wardcrest

Crypto link checker

New
Paste a link someone sent you. Wardcrest compares it with the real domains of 169 crypto brands, asks the registry how old the domain is, follows its redirects and reads the page’s code for wallet-drainer kits, without you opening it.

No red flags does not mean safe. These checks read the address, the registry and the first 256 KB of the page. Drainer kits often load their code later, show checkers a harmless page or change within hours, so a clean result proves nothing. Open sites from the project’s own documentation or your bookmarks.

What the checks cover. Lookalikes: 169 exchanges, wallets, protocols and chains, NFT marketplaces, explorers and bridges, with the domains each really uses. Age: the registration date from the registry’s RDAP service, found through IANA’s bootstrap file; .io, .co and most country endings publish none. Hosting: free hosts, page builders, IPFS gateways, bare IP addresses and shortened links, followed for up to five redirects. Page code: the first 256 KB of HTML, read as text and never run. Wardcrest’s blocklist: domains our operators have checked by hand.

Questions

Does the checker open the site?

Not in a browser. Wardcrest’s server asks for the page, follows up to five redirects and reads the first 256 KB of its HTML as text, so nothing on the page runs and your device never touches it. Every request goes through a guard that refuses private and reserved network addresses.

Is the link I paste stored?

No. It is sent in the body of the request rather than in the page address, so it stays out of access logs, and it is never written to the database or the logs. The result stays in the server’s memory for five minutes, filed under a hash of the link, so the same link pasted twice costs one check.

No red flags. Can I connect my wallet?

Not on the strength of this check alone. Many drainer kits load their code after the page opens, show checkers a harmless page, or change within hours. Open sites from the project’s own documentation or your bookmarks, and read every request with the signature request decoder before you approve it.

Why does the age of a domain matter?

Drainer sites are set up for one campaign and dropped once wallets start warning about them, so most are days old when their links go round. A project you already use will have had its domain for years. The date comes from the registry’s RDAP service; .io, .co and most country endings do not publish one.

How does it spot a copy of a site?

It compares the domain with the real domains of about 160 crypto brands: letters swapped for lookalikes from other alphabets, 0 for o, “rn” for “m”, the name with another ending, on a free host, in front of someone else’s domain, or next to words like “claim” and “verify”. A brand’s own domains are never flagged.

I already connected my wallet. What now?

If you signed anything, find out what it allowed: the token approvals checker lists the contracts that can still spend your tokens and how to revoke them from your own wallet. If you typed your recovery phrase anywhere, move everything to a new wallet at once: a revoke cannot help then.