Wallet scanner
LiveCheck a wallet for risky approvals and contract exposure
A risk score, the findings behind it, and a prioritised list of what to fix first.
Open toolCrypto Security Center
Most crypto losses are not sophisticated hacks. They are permissions granted months ago, a signature on a look-alike site, or a token contract nobody read. These tools show you what is actually exposed — in plain English, without connecting your wallet.
Read-only by design. You paste a public address — we never request a wallet connection, a signature, a private key or a recovery phrase, and we do not store the addresses you check.
The toolkit
Each tool answers one question, shows the evidence behind its answer, and tells you what to do next. Where a check cannot be completed, it says so rather than implying everything is fine.
Check a wallet for risky approvals and contract exposure
A risk score, the findings behind it, and a prioritised list of what to fix first.
Open toolSee every contract allowed to spend your tokens
A table of active approvals, ranked by how much they expose the wallet.
Open toolUnderstand what a transaction actually did
A readable explanation of the transaction and the permissions it created.
Open toolReview a token contract before you interact with it
A contract-level risk assessment with the specific code patterns detected.
Open toolTest a link, message or address for known scam patterns
A pattern-by-pattern breakdown of what looks wrong and what to do next.
Open toolGet told when a wallet's risk profile changes
Ongoing monitoring with alerts — currently in development.
See what's comingWhy this exists
Understanding the mechanism is what makes the tools useful. None of these require a vulnerability in your wallet software.
One signature can give a contract permission to spend a token indefinitely. Most drained wallets were not hacked — they approved something and forgot about it.
A look-alike site asks for a single, innocuous-looking signature. That signature is the theft. Checking a link before connecting costs nothing.
Honeypots and rug pulls are visible in code: unverified source, owner-only functions, upgradeable logic, a contract deployed days ago.
Risk accumulates. An approval granted last year for an application that has since been abandoned is still live until someone revokes it.
How the analysis works
Every finding comes from a fixed rule applied to on-chain data: an allowance that is effectively unlimited, a contract with no verified source, a contract deployed within the last 30 days, an approval to an address with no public reputation. The rule that fired, the evidence it fired on, and how confident that evidence is are all shown with the result.
The score is arithmetic, not opinion. It starts at 100, each risk finding subtracts a documented weight, and the total maps to a band. Language models are used only to re-phrase a result that has already been decided — they never create a finding, change a severity, or move a score.
When a data source is unavailable, the affected check is reported as unverified. An incomplete scan is presented as incomplete. We would rather tell you we do not know than tell you something is clear when we have not checked it.
What we never do
If you think you have been drained
Move remaining assets to a new wallet created on a clean device first — revoking approvals on a compromised wallet does not help if the attacker holds the keys. Then review approvals on the old address to understand what happened.
Questions
Important
Cyber Security Space provides automated security analysis based on available blockchain and threat intelligence data. Results may be incomplete or inaccurate and should not be treated as a guarantee of safety, financial advice, or investment advice. This score reflects the security signals currently detected. A low-risk score does not guarantee that a wallet or transaction is safe.
Nothing on this page is financial or investment advice.