EST · MMXXVI
Home/Insights/Guides/How to Respond in the First 48 Hours After a Crypto Theft
Disputes & Asset Recovery

How to Respond in the First 48 Hours After a Crypto Theft

How to Respond in the First 48 Hours After a Crypto Theft. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to

Recovery windows for misappropriated digital assets are measured in hours, not weeks. When a crypto theft hits a business – whether an exchange, a custodian, a fund, or a corporate treasury – the instinct is often to pause, to investigate internally, to wait for certainty. That instinct is expensive. The blockchain does not wait. Funds move, mixers obfuscate, exchanges process withdrawals, and the legal levers that could have worked on Day One become harder and, in some cases, impossible to pull by the end of Day Three.

This guide sets out the legal and operational steps a business should take in the first 48 hours after a digital-asset theft is identified. Each step names the applicable regime or forum, the cross-border dimension, and the most common mistake at that stage. The goal is a coordinated response that keeps legal options open and preserves the forensic record.

Step 1: Declare an Internal Incident and Preserve All Evidence

The first action is to declare a formal internal incident and place a litigation hold on every relevant system, log, and record. This is not a preparatory step – it is itself a legal obligation in most regulated environments. Under AML/CFT regimes in every leading jurisdiction, a licensed operator has affirmative duties to document suspicious activity. Destroying, overwriting, or simply failing to preserve access logs, API call records, wallet configurations, and key-management audit trails has caused victims to lose standing in subsequent proceedings. Regulators in major hubs – including VARA in Dubai, the FCA in the UK, and the MAS in Singapore – expect operators to demonstrate that their incident-response procedures were followed from the moment the event was identified.

In practice, the incident declaration means three immediate actions. First, suspend the affected wallets or addresses; do not transact from them. Second, export and preserve all relevant logs in a read-only format with timestamped checksums. Third, identify the individuals who had access to the affected infrastructure and place their device records under hold. If your business operates across multiple legal entities in different jurisdictions, the hold must extend to every entity that touched the relevant keys or accounts. A single missing server log in a subsidiary can unravel a disclosure application six weeks later.

The common mistake at this step is treating the incident as an IT problem rather than a legal event. By the time legal counsel is engaged, logs have been overwritten in the ordinary course of business or access credentials have been reset without preservation. That record is gone. The forensic and legal response depends entirely on what the first responders kept.

Step 2: Obtain a Blockchain Forensic Trace Immediately

A professional blockchain forensic trace is the evidentiary foundation for every legal step that follows – without it, no court will grant emergency relief. The trace maps the movement of stolen assets from the victim address through intermediate wallets, to destination addresses, and ideally to an identifiable custodial exchange. Forensic capability is supplied by specialist firms whose reports are regularly accepted by courts in England and Wales, the DIFC Courts in Dubai, Singapore, and Hong Kong. The key deliverable is a report that attributes the destination address to a known exchange or custodian, accompanied by transaction hashes and a chain-of-title analysis.

Speed here is non-negotiable. Most major centralized exchanges apply a time window to asset-tracing requests: funds that have been on-boarded, traded out, and withdrawn before a request is received are far harder to recover than funds sitting in a deposit address at the time of the request. The cross-border dimension matters acutely. If the stolen assets are traced to a platform regulated under the MAS Payment Services Act in Singapore, the legal tools differ from those available if they sit on an exchange supervised by the SFC in Hong Kong or within a VARA-licensed entity in Dubai. The choice of forum for emergency relief is driven by where the assets – or the exchange's obligations – can be reached by a court order.

The common mistake at this step is waiting for the forensic trace to be "complete" before contacting counsel. A partial trace showing assets at a custodial platform is enough to begin drafting emergency applications. Waiting for a polished report costs days that the recovery window does not have.

If your business is facing a live theft and the trail is still warm, contact OBOLUS at info@oboluslaw.com now. The process above describes the standard path. Your facts – the platform, the jurisdiction, the asset type – change which lever to pull first.

How Does a Freezing Order Work for Stolen Crypto?

