Read the contract before you sign.
Paste any EVM contract address. Dralvia returns a structured verdict, owner privilege, hidden mint, approval-drain vectors, transfer locks, source verification, and historical signal, with the exact line that triggered each finding. Built for wallets, treasuries, and protocols that decide in the time it takes to read a prompt.
Smart contract review
See Dralvia in action.
Choose a chain, submit a contract address, and review the verdict and supporting evidence together.
- Choose the correct chain
- Submit the contract address
- Review readable privilege and proxy evidence
This preview shows the Dralvia workspace. Sign in to see your own scans, alerts, and activity.

What we read so you don't have to.
Every finding cites the function or line that triggered it. Static analysis (Slither), source verification (Sourcify, Etherscan), and risk heuristics combine into one verdict.
Owner privilege audit
Whether the owner is an EOA, multisig, or timelock, and which functions only the owner can call: fee changes, blacklists, pausing, upgrades, role grants.
Hidden mint & supply caps
Mint functions reachable by the owner, missing or movable max-supply caps, and inflation paths through internal helpers or proxy delegation.
Tax & transfer hooks
Buy / sell tax current values and maximums, blacklist-on-transfer, anti-whale limits, and pause hooks that can block exit on demand.
Approval-drain detection
Common drain patterns: ERC-20 Permit abuse, infinite allowances, callback re-entry, hidden router redirects, and proxy delegate-call swaps.
Source vs. bytecode diff
"Verified" does not mean "matches." Dralvia compares the verified source against the deployed bytecode and surfaces any function-level divergence.
Proxy & upgradeability
EIP-1967 / UUPS proxies, implementation-slot reads, admin keys, and whether the implementation can be hot-swapped, and by whom.
Deployer reputation
Other contracts the deployer has shipped, prior incidents, and on-chain clustering with addresses flagged in earlier rugs or exploits.
Audit footprint
Whether a recognised auditing firm has published a report for this exact bytecode, and what the report actually said: severity, scope, remediation.
Address in, verdict out.
Paste a contract address
Dralvia resolves the chain, fetches verified source where available, and detects proxy patterns before analysis begins.
Static analysis + heuristics
Slither detectors, source-vs-bytecode diffing, owner-privilege mapping, and approval-drain heuristics run together, each independently scored.
Evidence you can act on
A clear risk verdict with the function or line behind each finding, plus a one-click EvidencePack for the treasury or signing record.
Honest answers.
EVM chains are live today, including Ethereum mainnet, BNB Chain, Polygon, Arbitrum, Optimism, and Base. Non-EVM chains such as Solana, Starknet, and Sui are on the roadmap, if you have a specific need, tell us and we will shape the next chain by demand.
Scan a contract before funds move.
Paste an address, read the privilege map and risk vectors, and export the evidence for your signing record.
Trust the whole picture, not one address.
Check a wallet or transaction
Approval exposure, drainer patterns, and counterparty risk before you confirm.
Inspect the link first
Most contract scams start with a lookalike site. Scan the URL before you connect a wallet.
Read the code behind the dApp
Leaked secrets, risky dependencies, and supply-chain signals across the repository.