$DRAINCHECK6FRvn9KWeDDEzWngdxKw3vDv39ZYc2GUT5a24oAZpumpBuy
Drainer Check

Lab online

Wallet-drainer lab · Solana + EVM

Know what a link wants you to sign.

Paste any link. A sandboxed browser opens it as a decoy wallet, presses the buttons a victim would press, and decodes every signature request into plain English.

Opened on our server, never on your device. Nothing is ever signed.

SPECIMEN 0418 SANDBOX · JITLESS · GUARDED hxxps://claim-season2[.]example Season 2 rewards are live 2,500 JUP Claim airdrop PHANTOM · signTransaction System Program · Transfer 24.68 SOL → 7xKX…gAsU ALL of your SOL REFUSED · NOTHING SIGNED VERDICT DRAINER LOCKED · 7.1 s

Links scanned

4

Drainers caught

0

Flagged suspicious

1

Per scan, at most

25s

How it works

Five steps, about twenty seconds.

  1. 01

    Quarantine

    The link opens on our server, never on your device: a fresh Chrome with its own empty profile, its sandbox on, no JIT, and every request checked by a guard that refuses private networks.

    ISOLATION · SCAN 25 s MAX

    • Profilefresh, deleted after
    • Chrome sandboxon
    • JavaScript JIToff (jitless)
    • Networkguard proxy only
    • Private rangesrefused
    • Traffic cap50 MB
    • Downloadsrefused
  2. 02

    A decoy wallet

    Before the page runs a line of code it finds Phantom, Solflare, Backpack and MetaMask. They are decoys: they approve the connection, show a believable balance, and record every call.

    DECOY WALLETS INJECTED

    • PhantomFsh4…ndSz
    • SolflareFsh4…ndSz
    • BackpackFsh4…ndSz
    • Wallet Standardregistered
    • MetaMask0x7a74…fb96
    • Decoy balance24.683 SOL · 3 tokens
    • Private keynone exists
  3. 03

    Press the buttons

    Connect. Claim. Verify. Mint. The lab presses what a victim would press, with real mouse events, and waits for the site to show its hand.

    BUTTONS PRESSED

    1. 00:03.9 Pressed "Connect Wallet"
    2. 00:04.3 connect() approved, decoy address shown
    3. 00:06.2 Pressed "Claim 2,500 JUP"
    4. 00:07.1 signTransaction requested
    5. 00:07.4 Refused: User rejected the request
  4. 04

    Decode the ask

    Every transaction and message is read instruction by instruction: transfers, approvals, ownership changes, Permit2 batches, sign-ins for other sites. Then it is refused.

    DECODED · LEGACY TRANSACTION

    • Compute Budgetlimit 1,400
    • Compute Budgetprice 50,000
    • System · Transfer24.6829 SOL
    • To7xKX…gAsU
    • Share of balance100%

    Would send ALL your SOL to 7xKX…gAsU

  5. 05

    Lock the verdict

    Drainer, Suspicious, or No drainer behaviour seen. With the evidence: the decoded requests, screenshots, domain facts and the redirect chain.

    VERDICT

    Drainer
    Suspicious
    No drainer behaviour seen

Recently flagged

Caught on the bench.

Addresses are defanged and never linked, so this page can't send anyone to them. Each row opens our report.

Three answers

Evidence first. Then a word.

Verdict

Drainer

The site asked the wallet to sign something that would move or hand over its assets: all its SOL, a token sweep, an unlimited approval, an ownership change, a Permit2 batch. Or it asked for the recovery phrase.

Verdict

Suspicious

No drain request was seen, but strong signs were: a lookalike domain, a known drainer kit in the code, a sign-in for another site, a clipboard trick, a blind signature.

Verdict

No drainer behaviour seen

Nothing the site asked for would take the wallet's assets. Not proven safe: drainers can wait, target other wallets, or show a different page to different visitors.