Onchain investigations
Investigations into linked wallets, token distribution, control rights and money flows.
See the method
MASTR investigates crypto projects, traces funds and examines the permissions behind wallets and applications. The research documents scams, conflicts of interest and security weaknesses.
Public reach, working products and 3 years of security research.
MASTR publishes investigations, scam warnings and practical security guidance. People can examine the work and its sources before deciding whether to support it.
Wiki home
Investigations, alerts and public evidence from the main MASTR account.
A recommendation can conceal a financial interest. MASTR checks who benefits and compares public statements with contracts, wallets and actual control.
Investigations into linked wallets, token distribution, control rights and money flows.
See the methodAnalysis of fraudulent websites, malicious interfaces and social-engineering attacks.
Explore the toolsAutomated tools assist with collecting records. MASTR evaluates the evidence and takes responsibility for the published conclusions.
Why MASTRChoose a question, inspect the mechanism and follow it into an original MASTR investigation.
Identify the asset, inspect its controls, understand the liquidity and examine the ANSEM pool research.
MASTR publishes investigations and warnings, reviews projects and develops apps and security tools.
Apps, research and tools connected through MASTR.


More in development All links ↗Verified projects ↗

External security assessments, bug-bounty research and private vulnerability reports for products handling wallets, signatures or funds.
Explore
Investigations into wallet networks, token distribution, privileged access and the money behind public claims.
Explore
Automated token checks and answers to Web3 questions through MASTR’s tools.
Explore
MASTR community apps for Android and iOS.
Explore
A documented project assessment with a defined scope and review date. New evidence can change the assessment.
Explore
MASTRpass Pro is live for Solana Seeker users. Google Play and iOS are close to submission; Windows is in development.
Explore
Original investigations and references on KOL incentives, token markets, exchanges, wallets, DeFi and scams.
Explore
The MASTR ecosystem token. The GREENPAPER describes its proposed uses and development status.
ExploreThe GREENPAPER describes the planned role of $MASTR in access, project reviews, community services and a proposed protection model. Holding the token does not prove a project is safe.
Official releases and current product status from MASTRlabs. Use the links published here or through the official MASTR Linktree.

MASTR community conversations and direct or group messaging on Android.
MASTR community conversations and direct or group messaging on iPhone and iPad.
AskMASTR answers Web3 questions and provides automated token checks on Telegram. Check important results against the underlying records.
MASTRpass Pro is live in the Solana dApp Store. Recovery phrases, passwords, notes, documents and images stay encrypted on the user’s device.
Unfortunately, the Solana dApp Store is only available to Solana Seeker users. Search for “MASTRpass Pro” directly in the store on the device.
Two more MASTRlabs products are in development. Only their names and current status are public for now.

MASTRful is in development. Product details will be announced later.

Each report explains the affected component, the evidence, the conditions needed to reproduce the issue, its impact and the limits of the tests. It also records what needs to change.
Record what users connect, sign, approve or upload, and who gains access or control.
Compare the public claim with the deployed contracts, permissions and observed application behaviour.
Preserve reproducible evidence. Use safe tests that do not put other people’s accounts or funds at risk.
Give the affected team the findings, supporting evidence and remediation steps before public disclosure.
Repeat the original test against the changed product and check for related ways to reach the same outcome.
A fix must correct the control that allowed the problem. An independent retest must confirm that the demonstrated attack no longer works.
The underlying permission, validation or trust failure is corrected.
The submitted proof no longer reproduces under the same preconditions, account state and user permissions.
Equivalent accounts, chains, sessions, APIs and fallback flows are tested for the same class of failure.
The changed control, test date, remaining limits and evidence are documented clearly enough for another reviewer.
Names and exploit details stay private while findings are open. The scope, report length and remediation status are listed below.
Authority concentration, network-state representation, backend amplification and user trust boundaries were retested. Verification remains withheld until Critical and High issues are remediated.
PRIVATE RESPONSIBLE DISCLOSUREThe 38-page report recorded 3 High and 2 Medium findings, plus 5 assurance observations about agent permissions in production. The release recommendation remained on hold pending fixes and independent verification.
PRIVATE RESPONSIBLE DISCLOSUREThe review covered the website, API, CMS, email security and transport settings. It identified 3 High, 3 Medium and 2 Low issues; it did not establish that an intrusion had occurred.
PRIVATE RESPONSIBLE DISCLOSUREProject names and exploitable details remain private while disclosure could expose users or interfere with remediation.
Fake support accounts, compromised Discord servers, malicious approvals and wallet drainers often pressure people to act before checking. Telegram trading groups and manufactured social proof can reinforce that pressure. MASTR examines both the technical attack and the manipulation around it.
I AM MASTR.
YOU’RE LOUD.
I’M RIGHT.
Paid promotions, undisclosed token allocations and referral commissions can put an influencer’s interests in conflict with those of their audience. The research examines those arrangements and the records behind them, including who can sell while followers are being encouraged to buy.
MASTR does not sell favourable conclusions or promote unknown teams for a fee. Readers can examine the evidence and challenge the analysis.
Payment never buys a clean result, a badge or silence about a material risk.
A review is a point-in-time assessment. It is not a guarantee and is never presented as one.
Exploitable detail stays private while responsible remediation is still possible.
MASTR grows through useful work and public evidence, not paid shillers manufacturing consensus.
MASTR began by publishing scam warnings and investigating the people, wallets and financial interests behind them. The work now includes onchain investigations, external security assessments, tools, apps and educational material.
The operator’s identity remains private following threats connected with this work. Published findings include supporting evidence and reproducible methods where disclosure allows it.
The work helps users and teams examine risks before making decisions.
Donations fund research, hosting and product development. MASTR does not accept paid token promotion, casino promotion or arrangements that give a sponsor control over the conclusions.
6ELa36JmfYL8RFFu5i6WfRAQAykkyVNRqBtpoaTaEwNq
Solana address only. Always compare the full address before sending.
Open walletSend SOL on Solana. Choose an amount and confirm in your wallet. If no wallet opens, copy the address. No payment is sent by this website.