← NightFall Crypto Access Exit Check
Removing an AI agent, bot, employee, contractor, or automation account from one signer list does not prove that every supported permission path has disappeared. Use this checklist after the intended revocation procedure is complete.
Check whether the departing address is still an owner or signer of the treasury or smart account. For Safe accounts, verify current owner membership against live chain state.
Modules can create authority paths separate from ordinary owner signatures. Record every enabled module and determine whether the departing subject can still act through one.
If Safe Allowance Module or another delegated-spend mechanism was used, confirm the subject is no longer a delegate and that token spending limits are zero or removed.
Inspect ERC-20 allowances and ERC-721/ERC-1155 operator approvals granted to the departing address. Approval state is independent of whether the address is still a wallet owner.
Do not turn missing data into a green check. Unsupported modules, unavailable RPC state, or unknown delegation mechanisms should produce an explicit unable_to_verify result.
Record the treasury, subject, chain, contracts checked, observed state, block context, and final verdict. Offboarding should be provable after the fact, not dependent on someone remembering what buttons were clicked.
Buy a verified exit report — $49Run the open-source tool
If the problem extends beyond one wallet or agent, NightFall Technologies offers a fixed-price Security Architecture Risk Sprint.