File a dual-signature claim
Two signatures needed: one from your drained wallet to prove control, one from a fresh payout wallet to bind the destination. Contract-enforced: the two must be different addresses.
The drained wallet's key is compromised. Do not perform any other transaction from it during this flow. Use a hardware wallet for the fresh payout wallet — its key must not be shared with any service that also touches the drained wallet.
MUST NOT be the drained wallet. Contract reverts on payoutWallet == drainedWallet.
Only keccak256(text) is committed on-chain; the full text lives in Supabase for the transparency log and Tier-3 verdict draft.
Connect the wallet that got drained. It signs a message committing to your chosen payout wallet, so the payout can't be swapped later.
Now switch your wallet to the payout address and sign the destination-binding message. Same personal_sign flow.
Any wallet can pay gas — the signatures are what identify the parties.