← Back to FAQ page

My Phantom wallet was drained on Solana. What information should I collect first?

FAQ | Updated 2026-03-31
Recovering Assets from a Drained Phantom Wallet: The Ultimate Solana Incident Guide

Discovering that your Phantom Wallet has been drained on the Solana (SOL) network is a high-stress emergency. Unlike slower blockchains, Solana’s high-speed infrastructure means assets move in milliseconds. If you are a victim of a wallet drain, your first 30 minutes are critical for a successful recovery audit.

At RefundRequest, we specialize in Solana-based forensics and "Fast Track" processing to help you regain control. Here is the professional data-collection checklist you need to follow right now.


The "Big Three": Information You Must Collect Immediately

To begin a professional recovery audit, our specialists at RefundRequest require specific digital evidence. Collecting this correctly is the difference between a "dead end" and a "smooth resolution."

  • The Transaction Signature (TXID): On Solana, transactions are identified by a long string of characters called a "Signature." Go to the "Activity" tab in Phantom, click the suspicious transaction, and select "View on Solscan." Copy that URL or the Signature hash.
  • The Attacker’s Wallet Address: Identify the "To" address where your SOL, USDC, or NFTs were sent. If the assets were moved multiple times, try to find the very first destination address.
  • The "Permission" History: Did you interact with a new NFT mint, a "free" airdrop, or a decentralized exchange (DEX) right before the drain? Save the URL of the website you visited. This helps us identify if a malicious smart contract still has access to your wallet.

Phase 1: Secure Your Assets (The RefundRequest Quick Start)

Before we can investigate, you must stop the attacker from taking anything else.

  1. Revoke All Approvals: Use a tool like Solana-Revoke or the security settings within Phantom to "Revoke" all active token permissions. This disconnects the hacker’s "spending power."
  2. Move "Dust" and Remaining NFTs: If there are any assets left, move them to a "Cold Wallet" or a brand-new Phantom account created on a completely different device.
  3. Do Not Delete the Wallet: You will need the history and the public key of the drained wallet for official documentation. Keep the app installed, but do not use it for new deposits.

Why Choose RefundRequest for Solana Recovery?

Solana’s ecosystem is unique, and standard recovery methods often fail here. RefundRequest provides a dedicated approach:

  • Around the Clock Support: Our team monitors Solana "off-ramps" 24/7 to see if your stolen assets hit a centralized exchange.
  • NFT Forensics: If your rare NFTs were stolen, we track the metadata to flag them on marketplaces like Magic Eden, preventing the thief from selling them.
  • Detailed Documentation: We present your facts chronologically, building a clear timeline that is essential for a comprehensive security review.

Stop the Hacker Today

Timing is everything on the Solana network. The faster you provide your RefundRequest specialist with the transaction trails, the faster we can move toward a resolution.

Contact Our Official Support Team for a Professional Audit:

RefundRequest: Your Fast and Secure Partner in Multi-Chain Account Recovery.

Request an initial assessment