Your wallet was drained by malware, and the hacker used FixedFloat to swap the stolen crypto — often through the Lightning Network — before withdrawing to the final destination. FixedFloat is a non-custodial swap service specializing in Lightning Network swaps. Like Changelly, FixedFloat does not hold user funds — but it records IP addresses, device fingerprints, and destination addresses.
A wallet hack is when an attacker gains access to your crypto wallet through malware, a malicious dApp, a compromised seed phrase, or a browser extension vulnerability. Unlike a SIM swap (which targets your phone) or phishing (which tricks you into entering credentials), a wallet hack directly compromises your wallet software or private keys. The attacker signs transactions from your wallet and sends your crypto to addresses they control.
Why FixedFloat users are targeted for wallet hacks: FixedFloat specializes in Lightning Network swaps — instant Bitcoin transfers through the Lightning Network. If the hacker used FixedFloat to swap stolen BTC through Lightning, the swap is nearly instant (seconds). However, FixedFloat records the destination on-chain address, IP, and device fingerprint. The Lightning Network creates a different tracing challenge — but the destination is identifiable.
The Lightning Network laundering attack: A common wallet hack involving FixedFloat works like this: the hacker drains your wallet (through malware or a malicious dApp), then uses FixedFloat to swap the stolen BTC through the Lightning Network. The Lightning payment is off-chain and instant — it does not appear on the Bitcoin blockchain. The hacker then receives the swapped BTC at a destination on-chain wallet. FixedFloat provides the destination address, IP, and device fingerprint.
Regulatory structure: FixedFloat is operated by a team based in Estonia and Panama. Not formally regulated. Response times: 5-14 business days. FixedFloat cooperates with law enforcement when presented with a police report.
Freeze capability: FixedFloat cannot freeze funds (non-custodial) — but it CAN provide the destination address, IP records, and device fingerprint. Response: 5-14 business days. FixedFloat cannot reverse swaps (no 24-hour refund window like Changelly).
KYC disclosure: FixedFloat discloses swap creator information to law enforcement or through a court order. FixedFloat records IP address, device fingerprint, and (for larger swaps) KYC. For very large swaps, FixedFloat may require email verification.
The Lightning Network tracing challenge: If the hacker received BTC through the Lightning Network, the on-chain trail is different from regular BTC transfers. Lightning payments are off-chain. However, the hacker must eventually close their Lightning channel and settle on-chain. We monitor the Lightning channel close transactions and trace the on-chain settlement. FixedFloat provides the destination on-chain address.
A client wallet was drained by a keylogger that captured their seed phrase. The hacker stole €28,000 in BTC and used FixedFloat to swap the BTC through the Lightning Network. The swap was instant — the hacker received the swapped BTC at a destination on-chain wallet within seconds. The hacker then sent the BTC to an Electrum personal wallet.
Our response: We traced the stolen funds on-chain, identified the destination addresses, and filed freeze requests with the receiving exchanges. We also analyzed the malware to understand how the wallet was compromised.
Outcome: 18% recovery (€5,000 of €28,000). FixedFloat provided the destination on-chain address and IP records within 7 business days. The IP address was a VPN (Estonia) — but the device fingerprint was consistent. We traced the destination on-chain address: it went to an Electrum personal wallet, then to a Binance deposit address. We filed a freeze request with Binance and recovered €5,000. The remaining €23,000 had been withdrawn from Binance to a bank account (traced but in a non-cooperative jurisdiction). Lower recovery due to the Lightning Network instant swap (no refund window) and the use of a personal wallet.
Details anonymized to protect client confidentiality. Swiss professional secrecy applies.
How does a wallet hack differ from a SIM swap? A wallet hack compromises your wallet software or private keys directly. A SIM swap takes over your phone number to intercept 2FA. See SIM swap on FixedFloat →
Warning: After a wallet hack, fake "recovery services" may contact you. Read our recovery scam warning.
A wallet hack compromises your wallet software or private keys directly. A SIM swap takes over your phone number. FixedFloat is a swap service, not an exchange — it does not hold user accounts. The SIM swap is not applicable to FixedFloat (no account to access). See SIM swap on FixedFloat
We trace through FixedFloat to the destination on-chain address. FixedFloat provides the destination address, IP records, and device fingerprint. We then trace the destination on-chain and file freeze requests with whatever exchange holds it. If the destination is a personal wallet, we monitor for movement — when the hacker eventually sends to an exchange to cash out, we file a freeze request there.
Lightning Network payments are off-chain — they do not appear on the Bitcoin blockchain. The swap is instant (seconds). However, the hacker must eventually close their Lightning channel and settle on-chain. We monitor the channel close transactions and trace the on-chain settlement. FixedFloat provides the destination on-chain address, which is the key to tracing.
A VPN masks the real IP address, making direct identification harder. However, FixedFloat records the device fingerprint — a unique identifier based on browser/device characteristics. If the hacker made multiple swaps, the device fingerprint is consistent. We also trace the destination on-chain address, which may lead to an exchange with KYC. The VPN makes IP-based identification harder, but the on-chain trace and device fingerprint provide alternative paths.
5-14 business days. FixedFloat is not formally regulated but cooperates with law enforcement. For wallet hack cases, we focus on the destination address trace rather than freezing funds on FixedFloat (which does not hold them).
Use a hardware wallet for large balances. Never enter your seed phrase on any website. Install a reputable anti-keylogger solution. Use a separate browser profile for crypto activity. Never store your seed phrase on a computer or phone. These measures prevent the malware attacks that lead to FixedFloat Lightning Network laundering.
Describe what happened. Include your wallet type, when you noticed the hack, transaction hashes, destination addresses, and total amount lost. We respond within 6 hours.