How to Check What Your Wallet Has Approved
A token approval is a standing authorisation that outlives the transaction that created it. Here is how to see what yours have authorised, using tools you already trust.
Most recent incident record
All incidents →Incident Tracker
All incidents →| Disclosed | Incident | Chain | Reported impact | Status |
|---|---|---|---|---|
| WazirX Multisig Compromise, July 2024: What Happened & What to Check | Ethereum | approx. US$234.9 million(WazirX, 18 Jul 2024) | Contained | |
| DMM Bitcoin Unauthorised Outflow, May 2024: What Happened & What to Check | Bitcoin | 4,502.9 BTC(DMM Bitcoin, 31 May 2024) | Resolved | |
| Ledger Connect Kit Supply Chain Attack, December 2023: What Happened & What to Check | Ethereum | approx. US$600,000(Ledger, 14 Dec 2023) | Resolved | |
| Curve Finance Vyper Compiler Reentrancy, July 2023: What Happened & What to Check | Ethereum | approx. US$70 million across affected pools(Curve Finance, 31 Jul 2023) | Resolved | |
| Euler Finance Donation Attack, March 2023: What Happened & What to Check | Ethereum | approx. US$197 million (substantially all returned)(Euler Labs, 13 Mar 2023) | Resolved | |
| Wintermute Vanity Address Compromise, September 2022: What Happened & What to Check | Ethereum | approx. US$160 million(Wintermute (Evgeny Gaevoy, CEO), 20 Sep 2022) | Resolved |
Regulation watch
All jurisdictions →the United States
Broker reporting on Form 1099-DA phased in from the 2025 tax year, materially increasing third-party reporting to the IRS.
As ofthe United Kingdom
The financial promotions regime for cryptoassets, in force since October 2023, continues to govern how firms may market to UK consumers.
As ofSingapore
MAS has progressively tightened consumer-access measures and restrictions on retail marketing of digital payment token services.
As ofJapan
Japan has continued to review the treatment of crypto-assets under its financial regulation framework, including questions of tax treatment and classification.
As ofLatest
Nomad Bridge Replay Exploit, August 2022: What Happened & What to Check
A routine upgrade left Nomad accepting any message as proven. Hundreds of addresses copied the same transaction and drained the bridge in…
Ronin Bridge Validator Key Compromise, March 2022: What Happened & What to Check
Attackers obtained enough Ronin validator signatures to forge withdrawals, draining 173,600 ETH and 25.5m USDC. The theft went unnoticed for six days.
Wormhole Signature Verification Exploit, February 2022: What Happened & What to Check
A flaw in Wormhole's Solana signature verification let an attacker mint 120,000 wETH without depositing collateral. Jump Crypto replaced the shortfall.
BadgerDAO Front-End Injection, December 2021: What Happened & What to Check
A compromised Cloudflare API key let attackers inject approval-harvesting script into the BadgerDAO front end. The contracts were never touched.
Poly Network Cross-Chain Exploit, August 2021: What Happened & What to Check
An attacker exploited Poly Network's cross-chain contract to reassign the keeper role, taking roughly $611m — then returned substantially all of it.
Guides & security tips
All guides →How to Read a Transaction Before You Sign It
The most expensive failures in crypto have not broken cryptography. They changed what the signer was shown. Here is what to look…
How to Verify a Security Incident Is Real
The hours after a genuine incident are when fake advisories, fake support and fake recovery tools work best. Here is how to…
What Self-Custody Actually Means (And What It Doesn’t Protect You From)
Self-custody removes one category of risk and adds another. Understanding which is which is the whole decision.
How Crypto Bridges Work, and Why They Keep Getting Exploited
Bridges account for several of the largest losses on record. The reason is structural, and it is visible in every one of…
Free tools
All tools →No tool on Conisec asks for a seed phrase, a private key, a signature or a wallet connection. Nothing on this site connects to a wallet.
What Conisec covers
Conisec is an independent publication covering crypto security incidents, exploits and regulation. We report on what broke, who it touched, and what the rules now say — across exchanges, protocols, wallets and jurisdictions. We are not a price site, and we do not make market calls.
Every security, incident and regulatory story carries The Ledger: four fixed lines telling you what happened, who's exposed, how to verify it yourself, and what materially changes. The verification line is the point — Conisec never asks to be trusted, it hands you the check. The Ledger is descriptive and procedural. It is not financial, legal, tax or security advice, and it never tells anyone to move funds.
Every row in the Incident Tracker and every field on a jurisdiction page cites a primary document — an official advisory, a post-mortem, a court filing or a regulator notice. If a claim cannot be sourced, it does not publish. How we source, verify and update is written out in full on our methodology page, alongside who we are, our regulation coverage and our security tips.