1 / 12

Anchrion

See how a drain happened.
Then close what is still open.

Paste any wallet address. See the permission that moved the funds — and what the same address can still reach.

Live: anchrion.sithunyein.com github.com/thesithunyein/anchrion 3rd-Web-Hack · Blockchain / Open Ended Web

Problem

A drain takes seconds. The hour after it takes hours.

Who has this problem. Someone whose wallet was emptied by a transaction they did not sign — which means no private key was stolen. A permission they granted once, months ago, was used to move the tokens.

What they have to work with today. An empty wallet, a transaction they cannot read, and eleven permissions left — three of them unlimited — with no way to tell which one was spent, or whether the same address can still reach the rest.

The question nobody answers. Not "is this signature dangerous?" and not "what have I approved?". The unanswered one is:

Which permission was used against me — and can it still reach me?

They solve it by hand: scrolling a block explorer, matching an outflow to a token contract, guessing at an allowance page that lists everything the wallet ever granted, and revoking whichever name looks most suspicious — usually after the second drain, not before it.

Problem

The tools people already have are answering different questions.

Each row is what that product is built to answer, taken from its own published description. These are mature, working tools — simulation is why drainer losses fell. This is a different hour of the same day.

Tool Built to answer Warns before you sign Revokes Names the permission used Rebuilds a past incident
Wallet simulationRabby · MetaMask · Blockaid “Is this signature dangerous?” yes no no no
Revoke.cashinventory + exploit checker “What have I approved?” no yes no no
Etherscantransaction viewer “What did this transaction do?” no no no no
Anchrionpermission reconstruction “Which permission was used against me, and can it still reach me?” no yes yes yes

Anchrion is not preventive, and the table says so in its own row. It is the hour after.

Solution

One address in. The permission, the outflows it explains, and what is still open.

01

Paste an address

Five networks. No wallet, no install, no API keys — so you can inspect an address you do not own, including the one that just drained you.

02

Read the reconstruction

Approvals are read live from each token contract. Outflows are paired with the address that submitted them, and with the permission that made them possible.

03

Revoke, then verify

Connect the wallet that owns the address and sign. The allowance is read back from the contract: a surviving allowance is reported as still allowed, never as a green tick.

Not a wallet replacement, and not a bank. Anchrion never asks for a private key, cannot move funds, and ships no list of malicious addresses. Revoking is a transaction your own wallet signs; Anchrion reads the chain before and after it.

Innovation · 1 of 3

An outflow is evidence only if you can pair it with the permission that let it out.

  • Tokens that left inside transactions the wallet did not send. That is the drain fingerprint: a key was not used, so something else authorised the transfer.
  • The submitting address, named. Not "suspicious contract" — the exact address that landed the transaction, on every row.
  • Whether that address still holds a live permission right now. That is what turns a list of transfers into a containment list.
The part we refuse to overstate. A transfer with no live permission behind it is not proof of theft. A permit signature leaves nothing on chain until it is redeemed, and a transaction the wallet signed itself can be submitted by a relayer. Both look identical to us, so the panel names them instead of accusing — No live permission from this address. Either a permit signature, or a relayed transaction you signed.

A tool that cries theft on ambiguous evidence is worse than one that reports what it measured.

Innovation · 2 of 3

The first drain already happened. The second one is the one we close.

  • Attacker family, not a single address. Approvals are grouped by the address that deployed the spender — falling back to bytecode hash — so a drainer's sibling contracts appear together instead of one at a time.
  • One-click revoke of the whole family, executed sequentially and verified one by one, because a batch that reports success while allowances survive is how people get drained twice.
  • Exposure that is measured, never estimated up. Exposure is capped at the wallet's real balance, so an unlimited permission cannot produce a scary number that is not actually reachable.

Live, on mainnet

768,161.778096 USDC

One real permission on a real wallet, read from the token contract and matched against an independent eth_call during review.

Reachable through it

$540,082

Capped at the wallet's balance, priced live — the figure a person needs in order to decide whether to act now.

Innovation · 3 of 3

“Not measured” is not “safe” — and the product says so in the interface.

