You did the first 24 hours right. You triaged the intrusion, secured what was left, and screenshotted everything. Now there is one document standing between this theft and every legal mechanism that could ever touch the stolen funds: the report.

This is the reporting deep dive promised in our first-24-hours runbook. That article told you to report within day one; this one walks through how — what the IC3 form actually asks for, what an exchange freeze request needs to contain, which channels exist outside the US, and what happens in the weeks after you hit submit. It is written for the person whose hands are still shaking, and for the calmer reader preparing in advance.

One framing before the mechanics: reporting crypto crime feels pointless to victims because the blockchain is irreversible. But nobody freezes an exchange account, seizes a hardware wallet at a border, or forfeits funds to victims without a case number — and case numbers only exist because someone filed. Every public recovery in the record — Colonial Pipeline, KuCoin, Bitfinex — started as a stack of complaints. Your report is not a message in a bottle. It is an input to the only machine that has ever returned stolen crypto at scale.

What a report actually does

Before the field-by-field walkthrough, understand the machine you are feeding, because it explains every “weird” part of the process — the silence, the aggregation, the months of nothing.

It creates the legal predicate. An exchange cannot lawfully freeze a customer’s funds because a stranger emailed claiming theft. It can freeze in response to a law enforcement request — and law enforcement issues that request only inside an open case. The case opens with your complaint. No report, no freeze, no seizure, no forfeiture. This is why the report is not optional paperwork: it is the on-ramp for everything downstream.

It feeds aggregation. Cybercrime units do not work one $4,000 theft. They work patterns: the same wallet drainer infrastructure, the same deposit addresses, the same phishing kit. Your complaint contains hashes and addresses that match those patterns — investigators join them into aggregate cases that can represent tens of millions of dollars. This is also why precise data matters more than emotional narrative: the matching is done on transaction hashes and addresses, not on how you felt.

It starts the clock on freezes. Stolen funds typically move from the drainer wallet through hops into an exchange deposit address within hours to days — that is where they can be stopped, because that is where identity (KYC) exists. The faster your report exists, the higher the chance funds are still sitting in an identifiable place when someone looks. Chainalysis tracked over $2.2 billion stolen across 303 incidents in 2024 alone; the cases that got worked are the ones where funds were still traceable to an exit when the request landed.

It produces the paper you need regardless. Insurance claims, tax-loss documentation in jurisdictions that allow theft deductions, exchange disputes, civil suits — all of them want one thing first: proof you reported the crime to authorities. The complaint ID you receive on filing is that proof.

Step 1 — Assemble the evidence package (before any form)

Every reporting channel, from IC3 to your local police station, consumes the same inputs. Build this once, in a text file, and you can paste it everywhere. From our experience reading what victims send, reports fail on missing data far more often than on weak narratives.

The package:

  • Transaction hashes — every on-chain movement related to the theft, yours and the thief’s. Start from the malicious transaction (the one that drained you) and follow outbound hops on a block explorer until funds enter a labeled address (exchange, bridge, mixer). Copy full hashes, not truncated ones.
  • Wallet addresses — your drained address, the receiving address, every hop address you recorded, and if you found one, the labeled exchange deposit address at the end of the trail.
  • Timestamps in UTC — when you signed the malicious approval or sent the funds, when you noticed. UTC because investigators and exchanges run on it; convert your local time once, carefully.
  • Amounts — in the original asset (e.g., 1.4 ETH) and the USD value at time of theft.
  • The attack surface — the phishing URL you visited, the fake airdrop domain, the Telegram handle, the Discord server invite, the NFT you were tricked into listing. If it was an approval phishing attack, say which token and which contract you signed.
  • Communications — chat logs with the scammer, screenshots with visible usernames and dates, emails. Export rather than screenshot where possible.
  • Your side — the wallet you used, how you accessed it, when you created it, whether it is custodial or self-custodied.

If the compromise was a malicious token approval rather than a seed-phrase leak, our infinite approval explainer helps you describe the mechanism precisely in the narrative — “I signed an unlimited ERC-20 approval to contract 0x…” reads very differently to an investigator than “my tokens vanished.”

