XPR Network · Security Utility · by ProtonNZ

Remove a wallet-drainer permission from your account.

Tricked by a fake XPR airdrop (like xprdrop.com)? A hidden permission may still let an attacker drain you. This tool finds it and removes it in one signed transaction. Non-custodial — it never touches your keys.

Shipped by ProtonNZ within hours of the scam being reported
01 · Connect 02 · Review findings 03 · Remove
Prefer not to connect? Audit any account read-only: 

🛡️ Verify before connecting: announced by @protonnz on X · served only from protonnz.com · source on GitHub. Never trust a copy on another domain.

🚫 Two rules that stop this attack

How the scam works

You sign it yourself — no key is stolen

It's a permission-delegation drainer. You authorize it by signing what looks like an airdrop "claim".

You receive an unsolicited token (e.g. XPRDROP) whose memo advertises an airdrop site.
"Claiming" on the site makes you sign a transaction creating a permission (usually claim) controlled by the attacker and linked to your token transfers — sometimes your unstaking too.
Seconds later they drain you. It's a persistent permission, so they can drain you again when new funds arrive — until you delete it. That's what this tool does.
⚠️ The lure in your wallet — an unsolicited XPRDROP token whose memo links to the fake site. Receiving it is harmless; never open the link.
Scam token: xprdrops sends 1,000 XPRDROP, memo linking to xprdrop.com
⚠️ The fake site itself (annotated). A page asking you to connect and "claim" an allocation — close it. It exists only to make you sign the drainer permission.
The fake xprdrop.com phishing site, marked WARNING - FAKE
How this tool helps

It inspects every permission and linked action on the account, flags anything controlled by an account that isn't you, and — if it finds the malicious permission — builds one transaction (unlinkauth per link, then deleteauth) for you to sign. No backend; it can only remove permissions, never move funds.

Trust check. This tool is the mirror image of the scam: it asks you to connect and sign an auth transaction — but only to remove access, never grant it. Every action is shown before you sign. If you hold staked XPR, clean up FIRST, then unstake (explained after the audit).