What is Chainlens?
Chainlens is an open-source risk scanner for EVM wallets and smart contracts. Paste an address or ENS name and it reads live on-chain data — transaction history, token approvals, proxy admin slots, owner() and EIP-7702 delegations — then flags approvals to phishers, address poisoning, flagged counterparties, brand-new unverified contracts and admin keys that can mint, freeze or upgrade, in a plain-English report with evidence.
How do I check if my wallet has risky token approvals?
Paste your address or ENS name into Chainlens. It decodes the approve, increaseAllowance, setApprovalForAll and Permit2 approvals in your recent transactions, re-reads each one's live allowance on-chain, and flags the ones still active to flagged addresses, plain wallets (EOAs), unverified contracts, or unlimited amounts — with a link to the approving transaction so you can revoke it.
What is address poisoning and how does Chainlens detect it?
Address poisoning is when an attacker generates an address matching the first and last characters of someone you pay, then plants it in your history with a zero-value transfer or fake-token dust, hoping you copy it next time. Chainlens compares the recipients you genuinely paid with every address that appeared in transfers you didn't initiate; a match on the first and last four hex characters (about a 1-in-4-billion coincidence) is flagged, and paying two lookalikes is flagged as critical.
What is an EIP-7702 delegation, and why does Chainlens check it?
Since Ethereum's Pectra upgrade, EIP-7702 lets a normal wallet (EOA) delegate its account code to a smart contract — that's how smart-account features work. It is also how 'sweeper' drainers take over wallets. Chainlens reads the account's code, extracts the delegate address from the 0xef0100 designator, and flags delegations to unverified or flagged code as critical.
Why does Chainlens give USDC a C grade?
Because the grade measures risk to a holder, not legitimacy. Chainlens finds no scam signals in USDC, but it does find that the proxy's upgrade admin is a single-key account and that privileged roles can mint, blacklist and pause — normal for a regulated stablecoin, and exactly what a holder should know they are trusting. The verdict says so explicitly: “No scam signals — but this contract is centrally controlled.”
Do I need to connect my wallet or give an API key?
No. Chainlens only reads public data: Blockscout's public API and public JSON-RPC nodes, all keyless. It never asks for a signature, a wallet connection or a private key — and you should be suspicious of any 'scanner' that does.
Which chains does it support?
Ethereum, Base, Arbitrum One, OP Mainnet and Polygon PoS. ENS names resolve on Ethereum; Basenames resolve on Base.
Is a Chainlens report a security audit?
No. It is an automated first pass over public data. It scans a recent window of activity, can't see off-chain signatures such as EIP-2612 permits until they're used, and relies on community labels for known-bad addresses. Its value is catching the common, costly mistakes fast — not replacing an audit.