Not sure how to trace the hops yourself? Our tracking guide walks through following stolen funds on public block explorers — you do not need forensic tools to produce the first three hops, and those hops are often where the labeled exchange address appears.

Step 2 — File the IC3 complaint (US), field by field

The FBI’s Internet Crime Complaint Center at ic3.gov is the US intake for cybercrime, including crypto theft, regardless of the victim’s or thief’s location when funds touch US exchanges. Filing takes 20–40 minutes if your evidence package is ready. What the form asks for, and how to answer it well:

Victim information. Name, address, phone, email. Use the contact details you will still have in six months — cases surface late. If you are filing on behalf of someone else (an elderly parent, for example), there is a pathway for that; answer as the filer and identify the victim in the narrative.

Incident information. Date and time range — give the precise UTC window from your package, not “last month.” Category: select the cryptocurrency fraud/theft option (the form’s category list evolves; pick the closest crypto-related option). The platform or venue: the phishing site, the fake exchange, the Telegram contact — whatever the attack surface was.

Financial details. Amount lost (use the USD figure from your package), the payment/transfer method (on-chain transfer from a self-custody wallet, withdrawal from exchange X, etc.), and any financial institutions involved — including the exchange where stolen funds landed, if you identified one. This field is what lets IC3’s Recovery Asset Team coordinate with institutions; the team exists to help freeze funds that pass through reachable intermediaries, and it cannot act on an entry that names no institution.

Narrative. Chronological, factual, dense with the identifiers from your package. A working skeleton:

On [UTC date], I visited [URL], which presented itself as [what it claimed]. I connected wallet [address] and signed [what was signed]. At [UTC time], transaction [hash] moved [amount] to [address]. Funds then moved via [hashes] to [addresses]. The final destination I identified is [address], labeled on [explorer] as a deposit address for [exchange]. I have chat logs and screenshots. Total loss: [amount] (USD [value] at time of theft). Local police report filed: [number] or “not yet filed.”

Paste, do not paraphrase. A narrative full of exact hashes is machine-matchable against other complaints — that is the aggregation layer working for you.

After you submit. You get a complaint ID on screen and by email. Save it. That ID goes into your exchange freeze requests, your insurance claim, and any follow-up correspondence. Do not expect a call next week; IC3 refers complaints to field offices and task forces based on patterns and thresholds, and most communicants hear nothing for a long time. That is the system, not a brush-off.

Step 3 — Exchange freeze requests in parallel

Law enforcement timelines run in months. Exchange risk desks can act in hours — but only on specifics, and only within what the law lets them do. You are not asking the exchange to give you money back; you are asking it to flag the deposit address, restrict the receiving account, and preserve its KYC and transaction records for the investigation your report opened.

Finding the address to send it to: every major exchange publishes an abuse or fraud channel — Binance’s published fraud-reporting address is reports@binance.com; Coinbase and Kraken route fraud reports through their security report forms; for others, search “[exchange name] report fraud” and use the official domain only. Phishing sites impersonate exchange security teams too, so type the domain yourself.

A freeze request that gets read:

Subject: Freeze request — suspected stolen funds deposited to [exchange] — [amount] — case reported to IC3 #[ID]

To the [exchange] security team:

I am reporting the deposit of stolen cryptocurrency to [exchange], connected to my report to the FBI IC3 (complaint #[ID]) and [local police report #, if filed].

— Theft transaction: [hash], [UTC time], [amount] moved from my address [address] to [address] — Subsequent hops: [hash], [hash] — Deposit address on [exchange] that received funds: [address] (labeled on [explorer]) — Total: [amount], approximately USD [value] at time of theft — Attack vector: [phishing URL / fake airdrop / contract approval / account takeover]

I request that you flag the deposit address, review the receiving account, and preserve relevant KYC and transaction records for law enforcement. I can provide full transaction exports and correspondence on request.

