skip to content
Scan. Stop. Earn. · 0.9.0 · internal preview
Chrome · Brave0.9.0 · internal preview

scan.
stop.
earn.

A crypto browser extension that scans pages, links, contracts, claims, mints, wallet prompts, and signatures before you interact, and pays you for verified signals that make crypto safer.

add to chrome
scanningruns locallyno browsing historynever your seed phrase
Arbitrum Reward Claim · round 4
arb-claim-portal.app/claim
12/100
arb-claim-portal
claim your round 4
rewards
connect walletexpires in 04:11
4,200 ARB allocated to your address
demo data
guardlyscanned 0.3s ago
12/ 100 safe
threat
Drainer signature pattern

This page asks for a Permit2 approval that moves every token you hold, not the one it names. Nine wallets lost funds to this contract in the last four days.

  • wallet address 0x7F3a…B19c
  • contract 0x4d2E…77aF
  • claim link arb-claim-portal.app/claim
[ leave this page ]continue
report this page+4.0 GRD pending verification
8 checks ran locally1 signal queued

what you stopped

Brave pays users for attention. Guardly pays users for protection intelligence. The panel counts the same way a shields panel does: what was blocked, what was refused, what you gave back, and what you are owed for it.

your protectiondemo data · one device · 30 days
scam pages blocked
1,284
this device, last 30 days
unsafe signatures stopped
37
before the wallet opened
useful signals contributed
612
anonymised, after dedupe
rewards pending
128.4GRD
clears after verification
checks per page8
run on your deviceall of them
sent off itonly the finding

every address on the page

A wallet sees the transaction. Guardly sees the page that produced it: the domain that got you here, the link you clicked, the contract the approval points at, and the prompt about to open. That is the part that tells you it is a trap.

domain registered 6 days ago · score 12/100 · demo data

[ open the full demo → ]
page scan8 found3 threat3 caution2 clear
  • wallet address0x7F3a…B19cno history before last week, 412 inbound dust transferscaution
  • token contract0xA0b8…eB48USDC, verified source, matches the canonical addresssafe
  • contract0x4d2E…77aFunverified source, owner can move approved balancesthreat
  • claim linkarb-claim-portal.app/claimlookalike domain, not the project's published hostthreat
  • mint linkmint.arb-claim-portal.appmint function is payable and has no supply capcaution
  • payment linkpay.arbitrum.foundation/inv/8841host matches the invoice issuer on recordsafe
  • wallet prompteth_signTypedData_v4Permit2, unlimited amount, spender is the unverified contractthreat
  • signature requestpersonal_signmessage is hex, not readable text, so you cannot see what you agree tocaution
every page, every time · demo data
wallet addressestoken and contract addressesclaim linksmint linkspayment linkswallet promptsphishing pagesdrainer contractsrisky approvalssuspicious signatures

in normal language

A signature prompt is a wall of hex. Guardly rewrites it into the four sentences that matter, then shows what your balances look like after you agree, so the decision happens before the wallet opens, not after.

Simulated locally. No transaction is ever sent from this site or the extension.

before you signdemo data
requesteth_signTypedData_v4
chainEthereum mainnet
asking forPermit2 · approve
  • Gives one address permission to move every USDC in your wallet.
  • The permission does not expire. It stays after you close the page.
  • The page says 0.1 ETH. The signature does not mention an amount at all.
  • Nothing leaves your wallet the moment you sign. The spender takes it later.
what changesnowafter signing
USDC4,120.000.00
ETH1.841.84
approvals34

Do not sign. The amount is unlimited and the spender is six days old.

one inbox for the wallet

Claims, alerts, receipts, payment requests, project updates and warnings, sorted by what they are and who can prove they sent them. A sender who cannot prove who they are is filed as advertising, not as a claim.

wallet inboxdemo data
  • Guardly12m
    An approval you hold went unsafe

    The contract you approved for USDC on 2 March changed owner yesterday. Revoke it.

    alerts
  • Guardly1h
    A page you opened is impersonating a project

    arb-claim-portal.app is not a host Arbitrum publishes. Nothing was signed.

    alerts
  • Arbitrum Foundation3h
    Round 4 claim is open

    Signed by the address in the project's published registry. Expires in 19 days.

    claims
  • unverified sender5h
    You have 4,200 tokens waiting

    Sender paid to reach you and cannot prove who they are. Treated as advertising.

    claims
  • Uniswapyesterday
    Swapped 0.5 ETH for 1,642.18 USDC

    Settled in block 21,884,003. Fee 0.0021 ETH. Matches what the page quoted.

    receipts
  • studio.ethyesterday
    Payment request · 1,200 USDC

    Invoice 8841. Host matches the issuer on record. Due in 7 days.

    requests
  • Lido2d
    Withdrawal queue is clear

    Project update, signed with the key in Lido's published registry.

    updates
  • Guardly3d
    Seed phrase field detected on a page you visited

    No legitimate site asks for twelve words. The page was blocked before it loaded.

    warnings

paid for protection

A drainer found an hour earlier takes one wallet instead of a hundred. That hour is worth money to wallets, explorers and projects, and the person who ran into it first is the one who should be paid for it.

Nothing clears until a signal is reproduced independently. Pending is pending, and the panel says so on the row.

rewardsdemo data · no token exists
pending verification
128.4GRD
held until each signal is reproduced
cleared, lifetime
904.2GRD
verified by someone other than you
signalweightGRD
drainer contract, first reportverifiedx448.0
lookalike claim domainverifiedx224.0
unlimited approval on a new spenderpending verificationx218.4
seed phrase field on a pagepending verificationx332.0
page already reported by 2,104 othersduplicate, not paidx0—
report that did not reproducerejectedx0—
  • A signal pays once, to whoever saw it first.
  • Verification is independent. A report nobody can reproduce pays nothing.
  • Rewards are funded by the projects and wallets that read the feed, not by selling what you browse.

local first, then a fingerprint

Protection intelligence only works if the thing being shared is the threat, not the person who met it.

01

Scanning runs locally first

The address and signature checks happen in the extension, on the page you are already looking at. A page that is obviously fine never leaves your device.

02

A signal is a fingerprint, not a visit

When something looks wrong, what goes out is the host, the contract address and the prompt shape. Not the tab, not the session, not who you are.

03

Rewards are counted without a profile

Signals are attributed to a rotating key you can reset. Resetting it keeps your pending balance and drops the link to everything before it.

04

You can read every signal you send

The outbox is a list in the extension. Nothing is sent that is not in it, and you can turn any category off.

what never leaves your device
  • your full browsing history
  • your seed phrase or private keys, ever, for any reason
  • page contents from sites that scanned clean
  • a persistent identifier tied to your wallet
  • anything sold to advertisers
not yet in the store
Chrome · Brave
scan before you sign

Guardly is an internal preview. When the listing exists, this button installs it in one click and the extension starts scanning the page you are on. Until then the honest version of this button is a demo.

[ add to chrome ][ view the demo → ]

waitlist

local only

No backend, no third party. What you type stays in your own browser.

status 0.9.0 · internal preview · no token, no sale, nothing on this site takes payment.

questions?