Crypto Crisis Comms: The First 24 Hours
In an incident the damage is rarely done by the facts. It is done by the silence, the premature all-clear and the statement that turns out not to be true.
The short version
- Acknowledge fast, even with nothing to report. Silence is read as concealment.
- Never give an all-clear you cannot sustain. Retracting one is far worse than never giving it.
- One channel, one voice, timestamped updates on a stated cadence.
- Write the post-mortem. The teams that publish honestly recover fastest.
Crypto incidents are unusually brutal because they are public in real time. On-chain activity is visible, users coordinate faster than you can convene a meeting, and the gap between something happening and the market knowing is often zero.
That inverts the normal crisis sequence. You cannot gather facts and then communicate. You have to communicate while gathering facts, without saying anything that turns out to be false.
Hour zero: acknowledge
The first message should go out fast and should not pretend to know things you do not. It needs four elements: that you are aware, what you are doing, what users should do right now, and when you will next update.
That is achievable within minutes of becoming aware and it is the single highest-leverage action available. Silence in the first hour is universally read as concealment or incompetence, and the interpretation hardens quickly.
What it must not contain is an estimate of scope. “We believe user funds are safe” before you know is the most damaging sentence available, because retracting it converts a technical incident into a credibility incident.
Hours 1–4: establish the channel
Pick one primary channel and say that it is the primary channel. Every subsequent update goes there first and is mirrored elsewhere. Fragmented updates across several platforms guarantee contradictions, and contradictions become the story.
Set a cadence and hold it: “we will update every two hours whether or not there is news”. Then update on schedule even when the update is that there is nothing new. The cadence itself is reassuring in a way the content often cannot be.
Designate one voice. Multiple team members posting their own read of the situation is how a manageable incident becomes an unmanageable one.
Hours 4–12: the facts arrive
As you establish what happened, publish it in plain language, including the parts that reflect badly. Two rules:
Distinguish confirmed from suspected, explicitly. Label them. Audiences can handle uncertainty that is described as uncertainty; what they cannot forgive is being given a confident answer that changes.
Do not minimise. Scope that expands after you characterised it as limited is the most common way an incident response fails. If you are unsure of the boundary, say the boundary is not yet established.
Hours 12–24: the questions
By now reporters are asking, and the hard questions are predictable: was this known beforehand, was there an audit, who had the keys, will users be compensated, has it happened before.
Have written answers agreed with your legal counsel before the calls start. The failure mode here is improvisation by a founder who is exhausted and wants the conversation to end.
On compensation specifically: do not commit to a mechanism you have not confirmed you can deliver. “We are assessing how to make users whole and will publish the approach by date” is honest and buys the time you need. A promise you later modify is a second incident.
The three mistakes
Saying nothing until you have the full picture. By the time you do, the narrative is set and it was written by other people.
Premature reassurance. Every all-clear you retract costs more than the original problem.
Blaming. Pointing at a third-party dependency, an auditor or an individual employee reads as evasion, even when it is factually correct. You chose the dependency.
Afterwards: publish the post-mortem
The teams that recover best are the ones that publish a genuine technical post-mortem — what happened, why, what was missed, what changed as a result. It is uncomfortable and it works, because it converts the story from “they had an incident” to “they handled it properly”, which is the only good ending available.
The teams that never publish one are still associated with the incident years later, because nothing ever replaced it.
Prepare before you need it
None of this can be assembled on the day. Decide in advance who speaks, which channel is primary, who has publishing access at three in the morning, and what your holding statement says. That work takes an afternoon and it is the difference between a bad day and a bad quarter.
Crisis planning and live support are part of our PR service. The planning is considerably cheaper than the support.
Keep reading
Related from the newsroom
Measuring Crypto PR Without Lying to Yourself
Why impressions and media value are not PR results, and the four measures that actually indicate whether crypto PR is working for…
The Crypto Press Release Template That Gets Read
A crypto press release template built around what reporters actually check first, with the structure, the verification section…
How to Build a Crypto Media Map That Works
Build a crypto media map that produces replies: how to identify the right reporters, what to record about each, and why bought…
Leave a comment