YOUR WALLET. YOUR PERIMETER.

Permission is a bridge.
Control the crossing.

See who can reach your tokens.
Close the access you no longer need.

Check your wallet No signature to scan

READING PUBLIC WALLET

Every bridge comes from a real permission.

Move the light. Inspect a bridge.
Click a red crossing to preview a revoke.

Finite approval Broad / flagged accessBlue is not a safety verdict. Boats illustrate threats.

BUILT WITH GOLDSKY · GOPLUS SECURITY · ZERODEV

Find the access. Read the context.
Close it on your terms.

Goldsky indexes approvals. GoPlus Security checks spender and operator addresses. ZeroDev powers a sponsored revoke batch on Robinhood Chain, when your wallet supports it.

01 / INVENTORY

Goldsky

Indexed approval history, checked against the token contract.

Checking Goldsky availability…
02 / CONTEXT

GoPlus Security

Address intelligence for every spender and operator.

Checking the public tier…
03 / REVOKE

ZeroDev

One reviewed batch. Sponsored gas. Your wallet keeps its address.

Checking ZeroDev availability…
LIVE ADDRESS CHECK / 4663

A real contract. A fresh check.

Uniswap V2 Router on Robinhood Chain. A public reference address, not your wallet.

0x89e5db8b5aa49aa85ac63f691524311aeb649eba
What powers MOAT ↗
Waiting for GoPlus Security

A live response will appear here with its source and check time.

View GoPlus source response ↗

One view. Three networks.

◈ Robinhood Chain◇ Ethereum● Base
Network details ↗
Ring 01 · Start with your address

See what you left open.

A clear view of your active approvals.
Read the reasons. Make your own call.

  APPROVAL SCANNER
READ FIRST. SIGN ONLY TO REVOKE.
Read-only scan. No signature. No token needed.

Who still has access?

Find active token and operator permissions, then decide what stays.

ERC-20 / ERC-721 / ERC-1155

Inventory from Goldsky when configured, with public RPC fallback and contract checks. Live spender context from GoPlus Security. Additional context from ScamSniffer, MetaMask and public contract lists. Loading source dates.

Ring 02 · From the outside in

Three rings around your wallet.

Approving an app can leave a lasting connection to your wallet. MOAT helps you see it, understand it, and close it.

01SCAN

Trace the permissions.

MOAT reads approval events from chain history, starting at block zero.

01 · SCAN · EVERY APPROVAL EVENT02 · JUDGE · LIVE STATE AND REASONS03 · REVOKE · CLOSE AND RECHECK
02JUDGE

Check what is still open.

Each permission is checked against the token contract. Revoked permissions drop out. Every score lists its reasons.

03REVOKE

Close the connection.

Review the change in your wallet. Once confirmed, MOAT checks that the permission is gone.

Why we built MOAT

Keys are only
part of the story.

On 24 September 2026, attackers compromised Bitget's wallet backend and spoofed unsigned transaction data. Its own approval process signed the transfers. Private keys were not stolen.

MOAT focuses on a different, everyday boundary: the spending permissions attached to your wallet. It does not inspect exchange backends or prevent that attack.

Reported impact and recovery

Reports put losses at roughly $352 million to $387 million. The attack was attributed to Lazarus. Bitget's protection fund covered user funds. Withdrawals reopened in stages from 28 September.

Withdrawal update ↗
01 / COMPROMISED BACKEND×
02 / SPOOFED TRANSACTION DATA×
03 / EXCHANGE APPROVAL PROCESS↗

A diagram of the reported mechanism. Not a MOAT detection result.

The MOAT token

The tool comes first.

NOT LAUNCHED / ROBINHOOD CHAIN

Check permissions without holding $MOAT. The token has not launched, and there is no official contract address yet.

No token is required to scan or revoke. Network gas still applies.

Your wallet stays yours

Choose your wallet.

Connecting shares your public address. Scanning never asks you to sign.

You can also paste an address for a read-only scan.

Review the change

Close this permission?

Your wallet will show the transaction and network fee. You pay gas. MOAT does not charge a revoke fee.