My savings were drained from MetaMask after clicking a fake 'Uniswap update' link, is it recoverable?

asked 35d ago17 views45 answers
0

Okay, so I messed up big time last night. I was just chilling, watching some Netflix, and an email popped up, looked totally legit, like it was from Uniswap, saying there was a critical security update for MetaMask that needed to be applied through their portal. Ngl, it looked super real, like even the logos and everything were perfect. I clicked the link, it asked me to 'reconnect' my wallet, which I did, and then... boom. My ETH, all my USDC, GONE. Literally watched the transactions clear on Etherscan in real time. It was about $8,000 in total. I feel so stupid. I reported it to MetaMask, but they just sent an automated reply. Has anyone ever gotten anything back after something like this? Is it even worth trying to trace it? What are the next steps beyond feeling like a total idiot?

Mentioned in this discussion
MetaMask· neutralEtherscan· neutral

45 Answers

37

Oh mate, I'm really sorry to hear this. It's a classic phishing scam, sadly, and they've gotten really sophisticated. The 'security update' or 'reconnect wallet' is a super common trick. Once you connect to their malicious site and 'approve' the transaction, you've essentially given them permission to drain your assets. It's like handing over your house keys.

Recovery is extremely difficult, bordering on impossible, in these cases. Here's why: the moment you approved those transactions, the assets moved out of your wallet and into the scammer's. Blockchain transactions are irreversible. You can trace them on Etherscan, yes, but that only shows you where they went. Unless the scammer sends it to a KYC-compliant exchange like Kraken or Binance and they freeze the funds (which is a long shot and requires police involvement), it's generally gone.

*However*, you absolutely *must* report it to the police, your national cybercrime unit (like Action Fraud in the UK), and the FBI IC3 if you're in the US. They might not get your money back, but it helps build a case against these criminals. Also, immediately revoke any active approvals on your wallet if you haven't already – you can use tools like Revoke.cash for that. Sorry, it's not the news you want to hear, but setting realistic expectations is important here.

Grace Wood · Nottingham, United Kingdomanswered 35d ago
47

I really feel for you, Joshua. I lost a decent chunk of change, about $4k, to a similar phishing attack a while back, trying to claim some fake UNI tokens. Saw it drain from my MetaMask in real-time, just like you. The pit in my stomach was unbelievable. I tried everything – reported it to Chainalysis, told my bank (even though it was crypto, hoping they'd have some general advice), and even filed a report with the Canadian Anti-Fraud Centre. None of it led to recovery, but it felt like I was *doing* something, you know? It helps to channel that anger into action, even if it's just reporting. Eventually, you just have to come to terms with it. It's a harsh lesson, but a lesson learned. Stay strong.

Mia Morin · Halifax, Canadaanswered 35d ago
18

Ugh, feel your pain, my friend. Similar thing happened to me last year, but it was a fake airdrop. Clicked, connected my MetaMask, and boom, almost 2 ETH gone. I was furious at myself. I tried tracing it on Etherscan for days, watched it move through mixers, then to some exchange I'd never heard of. It's like watching your money disappear into thin air. I reported it to the local police here in Cologne, but they basically just shrugged. Said unless I knew *who* did it, there's not much they could do. It's a horrible feeling, that helplessness. I just accepted it as a very expensive lesson in not clicking suspicious links. Now i double-check everything, every single link, every email. Always go to the official site directly.

Andreas Schneider · Cologne, Germanyanswered 35d ago
11

Honestly, I wouldn't get your hopes up. Once it's off your wallet in crypto, especially after you've 'approved' a malicious contract or connection, it's usually gone for good. There are so many scam 'recovery services' out there that will just take more of your money. They promise the moon and deliver nothing. Don't fall for that second scam. Report it, learn from it, and be super careful next time. That's about all you can do.

