Your wallet stays your wallet
- REKT CHECK never asks for your seed phrase.
- REKT CHECK never asks for your private key.
- No wallet connection is required to analyze a public address.
- No transaction signature is required to receive a REKT Score.
How it works
- REKT CHECK reads public blockchain data that is already visible to anyone.
- You paste a public wallet address — nothing else is needed.
- Analyzing an address cannot move funds, approve spending or sign anything.
- Connecting a wallet is optional and only appears when you choose to prove ownership.
Wallet ownership verification
Claiming a wallet for your REKT Profile or entering the REKT League asks your wallet to sign a short text message. That is the only thing a connection is ever used for.
- You sign a plain text message containing a domain, your address, a single-use nonce and an expiry.
- It is not a transaction: it costs no SOL, transfers nothing and grants no approval or spending permission.
- REKT CHECK cannot build, sign or send a transaction — the app has no signer of any kind.
- The signature is verified against your public key and the nonce is then discarded.
- Disconnecting ends the browser session only. Removing a verified wallet is done in your profile.
- We still never ask for a seed phrase or private key — no exceptions, in any channel.
Scam warning
Security architecture summary
- Provider API credentials are read server-side only and never shipped to the browser.
- Privileged database operations run server-side with service-role access; the browser never holds those credentials.
- Authoritative leaderboard and Record Book metrics are derived server-side from stored analyses — a client cannot submit a P&L figure, a rank or a record.
- Reward voting is signaling only and cannot move treasury funds.
- Reward distributions are disabled and cannot be executed by this application.
- No treasury credentials, private keys or seed phrases exist in frontend code, and none are accepted or stored anywhere.
- The admin portal requires an authenticated sign-in; there is no shared admin password or shared access link.
- Authorization is enforced server-side on every admin request, with separate OWNER and ADMIN roles; privileged reward actions additionally require an explicit owner-level approval step.
- Admin routes are excluded from search indexing and expose nothing to unauthenticated visitors.
- Database access is protected by row-level security, so trust decisions are made on the server rather than in the browser.
- Every administrative action is audit-logged server-side.
We publish this summary without internal specifics or secret values on purpose. Nothing here should be read as a third-party security audit — no such audit has been performed.
If rewards ever launch
Checking a REKT Score never requires wallet connection or signing. If a future optional reward claim is offered, a wallet signature may be needed solely to prove control of the receiving address — that would be a separate, clearly labelled flow, and it does not exist today. Rewards are PRE-LAUNCH and disabled.
Reporting a problem
Found something that looks wrong? Report it through the official channels published on this site. Please do not include private keys or seed phrases in any report — we do not want them and cannot use them.