A drain takes four seconds. What follows takes hours — and nobody builds for it.
The problem
The wallet is empty. The transaction that emptied it is not one you signed, so no key was stolen: a permission you granted once was used to move your tokens. You have more permissions left, and no way to tell which one did it, or whether the same address can still reach the rest.
The tools that exist act before the loss or show you what is still open. MetaMask and Rabby warn you about what you are about to sign. Revoke.cash lists every permission you hold. None of them tells you what happened to you.
That gap is widening. Wallet-drainer losses fell 83% to $83.85M in 2025 (Scam Sniffer), while Chainalysis recorded personal wallet theft rising to about 158,000 incidents in 2025 from 54,000 in 2022 — fewer dollars, more victims. The average loss is now under a thousand dollars, which is exactly why no company builds the tool for the person it happened to. That person follows the search results instead, and the search results are thin — or worse, phishing clones that grant the attacker a fresh permission.
What it does
Paste any address. Anchrion returns two things:
- What is still open. Every live ERC-20 allowance, read directly from the token contract over public RPC — no key, no signup, no indexer.
- What happened. Incident reconstruction finds token transfers out of the wallet inside transactions the wallet did not send, resolves who sent each one, and checks that sender against the live permissions.
Then the fix: revoke to zero from your own wallet, and Anchrion reads the allowance back instead of showing a green tick.
How we built it
Next.js and TypeScript on the frontend, wagmi/viem for chain reads, Blockscout plus public RPC as the data source. Live on Ethereum, Base, Arbitrum One, Optimism and Sepolia. MIT licensed. It runs from a fresh clone with no signup, no API key and no indexer.
What makes it different
An outflow is evidence only if you can pair it with the permission that let it out. Existing tools answer "what am I about to sign" or "what do I still hold." Neither reconstructs the event. Anchrion treats the two halves as one question.
The first drain already happened. The second one is the one we close — reconstruction ends in action, because the still-live permission is the one that can be spent again.
"Not measured" is not "safe", and the product says so on screen. Where the sender holds no live permission, Anchrion names the two ordinary explanations — an off-chain permit, or a relayed transaction you signed — and refuses to call it theft. The risk score is a published rule set, not a trained model and not a threat feed. Every scan reports what it actually read: transactions, allowance pairs, the exact log window, and the rows it could not read.
Impact
Every hour a live permission stays granted is an hour it can be spent again. Anchrion gives the person who was drained the one thing nobody sells them: the name of the permission, and the list of what is still reachable — in seconds, with no key and no account.
What's next
- NFT approvals (ERC-721 / ERC-1155
setApprovalForAll) — same reconstruction, different transfer standard. - Off-chain permits, caught when they land — Permit2 and ERC-2612 are invisible until redeemed, the largest blind spot in every approval checker.
- Verifiable deployer clustering behind a cached index, so grouping is auditable rather than trusted.
Limits, stated on purpose
Anchrion covers ERC-20 allowance approvals. ERC-721 / ERC-1155 approvals and off-chain permits are not covered and stay invisible until redeemed. A clean dashboard is not a clean bill of health, and the interface says so on every scan.
Built With
- arbitrum
- base
- blockchain
- blockscout
- ethereum
- next.js
- optimism
- security
- typescript
- viem
- wagmi
- web3
Log in or sign up for Devpost to join the conversation.