Everything your wallet holds, and everything it's exposed to. One read-only report.
WalletAudit Pro audits a wallet address you paste, an address and nothing else, across EVM chains: what you hold, and what could hurt you. It never connects to your wallet, never asks you to sign anything, never sees a key or a seed phrase, takes custody of nothing, and keeps nothing after your report is delivered. The remediation is always yours to do, from your own wallet. We just hand you the map.
[ Get the read-only snapshot (no wallet connect, nothing retained) ]
THE PROBLEM
If you've been on-chain a few years, your wallet is carrying history you've lost track of: token approvals you granted to protocols you stopped using (each one a standing withdrawal permission that a compromised or malicious contract can exercise), airdropped dust and scam tokens designed to bait you into a malicious site, and a transaction history that touches counterparties you'd rather not be exposed to. The tools that check this mostly want the one thing you shouldn't give a tool you don't fully trust: a wallet connection. And the portfolio trackers that don't need a connection keep your address and holdings as their asset, forever, which is its own problem. So most people do nothing until a drainer headline scares them, and then they paste into whatever checker ranks first that day.
HOW IT WORKS
You paste a public address. WalletAudit reads public chain data across supported EVM chains (Optimism, Polygon, Linea, Scroll, zkSync, Blast, Mantle, Berachain today, via the same audit components Anya runs for our own wallets) and builds the report in two layers. The holdings layer: native balances and full token inventory per chain, with transaction activity, each item traceable to the chain data it came from. The exposure layer: standing approvals and allowances, dust and scam-token flags, and counterparty risk signals, each finding with its receipt and a confidence label, because a flag is a reason to look, not a verdict. Where a surface can't be decided, the report says undetermined and names why; an undetermined never quietly becomes a clean bill of health.
Structurally: the audit is built exclusively on read-only patterns. The components in our stack that can build transactions exist for other jobs and are declared outside this product's boundary. There is no code path from your report to your funds.
WHAT YOU GET
- the holdings snapshot, per chain: native balance, token inventory, activity, - the exposure report, approvals/allowances, dust/scam flags, counterparty signals, each with its receipt and confidence, - the action list, what you might want to revoke or ignore, stated as security hygiene information; you act from your own wallet, we never do it for you, - the privacy posture, address-only input, no identity linkage, nothing retained after delivery; a re-audit schedule exists only if you explicitly opt in, and you can delete it.
WHO IT'S FOR
Self-custody users with real value spread across L2s and years of accumulated on-chain history. DAOs and small teams auditing treasury and ops wallets on a cadence. People who read the last drainer post-mortem and thought "I should check mine" and then didn't, because every checker wanted a wallet connection. It is NOT for anyone who wants a tool to revoke or move funds for them, and it is not investment advice; the report will never tell you what to buy, sell, or hold.
PRICING (the ladder)
Every number is a hypothesis we validate with you, not a commitment. - Free snapshot, one address, the holdings layer, receipts included. - Pro, a monthly subscription: multiple addresses on a cadence, the full exposure report, history, and change alerts. - Team, treasury and ops wallets on a schedule, shared reports, per-seat.
Any step that takes your money is gated and explicitly confirmed before it runs; nothing charges silently.
THE PROOF (dogfood)
The audit spans this product reuses were built so Anya could audit our own farming wallets across L2s; the 8-chain snapshot exists because we wanted it for ourselves first. Privacy-first is not marketing copy here, it's our standing architecture doctrine (local-first, keys never leave the device, the server sees the minimum), applied to a product whose only input is already-public data. The composition was verified on disk before this page was written.
HONEST NOTE
We would rather under-promise, so here is the whole truth. What exists today, structurally verified: the cross-chain holdings/activity snapshot patterns. What does NOT exist yet: the exposure layer. Approval/allowance enumeration, dust and scam-token flagging, and counterparty risk signals are named, planned pattern work, not built, and no live audit has been run for a customer, or for us, because the chain-data credentials aren't provisioned yet. The first credentialed snapshot on one of our own wallets is the natural next test, and the exposure surfaces ship one at a time as each is built and verified, announced as they land, not before. Until then this page stays a draft and "Pro" stays a waitlist. Also permanent: false negatives and false positives are possible. Indexers lag, token metadata lies, heuristics over-flag and under-flag, and an audit is a snapshot in time. A clean report is not a guarantee of safety. The same discipline that makes us say that is the discipline that keeps this product read-only.
[ Get the read-only snapshot (no wallet connect, nothing retained) ]
*This page is a specification. The capability it describes is not built yet, and nothing here is a claim that it runs today.*