A freezing order (also called a worldwide freezing order, or WFO – an injunction restraining a defendant from dealing with or dissipating assets, including digital assets held on exchanges) is the primary legal instrument for preserving stolen crypto pending proceedings. Courts in England and Wales have long recognized digital assets as property capable of being frozen. The landmark decision in AA v Persons Unknown [2019] established that Bitcoin could be the subject of a proprietary injunction, and subsequent decisions have extended that principle to a wide range of token types.

In the DIFC Courts, freezing orders in support of foreign proceedings have been granted in recent matters, including cases involving substantial digital-asset balances. Hong Kong courts issued their first tokenized injunction in proceedings recorded as HCA 2417/2024 – a marker that the jurisdiction is actively developing its crypto-recovery toolkit. In Singapore, proprietary injunctions over crypto have been granted in reported decisions. The point is practical: there are now multiple common-law forums where a properly pleaded application for emergency relief over stolen digital assets will be heard seriously and quickly.

To obtain a freezing order, the applicant typically needs four elements: evidence that there is a good arguable case, a proprietary or restitutionary basis for the claim, a real risk that the assets will be dissipated, and – in most forums – a forensic report identifying where the assets are. The order can be made without notice to the respondent (ex parte) where notice would defeat its purpose, which in crypto cases is almost always the case. The cross-border dimension: a freezing order obtained in England and Wales can be recognized and enforced in many jurisdictions through treaty or common-law mechanisms. Counsel in the relevant forum – and, where necessary, allied counsel in the target jurisdiction – must be engaged before the application is filed.

The common mistake at this step is seeking a domestic order only. If the exchange holding the frozen assets is incorporated in a different jurisdiction from the court granting the order, a recognition or enforcement step is required. Missing that step means the order exists on paper but the exchange cannot be compelled.

How Do Disclosure Orders Identify the Thief?

A Norwich Pharmacal order (NPO – a disclosure order requiring a third party, such as an exchange, to provide identity information about an account holder who has allegedly wronged the applicant) is the standard tool for unmasking pseudonymous thieves. A Bankers Trust order is the related instrument for compelling production of account records and transaction histories. Together, these orders are the mechanism by which a "Persons Unknown" claim becomes a claim against an identified individual or entity.

In practice, the application is made to a court in the jurisdiction where the exchange is regulated or has assets. The exchange is not a wrongdoer; it is a neutral party holding information. Courts have been willing to grant NPOs against FCA-registered and –regulated entities in the UK, against Singapore MAS-licensed platforms, and against DIFC-based custodians. The threshold is that the applicant can show the mixed or wrongful funds passed through the respondent's platform, that the respondent holds the relevant KYC or transaction data, and that disclosure is necessary and proportionate.

The cross-border note is important. An exchange incorporated in the BVI but serving global users may hold its KYC data in a third country. An NPO obtained in England may compel the BVI entity's directors, but access to the underlying data may require a parallel application in the data-storage jurisdiction. In our practice, we have seen multi-step disclosure chains spanning three forums before the identity of the controller of a destination wallet was established. Building that chain at speed requires knowing which court in which sequence.

The common mistake at this step is filing an NPO application to a court that does not have personal jurisdiction over the exchange. A well-drafted application served on an entity with no connection to the forum – no office, no regulatory authorization, no assets – will be dismissed on jurisdictional grounds, wasting days.

Should I Contact the Exchange Directly Before Going to Court?

Contacting a regulated exchange's compliance team directly – before any court proceeding – can freeze assets faster than any court order if done correctly. Both Tether (USDT) and Circle (USDC) hold contract-level freeze authority over their issued tokens and generally act on law-enforcement reference or a credible court order. Major regulated exchanges have internal fraud-liaison procedures. A well-structured notification – including transaction hashes, a preliminary forensic report, and a statement of the legal basis for the claim – can prompt a voluntary hold while legal proceedings are initiated.