Isabella Gauthier · Toronto, Canadaanswered 35d ago
42

Joshua, what Grace said is spot on. And please, please, please be extra careful about anyone reaching out to you offering 'recovery' services. You'll likely see a lot of DMs and comments now. They're almost always scammers preying on your desperation. They'll ask for an upfront fee, or say they need your seed phrase or private keys – NEVER give those out. A legitimate recovery service simply doesn't exist for this type of scam where you willingly approved a transaction on a malicious site. The blockchain doesn't care about your mistake, it just executes what you approve. Stick to reporting it to official channels, even if the chances are slim. That's your only safe bet.

Omar Al Hashemi · Sharjah, UAEanswered 35d ago
25

Man, that sucks so much. It's like getting robbed but you were the one who opened the door, right? I had a similar scare, not quite drained, but almost. I got a fake 'MetaMask connection needed' email, clicked it, and it tried to get me to approve some weird contract interaction. Luckily, my partner was looking over my shoulder and screamed 'STOP!' before I clicked 'confirm'. I would have lost a chunk of my portfolio too. The feeling of dread... it's just awful. I just want to say, don't beat yourself up too much. These scammers are incredibly sophisticated now. They target you when you're distracted. All you can do is learn from it and try to warn others.

Charlotte Bouchard · Ottawa, Canadaanswered 35d ago
29

As others have said, the sad reality is that direct recovery from a wallet drainer scam, especially one where you signed a malicious transaction, is extremely rare. Your best bet is always prevention. Always, always verify the URL of any site you're interacting with crypto on. Never click links in emails for wallet connections or 'updates'. Go directly to the official site by typing the URL yourself or using a trusted bookmark. I've seen so many people lose their life savings this way. It's a brutal world out there in crypto, you gotta be your own bank AND your own security expert.

Henry Walker · Brighton, United Kingdomanswered 35d ago
41

Joshua, what you experienced is a classic 'wallet drainer' or 'phishing' scam. The email created a sense of urgency, the fake site mimicked the real one perfectly, and then the malicious contract approval gave them access. When you 'reconnected' your wallet, you essentially authorized the scammer to transfer your assets.

The technical side: Once funds are moved from your wallet to the scammer's wallet on the blockchain, the transaction is immutable and irreversible. Tracing it on Etherscan will show you the path, and potentially identify if it consolidates into a larger wallet or moves to an exchange. Tools like Chainalysis and ChainAbuse are used by law enforcement and larger entities to identify and track these funds, but for an individual, getting them to act without a significant amount or a large number of victims is challenging. Your best course of action remains reporting to law enforcement like the FBI IC3. They collect these reports and can sometimes act if they see a pattern or a large sum involved. But as for individual recovery, it's very, very tough. My sympathies.

Sophie Schulz · Munich, Germanyanswered 35d ago
15

Man, that totally sucks but yeah, pretty much what everyone else is saying. You're probably not getting it back. Anyone saying they can 'recover' it for a fee is just trying to scam you again. Don't fall for that. Just treat it as a hard lesson. It happens to so many people because these scams are getting so sophisticated. I nearly fell for a fake 'Kraken security alert' myself last month. Had my finger hovering over the link. Stay safe out there.

Amanda Lee · Houston, USAanswered 35d ago
8

Yeah, I'm sorry to say it, but when you 'reconnected' or 'approved' something like that, you effectively gave them permission. It's not like someone hacked into your wallet without your interaction. The blockchain recorded *your* permission. That's why recovery is practically non-existent. It's a tough pill to swallow but you gotta move on. Don't waste more energy or money chasing shadows. Just learn from it and beef up your security going forward. Two-factor authentication, hardware wallet, no clicking email links. That's the mantra now.

Amelia Smith · Hobart, Australiaanswered 35d ago
15

This sounds like a classic phishing attack targeting DeFi users. The fake Uniswap update is a common social engineering tactic. Unfortunately, once funds are moved out of your MetaMask and onto an exchange or into another wallet, recovery is extremely difficult, bordering on impossible. The speed suggests automated bots likely swept the funds immediately. Your best bet for reporting is the FBI's Internet Crime Complaint Center (IC3). Make sure you have all transaction IDs from Etherscan.

