Live on-chain data · open source · no API key

Chainlens — Wallet & Smart-Contract Risk Scanner for Ethereum, Base, Arbitrum, OP & Polygon

Chainlens is an open-source risk scanner for EVM wallets and smart contracts. Paste an address or ENS name and it reads live on-chain data — transaction history, token approvals, proxy admin slots, owner() and EIP-7702 delegations — then flags approvals to phishers, address poisoning, flagged counterparties, brand-new unverified contracts and admin keys that can mint, freeze or upgrade, in a plain-English report with evidence.

Scan an address ↓View on GitHub

Scan a wallet or contract

Real data, read live from the chain. Try a sample or paste any address — it never asks you to connect a wallet or sign anything.

Chainlens · live on-chain scanreal chain data · no API key · no wallet connection

What Chainlens checks

The ways wallets actually get drained — and the trust assumptions hiding inside “legit” contracts.

Wallets

  • Live approvals to flagged spenders — decoded from calldata, re-checked with allowance() so revoked ones stay quiet
  • Approvals to EOAs or unverified code — including setApprovalForAll and Permit2 approvals
  • Address poisoning — lookalike addresses planted via zero-value transferFrom or fake-token dust — and payments sent to them
  • EIP-7702 delegation — whose code the account now runs, and whether it's verified or flagged
  • Flagged counterparties & scam airdrops — against Blockscout's public Phish / Hack and scam registry
  • Fresh unverified contracts — called within a week of deployment — worse if they got funds or an approval

Contracts & tokens

  • Unverified source or implementation — a black box you can't audit — critical when a proxy hides it
  • Upgrade admin — read from the EIP-1967 / legacy OpenZeppelin slot; single-key (EOA) admins flagged high
  • Admin powers — mint, blacklist / freeze, fee or tax setters, trading switches, pause — only if the source shows an access-control guard
  • Ownership — owner() read live: single key, contract (multisig / timelock) or renounced
  • Holder concentration — one private wallet holding more than 20% of a token's supply
  • Age, lure names & deployer — days-old contracts, 'Visit … to claim' names, flagged deployers

How does Chainlens work? Collect → analyse → report

Network I/O is isolated in one stage; the analysis is pure, replayable and eval-gated.

1 · Collect

network, isolated

Blockscout's REST API supplies history, labels and verified source; the public tag registry adds Phish / Hack and scam labels; one batched JSON-RPC call reads allowance(), isApprovedForAll(), Permit2 allowances, proxy storage slots, owner() and account code. Everything lands in a plain-JSON snapshot.

2 · Analyse

pure functions

22 checks run over the snapshot with no network and no clock — ages are measured against the snapshot's own timestamp — so the same snapshot always produces the same findings. That's what makes the eval suite replayable.

3 · Report

grade + plain English

Findings roll up into an A–F grade and a verdict that separates “looks malicious” from “centrally controlled”. Every finding carries explorer-linked evidence and a concrete fix. It never says “safe”: the best verdict is “no red flags in what Chainlens checked”.

Zero dependencies

hand-written ABI layer

Calldata decoding, view-call encoding and storage-slot reads are ~200 lines of TypeScript. The tests re-derive every function selector and EIP-1967 slot with keccak256 and round-trip viem-encoded calldata through the decoder.

Eval-gated: 35 cases, 100% recall, zero false positives

  • 30 attack scenarios — drainer approvals, zero-value-transfer poisoning, a paid lookalike, EIP-7702 takeovers, honeypot and rug-pull profiles — plus negatives that must stay quiet (revoked approvals, near-miss addresses, a developer calling their own new contract, a Safe proxy).
  • 5 live mainnet fixtures — USDC on Ethereum and Base, Uniswap SwapRouter02, a registry-flagged phishing contract and the 2015 EthDev multisig — recorded from the real chain and replayed offline.
  • Results: 100% recall, 100% severity accuracy, 0 of 41 false-positive guards tripped, 100% grade accuracy.

The gate earned its keep during development: it caught a phishing contract being treated as “established” because its lure name looked like a label, and a transfer() function mis-marked as admin-only because the source scan ran past its closing brace.

Limits, stated plainly

  • It reads a recent window — the latest 100 outgoing transactions and 50 token transfers each way — so a very old, never-touched approval can be missed.
  • Off-chain signatures are invisible until used: an EIP-2612 permit or Permit2 signature doesn't show up on-chain before it's spent.
  • Known-bad labels come from Blockscout's public registry; a brand-new, untagged drainer is caught only by the structural checks (unverified, fresh, approval to an EOA).
  • The source checks are targeted patterns, not a Solidity parser. A report is a fast first pass, not an audit.

Frequently Asked Questions

What is Chainlens?

Chainlens is an open-source risk scanner for EVM wallets and smart contracts. Paste an address or ENS name and it reads live on-chain data — transaction history, token approvals, proxy admin slots, owner() and EIP-7702 delegations — then flags approvals to phishers, address poisoning, flagged counterparties, brand-new unverified contracts and admin keys that can mint, freeze or upgrade, in a plain-English report with evidence.

How do I check if my wallet has risky token approvals?

Paste your address or ENS name into Chainlens. It decodes the approve, increaseAllowance, setApprovalForAll and Permit2 approvals in your recent transactions, re-reads each one's live allowance on-chain, and flags the ones still active to flagged addresses, plain wallets (EOAs), unverified contracts, or unlimited amounts — with a link to the approving transaction so you can revoke it.

What is address poisoning and how does Chainlens detect it?

Address poisoning is when an attacker generates an address matching the first and last characters of someone you pay, then plants it in your history with a zero-value transfer or fake-token dust, hoping you copy it next time. Chainlens compares the recipients you genuinely paid with every address that appeared in transfers you didn't initiate; a match on the first and last four hex characters (about a 1-in-4-billion coincidence) is flagged, and paying two lookalikes is flagged as critical.

What is an EIP-7702 delegation, and why does Chainlens check it?

Since Ethereum's Pectra upgrade, EIP-7702 lets a normal wallet (EOA) delegate its account code to a smart contract — that's how smart-account features work. It is also how 'sweeper' drainers take over wallets. Chainlens reads the account's code, extracts the delegate address from the 0xef0100 designator, and flags delegations to unverified or flagged code as critical.

Why does Chainlens give USDC a C grade?

Because the grade measures risk to a holder, not legitimacy. Chainlens finds no scam signals in USDC, but it does find that the proxy's upgrade admin is a single-key account and that privileged roles can mint, blacklist and pause — normal for a regulated stablecoin, and exactly what a holder should know they are trusting. The verdict says so explicitly: “No scam signals — but this contract is centrally controlled.”

Do I need to connect my wallet or give an API key?

No. Chainlens only reads public data: Blockscout's public API and public JSON-RPC nodes, all keyless. It never asks for a signature, a wallet connection or a private key — and you should be suspicious of any 'scanner' that does.

Which chains does it support?

Ethereum, Base, Arbitrum One, OP Mainnet and Polygon PoS. ENS names resolve on Ethereum; Basenames resolve on Base.

Is a Chainlens report a security audit?

No. It is an automated first pass over public data. It scans a recent window of activity, can't see off-chain signatures such as EIP-2612 permits until they're used, and relies on community labels for known-bad addresses. Its value is catching the common, costly mistakes fast — not replacing an audit.