I got scammed or hacked

You see transactions you did not authorise, or funds are missing from your wallet.

dreamDEX is non-custodial, so funds leave your account in one of three ways. They overlap, so do not try to pick one and stop — the single prompt you signed on a drainer site is very often the thing that granted a permission still draining you now.

Something you signed. A drainer site or a fake prompt got you to approve a transfer or a contract call. This is the most common start by far, and what you signed may have been a one-off transfer or a standing permission. You usually cannot tell from the prompt you remember.

A permission that is still live. An approval you signed months ago can drain a token today without anyone holding your key. It keeps going until it is revoked.

A compromised signer. Someone has your login, or a key that can sign for your account. Everything that signer reaches is at risk, repeatedly.

Act in this order, and do all three — the number of withdrawals you have seen is not evidence that nothing is still live.

  1. If funds are still leaving, move what is left first, to a new address from a clean device. Revoking cannot outrun someone who can sign.
  2. Then check your permissions and revoke anything you do not recognise, whatever you think started it. See the section for your login type below, because how you revoke differs.
  3. Then secure the way in — the device, the login, or the key — using the section that matches how you log in.

First: which kind of wallet do you have?

First, one thing that surprises people: your wallet extension is not what signs your dreamDEX trades. Your trading balance sits in a smart account, and the key that signs for it is one the app holds for you, created when you first logged in. Your extension is how you log in, and it can also be added to the account as a second owner so you are not locked out — but a trade does not go through it.

That matters here, because it means your dreamDEX balance and the balance in your extension can be compromised separately.

You connected a wallet extension like MetaMask or Rabby, and you have a seed phrase written down somewhere. Treat your dreamDEX account as compromised too. That wallet is how you log in, so whoever holds the key can sign in as you and use the account's own signer — it does not matter whether the wallet was ever added as a second owner. Everything the extension holds directly is at risk as well.

You logged in with email or a social account. There is no seed phrase you wrote down, and no key of yours signs for the account. What was compromised is almost certainly the login, the email account or the social account.

Read the section that matches.

If you use a wallet extension

  1. Create a new wallet first, with a trusted provider, on a device you trust. You need somewhere safe to send to before you can move anything, so this comes first even though the urgent part is step 2. Do not change how you log in to dreamDEX yet — the withdrawal runs from your current login, and logging in with a different wallet opens a different, empty account
  2. Move what is left out of your dreamDEX account, to the address you just made. The login is compromised, so the account is reachable until it is empty. Check the recipient before you confirm: the withdraw form fills it in with the wallet you log in with, which is the compromised one, so replace it with the new address
  3. Stop using the old address. Treat it as permanently unsafe. Do not deposit to it again, and log in with the new wallet from now on
  4. Move everything remaining out of the old wallet to the new one. This applies to every app you use, not just dreamDEX
  5. Revoke contract permissions on the old address at https://revoke.cash, which you can sign for from the extension itself. Keep a little of the network's gas token back for the gas each revocation costs. This covers the extension's own address only. Approvals on your dreamDEX account cannot be revoked in the app yet, which is why step 2 empties the account
  6. Open a ticket with both addresses. We can check whether your old wallet was added to the account as a second owner. The app cannot remove an owner yet, so do not keep funds in that account
  7. Work out how it happened. Check the device for malware. If you do not find the cause, the new wallet is at risk too

If you log in with email or a social account

  1. If funds are leaving right now, move what is left first, to an address you control from a clean device. Securing a login takes minutes, and an attacker with a live session keeps draining through them. If nothing is moving, go straight to step 2
  2. Secure the login. Change the password on the email or social account, turn on two-factor authentication, and sign out every other session. Until the login is yours again, nothing else holds
  3. Check for forwarding rules and recovery addresses you did not set. Attackers add these so they can get back in after you change the password
  4. If it looks like an approval, open a ticket rather than a revocation site. Your account's signing key is held inside the app, so a site like revoke.cash can show you the approvals on your address but cannot submit the revocation — there is nothing there for you to sign with. Send us the address and we will walk you through it
  5. Once the login is secure, move anything still there out of the smart wallet to an address you control from a clean device, in case the attacker kept a session
  6. Work out how it happened. A reused password, a phishing page that captured the login, or malware on the device

What we cannot do

We cannot reverse the transactions and we cannot recover the funds. Nobody can. Anyone who tells you otherwise is running the second half of the same scam.

We will never DM you about it. In the hours after someone posts about losing funds, scammers move in offering recovery services. Every one of them is fake.

We can confirm what happened on-chain, which is sometimes useful for a report. Open a ticket with the address and the transaction hashes.

Avoiding it next time

  • Never enter your seed phrase into a website, and never share it with anyone calling themselves support
  • Never share a login code. If you use email login, the code that arrives is the key. Anyone asking for it is stealing from you
  • Use a hardware wallet for anything significant. Ledger, Trezor or Keystone, paired with a browser wallet, keeps the key off your browser
  • Read every transaction before signing. If your wallet warns you or the details are unclear, do not sign
  • Bookmark the sites you use. Do not reach them through search, and never through a sponsored result
  • Assume DMs are scams, especially anyone asking you to install something or open a file
  • Keep extensions updated and delete ones that are no longer maintained

Read more