Emma Schmidt · Dresden, Germanyanswered 35d ago
12

Oh no, that is absolutely devastating. I went through something similar, not with Uniswap but a fake ledger app. Felt like my stomach dropped out. I lost about 5k CAD. I reported it everywhere, but honestly, the money was just gone. It took me months to even want to look at crypto again. Don't beat yourself up too much; they're getting so sophisticated. What helped me a little was just talking about it, even here. It made me feel less alone.

Olivia Bouchard · Edmonton, Canadaanswered 35d ago
5

Are you SURE it was a fake link? Sometimes these things just happen. Like a wallet drain bug or something? I'm not saying you're wrong, but I've seen weird stuff happen with exchanges too, like Kraken having temporary issues. Did you get any confirmation emails or anything *directly* from Uniswap or MetaMask about this supposed update? Usually, they wouldn't ask you to reconnect via a random link. Did you check the URL very carefully?

Marie Becker · Cologne, Germanyanswered 34d ago
9

I am so, so sorry this happened to you. I can only imagine that sinking feeling. I was a victim of a similar phishing scam last year, it wasn't Uniswap but some fake NFT minting site. Lost my entire altcoin portfolio. They got me when I thought I was just connecting my wallet to claim some 'free' NFTs. I felt like such an idiot for days. The scammers are just relentless. I don't think I ever saw a penny back, but I did report it to ChainAbuse, which at least felt like doing something.

Laura Wagner · Dusseldorf, Germanyanswered 34d ago
11

This is why I'm so paranoid about clicking any links, even if they look legit. My cousin got hit by a similar Uniswap phishing scam. He clicked a link on Discord from what looked like an official announcement channel. Lost his whole savings. He learned the hard way: never trust a link that asks you to connect your wallet. Always go directly to the official website or app yourself. It’s a pain, but it’s safer.

Michael van der Merwe · Port Elizabeth, South Africaanswered 34d ago
7

Wait, an 'update' for MetaMask requiring a wallet reconnect? That's a massive red flag right there. MetaMask itself doesn't work that way. Updates are handled by the browser extension or app, not by visiting a website and reconnecting. You don't 'update' your wallet's security by entering your seed phrase or connecting to a site. Did you perhaps input your seed phrase anywhere? If you did, that's the absolute worst-case scenario. If you only connected, there's a *tiny* slim chance, but usually, they drain fast.

Alice Robert · Paris, Franceanswered 34d ago
14

This is precisely the kind of attack pattern we're seeing more of. The attackers are mimicking legitimate DeFi protocols and even wallet providers. Your best course of action is to report this incident thoroughly. Beyond MetaMask and the FBI IC3, consider if the destination addresses are visible on Etherscan and if they've been flagged by any block explorers or analytics firms like Chainalysis. Some exchanges might freeze funds if they can trace them quickly enough, but that's rare with these fast sweeps.

Faisal Khan · Ras Al Khaimah, UAEanswered 34d ago
3

I'm so sorry you went through this. It's a horrible feeling. These scams prey on our desire to keep our assets safe. Just remember, it's not your fault for being targeted. These scammers are professionals. Keep your head up. The crypto community is here for you.

Mohammed Al Maktoum · Sharjah, UAEanswered 34d ago
10

This is exactly the kind of scam that makes people scared to use crypto. They create fake websites that look identical to real ones, and then they trick you into signing transactions that drain your wallet. I've seen this happen to friends. They clicked on a fake Binance notification link. They lost everything. The advice from others is good: report it, but don't expect the money back. The real lesson is to *always* bookmark your important sites and never click links from emails or DMs, no matter how real they seem.

