Every Token In Your Wallet Already Knows What It Can Do.

381e35

381e35

10/4/2026

#wallets#poof#plugs
Someone opens their wallet on a Sunday morning to pay down a loan.
The wallet knows exactly what they have. It shows twelve thousand dollars of USDC deposited on Aave, a few ETH, a loan against it, and the dollar value of each, correct to the cent. It has never been better at telling them what they own.
Under every row are the same three buttons. Send. Swap. Receive.
So they leave. They open a browser, type the protocol's name into a search bar, pick the result that looks most like the real one, connect, pick their wallet from a list, approve the connection, find the loan, type a number, approve the token, and confirm. The wallet that had their full attention, at the one moment they wanted to do something with their money, handed them to a website and waited.
Every wallet does this. Not because anyone decided it should, but because the alternative used to be building every protocol into the wallet by hand, one at a time, forever.
That is no longer the alternative.

The Most Looked-At Screen In Crypto Is A Dead End

Give the industry its due first, because it has earned it. Reading a wallet is a solved problem. faviconZerion's API says it covers "4,500+ protocols — decoded into one clean schema, valued in USD, with PnL," and that is a genuinely hard thing done well. A wallet today can tell you what you hold in a lending market, a vault, a liquidity pool or a staking contract almost as well as the protocol can.
And then every one of those rows ends in the same place.
Look at what actually ships beside the reading. Swap, everywhere. Zerion's own API page lists exactly one thing a wallet can act on, its swap endpoint, which hands back "quotes and ready-to-sign transactions." Swap is the one verb every token in existence shares, which is exactly why it is the one every wallet has. It is the verb that needed no knowledge of the token at all.
Everything that needs the token to mean something, repaying the loan it represents, withdrawing the deposit it is a receipt for, unstaking it, redeeming it at maturity, is a link out.
That second column is not a mockup of a feature we wish existed. Every action in it is live in the catalog this post is about, and every one of them runs from the wallet.

The Hop Is Where People Get Robbed

The link out is not only friction. It is the single most dangerous thing a wallet asks its users to do.
faviconScam Sniffer, which tracks wallet-draining sites, counted $494 million taken from 332,000 people in 2024, and $83.85 million from 106,106 people in 2025. Their definition of the attack is worth reading slowly: tricking victims into signing malicious transactions "through phishing websites." Not through the wallet. Through a page the wallet did not draw.
Look at what was in the biggest single theft of 2025. Six and a half million dollars, in September, through one signature, and the assets were staked ETH and a deposit receipt from Aave. The third biggest was another Aave deposit receipt. Further down the list sits a Compound position and a set of Uniswap liquidity positions. These are not tokens people were trading. They are exactly the tokens a person has to leave their wallet to manage, because their wallet cannot.
We are not going to tell you a better button ends phishing. It does not, and the 2025 number fell for reasons that have nothing to do with us. What it ends is the reason to go. A user who can repay the loan from the row that shows the loan has no search bar to type into, no lookalike site to pick, and no page asking for a signature the wallet never drew.
Count the steps where somebody else's page is in front of the user. In the hop it is most of them. In the row it is none.

We Turned The Question Around

The reason every wallet stopped at swap is that the obvious way to build this is backwards.
The obvious way is to start from the protocols. Integrate Aave, and teach it which tokens it takes. Integrate Lido, Morpho, Pendle, each vault, each pool, and for each one, write the code that decides which of a user's tokens it can do something with. Every protocol is its own project, every project needs maintaining when the protocol changes, and the long tail of verbs never gets built, because the fortieth integration costs as much as the first and is used by a fraction of the people.
Token to action starts from the other end. Every token carries what it can do.
A deposit receipt from a lending market says it can be withdrawn. A loan says it can be repaid, and if the same market holds a deposit in the same asset, that it can be repaid out of the deposit. A vault share says it can be cashed in. Staked ETH says it can be unstaked, and the exact token the exit accepts is the only one that says so, so staked ETH offers it and its wrapped twin does not. A wrapped token says it can be unwrapped. A fixed-yield token says it can be redeemed once its date has passed. A liquidity position says it can be pulled out and its fees collected. An NFT says it can be sent, and it is sent as the NFT it is.
There are nineteen of those verbs. Every action that moves money declares which of them it answers to, and they are all folded into a single index, so turning a wallet's holdings into its buttons is one lookup per token rather than a question put to every protocol in turn. Today, on Ethereum, 88 actions answer to one of those verbs, across Aave, Spark, Compound, Morpho, Fluid, Lido, ether.fi, Rocket Pool, Ethena, Ondo, Pendle, Curve, Convex, Balancer, three versions of Uniswap and any standard vault, plus the plain moves every token has.
The part a wallet team should sit with is what this does to the cost curve. When a new protocol is added, its actions declare their verbs and every wallet showing token to action gets them, on every token they apply to, without a line changing on the wallet's side. The hundredth action costs a wallet exactly what the first one did, which is nothing.

