Anchrion
See how a drain happened.
Then close what is still open.
Paste any wallet address. See the permission that moved the funds — and what the same address can still reach.
Problem
Who has this problem. Someone whose wallet was emptied by a transaction they did not sign — which means no private key was stolen. A permission they granted once, months ago, was used to move the tokens.
What they have to work with today. An empty wallet, a transaction they cannot read, and eleven permissions left — three of them unlimited — with no way to tell which one was spent, or whether the same address can still reach the rest.
The question nobody answers. Not "is this signature dangerous?" and not "what have I approved?". The unanswered one is:
Which permission was used against me — and can it still reach me?
They solve it by hand: scrolling a block explorer, matching an outflow to a token contract, guessing at an allowance page that lists everything the wallet ever granted, and revoking whichever name looks most suspicious — usually after the second drain, not before it.
Problem
Each row is what that product is built to answer, taken from its own published description. These are mature, working tools — simulation is why drainer losses fell. This is a different hour of the same day.
| Tool | Built to answer | Warns before you sign | Revokes | Names the permission used | Rebuilds a past incident |
|---|---|---|---|---|---|
| Wallet simulationRabby · MetaMask · Blockaid | “Is this signature dangerous?” | yes | no | no | no |
| Revoke.cashinventory + exploit checker | “What have I approved?” | no | yes | no | no |
| Etherscantransaction viewer | “What did this transaction do?” | no | no | no | no |
| Anchrionpermission reconstruction | “Which permission was used against me, and can it still reach me?” | no | yes | yes | yes |
Anchrion is not preventive, and the table says so in its own row. It is the hour after.
Solution
01
Five networks. No wallet, no install, no API keys — so you can inspect an address you do not own, including the one that just drained you.
02
Approvals are read live from each token contract. Outflows are paired with the address that submitted them, and with the permission that made them possible.
03
Connect the wallet that owns the address and sign. The allowance is read back from the contract: a surviving allowance is reported as still allowed, never as a green tick.
Innovation · 1 of 3
A tool that cries theft on ambiguous evidence is worse than one that reports what it measured.
Innovation · 2 of 3
Live, on mainnet
768,161.778096 USDC
One real permission on a real wallet, read from the token contract and matched against an independent eth_call during review.
Reachable through it
$540,082
Capped at the wallet's balance, priced live — the figure a person needs in order to decide whether to act now.
Innovation · 3 of 3
Every scan ships with the list of checks that ran and the ones that could not be completed. It is the difference between a scanner you trust and one that looks complete.
Technical feasibility
Impact
For the victim
Hours → minutes
The manual job — explorer, token contract, allowance page, guesswork — becomes one scan with the permission named and the exposure priced.
At risk per wallet
$540,082
Measured on one real address during review, reachable through a single permission that was still granted at the time of the scan.
Cost to run
$0
No API keys, no signup, no paid indexer. A tool that needs a subscription is not available at 3am on the worst night of someone's year.
Limits
Future scope
01
Match Permit2, ERC-2612 and Seaport nonces to outflows, so the ambiguous rows in the reconstruction become attributable instead of named as unknown.
02
A self-hosted log index so an old permission is always in reach, and the coverage panel stops needing a bound to disclose.
03
Standing consent to alert on a new unlimited grant or a fresh approval to a freshly-deployed spender — stopping the drain before it happens, from the same evidence base.
04
ERC-721/1155 operator approvals, and the delegation patterns used by account abstraction wallets.
05
A multicall so closing a family costs one wallet confirmation instead of six.
06
Open this reconstruction from inside the drain warning a wallet already shows — the same evidence, at the moment a person is still looking.
Anchrion
Public chain data only. No wallet, no API keys, five networks. MIT licensed.
It never asks for a private key and cannot move your funds. Revoking sends a transaction your own wallet signs, and the allowance is read back from the token contract afterwards.