Mindset in the first minutes
When something feels wrong — a signature you regret, a plugin you should not have installed, a seed you pasted into a form — your job is damage control, not self-blame. Panic causes second mistakes: signing “cancel” prompts from the same phishing site, reusing the same seed on a “recovery helper,” or sending more funds to “unlock” a wallet.
Work from a device and browser you still trust when you can. Prefer official wallet UIs opened from bookmarks, not from the tab that attacked you. OptionsMatch remains a research site only; it cannot reverse chain transactions, and it will never ask for your seed to “fix” an account.
Document transaction hashes, domains, and timestamps for your own records and for any venue security contact. Do not post seeds or private keys in tickets, screenshots, or group chats.
If you just signed a bad transaction
Stop signing immediately. Do not approve follow-up “cancel,” “speed up,” or “refund” prompts from the same site. Close the phishing tab. Open your wallet application from a trusted bookmark or installed app icon.
Review recent activity and pending transactions. Revoke token approvals and operator permissions for unknown spenders using a known revoke workflow or the venue’s documented method — not a random “revoke helper” linked from the attacker. Move remaining assets you still control to a new wallet that was never connected to the malicious site.
If funds already left, they are usually unrecoverable on public chains. Preserve tx hashes, report phishing domains to the venue’s security contact when available, and focus on protecting what is left rather than chasing irreversible transfers with more signatures.
If you installed a malicious extension or app
Disconnect network if you need a clean moment to think, then remove the extension or app. From a clean device or at least a clean browser profile, change passwords for email and any exchange accounts that were unlocked in the compromised environment.
Treat every wallet that was unlocked or imported in that browser as compromised for practical purposes. Create new wallets with new seeds on trusted hardware or a clean install. Never reuse the old seed. Sweep remaining balances carefully: confirm destination addresses on-device or via a second channel you trust.
Malicious extensions can persist via clipboard hooks and injected scripts even after you close a tab. Do not consider the incident closed until the extension is gone, passwords are rotated, and hot funds have moved to fresh keys.
Approvals, allowances, and operator roles
Many drains start with an unlimited token allowance or a contract operator role rather than an immediate full-balance transfer. After any suspicious connect, inventory approvals for the addresses you use with on-chain options venues. Revoke what you do not recognize; re-approve narrowly later when you truly need a venue again.
Session signatures alone may not move funds, but combined with a malicious front end they can normalize reckless confirming. After an incident, disconnect sessions in wallet UIs that support it, and reconnect only via official bookmarks when you return.
For large treasuries, prefer hardware confirmation on any new spender or large allowance change. Small hot wallets limit how much a single missed revoke can cost.
What OptionsMatch can and cannot do
OptionsMatch provides research, education, venue profiles, and multi-venue terminal views. It does not custody assets, does not process withdrawals, and cannot freeze chain funds. Use OM to re-orient after an incident: re-read wallet guides, re-check venue official links via profiles you trust, and return to trading only when keys and allowances are clean.
When you are ready to re-engage, follow on-chain venue safety and the specific Paradex or Derive onboarding guides: test deposits, small size, hardware for treasury, and no seed on web forms. The goal is a calm return to research-first workflow, not a revenge trade from a half-compromised browser.