Security
Popular M complexity

Crypto Phishing & Wallet Drainer Scanner.

Inspect URLs, dApps, and Telegram links client-side for Web3 threat vectors: Cyrillic homograph spoofing, disposable TLDs, brand impersonation, and Permit2 wallet drainer signatures with zero network leaks.

Free Runs in your browser Data: Client-Side Threat Heuristics (No API)
Trading & Calculation Currency:
Test Vectors:
Threat Vector Detection:Zero-Leak Local Sandbox
Homograph / Punycode:CRITICAL SPOOF
Brand Impersonation:FAKE COINBASE
TLD Registry Risk:Standard TLD
Phishing Bait Keywords:airdrop, claim
Unicode Homograph Exploit Detected:

Domain uses Punycode encoding (xn--), typical of internationalized spoof domains.

100% Client-Side Evaluation. No links are queried or visited over the network.
Real-Time Threat Score
Phishing & Drainer Probability:

99/100

CRITICAL WALLET DRAINER
Domain StatusSPOOFED
TLD RiskLOW
Permit2 RiskCRITICAL
Security Forensics Verdict:

CRITICAL DRAINER: Disguised Unicode homograph spoof detected targeting Coinbase. Do not connect your wallet or sign Permit2 requests.

Specification & Methodology

Understanding your results.

A rigorous breakdown of the mathematical equations, market assumptions, and step-by-step calculations powering this tool.

Executive Summary & Threat Intelligence

Modern crypto drainers don't steal passwords - they exploit human visual trust and off-chain signature standards. By detecting Unicode homographs and deceptive claim mechanics in advance, investors can verify dApp authenticity before signing away their assets.

Primary Attack Vector Permit2 EIP-712 Signatures
Domain Deception IDN Homograph Spoofing
Privacy Guarantee 100% Zero-Leak Sandbox
Web3 Security Architecture

How Malicious DApps Exploit Wallet Signatures.

Exploit 01 Gasless Drainers
Zero-Gas Approval Traps

Victims are prompted to sign a gasless permit rather than broadcast a transaction. Because no gas fee is paid, users assume the signature is safe, unaware that it provides the contract with unlimited spending rights.

Exploit 02 Disposable TLD Churn
Punycode & Disposable Registrars

Drainer operators purchase dozens of $1 domain names on loose TLDs (.top, .xyz) that are cycled every 24 hours to evade traditional antivirus URL blocklists and browser blacklists.

Frequently asked questions.