You still have access to your wallet. The seed phrase works, the app opens, your tokens are displayed. And yet: Every time money arrives, it disappears again after a few seconds.
Many victims mistake this for a wallet software error or an ongoing network attack. Neither is usually the case. What's happening here is a sweeper bot: an automated script that monitors your address around the clock and immediately forwards every attempt to an address belonging to the attacker.
The bad news lies in the prerequisite. For a cyberattack sweeper to work at all, the attacker must know your private key or seed phrase. The actual incident, therefore, occurred weeks ago. This article explains the technical details of how this works, how to recognize it, what you should absolutely avoid, and what to make of promises of recovery.
What a sweeper bot is and what it is not.
A sweeper bot is not software installed on your phone or wallet. It runs on a server belonging to the perpetrator. Therefore, there is nothing to delete, uninstall, or clean on your device that would resolve the problem.
The bot only needs two things: a key to sign on your behalf and a connection to the blockchain. Everything else is automation.
It's also important to distinguish between different types of attacks: not every loss constitutes a sweeper attack. If you lose individual tokens or NFTs while your Bitcoin or Ethereum remains untouched, the perpetrator likely doesn't have a key, but rather an authorization that you yourself confirmed at some point. Our article on [topic missing in original text] describes in detail how such an attack unfolds, from authorization and disguised signatures to extensive account permissions. Wallet Drainer.
The difference is crucial because it determines your options. You can revoke a permission granted. You cannot revoke a compromised key.
Your seed phrase is not a password that can be changed. All the keys for your wallet are permanently calculated from it. Anyone who knows it can restore all associated addresses at any time, regardless of the app used. Reinstalling the app, changing your device password, or switching wallets won't change this.
Incidentally, "sweeping" as a method is not automatically criminal. Exchanges and payment service providers routinely and automatically transfer their deposit addresses to pooled wallets. It only becomes criminal when someone uses your private key.
How the seed phrase or private key were even compromised
Before we discuss the bot, this question must be answered, as it determines everything else. Typical ways in which seed phrases or private keys can fall into the wrong hands:
- Phishing sites that ask for the seed phrase for "verification" or "recovery".
- manipulated wallet apps and fake browser extensions
- Malware on the computer that specifically searches for wallet data
- unencrypted cloud backups, screenshots or photos of the seed phrase
- Fake manufacturer emails and alleged support that wants to "help".
- Social engineering via Telegram, WhatsApp or Discord
The answer to this question is not a trivial matter. It determines whether your address can still be saved or must be permanently abandoned.
This is how a sweeper bot works technically.
Your address is being constantly monitored.
Blockchains are public. Anyone can monitor any address, and modern interfaces allow this to happen practically in real time. The bot often detects an incoming transaction even before your own wallet app displays the change.
With Bitcoin and similar networks, it doesn't just monitor the one address you know, but all addresses that can be derived from your seed phrase. Therefore, generating a new receiving address in the same wallet won't help.
One point surprises many: The bot doesn't have to strike from the very first cent. Many scripts only react once the amount reaches a point where the transfer is worthwhile after deducting network fees. A compromised wallet can therefore appear perfectly normal for a long time.
Why you practically always lose the race
The bot has its transaction already prepared and sends it with high priority the moment it is received. In addition, there is a technical factor that is often overlooked in guides: you and the perpetrator are sending from the same address. However, on Ethereum and similar networks, only one transaction per address and meter reading can be recorded on the blockchain.
So, if you deposit ETH to secure your tokens, both transactions will compete for the same slot. The bot automatically adjusts its fee and is ready to go instantly. Once one of the two transactions is confirmed, the other can no longer be executed normally. Manually outbidding via the wallet interface is therefore not a realistic option.
Solana's approach is different. There, a different address can pay the fee than the one from which the funds are withdrawn. In this case, a recovery does not require a deposit to the compromised address.
The gas trap: the most expensive pattern for victims
This mechanism creates a cycle that systematically harms those affected: gas is deposited, gas is withdrawn, gas is deposited again, and there is another loss.
