Digital Dreamer

Project

Have I Been Drained?

First decentralized, community-powered wallet security checker on Solana with a comprehensive scam wiki and structured security education.

Role

Sole developer – Anchor program, API, frontend, and documentation.

Tech stack

Anchor, Rust, Solana Web3.js, Helius, Astro, Svelte, Hono, Bun, PostgreSQL, Redis, TailwindCSS

Project type

Fullstack Solana security platform – on-chain registry, API, and web app.

Highlights

First on-chain drainer registry, multi-pattern detection, 45+ story-based security articles.

Demo video

Current status & demo wallets

My personal servers currently run multiple production apps, so some infrastructure for this project is intentionally throttled. Live wallet checks can be flaky under load. The demo addresses below are wired to internal fixtures and will always return rich analysis results end-to-end.

Demo / test wallets (reliable checks):

  • Safe wallet (no issues)

    11111111111111111111111111111111
  • At-risk wallet – unlimited approvals pattern

    7xKXtg2CW87d97TXJSDpbD5jBkheTqA83TZRuJosgAsU
  • Fully drained wallet – SetAuthority + known drainer

    9WzDXwBbmkg8ZTbNMqUxvQRAyrZzDsGYdLVL9zYtAWWM
  • High-risk wallet – interaction with known drainer

    5Q544fKrFoe6tsEbD7S8EmxGTJYAKtTVhAW5Q5pge4j1

Quick stats

Detection patterns

3 implemented (SetAuthority, unlimited approvals, known drainers) + 2 planned.

Analysis speed

< 15 seconds target (P95) using Helius RPC and caching.

On-chain registry

Drainer reports stored on-chain via Anchor PDAs for O(1) lookups.

Scam wiki

45+ real-world stories across 4 threat categories (Hacks, Frauds, Blackmail, Privacy).

The problem

In 2024–2025, Solana wallet drainers stole over $300M from more than 324,000 users. Existing tools are mostly centralized, opaque, and focused on pre-transaction simulation. At the same time, security education is scattered across Twitter threads and forum posts, with no OWASP-style framework for wallet scams.

  • Centralized, closed registries that require trusting a single provider.
  • Little or no community reporting; users cannot contribute collective knowledge.
  • Reactive education – people learn only after being scammed.
  • No structured taxonomy of attack patterns or red flags.

The solution

Have I Been Drained? combines an on-chain drainer registry, a transaction analysis engine, and a story-driven scam wiki into one platform. It focuses on post-transaction analysis and community reporting, complementing real-time simulation tools like Blockaid and Vibernative.

  • On-chain registry of drainers via Anchor program and PDAs.
  • Multi-pattern detection engine focused on Solana-specific attacks.
  • Public REST API and embeddable widget so any dApp or wallet can integrate checks.
  • OWASP-style scam taxonomy with 45+ real-world stories and prevention guides.

Architecture

The system is split into an Anchor program for the on-chain registry, a Hono + Bun API for transaction analysis, and an Astro + Svelte frontend for visualizing results and surfacing education content.

Frontend (Astro + Svelte)  ───▶  API Server (Hono + Bun)  ───▶  Helius RPC (transaction analysis)
        │                                   │
        │                                   ▼
        ▼                          Anchor Program (on-chain registry)
Solana Actions (Blinks)
      
  • Anchor program: PDA-based drainer accounts, 0.01 SOL anti-spam fee, immutable report history.
  • API server: Hono + Bun microservice that queries Helius RPC, applies detection rules, aggregates risk, and drives the public REST API.
  • Frontend: Astro + Svelte app for wallet checks, risk visualization, and scam wiki access.

Program (devnet): BYbF6QC9PoeHGH4y1pLNC2YHBChpnFBq46vBydyBFxq2

Detection patterns

The first version of the engine focuses on three high-signal patterns, with two more specified and planned.

1. SetAuthority attacks (critical)

Parses Token Program SetAuthority instructions to detect account owner changes and unauthorized ownership transfers.

2. Unlimited approvals (high)

Detects u64-max approvals that grant unlimited token spending, and flags them as dangerous with revocation recommendations.

3. Known drainers (critical)

Looks up addresses in the on-chain registry and database of known drainers, treating matches as critical severity.

Development & quick start

The repo is structured as a monorepo with separate packages for the Anchor program, API, frontend, and shared utilities.

haveibeendrained/
├── packages/
│   ├── anchor/      # Anchor program (Rust)
│   ├── api/         # API server (TypeScript + Hono)
│   ├── frontend/    # Frontend (Astro + Svelte)
│   └── shared/      # Shared types and utilities
├── docker-compose.yml
└── README.md
      
git clone https://github.com/digitaldrreamer/haveibeendrained.git
cd haveibeendrained
bun install

cp .env.example .env
cp packages/api/.env.example packages/api/.env
cp packages/frontend/.env.example packages/frontend/.env

docker compose up -d

# Frontend: http://localhost:3000
# API: http://localhost:3001
      

Links

Gallery

Selected screens from the wallet checker, on-chain registry views, scam wiki, and developer documentation.