The field guide

Clear enough to use.
Open enough to inspect.

Start with plain language. Switch to Technical for calls, data formats, and verification steps.

Built with Goldsky, GoPlus Security and ZeroDev

What powers MOAT

Three jobs, with a source for each. Partner availability never clears an existing warning.

Goldsky / approval inventory

Indexes ERC-20 Approval and ApprovalForAll events from block zero on Robinhood Chain (4663). Definitions also cover Ethereum (1) and Base (8453). MOAT checks the indexed block against RPC and reads each permission from its token contract. A stale, incomplete or unavailable index falls back to the public RPC reader with a visible note.

Goldsky does not label malicious spenders or guarantee that events describe every possible permission. The immutable event schema is ready for Goldsky webhooks; MOAT does not run background alerts or store a watchlist.

Coverage and indexing docs ↗

GoPlus Security / spender context

Checks every distinct spender and operator found in a scan. Address security covers Robinhood Chain, Ethereum and Base. Approval security adds contract context on Ethereum only in this build. It is not covered on Robinhood Chain or Base. Coverage is checked against the provider before a call.

The public tier needs no key. Requests are paced and throttling is shown. Positive flags raise review priority; an empty, missing or zero-valued response never lowers a deterministic warning. This is intelligence, not a wallet inventory or a safety verdict.

Address security API ↗

ZeroDev / sponsored revoke batch

Uses Kernel and EIP-7702 on Robinhood Chain (4663) to revoke up to 30 selected approvals in one atomic operation at the owning address. An explicit review precedes wallet authorization and signing. ZeroDev must approve gas sponsorship. The receipt and every permission are checked before rows are removed.

Requires an enabled project, a funded gas policy and either an existing Kernel delegation or a native authorization-capable signer. Generic injected wallets cannot install Kernel through this SDK; they can use individual revokes. Delegating smart-account code persists beyond this operation. It does not recover funds or revoke permissions belonging to another wallet. Ethereum and Base use individual wallet-paid revokes in this build. Without project access, the UI says “ZeroDev offline, key pending”.

ZeroDev authorization and batch flow ↗

Goldsky and ZeroDev integrations are built but await owner configuration. GoPlus public calls work without signup. Local fork evidence proves batch execution with a local test sponsor; it does not prove the hosted ZeroDev paymaster accepted a request.

Start with a public address.

Choose a network. Paste an address and select Check permissions, or connect your wallet first. Scanning reads public information and needs no signature. Large histories can take several minutes. Keep the tab open.

Your wallet is the vault. Its address is public, so anyone can read which permissions touch it. Reading needs no signature and cannot move funds. Hover or tap the vault.

Motion is reduced. Shown: the public address tag and a reader on the moat.

Under the surface
The browser requests eth_chainId, pins eth_getBlockByNumber("latest"), then queries logs from block 0 to that head. The same head is used for state calls. The block hash is checked again at the end.

An approval is lasting access.

A token approval lets another address spend up to a limit. An operator permission lets an address move every item you own in one ERC-721 or ERC-1155 contract. These permissions can survive after you stop using an app.

An approval is a bridge you build. One signed transaction stores approve(spender, amount) in the token contract. It stays there after you close the app. Hover or tap the vault.

Motion is reduced. Shown: the key has crossed and the bridge is in place.

The spender sits at the far end. It can pull the approved token, up to the allowance, without asking you again. The token and amount are an example. Tap the tower.

Motion is reduced. Shown: the spender card and tokens that could cross.

Under the surface
ERC-20 Approval events use three topics with the amount in data. ERC-721 token-specific Approval events use four topics and are outside this operator scanner. ApprovalForAll is shared by ERC-721 and ERC-1155. allowance(owner, spender) and isApprovedForAll(owner, operator) determine the displayed state.

Close access you no longer need.

Connect the wallet that owns the permission and use the matching network. Select Revoke, review the token and spender, then approve the transaction in your wallet. You pay the network fee. Revoking does not move your tokens. The app may ask for approval again next time you use it.

Revoking raises the bridge. Your wallet sends approve(spender, 0) to the token contract. Your tokens stay where they are, you pay the network fee, and MOAT reads the allowance again. Tap the red bridge.

Motion is reduced. Shown: the bridge raised and the allowance at zero.

A drainer needs a way in. A malicious spender moves tokens with transferFrom through an allowance you granted. Closing that allowance removes this route. Other risks, like signing a new approval, are outside this picture.

Motion is reduced. Shown: the bridge revoked and the boat turned away.

Under the surface
For tokens: approve(spender, 0). For operators: setApprovalForAll(operator, false). Native value is always 0. Account and chain are checked before sending. The individual revoke path sends separate transactions with separate confirmations. The ZeroDev option sends one reviewed, gas-sponsored batch on Robinhood Chain through EIP-7702 when configured. A failure stops the sequence. Pending transactions remain visible and must be checked before retrying.

A reason, not a verdict.

