Who else has a key to your wallet?
Every approval, NFT permission, Permit2 signature and EIP-7702 delegation is a spare key. Paste an address: we check six chains, test what we find, and tell you in plain words which keys to take back.
Read-only. Nothing to sign, and we will never ask for your seed phrase.
Checking six chains
This usually takes 15 to 60 seconds. Nothing is signed or sent.
The spare keys we look for
-
Token approvals
Permission for an app, or a stranger, to move one of your tokens. Unlimited ones never run out.
-
Permit2 signatures
Gas-free signatures that work like approvals. They are the drainer's favourite trick because signing feels harmless.
-
EIP-7702 delegations
Your address runs someone else's code. Wallet upgrades do this on purpose. Sweepers do it to steal every coin you send in.
-
NFT "all items" access
One click on a fake marketplace can hand over a whole collection, including pieces you buy later.
We also flag the traps around them: look-alike addresses planted in your history, counterfeit USDT, tokens that say "claim your reward", and tokens moved out by someone other than you.
We test delegations instead of guessing
For every delegated wallet we simulate sending it 1 ETH and read its balance inside the same transaction. A healthy wallet keeps the coin. A sweeper forwards it to the attacker before the block ends. The test runs in a simulation, so nothing is signed or sent.
Explained by Claude, decided by checks
Claude reads the findings and writes what happened, what to do first and what is fine, in English or Bahasa Indonesia. The verdict and every risk level come from deterministic checks, never from the model, and text written on-chain by strangers is treated as data, not instructions.