What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
If you see an exchange sign-in, withdrawal, wallet transaction, or token approval you did not authorize, treat it as a warning and check it promptly. Exchange accounts and self-custody wallets need different checks: exchanges may be able to lock account activity, while confirmed blockchain transfers generally cannot be reversed. Start with the relevant checklist below, then secure the account or wallet before investigating further.
First, identify what kind of account you use
| Account type | Evidence to check | Immediate containment | What may be reversible |
|---|---|---|---|
| Centralized exchange account | Sign-ins, devices, sessions, withdrawal addresses, orders, API keys, connected apps, and security changes | Use the exchange’s official lock or freeze controls if available, and contact official support | The provider may be able to restrict account activity or investigate a receiving account, but recovery is not guaranteed |
| Self-custody wallet | On-chain transactions, destinations, dapps or contracts, token approvals, and whether a recovery phrase or private key was exposed | If its secret was exposed, create a new wallet with a new phrase on a trusted device and move remaining assets; revoke suspicious approvals where possible | Confirmed on-chain transfers generally cannot be reversed |
A wallet app may show both self-custody activity and connections to third-party services. Determine whether you are reviewing exchange-held funds or assets controlled by a wallet phrase before taking action.
How to check an exchange account
- Open the exchange through its official app or a URL you saved independently. Do not use a link in an unexpected email, text, social post, or search ad.
- Review recent activity, sign-ins, active sessions, recognized devices, and security notifications. Remove sessions or devices you do not recognize. Coinbase says its account activity tools show active sessions and authorized devices, and advises removing unfamiliar access (Coinbase account compromise guidance).
- Check withdrawals, new or changed withdrawal addresses, trades or orders, security-setting changes, connected applications, and API keys. An API key’s capabilities depend on its permissions; remove unknown keys and contact the exchange if activity looks unfamiliar. Kraken recommends removing API keys during a compromise response (Kraken compromised-account guidance).
- Compare unfamiliar sign-in locations and IP addresses with your own travel, VPN, mobile network, and browsing. A location mismatch by itself does not prove an intruder accessed the account.
- Check the linked email account too: inspect forwarding rules, recovery email addresses and phone numbers, and logged-in devices. An attacker with access to email may be able to reset or approve exchange access (Coinbase account compromise guidance).
How to check a self-custody wallet
- Compare the wallet’s activity with transactions you remember making, such as a swap, deposit, contract interaction, or network-fee payment.
- For each transaction you cannot explain, inspect its time, recipient address, dapp or contract, and amount. Use the wallet’s activity view and a block explorer for the relevant network. MetaMask recommends checking transaction details in a block explorer (MetaMask transaction investigation guidance).
- Review connected dapps and token approvals. Connecting a site can reveal your public address; signing an approval can give a contract continuing permission to move particular tokens. Review and revoke approvals you do not recognize using the wallet or a trusted chain-specific approval tool (Ethereum.org guide to revoking token access).
- Do not interact with links in unfamiliar NFTs or tokens, or sign a transaction you do not understand. An unexplained approval is a risk even if no suspicious transfer has happened yet.
A successful transaction you did not authorize is a serious warning, but public blockchain data does not prove who controlled an address or whether a particular person authorized an action.
What to do if you find suspicious activity
If an exchange account may still be under someone else’s control
- Use the exchange’s official lock or freeze option if it offers one, then contact official support or its security team promptly. Coinbase says Security Lock signs out all devices and pauses trading, transfers, and account changes while allowing activity review and support contact (Coinbase Security Lock). Controls vary by exchange and region.
- Change the exchange password and the linked email password to unique passwords. Secure email recovery methods and enable strong two-factor authentication; reset sign-in 2FA where appropriate.
- End unfamiliar sessions, remove unknown apps and API keys, and inspect or remove suspicious withdrawal addresses. Kraken’s guidance includes resetting the password and sign-in 2FA, removing sessions or devices and withdrawal addresses, and removing API keys (Kraken compromised-account guidance).
If a wallet recovery phrase or private key may have been exposed
Treat every wallet derived from that secret as compromised. On a clean, trusted device, create a new wallet with a new recovery phrase and transfer any remaining assets to it. Importing the old phrase onto another device does not make it safe. Revoke suspicious token approvals where possible; revocation cannot retrieve assets already transferred.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Clear out junk files and repair common Windows errors3Fix the driver behind crashes, sound loss and screen glitches#1 Best Overall
If you found a suspicious dapp or approval
Stop using the site, disconnect it from the wallet, and revoke approvals you do not recognize with a trusted tool for the relevant chain. Do not sign further prompts from the site while you investigate.
Secure connected devices and preserve evidence
- Secure the email, cloud, and phone accounts tied to the exchange or wallet. Check email forwarding and recovery settings, update device software, and look for suspicious downloads or remote-access tools. Kraken recommends device scans and email-security measures; Coinbase notes malware can steal credentials and sessions (Kraken compromised-account guidance; Coinbase account compromise guidance).
- Keep transaction hashes, addresses, timestamps, screenshots, relevant URLs, emails, and chat records. Contact the provider through its official support route and consider reporting the incident to local law enforcement or the relevant regulator. Ethereum.org recommends documenting evidence and promptly contacting a centralized exchange if stolen funds appear to have reached it (Ethereum.org guide to revoking token access).
What these checks can and cannot tell you
An unfamiliar login, transaction, or approval is evidence to investigate, not always proof of a specific attacker’s identity. A block explorer records blockchain activity; it does not establish who initiated a transaction or whether it was authorized. For confirmed on-chain transfers, Kraken’s support guidance states: “Onchain transactions cannot be reversed” (Kraken compromised-account guidance). An exchange may sometimes investigate or restrict a receiving account if funds reach its platform, but that is not a guaranteed recovery route (Ethereum.org; Singapore Police cryptocurrency scam advice).
Rank #2
- Ideal for Gifting
- Ideal for a bookworm
- Compact for travelling
Be wary of anyone promising to recover crypto for a fee. Ethereum.org warns that recovery-fee offers are almost certainly a second scam (Ethereum.org). Never provide a seed phrase, private key, password, one-time code, or remote access to someone claiming to be support or a recovery service.
Quick Recap
Best Value
- It can be a gift option
- Comes with secure packaging
- Helpful in various ways
Rank #4
Rank #3
Reduce the chance of another compromise
- Use unique passwords for the exchange and its linked email account; a password manager can help manage them (Coinbase account compromise guidance).
- Consider a FIDO2-compatible hardware security key for sign-in two-factor authentication where the exchange supports it. Kraken recommends a hardware security key as an option for sign-in 2FA (Kraken 2FA guidance). It strengthens sign-in but does not inspect wallet transactions or recover funds.
- Review exchange sessions, withdrawal addresses, connected apps, and API keys periodically; review wallet approvals and dapp connections before signing new requests.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




