Curriculum·O101 After a Loss·about 30 min

The first hour

Jurisdiction·as of 2026-09·Reporting and tax treatment in this course are United States federal, as they stood on the date beside this line: the FBI's IC3 and the IRS. Reporting routes and any deduction differ by country. The evidence file it tells you to keep is the same everywhere.

By the end of this lesson you can

  • Identify, from what happened, which secret or permission is compromised: a seed, a device, an approval, an exchange login or a signed message
  • Move what is still yours to a clean device before doing anything else, and explain why the order matters
  • Revoke the standing permissions the attacker can still use, and freeze the accounts they can still reach
  • Preserve the evidence a report will need: transaction hashes, addresses, screenshots and a timeline, written while it is fresh
AutopsyThe Ledger Connect Kit supply chain attack, December 2023at least $600,000 in about forty minutes

On 14 December 2023 an attacker took over an npm account belonging to a former Ledger employee and published poisoned versions of Ledger Connect Kit, a small library that many decentralized applications embed so their websites can talk to wallets.

For about forty minutes, anyone who visited an affected site and clicked to connect was shown a drainer dressed up as the normal prompt. It did not steal keys. It asked for signatures and approvals, and the users who gave them had granted the attacker's contract standing permission over their tokens.

Ledger shipped a fix within about forty minutes of being alerted. The sites were clean within hours. At least $600,000 was gone.

For the people who had signed, the theft was not over when the site was fixed. An approval stays valid until it is revoked, so the same wallets could be emptied again later. The advice from Ledger and from everyone who covered it was one word: revoke.

That is what the first hour is. Not getting anything back. Closing the doors that are still open, in an order that does not open new ones, and writing down what happened while you still can.

Primary source

If you are reading this because something was just taken from you, this lesson is for now. Read it to the end before you do anything, because the order matters and the wrong first move makes it worse. It takes ten minutes. The rest of the course can wait until tomorrow.

First: what do they have?

Everything in this hour depends on one question. Which secret or permission does the attacker now hold?

  • Your seed phrase, if you typed it anywhere, photographed it, or restored it into an app you did not verify. Everything derived from that seed is theirs, forever. That wallet is finished.
  • A device, if malware was on it or you handed control of it to a "support agent". Anything you do on that device can be watched, including typing a new seed.
  • An approval, if you signed something on a site that turned out to be hostile. Your seed is safe. The attacker's contract has permission to move specific tokens from your wallet, and keeps it until you take it away.
  • An exchange login, if your password, email or two-factor code was phished. The attacker can withdraw whatever the exchange holds for you and change the settings that would stop them.
  • A signed message that was not a transaction, per F105-02's taxonomy: a permit, an order, a listing. It may still be usable.

You may have more than one. Write down which. The rest of the hour is a different list for each.

Second: move what is still yours

If the seed or the device is compromised, the remaining funds are not safe where they are, and they are not safe on anything you create from that device.

From a different, clean device, one the attacker has not touched, create a new wallet with a new seed, per F104-07 watching it be generated. Send what remains to it. Yes, the fee is real and the market may be moving. A wallet an attacker can drain is worth exactly nothing, so the fee is the cheapest thing that happens today.

If only approvals were granted and the seed is safe, skip this step for now and go to the next one first: moving tokens into a wallet that still carries an approval to the drainer moves them within reach.

Third: close the doors

Revoke every approval the compromised wallet has granted. Any of the public approval-checker tools, of which there are several and this course names none, will list every contract with permission over your tokens; revoke the ones you do not recognize, then the ones you do not need, which per F105-05 is most of them. Each revocation is a transaction and costs gas. Pay it.

Freeze and re-secure accounts. Change the password on the exchange, on the email behind it, and on anything that shares either. Change them from the clean device. Re-enroll two-factor on the clean device and remove the old enrollment. If the exchange offers a withdrawal lock or a support freeze, use it. If the attacker had the login, assume they added an API key or a withdrawal address; remove both.

Do not interact with the attacker. Not the contract, not the address that took the funds, not the person who messages you offering to help. F105-06 and O101-04 cover why; for now, the rule is that nothing they can say to you in this hour is worth hearing.

Worked example
One loss, three lists

Someone types their seed into a fake app on their laptop. Minutes later, most of a wallet is gone. They also had two tokens in that wallet that the attacker has not moved yet, and they have an exchange account whose password is saved in the laptop's browser.

What they have. The seed, so the wallet is finished. The laptop, so it is compromised. Possibly the exchange login.