Joshua Dlamini · Durban, South Africaanswered 34d ago
12

Oh man, this is heartbreaking. Similar thing happened to me back in 2021, a fake Metamask 'security alert' email. Clicked it, reconnected my wallet, and boom. About $3k gone. I felt like such a fool. I tried reporting it to the police here in Singapore but they basically said crypto theft is too hard to trace. I learned that day to *never* click links for wallet actions. Always go directly to the app or website yourself. Bookmark everything important.

Aaron Lau · Singapore, Singaporeanswered 34d ago
8

Ugh, I know this feeling too well. A few months ago, I fell for a fake Trust Wallet support scam. They had a fake support page that looked legit and convinced me to share my screen. I lost about $3,000 worth of SOL. They even had me approve a transaction that supposedly 'verified' my account. Took me a week to realize what happened. I never got anything back. My partner told me to just accept it and move on, which was hard but kinda necessary.

Maximilian Meyer · Cologne, Germanyanswered 34d ago
9

This is brutal. I got hit by a similar scam last year, a fake NFT marketplace pop-up that looked like OpenSea. It asked me to 'sign a message' to claim some airdrop. Sounded fine, I signed it. Next thing I know, my collection is gone, and they transferred it out. About $6,000 worth. I reported it to IC3 and even contacted a blockchain forensics firm, but it was a dead end. They moved the funds through so many mixers, it was impossible.

Daniel Moore · Boston, USAanswered 34d ago
16

This is a hard lesson, and unfortunately, the crypto space is rife with these scams. The key takeaway here is to understand wallet interactions. MetaMask will *never* ask you to go to a website to 'update' its security by reconnecting. Updates are handled natively. If a site prompts you to connect your wallet for an update or to 'verify' something, it's almost certainly a scam. Reporting to IC3 is correct, but focus on proactive security: use a hardware wallet for significant holdings and be extremely judicious about website permissions.

Thabo Naidoo · Johannesburg, South Africaanswered 34d ago
7

Heartbreaking to read this. These scammers are getting bolder. A friend of mine received a fake email that looked like it was from Binance, claiming his account was compromised and he needed to 'verify' his details via a link. He clicked it, entered his login, and they took over his account. He lost a significant amount. We reported it, but Binance said they couldn't help once the funds were withdrawn. Always enable 2FA and never trust email links.

Maryam Sheikh · Ajman, UAEanswered 34d ago
13

That's a nasty one. The 'fake update' is a classic lure. For Uniswap specifically, always ensure you are using the official domain: app.uniswap.org. Bookmark it. Never click links from emails, social media, or unsolicited DMs for critical actions like connecting your wallet or approving transactions. Treat your wallet connection like a physical key – only give it to trusted, verified entities directly.

Saoirse Ryan · Dublin, Irelandanswered 34d ago
6

This sounds exactly like the kind of phishing attack that took my friend's funds last month. He got a pop-up in his browser that looked like a MetaMask warning, telling him to click a link to secure his wallet. He did, and his entire ETH balance vanished. He was devastated. He did file a report with the FBI IC3, but as everyone says, recovery is rare. It really hammered home how important it is to be vigilant.

Saar Mulder · Utrecht, Netherlandsanswered 34d ago
4

Oh no, that's awful. I've heard stories like this. It's the worst feeling, isn't it? You work hard for that money and then it's just... gone. My uncle lost money on a bad crypto investment, not exactly a scam, but still a huge loss. He just had to accept it and start saving again slowly. It's a tough crypto world out there.

Ryan Rodriguez · San Antonio, USAanswered 34d ago
10

This is precisely why I stick to the official app and never click email links. My mate almost fell for a fake Kraken support scam where someone messaged him on Telegram pretending to be support. They asked for his login details to 'fix' an issue. Thankfully, I convinced him it was fake before he sent anything. Never give out your private info or login details, especially through unsolicited messages.

