Check the link before you connect.
Most drained wallets start with a link that looked right. Paste it here first. ClaimGuard reads the domain the way an attacker writes it and tells you, in plain words, what is off. Nothing is sent anywhere; the check runs in your browser.
Wallet hygiene check.
Connect read-only and ClaimGuard looks through your token accounts for the usual airdrop spam: tokens Jupiter has never priced, unverified dust, and anything that arrived with no value. Those are the ones you never click.
Scores run from 0 (nothing odd) to 100 (walk away).
Findings
The read-out appears here: what the domain is really, which brand it is imitating, and which tricks it uses.
Six questions that stop most drains.
A green score is not a pass. Tick these honestly for any claim, mint or airdrop, every time.
Lookalike brands
Known names hidden in subdomains, hyphens or extra words: pump.fun.claims-portal.top is not pump.fun.
Punycode and homoglyphs
"xn--" hosts and Cyrillic letters that render like Latin ones. Your eye cannot tell; the parser can.
Fresh, cheap TLDs
.top, .xyz, .icu, .click and friends are not bad by themselves, but drainers love them because they cost a dollar.
Suspicious paths and words
/connect, /verify, /claim, /sync, /restore and "wallet validation" are the vocabulary of the trade.
What it cannot do
It cannot read the site's code or know a brand-new scam on a clean-looking domain. It raises the right questions; the checklist does the rest.