Back to Blog
Solana

Hacked Solana Wallet Can't Send Tokens? How to Move Them Safely

S
Sol Slugs Team
Sol Incinerator
Share on X

Some Solana drainers do more than empty your SOL. They change the wallet account itself, so it can no longer send SOL, and any SOL you add can be withdrawn by the attacker. Your tokens and NFTs usually stay put, but the normal way to move them, a send from your wallet app, fails or hands the attacker more SOL.

This guide covers what changed, why you should not send SOL to the wallet, and how to move what is left to a new wallet while another wallet pays the fees.

How do you know your Solana wallet was converted?

Sends from the wallet fail even though it still holds tokens, and an explorer shows the address as a nonce account with an authority that is not you, or as an account owned by a program. When you connect to Sol Incinerator, it shows "Your wallet has been hacked" with the takeover time and a link to the transaction.

A normal Solana wallet is a plain System Program account with no data. A converted wallet is still at the same address, but the account behind it has changed. Check it three ways:

  1. Open the address in an explorer. Solana Explorer shows nonce account details for a converted wallet, including an authority address. If that authority is not an address you own, someone else controls the account's SOL.
  2. Find the transaction that did it. In the cases we examined, the victim had co-signed a transaction with two System Program instructions: allocate gave the wallet address 80 bytes of data, and initializeNonce made it a durable nonce account with the attacker as its authority. The attacker paid the network fee. In one case, the withdrawal of the victim's SOL followed 30 seconds later.
  3. Connect the wallet to Sol Incinerator. It reads the account when you connect and shows a warning with the takeover time and a Solscan link when it finds a takeover.

Some drainers use a different change: they assign the address to a program instead. The result for you is the same: the wallet can no longer pay its own way.

Why can't a hacked wallet pay network fees?

A durable nonce account is a normal Solana feature for signing transactions in advance. It stores a nonce value and an authority, and only that authority can advance the nonce, change the authority, or withdraw the account's SOL. When a drainer turns your address into one, they become the authority over your address's SOL.

  • SOL cannot leave the normal way. The System Program refuses to transfer SOL out of an account that carries data, and your wallet now carries the nonce data.
  • Fees come from SOL the attacker can take. A nonce account can pay network fees only from SOL above its rent reserve, and the authority can withdraw that SOL whenever it appears.
  • A program-owned address cannot pay fees at all. Solana accepts fees only from a plain System account or a nonce account.
  • You cannot undo it. Only the current authority can change a nonce account's authority, so no transaction you sign can take it back.

Your tokens are a different story. Each token account records your address as its owner, and the token program checks your signature, not the state of your wallet account. Your key can still move every token and NFT; another wallet just has to pay the network fee.

Do not send SOL to the hacked address, even a small amount for fees. Assume a bot is watching it. Do not sign anything from a site or a direct message that promises to "unlock" or "repair" the wallet: paid recovery offers in direct messages are a common follow-on scam.

How do you move tokens out of a hacked Solana wallet?

Use a transaction where a different wallet pays the network fee and the hacked wallet signs only as the token owner. Wallet apps charge the fee to the sending wallet, so use a recovery tool built for compromised wallets, such as Sol Recovery, and send everything to a new wallet.

Sol Recovery is an independent service for compromised Solana wallets. It identifies converted wallets, and its free account separates the wallet that receives your assets from the wallet that pays the fees.

  1. Create a new wallet. If you ever typed your recovery phrase or private key into a website, create the new wallet with a fresh recovery phrase. Another account under the old phrase is not a new wallet.
  2. See what is left. Paste the hacked address into Sol Recovery. It scans tokens, staked positions, DeFi positions, collectibles, and domains without a wallet connection.
  3. Set the safe wallet and the payer. Add your new wallet as the destination and a separate wallet to pay network fees. Fund only the payer wallet, never the hacked address.
  4. Review and sign. The hacked wallet signs each transfer as the token owner. Check what each transaction does before you approve it, and confirm the assets arrive.

Sol Recovery also runs a bot service for staked or locked positions that unlock at a set time, racing the attacker at the moment of unlock. That service charges 10% of what it recovers and needs the hacked wallet's private key so it can sign instantly. That is a real trust decision: share only the key of the wallet that is already compromised, and never the recovery phrase of your new wallet.

Sol Recovery is not affiliated with Sol Incinerator. Check its current fees and every transaction before you sign. Developers can build the same transfer themselves: a token transfer is valid when the token owner signs, whichever wallet pays the fee.

Can you still claim the SOL in your token accounts?

Yes. Empty token accounts hold a refundable rent deposit, and closing them returns that SOL. A normal claim pays it to the wallet itself, which here means paying it to the attacker, so Sol Incinerator handles converted wallets differently.

When you connect a converted wallet, Sol Incinerator asks for a safe wallet address and pays the reclaimed SOL there instead. It pays the network fee itself, and that fee and the usual cleanup fee come out of the reclaimed SOL. Nothing is sent to the hacked address. Closing empty token accounts and withdrawing excess rent are supported; burns and other actions that need the wallet to pay its own fees are not.

Moving your tokens out leaves their token accounts empty. If your recovery tool does not close them, claim again afterwards to collect that rent too.

What else should you check?

  • Read the whole takeover transaction. It may also have moved assets or approved a delegate. Note the signature and every unfamiliar address for reporting.
  • List staked and locked positions. Some need unstaking or a cooldown before they can move, and the attacker may be waiting for the same moment.
  • Replace the old address everywhere it receives funds. Exchange withdrawal lists, payout settings, and airdrop registrations that pay to the hacked address now pay the attacker.
  • Stop using the address. Once your assets are out, do not reuse the wallet, even for small amounts.
Sol Incinerator

Sol Incinerator

Connect the hacked wallet and claim its reclaimable SOL to a safe wallet address. Nothing is sent to the hacked address.

Try it now

Related Reading

Frequently Asked Questions

Why can't I send tokens from my hacked Solana wallet?

A drainer's transaction can turn your wallet address into a durable nonce account it controls, or hand the address to a program. Network fees must come from SOL the wallet holds, and the attacker can withdraw any SOL above the account's reserve, so transfers fail or the SOL you add is taken first.

Should I send SOL to my hacked wallet to pay the fees?

No. If the wallet was turned into a nonce account, the attacker is its nonce authority and can withdraw anything above its rent reserve, so assume a bot is watching the address. Use a tool where a separate wallet pays the network fees and the hacked wallet only signs as the token owner.

Are my tokens and NFTs still mine after a nonce takeover?

Usually, unless the same transaction also moved them or approved a delegate. A nonce takeover changes your wallet's own account, not the token accounts it owns, so your key still signs token transfers. Open the takeover transaction in an explorer to see everything it changed before you plan the move.

Can I still claim the SOL in my empty token accounts?

Yes. Sol Incinerator detects a converted wallet, pays the network fee itself, and sends the reclaimed SOL to a safe wallet address you paste instead of the hacked one. The network fee and the usual cleanup fee come out of the reclaimed SOL, and nothing is sent to the hacked address.

Do I need to share my private key to recover my assets?

Not for ordinary transfers. A recovery tool can build a transaction your hacked wallet signs while another wallet pays the fees. Sol Recovery's bot service for staked or locked positions does ask for the private key so it can act at unlock time. Treat that as a trust decision, and never share your new wallet's recovery phrase.

Hacked Solana Wallet Can't Send Tokens? How to Move Them Safely | Sol Incinerator