Every Anchrion score is the sum of the weights below. It is a transparent rule set, not a trained model and not a third-party threat feed. You can recompute any score by hand from the numbers in the row detail, and you should feel free to argue with it.
Read from the token contract: allowance is at or above 2^255. No cap means the whole balance of that token is reachable.
A cap exists, but it is larger than one million units of the token. Capped does not mean small.
`eth_getCode` returned nothing. The spender is an externally-owned account or a self-destructed contract. A permission granted to a non-contract is not a normal protocol permission.
The block explorer publishes its own scam flag for this address. Anchrion is not the source: it ships no threat intel, it only reads the flag the explorer already shows. Where the explorer reports nothing, this weight adds nothing and the UI says not reported.
The explorer holds no verified source for the spender, so nobody outside the deployer can confirm what it does with the permission.
Deployment age comes from the creation transaction. New contracts have no track record.
Only fires for addresses you supply through NEXT_PUBLIC_THREAT_LIST. Anchrion ships no threat feed of its own.
What the permission can actually move — the smaller of its allowance and this wallet’s live token balance — multiplied by a USD price. Price is live when reachable, otherwise a dated static snapshot, and the value is labelled an estimate either way. An unlimited permission is not scored on a dollar figure: unlimited is already scored above, and its reachable amount is today’s balance rather than what the permission permits.
Derived from the last observed transfer of that token for this wallet. Dormant permissions are the ones people forget they granted.
A small bundled list of well-known routers, matched by contract address. Only an address match earns the discount: a name the explorer reports cannot move a score, because whoever deploys a contract chooses that name. A name on the list is still not a safety guarantee.
Total is clamped to 0–100. Critical is 70 and above, high 50–69, medium 30–49, low 10–29, and anything below 10 is shown as safe. A score of zero means no measurable signal fired — it does not mean the permission is harmless, and the UI says so.
Public JSON-RPC endpoints for live allowance, bytecode, and log reads, and keyless Blockscout explorer endpoints for transaction history, contract verification, and deployment age. Value-at-risk prices come from CoinGecko when reachable, with a dated static snapshot as a labelled fallback. No API key is required to run Anchrion with full functionality.