Paste any public wallet address and see what it really holds, how concentrated it is, and how many worthless tokens have been airdropped at it as bait. No wallet connection, no signature, no key, and nothing stored. A public address is already public.
You will never be asked to connect a wallet here. A public address is public: anyone can already look at it, including you. This reads it and nothing else. There is no connection, no signature, no key, and nothing you type is stored. A tool in this category asking you to connect is the exact shape of the attack it claims to protect you from.
What it tells you. What the address actually holds, how concentrated it is, and how many worthless tokens have been airdropped at it. That last one matters more than it sounds: a free token with a website in its name is not a gift, it is bait, and interacting with it is the whole point of sending it.
Sending a worthless token to a hundred thousand addresses costs almost nothing. The token is created for free, given a name containing a claim, a reward or a web address, and scattered across every wallet with a balance. It has no market, so it is worth nothing, and it was never meant to be. It is an advertisement that arrives inside your wallet.
The site it points at is where the loss happens. You go to claim, swap or sell it, and are asked to connect and approve something. The approval is the product. The token was only ever the delivery.
Approvals. Whether this wallet has granted a contract permission to move its tokens is not visible in a balance, and it is the single most important thing about a wallet's safety. Use a revocation tool to review those, and check a contract with the approval risk checker before granting a new one.
It also cannot see anything on a chain not listed above, and it cannot tell you whether an address belongs to who you think it does. Nothing on chain can.
Because sending them costs almost nothing. Anyone can create a token for a few pence and send it to a hundred thousand addresses at once. They are given names containing a claim, a reward or a web address, and they are scattered across every wallet with a balance. They have no market and are worth nothing, which was never the point. The token is an advertisement that arrives inside your wallet.
Not while you leave them alone. A token sitting in your wallet is inert and cannot do anything by itself. The danger is entirely in what you do next. The name is designed to send you to a website where you are asked to connect and approve something, and that approval is the actual product. The token was only the delivery mechanism.
No. That is precisely the action the sender wants, because selling requires interacting with a contract they chose and often granting it an approval. There is nothing to recover: a token with no market is worth nothing no matter what your wallet displays as its value. Hide it in your wallet interface if the clutter bothers you, which changes nothing on chain.
Neither, and it never will. A wallet address is public information already recorded on a public ledger that anyone can read. This reads it and nothing more. If any tool claiming to check your wallet asks you to connect, sign or enter a recovery phrase, close it: that is the attack rather than the check.
Yes, any public address works, which is worth understanding in both directions. Everything you do on a public chain is visible to anyone with the address, permanently. That is a feature of how these systems work rather than a flaw, and it is why address reuse tells people more about you than most realise.
Approvals, which are the most important thing about a wallet\u2019s safety and are invisible in a balance. Whether a wallet has given some contract permission to move its tokens cannot be read from what it holds. It also cannot see chains that are not listed, and it cannot tell you who owns an address. Nothing on chain can.
We seal the list every week and keep re-checking every token on it, so you can see what actually happened to them rather than only what is trading today.