Recovery scan
Portuna Recovery scans your old deposit addresses and reports what is left on them and what it is worth recovering. It is in beta and free. The scan only reads public chain data: nothing is signed, no transaction is sent, no key is needed.
A processing collects leftovers on thousands of addresses over the years:
- dust that was never worth a classic sweep;
- tokens you don’t support, which users sent anyway;
- coins sent on the wrong EVM chain: the same address and key work on every EVM chain, so a user who withdraws USDT on BNB Smart Chain to your Ethereum deposit address leaves it there, on BNB Smart Chain.
How to run a scan
Section titled “How to run a scan”- In the console, open Recovery and create a project.
- Upload a list of deposit addresses: CSV, TXT or JSON, up to 5 MB and 50,000 addresses a project.
- Start the scan. It takes from minutes to a few hours, depending on the number of addresses; the page shows its progress. You can leave it: the scan goes on, and the report appears in the project when it’s done.
Upload more files to the same project to add addresses: addresses already in it are not added twice.
What the file may look like
Section titled “What the file may look like”Any text file works. The console takes every 0x followed by exactly 40 hexadecimal digits that stands apart from the
letters and digits around it, and ignores everything else: headers, user ids, balances, other columns, JSON keys.
user_id,address,created_at1042,0x5aAeb6053F3E94C9b9A09f33669435E7Ef1BeAed,2023-04-011043,0xfb6916095ca1df60bb79ce92ce3ea74c37c5d359,2023-04-02- Checksums. An address in mixed case must have a valid EIP-55 checksum. One that doesn’t was most likely mistyped, so it is rejected rather than scanned. All-lowercase and all-uppercase addresses carry no checksum and are taken as they are.
- Repeats within the file and addresses the project already has are counted once.
- What you see. After the upload the console shows how many addresses were added, repeated, rejected and ignored, and the numbers of the first lines with something left out. It never shows the content of the file.
- Limits are checked while the file is read: a file over the size or line limit, or one that would take the project past 50,000 addresses, is refused whole. Save spreadsheets as CSV in UTF-8; archives and Excel files are refused.
What the scan covers
Section titled “What the scan covers”Every address on every chain where EIP-7702 is live and the scan can read:
| Chain | Native coin |
|---|---|
| Ethereum | ETH |
| BNB Smart Chain | BNB |
| Base | ETH |
| OP Mainnet | ETH |
| Arbitrum One | ETH |
| Polygon PoS | POL |
| Gnosis | xDAI |
| Unichain | ETH |
On each chain it finds the native coin and every ERC-20 token the address holds.
What counts
Section titled “What counts”A balance counts when it has a reliable price and can be moved:
- The native coin always counts.
- Tokens are priced by DefiLlama, or by CoinGecko when DefiLlama doesn’t answer. A token is left out when it has no price, when the price comes from thin liquidity pools, when its trading volume is low, when the price is more than a day old, or when its symbol looks like spam (a link, “claim”, “reward”).
- Transfers are simulated. For each balance that would be worth recovering, the scan simulates a transfer from
your address with
eth_call, which needs no signature. A token whose transfer reverts or returnsfalse— a honeypot — is left out for that address.
The report lists the excluded tokens with the reason, and they don’t count anywhere in the totals.
Cost and what’s worth recovering
Section titled “Cost and what’s worth recovering”For every balance the report gives its value, the estimated cost of recovering it and the net:
- Cost is the gas of one sweep in a batch of 100 at the chain’s gas price during the scan, in dollars at the native coin’s price. An address’s first sweep includes its EIP-7702 authorization, and the creation of its account on that chain if it has none there — for example, a token sent there by mistake to an address that never had the native coin. The address’s other balances on the chain are repeat sweeps in the same batch.
- Worth recovering are the balances that bring at least $1 after their cost.
The totals are: found, worth recovering, the cost of recovering it, and the net before the Portuna fee. The fee is agreed individually — write to sales@portuna.io; once it is agreed, the report shows it and the net after it.
The report and the export
Section titled “The report and the export”- By chain and by token: what was found, what is worth recovering, the cost and the net; gas and coin prices of the scan.
- Balances: every address, token and amount with its value, cost, net and status, with filters by status, chain, token and address, and links to the block explorer.
- Export CSV: the balances on screen, with the same filters. Cells a spreadsheet would read as a formula (starting
with
=,+,-,@) are written as text.
Access and your data
Section titled “Access and your data”- Roles. Every member of the organization sees the reports. Creating projects, uploading, scanning, exporting and deleting take a developer role or above: the export is the whole address list in a portable file.
- Retention. A project — its addresses, scans and report — is deleted for good 30 days after it is created; the console shows the date. Delete it yourself at any time. Deleting the organization deletes its projects at once.
- Audit log. Creating a project, uploads, scans, exports and deletions are in the organization’s audit log.
What’s next
Section titled “What’s next”The scan shows what is there. Recovering it is a separate step: the funds would go only to addresses you choose, with EIP-7702 authorizations you sign, as with Portuna Sweep. If the report shows something worth recovering, write to sales@portuna.io.