Start with an address.
Paste any public 0x address and choose the network. Scanning reads public data. No signature. No token needed.
Every result begins with a public event and ends with a contract read. Here is what happens in between.
A historical approval only tells you what happened then. MOAT checks the current permission at a named block and keeps that block hash with your scan.
Make your own check ↗Scroll through the four steps. The scene follows each one.
Motion is reduced. Shown: the finished scan with one bridge revoked.
Paste any public 0x address and choose the network. Scanning reads public data. No signature. No token needed.
The scanner requests ERC-20 Approval and ERC-721/1155 ApprovalForAll events for your address from block zero. When an RPC refuses a large window, MOAT divides it and retries each half. No silently skipped blocks. Then it reads allowance or isApprovedForAll at one pinned chain head.
A zero allowance or false operator permission disappears from the result. Failed reads remain visibly unresolved. The score is a review aid, not a probability. An unlabelled spender adds 30 points; effectively unlimited spending or all-item operator access adds 30. A ScamSniffer address match sets 100. The starting score is 10.
Your wallet sends approve(spender, 0) or setApprovalForAll(operator, false) directly to the token contract. MOAT waits for the transaction, checks its status, and reads the permission again before removing the row.
Use Export proof in the scanner. The JSON includes the address, chain, RPC, block, coverage ranges, raw events, checked values and unresolved reads.
Open the scanner ↗Open the token's explorer page from a result. In Read Contract, call allowance with the wallet and spender, or isApprovedForAll with the wallet and operator.
Technical verification steps ↗The hero uses a recorded scan of a public address. Its bridges are counted from real active permissions. The scan date and block make its age visible.
Download the sample JSON ↓Local Anvil forks test the full path: grant permissions, find them, revoke them, and confirm they disappear. Fork transactions do not affect mainnet.
Read test evidence ↗Checking published test evidence.Robinhood Chain 4663, Ethereum 1 and Base 8453. Requests go from your browser to public RPCs. Ethereum uses separate history and state providers, cross-checked at the same block. Public endpoints can limit or refuse history.
RPC URLs and network references ↗Exact address matches from its public scam database. The public list has a seven-day publication delay. Absence from the list does not establish safety.
Open address source ↗Loading source date.A domain blocklist, not a spender address list. MOAT checks domains attached to known labels against this data. Unknown contracts have no inferred domain.
Open domain source ↗Loading source date.A small, chain-specific reference list from protocol deployment documentation. Unlisted spenders appear as Unknown contract. A familiar name is not a safety guarantee.
Inspect labels and citations ↗Built with open standards and public data. No implied partnership.