through careful review cannot be extracted from a stolen phone. A seed phrase stored in a cloud document, emailed to yourself, or kept as a screenshot on the device itself will be compromised along with the device.
The recovery process you just completed succeeded because you retained a seed phrase backup separate from the stolen device. Recreate that backup immediately, on the new device where you just recovered the wallet. Write the seed phrase by hand, on paper, in a location where only you will find it. Store a second copy in a separate secure location. Do not laminate the paper; ink can fade or smudge in ways that make words ambiguous during recovery. Consider using a stamped metal seed phrase backup tool, which is resistant to fire, water, and corrosion. The cost is modest relative to the assets at risk.
Document the backup location in a document separate from the seed phrase itself. If you die or become incapacitated, a trusted executor needs to know where to look, but they should not have the seed phrase. This separation—knowing where the backup is without knowing what it says—is the security model that balances resilience against theft.
Finally, evaluate whether a hardware wallet should have been part of your setup from the start. A hardware wallet such as a Ledger or Trezor keeps private keys offline and requires physical interaction to approve transactions. If a mobile device is stolen, the hardware wallet remains secure. You can still use the software wallet application to view balances and initiate transfers, but the actual signing of transactions happens on the hardware device. For anyone holding amounts that would be devastating to lose, a hardware wallet is not optional. You can learn more about integration options and whether a hardware wallet pair would improve your security posture.
Recovery from this point forward: new device practices
The device where you recovered your wallet is now extremely valuable. Treat it as such. Enable all available security features: a strong PIN or password, biometric authentication if you trust the device’s implementation, and encryption at the operating system level. For iOS devices, this means ensuring that Face ID or Touch ID is enabled and that passcode is set. For Android devices, ensure that screen lock is enabled and consider enabling additional protections such as Google Play Protect and the Play Integrity API checks.
Never install applications from third-party app stores or download applications outside official channels. The security of a non-custodial wallet depends on the integrity of the application you are running. A modified version of Bitget Wallet or any other wallet, even if it looks identical, can be designed to exfiltrate seed phrases or private keys. Stick to official sources and verify update notifications through the official channels before installing them.
Consider whether you need to access the wallet frequently from a mobile device. If the holding is substantial and transactions are infrequent, a desktop or hardware-based setup may reduce risk. If you must use a mobile device, ensure that it is kept in a physically secure location, that you use the strongest available screen lock, and that you do not allow unauthorized users to unlock it or access it during sleep. A phone left unattended in a shared space, a phone that someone else can temporarily access during a crowded moment, or a phone that auto-unlocks through weak biometrics is not safe for storing significant holdings.
Recognizing the permanent limitation: theft recovery is not guaranteed
This guide describes how to recover a wallet after theft, not how to guarantee recovery of stolen funds. The moment a seed phrase is compromised and an attacker has access to it, your assets are technically at risk. If the attacker acts before you do, the funds may be moved to addresses you cannot control. Blockchain transactions are irreversible. The cryptocurrency that was transferred out of your wallet onto an exchange, into a mixing service, or into a decentralized protocol cannot be simply reversed by a wallet provider or platform.
The security model of a non-custodial wallet places full responsibility on the user. This is by design and by necessity. Because no intermediary controls the private keys, no intermediary can also freeze transactions, reverse unauthorized transfers, or recover stolen funds. This is the trade-off that comes with private key control. It offers freedom from custodial risk but demands that the user become the sole safeguard against loss.
The best strategy is therefore not to recover from theft, but to prevent it. Keep seed phrases in secure physical storage. Use hardware wallets for substantial holdings. Enable all available device security features. Do not share device access with others. Do not use the same password across multiple services. Do not enter seed phrases into untrusted devices or websites. If you follow these practices consistently, the scenario of a stolen device with compromised funds becomes unlikely rather than inevitable. When it does occur—and for some users, despite precautions, it will—the recovery process described here can restore access to your assets if you retained a separate, secure backup.
Frequently asked questions
Can an attacker move my funds if they have my device but not my seed phrase?
Not immediately, but they may be able to access the wallet application if the device’s unlock is weak. If the device uses a PIN, fingerprint, or face recognition that is easy to bypass or guess, an attacker could open the wallet. However, if you set a separate PIN within the wallet application itself, that adds a second layer. The strongest protection is a hardware wallet, which stores private keys offline and requires physical interaction to approve transactions. An attacker with a stolen phone cannot move funds without the hardware wallet device present.
What if I entered my seed phrase into a phishing website during recovery?
If you entered your seed phrase into a website or application that was not the official wallet, treat it as completely compromised. Immediately recover your wallet on a new device using the original seed phrase, review the transaction history for unauthorized outflows, and consider the seed phrase burned. Move all accessible funds to a new wallet created with a fresh seed phrase. Do not use the compromised seed phrase again. If funds have already been stolen, document the blockchain transactions and contact law enforcement with the evidence.
Should I keep my seed phrase in a password manager or cloud storage?
No. A password manager or cloud storage creates a single point of failure. If your password manager is compromised or your cloud account is breached, the seed phrase is exposed. Store the seed phrase physically on paper in a secure location, use a metal seed phrase backup tool for additional durability, and keep a second copy in a separate secure location. This ensures the seed phrase cannot be stolen remotely and is resistant to digital compromise.