Every scan ships with the list of checks that ran and the ones that could not be completed. It is the difference between a scanner you trust and one that looks complete.

  • How many transactions, token transfers and approval events were actually decoded.
  • The log window that was validated as complete, and a note when a wider range was answered but demonstrably incomplete.
  • How many allowance pairs were read on chain, and how many permissions were granted and later revoked.
  • Risk factors are tagged detected or estimated, so a heuristic can never launder itself into a measurement.
  • Money and score are separate numbers: a $540,000 permission scores 15 when no danger signal fired. Correct — and the page says to read the two together.
  • An empty result is presented as a measurement, with the coverage panel attached, not as a failure or an all-clear.

Technical feasibility

It runs from a fresh clone with no signup, no key and no indexer.

  • Reads. Live allowance per token via eth_call, spender bytecode, deployment age and verification status, and owner-filtered approval logs — over public RPC with measured fallbacks, plus keyless explorer endpoints for history.
  • Writes. The only transaction is the one your wallet signs to set an allowance to zero. There is nothing to trust Anchrion with.
  • Networks. Ethereum, Base, Arbitrum One, Optimism and Sepolia — every endpoint probed for capability before it was added, and endpoints that silently truncate log queries are deliberately excluded.
  • Pricing. Live values with a dated static snapshot as a labelled fallback, so "unpriced" is never rendered as zero.
  • Reproducible. Scripts recompute a scan's coverage numbers independently, and the published risk model lets anyone recompute a score by hand and argue with it.
  • Stack. Next.js 16, TypeScript, viem and wagmi, MIT licensed, single repository, deployed and live.

Impact

Every hour a live permission stays granted is an hour it can be spent again.

For the victim

Hours → minutes

The manual job — explorer, token contract, allowance page, guesswork — becomes one scan with the permission named and the exposure priced.

At risk per wallet

$540,082

Measured on one real address during review, reachable through a single permission that was still granted at the time of the scan.

Cost to run

$0

No API keys, no signup, no paid indexer. A tool that needs a subscription is not available at 3am on the worst night of someone's year.

What we do not claim. Anchrion cannot recover funds, and it reports no adoption numbers because it has none yet. The impact today is that what is still reachable becomes a measurement a person can act on, and that a second drain can be closed before it happens. Honest reach beats an invented metric.

Limits

The boundaries are part of the product, not an omission.

  • ERC-20 allowances only. ERC-721 and ERC-1155 approvals are not covered today.
  • Off-chain permits are invisible. Permit2, ERC-2612 and Seaport signatures leave no trace on chain until they are redeemed, so no scanner can see them from here — including this one.
  • History is bounded. Approval events are read over a validated block window; a permission older than the readable window that never touched the wallet's history can be missed, and the coverage panel says so.
  • No threat feed. Anchrion ships no list of malicious addresses and will not call an address an attacker without on-chain evidence. That is a deliberate limit, not an oversight.

Future scope

The next three things, in the order they unlock the most.

01

Permit reconciliation

Match Permit2, ERC-2612 and Seaport nonces to outflows, so the ambiguous rows in the reconstruction become attributable instead of named as unknown.

02

Full history, not a window

A self-hosted log index so an old permission is always in reach, and the coverage panel stops needing a bound to disclose.

03

Watch mode

Standing consent to alert on a new unlimited grant or a fresh approval to a freshly-deployed spender — stopping the drain before it happens, from the same evidence base.

04

NFT and smart-account approvals

ERC-721/1155 operator approvals, and the delegation patterns used by account abstraction wallets.

05

Batch revoke in one signature

A multicall so closing a family costs one wallet confirmation instead of six.

06

Where the warning already lives

Open this reconstruction from inside the drain warning a wallet already shows — the same evidence, at the moment a person is still looking.

Anchrion

Understand what happened, and what can still be taken.

Public chain data only. No wallet, no API keys, five networks. MIT licensed.

It never asks for a private key and cannot move your funds. Revoking sends a transaction your own wallet signs, and the allowance is read back from the token contract afterwards.