scan.
stop.
earn.
A crypto browser extension that scans pages, links, contracts, claims, mints, wallet prompts, and signatures before you interact, and pays you for verified signals that make crypto safer.
scanningruns locallyno browsing historynever your seed phraserewards
This page asks for a Permit2 approval that moves every token you hold, not the one it names. Nine wallets lost funds to this contract in the last four days.
- wallet address 0x7F3a…B19c
- contract 0x4d2E…77aF
- claim link arb-claim-portal.app/claim
what you stopped
Brave pays users for attention. Guardly pays users for protection intelligence. The panel counts the same way a shields panel does: what was blocked, what was refused, what you gave back, and what you are owed for it.
every address on the page
A wallet sees the transaction. Guardly sees the page that produced it: the domain that got you here, the link you clicked, the contract the approval points at, and the prompt about to open. That is the part that tells you it is a trap.
domain registered 6 days ago · score 12/100 · demo data
[ open the full demo → ]- wallet address0x7F3a…B19cno history before last week, 412 inbound dust transferscaution
- token contract0xA0b8…eB48USDC, verified source, matches the canonical addresssafe
- contract0x4d2E…77aFunverified source, owner can move approved balancesthreat
- claim linkarb-claim-portal.app/claimlookalike domain, not the project's published hostthreat
- mint linkmint.arb-claim-portal.appmint function is payable and has no supply capcaution
- payment linkpay.arbitrum.foundation/inv/8841host matches the invoice issuer on recordsafe
- wallet prompteth_signTypedData_v4Permit2, unlimited amount, spender is the unverified contractthreat
- signature requestpersonal_signmessage is hex, not readable text, so you cannot see what you agree tocaution
in normal language
A signature prompt is a wall of hex. Guardly rewrites it into the four sentences that matter, then shows what your balances look like after you agree, so the decision happens before the wallet opens, not after.
Simulated locally. No transaction is ever sent from this site or the extension.
- Gives one address permission to move every USDC in your wallet.
- The permission does not expire. It stays after you close the page.
- The page says 0.1 ETH. The signature does not mention an amount at all.
- Nothing leaves your wallet the moment you sign. The spender takes it later.
Do not sign. The amount is unlimited and the spender is six days old.
one inbox for the wallet
Claims, alerts, receipts, payment requests, project updates and warnings, sorted by what they are and who can prove they sent them. A sender who cannot prove who they are is filed as advertising, not as a claim.
- alertsGuardly12mAn approval you hold went unsafe
The contract you approved for USDC on 2 March changed owner yesterday. Revoke it.
- alertsGuardly1hA page you opened is impersonating a project
arb-claim-portal.app is not a host Arbitrum publishes. Nothing was signed.
- claimsArbitrum Foundation3hRound 4 claim is open
Signed by the address in the project's published registry. Expires in 19 days.
- claimsunverified sender5hYou have 4,200 tokens waiting
Sender paid to reach you and cannot prove who they are. Treated as advertising.
- receiptsUniswapyesterdaySwapped 0.5 ETH for 1,642.18 USDC
Settled in block 21,884,003. Fee 0.0021 ETH. Matches what the page quoted.
- requestsstudio.ethyesterdayPayment request · 1,200 USDC
Invoice 8841. Host matches the issuer on record. Due in 7 days.
- updatesLido2dWithdrawal queue is clear
Project update, signed with the key in Lido's published registry.
- warningsGuardly3dSeed phrase field detected on a page you visited
No legitimate site asks for twelve words. The page was blocked before it loaded.
paid for protection
A drainer found an hour earlier takes one wallet instead of a hundred. That hour is worth money to wallets, explorers and projects, and the person who ran into it first is the one who should be paid for it.
Nothing clears until a signal is reproduced independently. Pending is pending, and the panel says so on the row.
- A signal pays once, to whoever saw it first.
- Verification is independent. A report nobody can reproduce pays nothing.
- Rewards are funded by the projects and wallets that read the feed, not by selling what you browse.
local first, then a fingerprint
Protection intelligence only works if the thing being shared is the threat, not the person who met it.
Scanning runs locally first
The address and signature checks happen in the extension, on the page you are already looking at. A page that is obviously fine never leaves your device.
A signal is a fingerprint, not a visit
When something looks wrong, what goes out is the host, the contract address and the prompt shape. Not the tab, not the session, not who you are.
Rewards are counted without a profile
Signals are attributed to a rotating key you can reset. Resetting it keeps your pending balance and drops the link to everything before it.
You can read every signal you send
The outbox is a list in the extension. Nothing is sent that is not in it, and you can turn any category off.
- your full browsing history
- your seed phrase or private keys, ever, for any reason
- page contents from sites that scanned clean
- a persistent identifier tied to your wallet
- anything sold to advertisers
Guardly is an internal preview. When the listing exists, this button installs it in one click and the extension starts scanning the page you are on. Until then the honest version of this button is a demo.
waitlist
local onlyquestions?