Project
Have I Been Drained?
First decentralized, community-powered wallet security checker on Solana with a comprehensive scam wiki and structured security education.
Role
Sole developer – Anchor program, API, frontend, and documentation.
Tech stack
Anchor, Rust, Solana Web3.js, Helius, Astro, Svelte, Hono, Bun, PostgreSQL, Redis, TailwindCSS
Project type
Fullstack Solana security platform – on-chain registry, API, and web app.
Highlights
First on-chain drainer registry, multi-pattern detection, 45+ story-based security articles.
Demo video
Current status & demo wallets
My personal servers currently run multiple production apps, so some infrastructure for this project is intentionally throttled. Live wallet checks can be flaky under load. The demo addresses below are wired to internal fixtures and will always return rich analysis results end-to-end.
Demo / test wallets (reliable checks):
-
Safe wallet (no issues)
11111111111111111111111111111111 -
At-risk wallet – unlimited approvals pattern
7xKXtg2CW87d97TXJSDpbD5jBkheTqA83TZRuJosgAsU -
Fully drained wallet – SetAuthority + known drainer
9WzDXwBbmkg8ZTbNMqUxvQRAyrZzDsGYdLVL9zYtAWWM -
High-risk wallet – interaction with known drainer
5Q544fKrFoe6tsEbD7S8EmxGTJYAKtTVhAW5Q5pge4j1
Quick stats
Detection patterns
3 implemented (SetAuthority, unlimited approvals, known drainers) + 2 planned.
Analysis speed
< 15 seconds target (P95) using Helius RPC and caching.
On-chain registry
Drainer reports stored on-chain via Anchor PDAs for O(1) lookups.
Scam wiki
45+ real-world stories across 4 threat categories (Hacks, Frauds, Blackmail, Privacy).
The problem
In 2024–2025, Solana wallet drainers stole over $300M from more than 324,000 users. Existing tools are mostly centralized, opaque, and focused on pre-transaction simulation. At the same time, security education is scattered across Twitter threads and forum posts, with no OWASP-style framework for wallet scams.
- Centralized, closed registries that require trusting a single provider.
- Little or no community reporting; users cannot contribute collective knowledge.
- Reactive education – people learn only after being scammed.
- No structured taxonomy of attack patterns or red flags.
The solution
Have I Been Drained? combines an on-chain drainer registry, a transaction analysis engine, and a story-driven scam wiki into one platform. It focuses on post-transaction analysis and community reporting, complementing real-time simulation tools like Blockaid and Vibernative.
- On-chain registry of drainers via Anchor program and PDAs.
- Multi-pattern detection engine focused on Solana-specific attacks.
- Public REST API and embeddable widget so any dApp or wallet can integrate checks.
- OWASP-style scam taxonomy with 45+ real-world stories and prevention guides.
Architecture
The system is split into an Anchor program for the on-chain registry, a Hono + Bun API for transaction analysis, and an Astro + Svelte frontend for visualizing results and surfacing education content.
Frontend (Astro + Svelte) ───▶ API Server (Hono + Bun) ───▶ Helius RPC (transaction analysis)
│ │
│ ▼
▼ Anchor Program (on-chain registry)
Solana Actions (Blinks)
- Anchor program: PDA-based drainer accounts, 0.01 SOL anti-spam fee, immutable report history.
- API server: Hono + Bun microservice that queries Helius RPC, applies detection rules, aggregates risk, and drives the public REST API.
- Frontend: Astro + Svelte app for wallet checks, risk visualization, and scam wiki access.
Program (devnet): BYbF6QC9PoeHGH4y1pLNC2YHBChpnFBq46vBydyBFxq2
Detection patterns
The first version of the engine focuses on three high-signal patterns, with two more specified and planned.
1. SetAuthority attacks (critical)
Parses Token Program SetAuthority instructions to detect account owner changes and unauthorized ownership transfers.
2. Unlimited approvals (high)
Detects u64-max approvals that grant unlimited token spending, and flags them as dangerous with revocation recommendations.
3. Known drainers (critical)
Looks up addresses in the on-chain registry and database of known drainers, treating matches as critical severity.
Development & quick start
The repo is structured as a monorepo with separate packages for the Anchor program, API, frontend, and shared utilities.
haveibeendrained/
├── packages/
│ ├── anchor/ # Anchor program (Rust)
│ ├── api/ # API server (TypeScript + Hono)
│ ├── frontend/ # Frontend (Astro + Svelte)
│ └── shared/ # Shared types and utilities
├── docker-compose.yml
└── README.md
git clone https://github.com/digitaldrreamer/haveibeendrained.git
cd haveibeendrained
bun install
cp .env.example .env
cp packages/api/.env.example packages/api/.env
cp packages/frontend/.env.example packages/frontend/.env
docker compose up -d
# Frontend: http://localhost:3000
# API: http://localhost:3001
Links
- Live app: docs.haveibeendrained.org
- Demo video: 3-minute demo
- Docs: docs.haveibeendrained.org
- Safety education / scam wiki: docs.haveibeendrained.org/safety-education
Gallery
Selected screens from the wallet checker, on-chain registry views, scam wiki, and developer documentation.