Your wallet stays your wallet

  • REKT CHECK never asks for your seed phrase.
  • REKT CHECK never asks for your private key.
  • No wallet connection is required to analyze a public address.
  • No transaction signature is required to receive a REKT Score.

How it works

  • REKT CHECK reads public blockchain data that is already visible to anyone.
  • You paste a public wallet address — nothing else is needed.
  • Analyzing an address cannot move funds, approve spending or sign anything.
  • Connecting a wallet is optional and only appears when you choose to prove ownership.

Wallet ownership verification

Claiming a wallet for your REKT Profile or entering the REKT League asks your wallet to sign a short text message. That is the only thing a connection is ever used for.

  • You sign a plain text message containing a domain, your address, a single-use nonce and an expiry.
  • It is not a transaction: it costs no SOL, transfers nothing and grants no approval or spending permission.
  • REKT CHECK cannot build, sign or send a transaction — the app has no signer of any kind.
  • The signature is verified against your public key and the nonce is then discarded.
  • Disconnecting ends the browser session only. Removing a verified wallet is done in your profile.
  • We still never ask for a seed phrase or private key — no exceptions, in any channel.

Scam warning

If anyone claiming to represent REKT CHECK asks for your seed phrase or private key, it is a scam. We will never ask, in any channel, for any reason.

Security architecture summary

  • Provider API credentials are read server-side only and never shipped to the browser.
  • Privileged database operations run server-side with service-role access; the browser never holds those credentials.
  • Authoritative leaderboard and Record Book metrics are derived server-side from stored analyses — a client cannot submit a P&L figure, a rank or a record.
  • Reward voting is signaling only and cannot move treasury funds.
  • Reward distributions are disabled and cannot be executed by this application.
  • No treasury credentials, private keys or seed phrases exist in frontend code, and none are accepted or stored anywhere.
  • The admin portal requires an authenticated sign-in; there is no shared admin password or shared access link.
  • Authorization is enforced server-side on every admin request, with separate OWNER and ADMIN roles; privileged reward actions additionally require an explicit owner-level approval step.
  • Admin routes are excluded from search indexing and expose nothing to unauthenticated visitors.
  • Database access is protected by row-level security, so trust decisions are made on the server rather than in the browser.
  • Every administrative action is audit-logged server-side.

We publish this summary without internal specifics or secret values on purpose. Nothing here should be read as a third-party security audit — no such audit has been performed.

If rewards ever launch

Checking a REKT Score never requires wallet connection or signing. If a future optional reward claim is offered, a wallet signature may be needed solely to prove control of the receiving address — that would be a separate, clearly labelled flow, and it does not exist today. Rewards are PRE-LAUNCH and disabled.

Reporting a problem

Found something that looks wrong? Report it through the official channels published on this site. Please do not include private keys or seed phrases in any report — we do not want them and cannot use them.

Privacy · Transparency