Remove a wallet-drainer permission from your account.
Tricked by a fake XPR airdrop (like xprdrop.com)? A hidden permission may still let an
attacker drain you. This tool finds it and removes it in one signed transaction. Non-custodial — it never
touches your keys.
Shipped by ProtonNZ within hours of the scam being reported
01 · Connect02 · Review findings03 · Remove
Prefer not to connect? Audit any account read-only:
🛡️ Verify before connecting: announced by
@protonnz on X ·
served only from protonnz.com ·
source on GitHub.
Never trust a copy on another domain.
Cleanup transaction — review before signing
Show raw actions (JSON)
🚫 Two rules that stop this attack
Never open a link from a token memo. Scammers airdrop tokens whose memo links to fake sites.
There are no free XPR airdrops. If a site says you can "claim" thousands of $XPR — it's a scam.
How the scam works
You sign it yourself — no key is stolen
It's a permission-delegation drainer. You authorize it by signing what
looks like an airdrop "claim".
You receive an unsolicited token (e.g. XPRDROP) whose memo advertises an airdrop site.
"Claiming" on the site makes you sign a transaction creating a permission (usually claim)
controlled by the attacker and linked to your token transfers — sometimes your unstaking too.
Seconds later they drain you. It's a persistent permission, so they can drain you again when new
funds arrive — until you delete it. That's what this tool does.
⚠️ The lure in your wallet — an unsolicited XPRDROP token whose memo links to
the fake site. Receiving it is harmless; never open the link.⚠️ The fake site itself (annotated). A page asking you to connect and "claim" an allocation
— close it. It exists only to make you sign the drainer permission.How this tool helps
It inspects every permission and linked action on the account, flags anything controlled by
an account that isn't you, and — if it finds the malicious permission — builds one transaction
(unlinkauth per link, then deleteauth) for you to sign. No backend; it can only
remove permissions, never move funds.
Trust check. This tool is the mirror image of the scam: it asks you to connect and sign an auth
transaction — but only to remove access, never grant it. Every action is shown before you sign. If you
hold staked XPR, clean up FIRST, then unstake (explained after the audit).