Move. From their phone, which has never seen the seed, create a new wallet and send the two remaining tokens to it. Two transactions, two fees, done.

Close. From the phone, change the exchange password and the email password, re-enroll two-factor, check for API keys and withdrawal addresses, and freeze withdrawals for the day. Nothing on the laptop until it has been wiped.

Record. The hashes of the theft transactions, the attacker's receiving address, the name and download link of the fake app, a screenshot of it, and the time.

Total: about twenty minutes. Nothing recovered. Two tokens kept, an exchange account kept, and a report that can be filed tonight.

Fourth: write it down

You will file a report, per O101-03, and a report without evidence is a form. The chain records the transfers and nothing else. Only you can record what you saw and did, and in three days you will not remember it accurately.

Before the hour is over, in a document on the clean device:

  • Every transaction hash for the theft, copied from a block explorer, per F101-05.
  • Every address: yours, the attacker's, anything in between.
  • What you clicked, signed, typed or downloaded, and roughly when. The name of the site or app. The message that led you there, screenshotted, with the sender.
  • What you have done since, with times. Moved funds, revoked, changed passwords.

That document is the evidence for everything that follows, and it takes ten minutes to write now and is impossible to write next week.

Common misconception

If I act fast enough, I can get it back.

Nothing in this hour recovers what was taken. A transaction that has confirmed is final; that is what F101 will teach you a chain is, and it does not stop being true because the transaction was theft.

What speed buys you is everything that has not been taken yet. The remaining tokens, the exchange balance, the second wallet that shares a password, the approvals the attacker was saving for later. Those are what the first hour is for, and the difference between acting in an hour and acting in a week is usually measured in the second theft rather than the first.

O101-02 says honestly what is and is not recoverable afterwards. Read it tomorrow.

When the hour is over

Stop. Do not spend the night reading recovery forums, and do not answer anyone who contacts you about the loss, however official they sound. The people who monitor victims for their second approach are covered in O101-04, and the one thing they need is for you to be exhausted and hopeful.

Tomorrow: O101-02 on what can and cannot be recovered, O101-03 on reporting and the tax treatment, O101-04 on the second wave. Then, when you are ready, the placement diagnostic and Year One, which is where the site teaches you how this does not happen again.

Key takeaway

The first hour after a loss recovers nothing and protects everything that is left. Decide what the attacker holds: a seed, a device, an approval, a login or a signed message. From a clean device, create a new wallet and move what remains if the seed or device is gone; revoke every standing approval, because a drainer keeps its permission until you take it away, as the Ledger Connect Kit victims learned after the sites were already fixed; change and re-enroll every credential from the clean device; and write down the hashes, addresses, what you did and when, tonight, because a report without evidence is a form. Then stop, and answer nobody.

4 cards, for an account that keeps them

Scheduling them needs somewhere to keep a schedule, so without an account these are just the summary.

What is the first question after a loss?
Which secret or permission the attacker now holds: a seed, a device, an approval, an exchange login or a signed message. That decides what is still at risk and what to do first.
What is the order of the first hour?
From a clean device: new wallet, move what remains, revoke every standing approval, freeze and re-secure accounts, then write the evidence down. Never act from the compromised device.
Why revoke after a drainer, even once the site is fixed?
An approval stays valid until revoked. The Ledger Connect Kit sites were clean within hours; the wallets that had approved the drainer stayed exposed until each approval was removed.
What evidence does a report need?
Transaction hashes, every address, what you clicked or signed and when, and screenshots. The chain records the transfers; only you can record the rest, and only while it is fresh.
Terms used here

Sources and review

Confidence high·Volatility medium·Reviewed 2026-09-09·Owner unassigned

Contested

Whether to move remaining funds before or after revoking approvals depends on what was compromised. This lesson says move first when the seed or device is gone and revoke first when only approvals were granted; a reader with both problems moves first, from a clean device, then revokes from the new wallet. Say so rather than giving one order for every case.

Loss figures for the Ledger Connect Kit incident vary between about $484,000 and $610,000 across sources. Ledger's own report is used here and the figure is stated as a floor.

8 assessment items

3 knowledge checks, 3 scenarios and 2 calibration items sit at the end of this lesson, for enrolled learners.

Enroll to keep your record

This lesson is open to read. Enrolled learners also mark it complete, answer the 8 assessment items at its foot, get its cards back on a schedule, and pick up where they left off. Enrollment is free and comes back to this page.