The perpetrator deliberately leaves valuable tokens or NFTs untouched because transferring them incurs fees the wallet doesn't have. They simply wait until you pre-finance these fees. In particularly cynical variations, wallets are intentionally filled with seemingly valuable tokens, and the seed phrase is then deliberately leaked so that strangers pay upfront. The fact that such tokens often have no value at all is part of the scheme.
How to recognize a Sweeper Bot
A single, rapid transfer proves nothing. Only the combination of several characteristics makes the picture clear:
- Always the same delay. The time between inflow and outflow is consistently only a few seconds. What's striking is not so much the speed, but the regularity.
- Always the same destination address. All outflows go to the same or to a small, stable group of addresses.
- Mathematically, it's zero. The amount transferred is exactly the available balance minus the network fee. People transfer rounded amounts.
- Only certain values disappear. Native coins sell, tokens and NFTs remain untouched, see gas trap.
- No day-night rhythm. The email address responds just as reliably at night, on Sundays, and on public holidays. People don't.
- Unusually high fees. Significantly above average, partly automatically adjusted.
- It doesn't stop. Even weeks or months later, the address continues to respond unchanged to every deposit.
- Not for normal use. Between the drains there are no swaps, no app usage, nothing to indicate the presence of a human.
The opposite is true if your ETH remains untouched and individual tokens or NFTs are missing. In that case, you should check..., why only certain values often disappear with a drainer, because in this case your key may not be affected at all.
Saving coins despite a sweeper bot: what else is possible
Sometimes, yes. But only with a single, carefully prepared attempt, never through repeated trials.
On Ethereum and similar networks, the established approach involves combining fee payments and rescue transfers into a single, inseparable package and sending it directly to the block-building entity. The bot doesn't see the gas deposit in advance; both transactions end up in the same block, eliminating any time window. This is technically challenging, not possible on all networks, and not guaranteed.
With Solana, you can move funds out via a separate paying address in a single transaction without having to deposit into the compromised address.
Bitcoin and other UTXO networks don't have this gas problem in the same way; incoming funds can be passed on directly. However, with actively monitored addresses, it remains difficult because both sides are competing for the same amount. You should immediately switch all future payments to a new, unencumbered address.
Assets tied up in staking, liquidity pools, or vesting require individual review. If the payout can be sent directly to a freely chosen address, that's preferable to going through the compromised wallet.
What you should absolutely not do after a Sweeper incident
- No further test or back payments to the address in question.
- Do not use the address as a payment address for any further purpose, not even "just briefly".„
- Do not enter the seed phrase again anywhere, especially not on alleged recovery pages.
- Do not install any unknown "rescue software" or "anti-sweeper tools".
- Avoid contact with self-proclaimed recovery agents via social media, Telegram, or comment sections.
The last point is the most important. A second wave of fraud regularly follows a cryptocurrency theft. Alleged recovery services, fake government profiles, and manipulated "recovery dashboards" target precisely the situation where you are willing to take another risk.
Remember this: No reputable investigator, support staff, or service provider will ever need your seed phrase or private key. We also never contact victims proactively.
Securing evidence after crypto theft: these are the documents you need
Before you do anything to the device or wallet, make sure you have the following points checked:
- complete transaction history of the affected address
- all transaction hashes with time and amount
- Screenshots with a recognizable date
- which wallet software in which version was in use
- which browser extensions are installed
- As far as can be determined: when and where you entered the seed phrase.
Don't erase the device prematurely. Finding malware can help trace the source of the theft and is important for filing a police report and obtaining insurance. However, this doesn't mean you should continue using it: A potentially compromised device is off-limits for wallets, banking, and email until it has been professionally examined. You can read about the types of evidence that ultimately count at [link to relevant information]. Evidence in cases of crypto fraud.
Then file a criminal complaint. We'll show you how to do this below. Report crypto fraud.
A piece of information that surprises many: Anyone who forwards payments or makes their account available after the incident could themselves become a target of the authorities. We describe what happens then below. Account blocked due to suspected money laundering.
