XDRIPACADEMY
Sign in

Curriculum·F106 The Threat Model·60 min

The incident runbook

By the end of this lesson you can

  • Triage a live incident into one of four compromise classes, because the correct first action differs for each
  • Execute the first fifteen minutes in the right order, and explain why the usual instinct is the wrong move
  • Record the evidence that any later investigation requires, in the form investigators can use
  • Refuse the second attack, and state the rule that identifies every recovery scam without judgment
AutopsyThe recovery scam, as documented by the FBIover $9.9M in second losses across one twelve-month window

In June 2024 the FBI's Internet Crime Complaint Center issued a public service announcement about fictitious law firms contacting crypto scam victims and offering to recover their money.

Between February 2023 and February 2024, victims defrauded a second time this way reported additional losses of more than $9.9M. The operators claim to be working with the FBI, or the Consumer Financial Protection Bureau, or another agency, and to have received the victim's case file.

A later advisory covered criminals impersonating IC3 itself, using AI-generated video, cloned voices, spoofed phone numbers and fake government websites. More than 100 reports of IC3 impersonation between December 2023 and February 2025.

Consider the position of the person receiving that call. They have lost money. They have usually told nobody, because of what F106-02 said about shame. They are being offered the single thing they want, by someone who already knows the details of what happened, because the same network caused it.

The decision point is not really theirs. Every defence in this course is degraded by isolation and by wanting it to be true. Which is exactly why the control here is not an assessment of the offer. It is a flat rule that runs without one.

Primary source

Everything so far has been prevention. This lesson assumes prevention failed, because sometimes it does, and the difference between a bad day and a total loss is usually what happened in the first fifteen minutes.

Read this before you need it. Nobody performs well at this reading a lesson for the first time at 2am.

Triage first: which of the four is it?

The single most expensive mistake is doing the right action for the wrong class. Establish which one you are in before you touch anything.

Class 1, seed compromised. You typed, photographed, pasted or spoke your recovery phrase, or it was in a service that has been breached. Every account derived from that seed is gone, present and future, on every chain.

Class 2, approval granted. You signed something on a site and tokens are moving or could move. The attacker has spend rights over specific assets. Your seed is intact.

Class 3, account taken over. An exchange, an email or a phone number is in someone else's control. Your on-chain keys may be untouched.

Class 4, device compromised. Malware, a malicious extension, remote access software you were talked into installing. Assume anything that machine touched is exposed, including class 1 if a seed was ever on it.

More than one can be true at once. The Genesis case in F106-02 was class 3 followed by class 4 followed by class 1, in that order, over a single conversation.

The first fifteen minutes

If class 1, seed compromised: move the funds. Nothing else, first.

Generate a new seed on a device you trust and send everything there. Do not revoke approvals first. Do not investigate. Do not contact anybody. The seed grants total control, so no other action matters until the assets are somewhere it does not reach.

Be honest with yourself about what "a device you trust" means. If class 4 is also possible, the new seed must be generated somewhere else entirely, on hardware that was not involved.

Order by value, highest first, and expect to lose the race on anything cheap. Automated sweepers monitor for exactly this, and they will take a small balance while you are moving a large one. That is an acceptable trade and it is why you sort first.

If class 2, approval granted: revoke, then move.

Revoke the specific approval using a revocation tool reached through your own bookmark, per F105-05. Then move the affected assets to a fresh address. Revocation costs a transaction fee and requires the same wallet, so it works only while you still control the keys, which you do in class 2.

If class 3, account taken over: reclaim the root, not the branch.

Do not start with the exchange. Start at the root of the recovery chain from F106-03, which is usually the phone number or the email. Reclaiming the exchange account while the attacker still holds the inbox that resets it accomplishes nothing. Call the carrier, lock the number, then the email, then each downstream account. Then withdraw to self-custody once you actually control the chain again.

If class 4, device compromised: disconnect, and do not clean.

Take it off the network. Do not attempt to remove the malware and continue using it, and do not use it to move funds, log in anywhere, or generate anything. Move value using a different device. The compromised machine is evidence now; wiping it is for later.

The instinct that costs the most

The instinctive first move is to contact support, or to post publicly asking what to do.

Both are wrong, in that order, for reasons this course has already established. Support is not the fastest path to anything and F111-03's autopsy is what answers a public post about a wallet problem within minutes. You will be surrounded by helpful people, and the helpful ones will be first.

Move the funds first. Ask afterwards, in a channel you opened yourself.

Record it, within the hour

Whatever happens next, from law enforcement to an exchange freeze to a tax deduction, depends on evidence that has to be captured before it disappears. Accounts get deleted within hours.

Capture, at minimum:

  • Transaction hashes for every unauthorised movement. These are the spine of everything.
  • Addresses: yours, and every destination the funds went to.
  • Timestamps with timezone. "Tuesday evening" is not usable.
  • Amounts and assets, and the fiat value at the time, which is a separate number from today's.
  • Screenshots of the entire conversation, including profile pages, handles, and the full links before you lose access.
  • A plain written timeline of what happened in order, written now while you remember, not in a week.