Thomas Thompson · Melbourne, Australiaanswered 34d ago
8

This is rough, mate. I had a similar experience with a fake 'Ledger Live' update link I got via email after buying a hardware wallet. Clicked it, installed what looked like the right app from the link, and it just sat there. Didn't drain anything immediately, but later I noticed my small ETH holdings were gone. About $1000 AUD. The email looked so convincing, even had a fake tracking number for my new Ledger. It's a jungle out there.

Lotte Smit · Breda, Netherlandsanswered 34d ago
5

I'm so sorry to hear about your loss. It's a terrible situation. It's easy to feel stupid, but these scammers are incredibly skilled at what they do. They exploit our trust and our desire to keep our assets safe. Just remember that this is a learning experience, albeit a very expensive one. You're not alone in experiencing something like this.

Mia Simon · Toulouse, Franceanswered 34d ago
12

Ugh, that sounds absolutely brutal. That Uniswap/MetaMask update scam is unfortunately super common. They craft those phishing pages to look *identical* to the real thing. When you 'reconnected,' it wasn't to Uniswap's official site but to a malicious smart contract that just drained your wallet. Sadly, direct recovery of funds once they've left your MetaMask on the blockchain is exceptionally difficult, bordering on impossible for most users. The money is likely already through multiple mixers or onto an exchange where it's being laundered. Your best bet is reporting it to the FBI IC3, even if you don't expect direct recovery. It helps build cases.

Sarah Moore · Portland, USAanswered 34d ago
9

Oh no. This happened to me too, about a year ago. Felt like the world ended. Lost about 5k SGD. The feeling of helplessness is the worst, right? I just stared at the screen for hours. What I learned the hard way is to *never* click links from emails for crypto stuff. Always go directly to the source. I ended up having to rebuild from scratch. I did report it to ChainAbuse, they have a database of known scams. Maybe it helps someone else avoid this.

Hui Koh · Singapore, Singaporeanswered 34d ago
3

Eight grand? Blimey. Honestly, I'm not sure what you expect to happen. Once it's gone from MetaMask, it's gone. The blockchain is transparent but not reversible. You clicked a link, gave permission, they took it. It's not a bank, is it? You can report it, sure, but don't hold your breath for any of that money coming back. Lesson learned, I suppose. Always double-check URLs.

Oliver Davies · Sheffield, United Kingdomanswered 34d ago
7

THIS IS EXACTLY the type of scam I warn my friends about. That 'critical update' or 'security alert' is a classic bait. They prey on our fear of losing our crypto. Never, EVER, click links from emails or DMs for wallet actions. Always go to the official website yourself. Bookmark it. Use that bookmark. Don't trust anything that pressures you to act fast. I saw a similar one targeting Trust Wallet users last week.

Ava Tremblay · Victoria, Canadaanswered 34d ago
10

I'm so sorry this happened to you. I'm in a similar boat, though not as much money. Lost about $1500 last month to a fake NFT marketplace link. I keep checking my bank app like a maniac, hoping some miracle happens. The support from MetaMask was useless for me too, just an automated response. I'm going to try filing a report with the FBI IC3, but honestly, I don't have much hope. Just feel sick about it, especially since it was money I saved up for a down payment.

Brandon Walker · San Diego, USAanswered 34d ago
6

Watch out for these phishing links, everyone! They are getting incredibly sophisticated. The email looked real, the website looked real, but it was a trap. The key red flag is being asked to 'reconnect' your wallet to perform an 'update.' Legitimate protocols don't usually ask for this via an email link. You should always navigate directly to the official site and check for updates or announcements there. Reporting it is good, but prevention is better.

Lea Leroy · Montpellier, Franceanswered 34d ago
2

Eight thousand dollars? You're joking. How can you be so careless? People fall for this all the time. The blockchain is public, mate. If you give away your keys or sign a malicious transaction, it's on you. MetaMask and Uniswap aren't liable for your mistakes. Reporting it to the FBI is probably a waste of time. Just chalk it up to a very expensive lesson. What platform do you even use for trading? Binance?

