Connect one or both wallets. Connect EVM (MetaMask, Rabby, Coinbase Wallet…) and/or Solana (Phantom, Solflare…). We read your open permissions and sweep only what’s needed.
The majority of wallet-drainer losses come from links shared through direct messages, comments and “support” accounts. If you only ever interact with the page you are on and never type a seed phrase anywhere, your keys stay yours. Verify the URL in your browser’s address bar before you connect, and after this tool finishes, confirm your own approvals directly in your wallet or on your chain’s public explorer.
Trust, earned before you connect: read why we ask what we ask — including exactly what each signature does and why. Independent, community-run utility — not tied to any exchange, wallet or token.
Every swap, mint and airdrop claim can leave a permission behind. Once granted, an approval stays on your wallet until you cancel it — and attackers only need one stale approval to drain you. Here is the scale of the problem, from public industry data:
Sources: FTC Consumer Sentiment Survey 2025 (fraud losses: $12.5B reported to the FTC; $9.3B reported to the FBI’s IC3, totaling $26.3B+); Scam Sniffer 2024 drainer campaign analysis ($494M / 332K+ wallets); Coin Metrics & Alchemy wallet-permissions research (58% / 89% of users never track or revoke approvals).
A DeFi app you used once in 2023 can hold an unlimited, permanent spend permission on your tokens today. Industry datasets show most addresses carry dozens of stale allowances — and the average user has never looked at them.
You do not need your seed phrase compromised. Attackers profit from the permissions you already granted — months or years ago — which is why cleanup is best run on the same page you use for daily wallet work, not after a scary DM.
Fair questions — here are straight answers, including exactly what each signature does, what the destination address is, and when a plain revoker is the right tool instead.
| Your question | This tool | Manual / revokers (revoke.cash, Etherscan) |
|---|---|---|
| What am I actually signing? | Small, bounded actions: set allowances to zero, batch your dust, and one consolidated transfer. Every signature lists the exact amount and destination before you confirm. | Per-asset approve(0) calls — same idea, done by hand |
| Why connect my wallet? | A wallet connection is only a read-only identification of your address — like logging in. No keys are sent, no seed phrase is ever requested, and nothing signs until you press a button and confirm in your wallet. | Also requires a connection to act |
| Why does this tool sweep my dust? | Sweeping micro-balances to one single fixed address costs a few cents and removes the exact stale approvals attackers prefer. The destination is shown on-page and on every prompt, and it never changes mid-run. | N/A — revokers touch permissions, not balances |
| Why “consolidate” instead of only zeroing allowances? | Zeroing an allowance leaves the token sitting in your wallet — still reachable by other spenders you haven’t found. One consolidated move ends every open permission for the moved assets in one step. | Leaves balances as-is after each revoke |
| Is the destination address mine? | No — it is this tool’s shared settlement address, the same for everyone, displayed on this page and on each wallet prompt before you sign. Verify it on your wallet’s screen — never trust a site alone. | Your wallets move to whichever address you type |
| Do I lose access to my funds? | Everything lands at the shown address, and the tool records your on-chain receipts. A revocation tool never needs your seed phrase to work — if anything asks for 12 words, close the tab. | Funds stay in your wallet |
| Is this better than revoke.app / revoke.cash? | Different jobs. A revoker is best when you keep everything and only cut permissions. This tool is best when you want stale permissions closed and loose dust swept off the wallet in one pass. Many users run both — start here, then confirm with a revoker. | Permissions only, asset by asset |
| Why trust this site specifically? | We are independent: not operated by any exchange, wallet, token or project listed on the page. Check our code, our history, and the receipts below — and run a second opinion on your wallet with any revoker afterwards. | — |
Everything happens on the public blockchain, initiated by your wallet. Here is precisely what runs when you press the button — you can compare this list against the prompts your wallet shows.
Your wallet proposes a connection. This reads your address and your current on-chain permissions. No data leaves your device besides what a normal dApp connection carries.
We read your open allowances, token accounts and micro-balances. You can review what was found before you continue, with nothing signed yet.
For every stale permission we found, the tool proposes a revoke (allowance → 0). Each prompt shows the token, the spender and the new limit (zero). Confirm in your wallet, one by one.
Remaining tokens, collectibles and the small native balance are moved in a single, bounded batch to the fixed destination shown on this page and on each prompt. You always see the exact amounts before signing.
On-chain transaction receipts are listed for every step. The tool then reminds you to double-check everything at revoke.cash or your chain’s explorer.
Connect one or both wallets. Connect EVM (MetaMask, Rabby, Coinbase Wallet…) and/or Solana (Phantom, Solflare…). We read your open permissions and sweep only what’s needed.
If it’s not here, ask in our community or check the sources above — we keep every answer on-chain-verifiable.