This is not a substitute for court proceedings. A voluntary hold by an exchange is precarious: it can be lifted at the exchange's discretion, it does not compel disclosure of account-holder identity, and it provides no legal certainty over ownership of the frozen balance. It buys time. In cases where the forensic trace shows assets sitting at a deposit address on a co-operative platform, that time can be the difference between a successful recovery and a dissipated balance.

The cross-border dimension: exchanges regulated under VARA, MAS, SFC, or the FCA each have different internal compliance structures and different obligations to respond to third-party fraud notifications. Some have well-developed liaison channels; others route all such requests through external legal counsel in their domicile. Knowing the right entry point for the platform at issue is a function of experience with that regulatory environment, not a matter of guessing from a website.

The common mistake at this step is sending an informal email to a generic support address and waiting for a response. That notification has no legal weight. The correct approach is a formal letter before action, addressed to the compliance function, setting out the claim basis, the transaction references, and the legal demand – and delivered in a way that creates a timestamped record.

If a prior attempt to reach an exchange stalled, or an account was closed before you acted, there may still be a route. A second read of the facts can surface the structural reason and the next step. Reach the OBOLUS disputes desk at info@oboluslaw.com.

What Is the Cross-Border Recovery Reality for Stolen Digital Assets?

Most crypto thefts are cross-border by nature. The victim is in one jurisdiction, the attacker used infrastructure in a second, the assets moved through exchanges in a third and fourth, and the final custodian is in a fifth. No single court has comprehensive jurisdiction over every element of that chain. Effective recovery requires a coordinated multi-forum strategy, not a single application in the victim's home jurisdiction.

The CFAAR network (the Crypto Fraud and Asset Recovery network, launched in London in September 2021) was established precisely to facilitate cross-border cooperation among insolvency practitioners, lawyers, and forensic specialists working on digital-asset recovery. Its existence reflects a practical reality: recovery counsel must have working relationships with allied counsel in the forums where assets sit, not just in the forum where the victim is based.

The decision about which forum to lead with turns on several factors. Where is the exchange that received the stolen funds regulated? In which jurisdiction can the victim most quickly obtain a freezing order and a disclosure order? Which legal system has the most developed crypto-property doctrine? England and Wales currently offers the most developed toolkit – established case law, a specialist judiciary familiar with digital assets, and a WFO regime that can reach assets globally. The DIFC Courts offer comparable tools in the UAE context. Singapore and Hong Kong are active and credible alternatives for assets traced to Southeast or East Asia. The choice is tactical, not aspirational.

The common mistake at this step is anchoring to the victim's home jurisdiction for procedural convenience. If the victim is in a jurisdiction with less-developed crypto-property law, filing domestically may produce a technically valid order that no foreign exchange will recognize. The forum should be chosen for reach, not for familiarity.

Step 6: Consider Regulatory and Law Enforcement Notification

Parallel regulatory and law-enforcement notifications serve two distinct purposes in a crypto recovery. First, under AML/CFT regimes applicable to most licensed operators – including the FATF Recommendation 15 framework that underpins VASP supervision worldwide – a theft or suspected fraud triggering suspicious transaction reporting obligations must be reported to the relevant financial intelligence unit. Failure to report is a compliance failure independent of the recovery strategy. Second, a law-enforcement case reference is frequently required before a stablecoin issuer will act on a freeze request: both Tether and Circle's published procedures contemplate law-enforcement or court-order triggers.

The cross-border dimension is significant. If the business is regulated in the EU under MiCA and licensed in Dubai under VARA, both regimes may impose reporting obligations with different timelines and different recipient agencies. An operator that reports to one competent authority but not the other exposes itself to regulatory sanction on top of the commercial loss. Mapping the applicable reporting obligations across all relevant jurisdictions is a legal task, not an administrative one.

Law enforcement engagement also carries strategic considerations. In some forums, law-enforcement action can accelerate exchange co-operation in ways that private legal proceedings cannot. In others, law-enforcement timelines are too slow to serve the recovery window. The decision whether to lead with law enforcement or with private civil proceedings – or both in parallel – depends on the facts of the case, the jurisdictions involved, and the recovery targets.