[Name, contact, complaint IDs]

Why include the IC3 ID even though the exchange cannot see the FBI’s file: it signals that a legal process exists, which changes how a risk desk treats the request. An unverifiable email claiming theft is one thing; a claim cross-referenced to a federal complaint number and a police report is another.

Two honesty notes. First, exchanges freeze; they do not refund — funds return to victims only through the legal process (seizure and forfeiture), which your report started and which takes time. Second, if the funds already passed through a mixer before reaching the exchange, the trail may be severed — say so plainly in your report rather than guessing; investigators respect “trail ends here” far more than a wrong attribution. And if someone has already messaged you offering to “handle the exchange freeze” for a fee, that is the second wave: our recovery scams explainer covers exactly how that industry hunts people who have just filed public complaints.

Step 4 — Report the attack infrastructure

Separate from the money, report the weapons. The phishing domain can be taken down at the registrar or host; the fake social account can be suspended; the Telegram bot can be reported in-app. This rarely recovers anything for you personally — do it anyway:

  • Phishing sites: report to the registrar (WHOIS shows it) and to Google Safe Browsing. Takedowns sometimes land within days.
  • Social accounts and Telegram: in-app report for impersonation/fraud. Include the evidence screenshots.
  • Malicious contracts and drainer infrastructure: chainside analytics firms and some exchanges accept infrastructure reports; the contract addresses in your package are exactly what they consume.

The reason is strategic: every takedown shortens the attack’s life for the next victim, and takedown records occasionally surface later as corroborating evidence in the aggregate case that includes yours. Reporting infrastructure is how your worst day becomes someone else’s avoided one.

Not in the US? Your equivalents

The same evidence package works everywhere; only the intake differs:

  • United Kingdom — Action Fraud (actionfraud.police.uk) is the national fraud reporting channel; crypto fraud goes through it.
  • Hong Kong — the Police Anti-Deception Coordination Centre runs the 18222 hotline; deception cases including crypto route there and to any police station report.
  • Singapore — file a police report (online or at a station) and report via ScamShield; crypto scams are a standing priority.
  • Australia — ReportCyber is the joint federal/state cybercrime reporting portal.
  • EU — most member states have a national cybercrime unit; your local police station is always a valid first entry point.

Two rules of thumb across jurisdictions. First, if the funds landed at a US-headquartered exchange, also file with IC3 — the freeze request ultimately lands at the exchange, and US process reaches US exchanges. Second, your local police may have never worked a crypto case; that is fine and not disqualifying. File anyway, get the report number, and attach the same package — national units pull case files upward, and your hashes are what make the file pullable. Our first-24-hours runbook covers assembling this package under pressure.

Why reports fail: the five classics

From reading victim threads and law enforcement guidance, reports die for predictable reasons:

  1. No transaction hash. “I lost 2 ETH on a scam site” is unmatchable. The hash is the fingerprint that joins your complaint to everyone else’s.
  2. Local-time timestamps. An investigator or analyst correlating transactions runs on UTC; a “3 PM” that is actually three timezones off makes your narrative contradict the chain, and contradictions slow triage.
  3. The essay instead of the timeline. Emotional context is human and understandable — put it after the facts, not instead of them. The first screen of your narrative should read like a log, not a letter.
  4. Public posting instead of reporting. Posting your full case on social media is not reporting — it is briefing the scammer and the recovery-scammers who watch those threads on everything you know. Report to institutions; tell the story to people who already know you.
  5. Waiting for a “better” report. Victims delay filing until they have traced every hop or understood every detail. File now with what you have; the complaint can be supplemented later, and the clock on freezes does not wait.

What to expect after filing

Set expectations honestly, because mismatched expectations cause victims to disengage from the one process that works:

Silence is normal. You may hear nothing for weeks or months. Complaints are triaged and aggregated; when your hashes match an active investigation, things can move suddenly — a call from a field office, a letter, a notice years later about a forfeiture fund. The 2016 Bitfinex recoveries surfaced in 2022; Colonial Pipeline’s funds were partially recovered within months because a single hop reached a reachable exchange fast. Both extremes exist.