Write the timeline even though it is uncomfortable. Accuracy about your own actions matters more than how it reads.

Reporting, in three categories

Names and remits differ by country, so learn the categories rather than a list that will be stale.

Law enforcement, both your national cybercrime reporting channel and local police. It will feel futile for an individual case. Report anyway: attribution in this field is built by clustering many small reports into one network, which is precisely how the LastPass and Genesis cases were pieced together.

The platforms involved. If proceeds reached a compliant exchange, that exchange can sometimes freeze them, and speed is the only variable that matters. This is the single action with a realistic chance of returning funds, and its window is hours.

Blockchain analytics firms and community investigators, where the amount justifies it. Some accept reports and contribute to the same clustering work.

Common misconception

Stolen crypto can be recovered if you act fast enough or hire the right people.

Both halves need separating, because the honest answer is uncomfortable in each direction.

Funds have genuinely been returned. Law enforcement seizures happen, and over $9M was frozen in the Genesis case. Exchanges do freeze proceeds that land on their venue quickly. Negotiated bounties happen; the WBTC victim in F105-04 recovered over 96 percent after offering 10 percent.

Every one of those started with the victim reaching outward through official channels, or with an attacker choosing to negotiate. Not one of them started with an inbound offer of help.

The second half is where the honesty has to run the other way: most losses are permanent, and no service can change that. Anyone who guarantees recovery, charges a fee to investigate, or asks for an advance is running the second attack. The autopsy on this lesson is that business, and $9.9M in one year is only the variant that got reported.

The rule that needs no judgment

Nobody who contacts you first can recover your funds. Law enforcement never charges a fee to investigate.

That is the whole control. Do not evaluate credentials, do not check the firm's website, do not look them up, because in the autopsy the websites, the videos, the voices and the phone numbers were all fabricated convincingly. Evaluation is the trap. The rule replaces it.

Expect the approach within days of the loss becoming visible on-chain, and expect it to be good.

Then the part nobody writes down

Do not act on money for a week if you can avoid it. The state you are in after a loss is the state every attack in this course is engineered to produce, and you are now in it for free.

Tell one person, today. This is F106-02's habit doing its second job. The shame is heavy and disproportionate, and it is also the mechanism that keeps you isolated for the follow-up.

And write your own postmortem, once, honestly. Which class was it, which control was missing, and what changes. Then implement that change and stop replaying it. The people who come out of this well are the ones who convert it into one procedural change and move on.

The runbook itself

The deliverable is one page, stored where you can reach it without the compromised device: the four classes, the first action for each, your recovery-chain root from F106-03, the revocation tool bookmark, the reporting channels for your country, and the one person you will call.

Written in advance, because at 2am you will not be composing anything.

Key takeaway

Triage before you touch anything, because the four classes have different first moves: seed compromised means move funds before all else, approval granted means revoke then move, account taken over means reclaim the root of the recovery chain rather than the account, and device compromised means disconnect and use something else. Contacting support or posting publicly is the instinct that costs the most. Record hashes, addresses and timestamps within the hour, report to law enforcement and to any platform that touched the proceeds, and then apply the one rule that needs no judgment: nobody who contacts you first can recover your funds, and law enforcement does not charge a fee.

These come back later

What is the first action when a seed phrase is compromised?
Move the funds to a wallet from a newly generated seed on a device you trust. Not revoke, not investigate, not contact support. The seed grants total control, so nothing else matters until the funds are somewhere it does not reach.
Name the four compromise classes.
Seed compromised. Approval granted. Account taken over. Device compromised. Each has a different correct first move, and doing the wrong one first is how people lose the remainder.
What is the flat rule that catches every recovery scam?
Nobody who contacts you first can recover your funds, and law enforcement never charges a fee to investigate. No assessment of the offer is required, and none should be attempted.
What do you record, and when?
Transaction hashes, addresses, timestamps with timezone, the amounts, and screenshots of the whole conversation including profiles and links. Immediately, because accounts get deleted within hours.

Sources and review

Confidence high·Volatility high·Reviewed 2026-08-05·Owner unassigned

Contested

Recovery outcomes are genuinely mixed and we should not flatten them in either direction. Funds have been returned through law enforcement seizure, exchange freezes when proceeds hit a compliant venue quickly, and negotiated bounties. These are the exception and none of them start with an inbound offer. Never promise recovery, and never state that recovery is impossible.

Reporting channels, agency names and their remits differ by country and change. The runbook teaches the categories of report rather than a jurisdiction-specific list, which would be stale within a year.

The $9.9M figure covers only the fictitious-law-firm variant over a single twelve-month window, from complaints that were filed. It is a floor on one subcategory, not the size of recovery fraud.

Track your progress

Create a free account to mark lessons complete and pick up where you left off.