The common mistake at this step is treating regulatory notification as an afterthought once civil proceedings are underway. The notification timeline is frequently fixed by the applicable regime. Missing it creates a separate compliance exposure that can complicate the recovery by drawing regulatory scrutiny to the victim's own procedures.

A Note From Our Practice

In a recent recovery matter, a digital-asset payments company identified the unauthorized transfer of a seven-figure stablecoin balance late in the business week. By the time OBOLUS was engaged – within hours of discovery – the assets had passed through two intermediate wallet clusters and reached a deposit address at a centralized exchange regulated in a leading common-law jurisdiction. We secured a without-notice freezing order and a disclosure order from that jurisdiction's court before the close of business the following day. The exchange voluntarily held the balance pending the formal order. The identity of the account holder was established through the disclosure process within a further week. The matter did not conclude with a guarantee – outcomes in recovery matters never do – but the speed of the legal response preserved the option of recovery where delay would have foreclosed it entirely.

Self-Assessment Checklist: First 48 Hours

Before the 48-hour window closes, the following actions should either be complete or have been consciously decided against on advice:

  • Formal incident declared internally; litigation hold placed on all relevant systems and logs.
  • Affected wallets or addresses suspended; no further transactions from those addresses.
  • Blockchain forensic specialist engaged; preliminary trace initiated with transaction hashes identified.
  • Legal counsel engaged in the primary forum for emergency relief; choice of forum made on the basis of where stolen assets can be reached, not where the victim is located.
  • Freezing order and disclosure order applications drafted or in preparation.
  • Formal compliance notification sent to the relevant exchange or custodian holding the destination address, with legal basis stated.
  • AML/CFT and suspicious-transaction reporting obligations mapped across all relevant jurisdictions; notifications filed or scheduled within the applicable deadlines.
  • Law-enforcement engagement assessed; decision made whether to file in parallel or to sequence after civil proceedings.
  • Cross-border enforcement strategy confirmed: if the court of primary jurisdiction and the exchange's domicile differ, recognition/enforcement steps identified.

No item on this list is optional. Each represents a step that, if missed in the first 48 hours, requires a separate and slower legal process to remediate later – if it can be remediated at all.

Related at OBOLUS

FAQ

Can stolen crypto actually be recovered?

Recovery is possible but never guaranteed. Courts in England and Wales, the DIFC, Singapore, and Hong Kong have all granted freezing orders and disclosure orders over digital assets, and stablecoin issuers hold contractual freeze authority over their tokens. The preconditions are speed, a professional forensic trace, and a properly pleaded application in a forum with jurisdiction over the exchange or custodian holding the assets. The further from the theft the action begins, the narrower the options become.

How fast must I act after a digital-asset theft?

Speed is the single most important factor. Assets move through mixers, cross-chain bridges, and withdrawal cycles in hours. Exchange compliance teams and stablecoin issuers have internal time windows for honoring freeze requests. Courts can grant without-notice freezing relief rapidly when the application is properly prepared. In our practice, the difference between a recoverable and an unrecoverable position frequently turns on whether legal action began within the first day rather than the first week.

Can a court freeze assets held on an exchange?

Yes. Courts in England and Wales, the DIFC Courts, Singapore, and Hong Kong have all issued freezing injunctions that extend to digital-asset balances held on centralized exchanges. The exchange is served with the order and placed under an obligation not to process withdrawals of the frozen balance. In parallel, a disclosure order can compel the exchange to produce KYC records identifying the account holder. The applicable regime and the exchange's domicile determine which court and which process applies.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers, and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking, and compliance that sit around them. Digital assets are the whole of our practice. We move for freezing relief and exchange disclosure while the trail is live – the speed of the legal response is what keeps options open. To discuss your situation, contact info@oboluslaw.com.

By Glen Sorensen, Disputes & Recovery Analyst – specializing in multi-forum crypto asset recovery, freezing applications, and on-chain tracing for business clients.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours