1 · The dust museum
Dozens of unsolicited tokens sitting in the wallet, each one a phishing lure with a website in its name. Holding them costs nothing, but every extra lure raises the odds that one bored evening you click one. The fix costs nothing too: hide them in your wallet UI, never approve or swap them, and stop treating unknown tokens as lottery tickets.
2 · Unlimited approvals from 2023
You swapped on some app once, granted an unlimited approval, and forgot it. The app got exploited two years later and the approval still stands. Standing permissions are the most common drain vector we flag. Fix: review approvals quarterly, revoke what you do not actively use, and approve exact amounts when the interface allows it.
3 · The eternal burner
A two-week-old address with three transactions and a large balance reads as either a scam wallet or a scam target, and attackers profile exactly this shape. History is a security feature: an address that ages with steady, explainable activity earns trust from every heuristic that looks at it, ours included. Fix: stop rotating wallets for no reason and let your main address build a track record.
4 · Everything on one key
The whole portfolio in one hot wallet means one signature, one phishing site, one bad evening is the whole game. The score reads heavy concentration with thin protective history as fragility, because it is. Fix: split holdings from activity. A hardware wallet holds, a small hot wallet plays, and the two never mix keys.
5 · A handshake with a drainer
Interactions with contracts already linked to drain patterns leave a permanent public mark and often leave live approvals behind. Sometimes it was a near miss, sometimes the wallet was rescued mid-drain. Either way the surface stays open until closed. Fix: revoke everything connected to the incident, move value behind a clean key, and let the monitor watch the old address instead of your nerves.
FREE SCAN · NO SIGN-UP · READ-ONLY. We never ask for keys or signatures.