Hassan Al Marri · Ras Al Khaimah, UAEanswered 34d ago
8

Hey, don't beat yourself up too much. This stuff happens to the best of us. It sounds like a really convincing phishing attack. While getting the funds back is unlikely, your experience is valuable for others. It's good you reported it to MetaMask, even if it was automated. Maybe share the details of the fake link (without clicking it again!) on forums like this or even ChainAbuse. Every little bit helps warn the community.

Joshua Teo · Singapore, Singaporeanswered 34d ago
11

This is a brutal lesson in operational security for crypto. That 'reconnect wallet' prompt is a massive red flag. Legitimate dApps might ask you to connect, but asking to *reconnect* specifically to apply an 'update' via a link is highly suspect. Always verify the URL manually. Don't trust email links for financial actions. Consider using a hardware wallet for significant holdings; it adds a crucial layer of security that requires physical confirmation for transactions, making it much harder for remote attacks like this to succeed.

Sophia Anderson · Vancouver, Canadaanswered 34d ago
5

Oh honey, I'm so sorry that happened to you. It sounds horrific. I lost a few hundred pounds on a fake NFT giveaway last year and was devastated. The feeling of being violated and stupid is awful. You did the right thing by reporting it, even if it felt like nothing. We all make mistakes, especially when these scammers are so clever. Just try and be kind to yourself. Maybe take a break from crypto for a bit?

Emma O'Brien · Belfast, Irelandanswered 34d ago
10

Yeah, that's a classic 'gas scam' variant, but instead of just draining gas, they drain the underlying assets. The key takeaway here for everyone is vigilance. Never trust a link, especially when it comes to wallet actions. Always type the URL yourself or use a trusted bookmark. For things like MetaMask, you should be interacting directly with the extension, not usually through a web link for 'updates.' Checking transaction details on Etherscan *before* approving anything, if possible, is also key.

Xin Wong · Singapore, Singaporeanswered 34d ago
3

Sounds like you got hit by a malicious contract approval. The link probably took you to a site that looked like Uniswap or MetaMask, and when you 'reconnected,' you signed a transaction that gave their contract permission to transfer your tokens. Recovering funds once they're moved off-chain or through mixers is almost impossible. Did you get any transaction ID from MetaMask support? Sometimes those can help track things, but honestly, don't expect much.

Hao Lee · Singapore, Singaporeanswered 34d ago
8

Oh no, that's awful! I had a scare with a dodgy link once, thankfully I caught it before approving anything. My spouse actually saw me almost click it and yelled 'Wait — is that legit?!' which made me stop and think. The advice here is solid: never click email links for crypto. Always go direct. I've bookmarked the main sites I use, like Kraken and Binance, and I only ever use those bookmarks. It's a small step, but it feels safer.

Julia Visser · Tilburg, Netherlandsanswered 34d ago
4

Right, so they tricked you into signing a transaction. It happens. That email was a fake. The link led to a fake website that mimicked the real one. When you connected your wallet and authorized the 'update,' you actually authorized a transfer to their address. It's like giving someone your keys and PIN. They can't just reverse it. You could report it to Chainalysis, maybe they can track the funds if they hit a regulated exchange, but don't get your hopes up.

Sophie Meyer · Berlin, Germanyanswered 34d ago
6

That's rough, mate. Those phishing emails are getting scarily good. I got one that looked like it was from my bank, ING, trying to get me to log in. Dodgy links like that are the absolute worst. You reported it, which is good. Did you check if the transactions were to a known scam address on Etherscan? Sometimes you can see if funds get mixed or sent to places like Binance, but recovery is another story entirely. You're not stupid, you were targeted.

Anna van Dijk · Nijmegen, Netherlandsanswered 34d ago

Your answer

You'll be asked to sign in to post.