MOAT prioritizes permissions that deserve a closer look. A flagged address, an unfamiliar spender, or unlimited access can raise the score. Every row explains why. Low scores and recognised labels do not establish safety.

Unlimited means no ceiling. Many apps ask for the maximum value. MOAT treats an allowance of at least 2^255 as unlimited and adds 30 to the review score. With an unknown spender, this example moves from 40 to 70. Drag the slider.

Motion is reduced. Shown: the slider at unlimited.

Under the surface
Score starts at 10. Unknown spender adds 30. Unlimited ERC-20 allowance or all-item operator access adds 30. A ScamSniffer address match sets 100. Unlimited means allowance at least 2^255; the exact base-unit value is always exported. Domain matches use MetaMask data separately. Source failure or stale data is disclosed, not treated as a clean check.

Choose the network you used.

MOAT supports Robinhood Chain, Ethereum and Base. Permissions on one network are separate from permissions on another. Scan each network where you have used apps.

Each network keeps its own permissions. The same address exists on Robinhood Chain, Ethereum and Base, but an approval on one does not appear on another. Bridge counts are examples. Tap a network.

Motion is reduced. Shown: Base selected with only its bridges.

Under the surface
Robinhood Chain / 4663 / https://rpc.mainnet.chain.robinhood.com Ethereum history / 1 / https://rpc.mevblocker.io Ethereum current state / 1 / https://ethereum-rpc.publicnode.com Base / 8453 / https://mainnet.base.org Network references: docs.robinhood.com/chain/add-network-to-wallet, ethereum.org/developers/docs/apis/json-rpc, docs.base.org/base-chain/network-information.

Follow the result back to the chain.

Export a scan or follow the token and spender explorer links. Compare the wallet, contract, spender and block. Repeat the contract read to check the allowance yourself. A later block may show a different result.

The beam is a contract read. For each bridge found in history, MOAT calls allowance or isApprovedForAll at one pinned block. A zero result drops out. Statuses shown are an example. Move the pointer or the slider.

Motion is reduced. Shown: the beam resting on an unlimited bridge.

Under the surface
Use eth_call at the exported toBlock. Encode allowance(owner, spender) with selector 0xdd62ed3e, or isApprovedForAll(owner, operator) with selector 0xe985e9c5. Pad both addresses to 32 bytes. Decode allowance as uint256 and operator permission as bool. Compare blockHash using eth_getBlockByNumber. Review public/js/scanner.js for the exact implementation.

Read the coverage, too.

A complete result covers standard token approvals and operator approvals found in available logs. It does not cover every possible wallet risk. The scan cannot recover assets or reverse transfers, and it does not audit contracts.

IN THIS SCANTOKEN + OPERATOR APPROVALSOUTSIDE THIS SCANUNSUBMITTED SIGNATURES
Under the surface
Nonstandard contracts can omit or falsify events. RPCs can withhold history, truncate logs, return stale data or reject calls. MOAT cannot independently prove a provider returned every event. Token-specific ERC-721 permissions, unsubmitted signatures, Permit2 internal permissions, smart-account modules and offchain exchange approvals are outside this scan. Token allowance to Permit2 is included. Chain reorganisations and later transactions can change a result. Unknown token metadata is shown without invented decimals.

Your address is public.

Connecting shares your public address with MOAT in this tab. Scanning sends it to the selected public RPC provider, which can also see your IP address, and to stateless partner API functions for inventory and spender checks. MOAT does not ask for a recovery phrase or private key.

YOUR BROWSERNO KEYS REQUESTEDADDRESS + IPPUBLIC RPC
Under the surface
The site has no analytics. Stateless MOAT API functions send queried public addresses to Goldsky and GoPlus Security, and signed operations to ZeroDev. Application code does not log addresses or persist results. Hosting and upstream providers may retain request metadata. Results remain in this tab until you export or leave. Public threat lists are served as dated local snapshots. No wallet provider icons or token logos are loaded from untrusted metadata. Wallet actions use the injected EIP-1193 provider discovered with EIP-6963.

The scanner is open before the token.

$MOAT has not launched on Robinhood Chain. There is no official contract address yet. No token holding is needed to use MOAT. A future token launch does not change the scanner coverage or establish safety.

SCANNEROPEN TO USENO TOKEN GATE$MOATSEPARATE FROM ACCESS
Under the surface
scripts/moat-live.mjs --ca
validates the chain, bytecode, token symbol, and Pons launch registration before updating the local token configuration. The --deploy flag is recognised but deployment is disabled under the standing instruction. No supply, allocation, price or launch date is invented.

Standards: ERC-20 · ERC-721 · ERC-1155 · EIP-6963

Your wallet stays yours

Choose your wallet.

Connecting shares your public address. Scanning never asks you to sign.

You can also paste an address for a read-only scan.

Review the change

Close this permission?

Your wallet will show the transaction and network fee. You pay gas. MOAT does not charge a revoke fee.