What blockchain analysis can and cannot do
An analysis cannot recover anything, and we want to make that very clear. What it can do is reconstruct the path: from your wallet via the sweeper address to pooled wallets, then via intermediate stations, bridges or mixers, to a payout point.
This is precisely where the real point of intervention lies. If the funds reach a regulated exchange with identity verification, there is a real entity to which authorities can address requests for information and security. In the case of stablecoins, a block by the issuer is also a possibility; see [link/reference]. Freeze USDT and USDC.
Ironically, automation is advantageous from a forensic perspective: it creates regularity, and regularity can be proven. Consistent response times, stable target addresses, balances reduced to zero, and the absence of a daily rhythm create a pattern that can be traced through the public transaction history. We describe what is and isn't possible in more detail below. Recover cryptocurrencies and asset recovery.
Whether values are ultimately secured is not decided by us, but by the participating stock exchanges, the authorities, and, if necessary, a court.
Here's how to protect yourself in the future
- Store the seed phrase offline only, never as a photo, screenshot, cloud note, or text file.
- Hardware wallet for larger holdings and actually reading the contents on the device display
- Separate wallets: one for long-term storage, another for anything experimental.
- Regularly review and revoke permissions; avoid unlimited permissions.
- Never confirm anything you don't understand, and always check the origin of links and extensions.
Separating accounts by purpose is the single most effective measure of all: An address that constantly interacts with new applications should never also be your savings account.
Conclusion: The bot is the consequence, not the cause.
A sweeper bot isn't some exotic attack tool, but rather the logical automation of damage that has already occurred. The problem doesn't begin with the script, but with the loss of control over your login credentials. And it doesn't end with the first data breach, because the attacker can maintain control indefinitely.
This results in a clear sequence for you: first clarify what actually happened, then secure evidence, then act. Not the other way around. And the affected address cannot be repaired, but must be abandoned.
If you are unsure how your case should be classified, use our Free initial assessment for crypto fraud or Contact us directly.
FAQs about the Sweeper Bot
Is it possible to remove a Sweeper Bot?
No. There is nothing to remove from your wallet; the script is running on the attacker's device. The cause is not software on your device, but rather knowledge of your key material.
Is my wallet secure again after a reinstallation?
No. A new app, a new password, or a different wallet does not change the fact that the same keys can always be derived from a known seed phrase.
Why does every deposit disappear immediately?
Because the bot constantly monitors your address and sends a pre-prepared transaction the moment it's received. Trying to counteract this manually is practically impossible.
Why do my tokens remain intact while only ETH disappears?
Because transferring tokens incurs fees that the wallet doesn't have. The perpetrator is waiting for you to pre-finance these fees. That's exactly what the gas trap is.
Can I still save my remaining coins?
Possibly, yes, but only with a one-time, pre-planned transaction and depending on the network. Repeated gas deposits, on the other hand, almost always lead to further losses.
Would it help to use a new receiving address in the same wallet?
No. All addresses in this wallet, including newly generated ones, can be derived from a known seed phrase. You need a completely new wallet with a new seed phrase.
How long will the address remain at risk?
Permanently. As long as the key material is known, the bot will respond to every deposit, even months later. The address is a lost cause, not salvageable.
Is it sufficient to revoke approvals?
Only if exclusively permissions are affected. If your seed phrase or private key is known, a revocation is ineffective. We explain when a revocation is actually sufficient in the article on... Wallet Drainer.
How do I distinguish a sweeper from a wallet drainer?
A drainer requires authorization or a signature from you and only captures what has been authorized. A sweeper, on the other hand, reacts to every incoming payment without any action on your part, always to the same address and always within seconds.
What is the most important first step?
Do not deposit any more money into the affected address, secure all evidence completely and unaltered, do not use the suspicious device for wallet and banking, and then have the cause of the incident professionally investigated.
Note: This article is for general information purposes only and does not replace legal advice in individual cases. Crypto Investigation is a forensic service provider and not a law firm.