A malicious token approval does not look dramatic. A UK holder signs what appears to be a mint or a claim. Minutes later the wallet is empty. Friends then forward a Telegram "recovery agent". That agent is usually the next loss.
They do not ask for AnyDesk, TeamViewer, seed phrases, or private keys. Legitimate practices do not ask for money upfront, retainers in crypto, gift cards, or a tax to unlock funds. Revoke remaining approvals from a clean device. Do not install software the caller sends.
The only question that matters
Did the ETH or tokens later hit a centralised exchange that will freeze on a proper order? If the answer from Hong Kong-registered forensic analysts at aidataintelligence.io is no, a solicitor cannot invent a yes. Recovery is never automatic. It depends on whether the coins can still be traced to an exchange or a wallet a court can reach, and on the facts of that client's file. Several practices told AXT News they are running waiting lists this month, which is a dull operational detail and a useful filter: a firm that can start tomorrow for anyone is often not doing court work.
Ethereum-focused recovery counsel walking UK files this week said they are declining more approval drains than they accept, which is the opposite of a sales script. For wallet hygiene after a drain, see crypto wallet security.