~/defi/hacks $ cat chto-delat-derzhatelyu-pri-vzlome.md
The Protocol Has Been Hacked: A Holder's Action Plan for the First 60 Minutes
A breach of the protocol where your money is stored is the moment when panic is most costly. A plan for the first hour.
The First 10 Minutes
- Verify the facts: the protocol’s official channels and 2-3 independent security accounts (PeckShield, SlowMist, and their colleagues-they’re in our chat). Fake “hacks” are a scam genre in and of themselves.
- If confirmed-withdraw immediately; don’t wait for better prices: it’s better to withdraw your deposit at a bad rate than not to withdraw it at all. The withdrawal queue is growing exponentially.
- DO NOT click on “rescue” links: a wave of “claim refund / migrate now” phishing attempts starts within minutes of the incident. Use only official channels, and do it manually.
The First Hour
- Revoke approvals for compromised contracts (using revoke services): some attacks continue to drain wallets using old permissions.
- Review related positions: this protocol’s LST is in collateral, LP pairs with its token, and loans secured by its assets-the infection spreads through these chains.
- Document your transactions (screenshots, hashes): this will be useful for potential compensation.
Next
Decisions on compensation take weeks of governance processes; partial refunds (negotiations with the hacker for a “bounty”) occur regularly. Whether to hold the protocol’s token for the sake of compensation is a separate consideration: more often than not, it’s cheaper to sell. We’re tracking the timeline of incidents and outcomes in this section.