Remove a wallet-drainer permission from your account.
Tricked by a fake XPR airdrop (xprdrop.com, xprgrant.com, or whatever domain it's on next — it keeps rotating)? A hidden permission may still let an
attacker drain you. This tool finds it and removes it in one signed transaction. Non-custodial — it never
touches your keys.
01 · Connect02 · Review findings03 · Remove
Prefer not to connect? Audit any account read-only:
🛡️ Verify before connecting: announced by
@protonnz on X ·
served only from protonnz.com ·
source on GitHub.
Never trust a copy on another domain.
Cleanup transaction — review before signing
Show raw actions (JSON)
🚫 Three rules that stop this attack
Never open a link from a token memo. Scammers airdrop tokens whose memo links to fake sites.
Never scan a QR code from an airdropped NFT. A new lure mints you an "XPR Reward Voucher" NFT whose image is a QR code — it leads to the same drainer.
There are no free XPR airdrops. If a site says you can "claim" thousands of $XPR — it's a scam.
How the scam works
You sign it yourself — no key is stolen
It's a permission-delegation drainer. You authorize it by signing what
looks like an airdrop "claim".
You receive an unsolicited token (e.g. XPRDROP) whose memo advertises an airdrop site.
"Claiming" on the site makes you sign a transaction creating a permission (usually claim)
controlled by the attacker and linked to your token transfers — sometimes your unstaking too.
Seconds later they drain you. It's a persistent permission, so they can drain you again when new
funds arrive — until you delete it. That's what this tool does.
⚠️ The lure in your wallet — an unsolicited XPRDROP token whose memo links to
the fake site. Receiving it is harmless; never open the link.⚠️ The fake site itself (annotated). A page asking you to connect and "claim" an allocation
— close it. It exists only to make you sign the drainer permission.How this tool helps
It inspects every permission and linked action on the account, flags anything controlled by
an account that isn't you, and — if it finds the malicious permission — builds one transaction
(unlinkauth per link, then deleteauth) for you to sign. No backend; it can only
remove permissions, never move funds.
New lure — the "XPR Reward Voucher" NFT
A QR code in your NFTs instead of a link in a memo
Same attacker, new delivery. Instead of a token memo, they now mint an NFT
called "XPR Reward Voucher" straight into your wallet. Its image is a QR code and its description says
"Scan the QR to open the claim portal." The QR points to the same drainer — now hosted on IPFS so there's no
website to shut down.
Holding it is completely harmless. An NFT sitting in your wallet can't touch your funds. The danger is
only if you scan the QR, open the portal, and sign.
Do not scan the QR code. There is no reward voucher. Scanning leads to the same "claim" page that makes
you sign the drainer permission.
You don't need to remove it to be safe — you can just ignore it.
"I tried to burn it but it's still in my wallet"
The NFT is burnable — there's no on-chain trick keeping it. The catch is that some
wallets' "hide" or "remove" option doesn't actually burn the asset, so nothing happens on-chain and it reappears.
If you want it gone for good, burn it from AtomicHub (open the asset → Burn) rather than hiding it in the
wallet. Either way, leaving it alone is safe — it does nothing on its own.
Already scanned the QR and signed something? The audit above finds and
removes the malicious permission — it's the same fix.
Trust check. This tool is the mirror image of the scam: it asks you to connect and sign an auth
transaction — but only to remove access, never grant it. Every action is shown before you sign. If you
hold staked XPR, clean up FIRST, then unstake (explained after the audit).