A Button That Fails Is Worse Than No Button

Here is the nuance nobody who has tried this talks about. Showing a verb because a token could do it is easy. Showing a verb because this wallet, right now, can do it is the whole job.
Hold USDC and the naive version shows "Withdraw from Aave," because USDC is a thing Aave holds. Tap it, and it fails, because this wallet never put USDC into Aave. Do that twice and the user stops tapping anything. So a token in the wallet is never treated as a position in a protocol. Withdraw appears only where this wallet has actually deposited that asset, and on a position, only in that exact market, so a deposit in one Morpho market never leaks a withdraw button onto another.
The same rule runs through everything. Repay only shows if the wallet is holding what it owes, and is sized to whichever is smaller, the debt or what the wallet has. Borrow only shows in a market where the wallet has room to borrow. A deposit button on a position only shows if the wallet holds something that market accepts. A market that has matured, been paused, or has nothing in it offers nothing at all. A listing is a fact about everyone. Whether it works is a fact about this owner, and the button reads the second one.

All Means All

The other thing every first attempt gets wrong is the word "all."
A user taps Repay all. The app reads the loan, writes the number down, and sends it. In the seconds between reading and landing, the loan keeps growing. Aave's USDC loans cost 4.39% a year this morning, so on a ten thousand dollar loan that is a little under a tenth of a cent a minute.
That is nothing. Say it out loud: nobody has ever been hurt by a tenth of a cent.
But the loan is not closed. The repay landed, the user saw it succeed, and the debt row is still sitting in their wallet with a fraction of a cent on it, still growing, still holding their collateral, and now they have to do it again and it will happen again. The cost was never the money. It was that the thing they asked for did not happen.
So "all" is never a number written down in advance. It is a word, and it is worked out at the moment the transaction runs, from the numbers as they are in that instant. Repay all pays whichever is smaller, the debt to the last unit or everything the wallet holds, and if it is the second, the user is told before they tap exactly how much will be left open. Withdraw all, while borrowing against the deposit, takes the most the loan allows, leaving just enough room that the market's own safety check passes, rather than asking for the whole deposit and failing. Cashing out of a vault takes exactly what the vault will release today, so a lockup or an exit limit is a smaller number, not an error.
The ceiling sorts itself out. Nothing hits it and falls over.

What The User Actually Signs

Nothing new.
Before the button even lights up, the exact transaction is run against the wallet's real balances, and the answer comes back as a sentence a person can read: what it will do, how much, and what will be left. If it would not work, the user finds out on the card, not in their history.
When they tap, the wallet sends one batch from their own address, the same way it sends anything. There is no extra message to sign, which matters, because the off-chain signature is the exact instrument behind the biggest theft Scam Sniffer recorded last year.
The batch does three things. It gives a permission to spend exactly what the action needs to an account that belongs to the user, created for them the first time they use it at an address worked out from their own, which can never belong to anyone else. Where the amount can only be known as it runs, as with an "all", the permission is switched back off before the batch ends. That account carries out the action. Then it hands every token that came in straight back to the user, in the same transaction. Nobody holds anything. There is no shared contract the user is trusting with an open-ended permission, because the permission names their own account and nothing else.
One honest limit, stated before anyone has to ask. A wallet that can send a batch in one go sends it in one go. A wallet that can only send one thing at a time asks the user to confirm each step, and if they walk away halfway, a permission can be left standing. It names their own account, which only they can drive, and nothing else.

Where This Leaves Everyone Else

Every option a wallet has today is real, and none of them is this.
A positions API tells your user what they own, beautifully, across thousands of protocols, and then hands them to a website. A swap API gives them the one verb every token already had. A built-in integration with one protocol is a project, and then the next one is another project, and the long tail is never reached. The browser tab is the hop, and the hop is where the drainers wait.
Token to action is the list your users already look at, with every row turned into the things that row can actually do, checked against what will work for that wallet right now, run from the wallet, with nothing new to sign. The wallet stays the place where the money moves, which is the only thing a wallet was ever for.
It is running now. Open faviconpoof with any Ethereum wallet and tap a token. Everything it does is the open API at faviconplug.to/docs, with no key and no sign-up.
Your users already trust you with the list. Let them touch it.

Every Token In Your Wallet Already Knows What It Can Do.

Back