Crypto Security Center

Check your crypto exposure before it costs you.

Most crypto losses are not sophisticated hacks. They are permissions granted months ago, a signature on a look-alike site, or a token contract nobody read. These tools show you what is actually exposed — in plain English, without connecting your wallet.

Read-only by design. You paste a public address — we never request a wallet connection, a signature, a private key or a recovery phrase, and we do not store the addresses you check.

The toolkit

Six checks that cover how crypto is actually lost

Each tool answers one question, shows the evidence behind its answer, and tells you what to do next. Where a check cannot be completed, it says so rather than implying everything is fine.

Wallet scanner

Live

Check a wallet for risky approvals and contract exposure

A risk score, the findings behind it, and a prioritised list of what to fix first.

Open tool

Approval checker

Live

See every contract allowed to spend your tokens

A table of active approvals, ranked by how much they expose the wallet.

Open tool

Transaction explainer

Live

Understand what a transaction actually did

A readable explanation of the transaction and the permissions it created.

Open tool

Token risk scanner

Live

Review a token contract before you interact with it

A contract-level risk assessment with the specific code patterns detected.

Open tool

Scam checker

Live

Test a link, message or address for known scam patterns

A pattern-by-pattern breakdown of what looks wrong and what to do next.

Open tool

Wallet monitoring

In development

Get told when a wallet's risk profile changes

Ongoing monitoring with alerts — currently in development.

See what's coming

Why this exists

Four ways wallets lose funds

Understanding the mechanism is what makes the tools useful. None of these require a vulnerability in your wallet software.

Unlimited token approvals

One signature can give a contract permission to spend a token indefinitely. Most drained wallets were not hacked — they approved something and forgot about it.

Wallet drainer phishing

A look-alike site asks for a single, innocuous-looking signature. That signature is the theft. Checking a link before connecting costs nothing.

Malicious token contracts

Honeypots and rug pulls are visible in code: unverified source, owner-only functions, upgradeable logic, a contract deployed days ago.

Silent exposure over time

Risk accumulates. An approval granted last year for an application that has since been abandoned is still live until someone revokes it.

How the analysis works

Deterministic rules first. Plain language second.

Every finding comes from a fixed rule applied to on-chain data: an allowance that is effectively unlimited, a contract with no verified source, a contract deployed within the last 30 days, an approval to an address with no public reputation. The rule that fired, the evidence it fired on, and how confident that evidence is are all shown with the result.

The score is arithmetic, not opinion. It starts at 100, each risk finding subtracts a documented weight, and the total maps to a band. Language models are used only to re-phrase a result that has already been decided — they never create a finding, change a severity, or move a score.

When a data source is unavailable, the affected check is reported as unverified. An incomplete scan is presented as incomplete. We would rather tell you we do not know than tell you something is clear when we have not checked it.

What we never do

  • Ask for a wallet connection or a signature.
  • Ask for a private key, recovery phrase or keystore file.
  • Store the addresses you look up.
  • Tell you an asset is safe, or worth buying.

Questions

Frequently asked

Is the Crypto Security Center free to use?
Yes. The wallet scanner, approval checker, transaction explainer, token risk scanner and scam checker are free, with a daily limit on scans so the shared data allowance stays available to everyone. Continuous monitoring and alerts are the paid part, and that is still in development.
Do I need to connect my wallet?
No, and you never should. Every tool works from a public address or transaction hash that you paste in. Nothing here can request a signature, so nothing here can move your funds.
Will you ever ask for my recovery phrase or private key?
Never. No legitimate security service needs them. If any site, message or person asks for your recovery phrase, seed phrase or private key, that is theft in progress — including anything claiming to be us.
Does a low-risk score mean my wallet is safe?
No. A score reflects the security signals we detected in the data available at the time of the scan. New risks appear constantly, some data sources are incomplete, and a check we could not complete is reported as incomplete rather than clear. Treat a score as a prompt to look closer, not as a guarantee.
Which networks are supported?
Ethereum, BNB Chain, Polygon, Arbitrum, Optimism and Base. The wallet scanner can auto-detect which of those an address is active on.
Can you recover funds that were already stolen?
No, and neither can anyone else who contacts you offering to. On-chain transactions are final. Anyone promising recovery for an upfront fee is running a second scam on top of the first.

Important

Cyber Security Space provides automated security analysis based on available blockchain and threat intelligence data. Results may be incomplete or inaccurate and should not be treated as a guarantee of safety, financial advice, or investment advice. This score reflects the security signals currently detected. A low-risk score does not guarantee that a wallet or transaction is safe.

Nothing on this page is financial or investment advice.