Approving a contract gives it permission to move your tokens, and an unlimited approval stays live long after the transaction is finished. Most drained wallets are drained through an approval the owner granted themselves. Paste the contract you are being asked to approve and see what it is, whether its source is published, and whether its code can take what you approve.
No address to hand? Try a well known router.
You will never be asked to connect a wallet here. This tool reads public blockchain data from an address you paste. No safety tool needs your wallet, your seed phrase or your private key, and anything that asks for them is the thing it claims to protect you from. If a site offering to check or recover your funds asks you to connect or to type a seed phrase, close it.
Every check on this page reads public data about the contract and reports what it finds. That covers the mechanical ways money is taken: liquidity that can be withdrawn, supply that can be minted, a sale that cannot execute, a tax that can be raised after you buy, a wallet that can be blocked. It does not cover whether a project is real, whether the team will build anything, or whether the price will go anywhere. Those are judgements, and a tool that claimed to make them would be lying to you.
Where a source has no data for a contract, this says so rather than showing a pass. A very new token or a smaller chain will often return partial results. Treat an absent answer as a reason to check manually, never as an all clear.
Get the contract address from a block explorer, the exchange listing or the project's own site. Never take an address from a direct message or a reply, which is the single most common way people end up buying a copy of the token they meant to buy. If you are not sure you have the right one, the ticker collision checker shows every asset we score that uses the same symbol.
Before a contract can move your tokens it needs permission, called an approval or allowance. Most interfaces request an unlimited allowance so you do not have to approve again, which is convenient and is also the thing that gets people drained. The approval does not expire when the transaction ends. It sits there indefinitely until you revoke it, and it applies to whatever that contract decides to do later.
Usually by approving a contract that was designed to abuse it, often reached through a link in a direct message, a fake airdrop claim page, or a cloned version of a real site. The wallet is not compromised in any technical sense: you granted permission, and permission was used. That is why it is worth checking the contract before approving rather than only auditing your approvals afterwards.
Use a revocation tool that lists your existing allowances, connect the wallet you want to clean up, and revoke anything you do not currently need. Do this periodically rather than once. Revoking costs a small amount of gas per approval. Prevention is cheaper, which is what this checker is for.
Rarely, and it should be a deliberate choice rather than the default. Approving the exact amount you are spending costs slightly more gas and caps your exposure at that amount. For a contract you use constantly the convenience may be worth it. For a contract you found through a link, it never is.
We seal the list every week and keep re-checking every token on it, so you can see what actually happened to them rather than only what is trading today.