You will not get a personal detective. The unit that eventually touches your case may be working a hundred like it. Your job after filing is responsiveness: answer contacts promptly, keep your evidence intact, do not spam the complaint portal with daily updates.

Recovery, if it comes, comes through process. Seized funds are forfeited through courts, and distribution to victims follows the forfeiture — often years out, sometimes pennies on the dollar, occasionally whole. The realistic function of your report is to maximize the probability of being inside that process when it exists, at the cost of a few hours now.

The second wave is coming regardless. Filing a public complaint or posting about your theft marks you as a fresh victim to recovery scammers. Anyone who contacts you promising action on your case for an upfront fee is running the exact playbook in our recovery scams explainer — and if their “proof” is a wallet screenshot from a block explorer, remember that anyone can paste your stolen address into Etherscan; reading the chain aloud is not tracing.

Where this fits in the series

This is the second piece of our victim-journey track: the first-24-hours runbook handles the emergency day; this article handles reporting; how stolen crypto is actually recovered walks the real freeze-and-forfeiture pipeline with cases; and crypto recovery scams explained arms you against the predators who arrive in week one. If your loss began with an airdrop claim or a snapshot verification site, our airdrop snapshot verification scams teardown covers that vector’s specifics — and if the scam you fell for involved inflated NFT volumes as social proof, how to detect NFT wash trading shows the on-chain tells. For checking whether an address that contacted you has priors, start with wallet labels — labeled addresses are the cheapest intelligence a victim can get.

This article is general information about reporting processes, not legal advice. Jurisdictions differ in reporting channels, deadlines, and what evidence is admissible; if the amount is significant, consulting a lawyer familiar with virtual asset cases in your jurisdiction alongside your police report is reasonable. Nothing here promises recovery — the honest base rate for individual small thefts is low. What reporting reliably does is put your case inside every mechanism that has ever returned stolen crypto, at the cost of an afternoon.

Frequently Asked Questions

How do I report a crypto scam in the US?

File a complaint with the FBI's Internet Crime Complaint Center at ic3.gov. Choose the cryptocurrency category, enter the exact transaction hashes, wallet addresses, UTC timestamps, and dollar amounts, and write a chronological narrative. You receive a complaint ID immediately — keep it, because it is what you cite in exchange freeze requests and any follow-up. In parallel, report to the exchange where the stolen funds landed; the exchange can flag or freeze a deposit address faster than any law enforcement timeline.

Is it worth reporting a small amount of stolen crypto?

Yes. Law enforcement aggregates complaints: five reports describing the same deposit address can turn 'one small theft' into a pattern investigation, and pattern cases are what get worked. The report also creates the paper trail you need for insurance, tax-loss documentation, and exchange disputes. The honest caveat: small amounts rarely get individually recovered — the report is a lottery ticket into aggregate cases, not a refund request.

How long does an IC3 crypto case take?

Weeks to months before any visible movement, and some cases surface years later when an aggregate investigation is unsealed. IC3 complaints are triaged, aggregated with related complaints, and referred to field offices or task forces — you will not get a personal detective or status updates. File the report, send the exchange freeze request, and then get on with securing what remains; waiting by the inbox is not part of the process.

I'm not in the US. Where do I report?

Your national cybercrime or fraud channel — Action Fraud in the UK, the Anti-Deception Coordination Centre (18222) in Hong Kong, ScamShield or a police report in Singapore, ReportCyber in Australia, your national cybercrime unit elsewhere in the EU. If the funds moved through a US-headquartered exchange (Coinbase, Kraken), also file with IC3 — the freeze request ultimately lands at the exchange, and US process can reach US exchanges.

Do exchanges actually freeze stolen crypto after a report?

Sometimes, and fastest when the request is precise. Exchanges can flag a deposit address, restrict an account holding suspected stolen funds, and preserve KYC records for law enforcement — but they act on specifics: transaction hashes, the deposit address, timestamps, and a case number. A freeze request that says 'my crypto was stolen please freeze it' gets nothing. Note that exchanges freeze; they do not return funds to you directly — return requires the legal process that your police report started.