Crypto Scam Detector
Real-time cryptocurrency scam detection with database-first architecture. Protects users from phishing, honeypots, rug pulls, and ponzi schemes. No external...
Rank
62
Safety
84
Downloads
1.0k
Updated
Oct 11, 2026
Version
2.2.0
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 1K downloads reported by the source. Last updated 10/11/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 11, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 11, 2026
- Adoption signal
- 1K downloadsadoption · observed Oct 11, 2026
- Latest release
- 2.2.0release · observed Feb 20, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s17838vwg83s6e1k93nh09zjwn884m26:crypto-scam-detector- Install using `clawhub skill install s17838vwg83s6e1k93nh09zjwn884m26:crypto-scam-detector` in an isolated environment before connecting it to live workloads.
- No published capability contract is available yet, so validate auth and request/response behavior manually.
- Review the upstream CLAWHUB listing at https://clawhub.ai/princedoss77/crypto-scam-detector before using production credentials.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-princedoss77-crypto-scam-detector/snapshot"
Run-check
$0.02 USD1 measured facts are behind this paywall: success rate and latency, uptime and estimated cost, when not to use it, how to call it, benchmark scores.
Agents pay $0.02 in USDC. A card payment is $0.50, the smallest a card allows.
Documentation
CLAWHUB
147,740 characters of source documentation, loaded on request.
Extracted files
5 files captured from the source.
SKILL.md
--- name: crypto-scam-detector displayName: Crypto Scam Detector version: 2.0.0 author: Trust Claw Team description: Real-time cryptocurrency scam detection with database-first architecture. Protects users from phishing, honeypots, rug pulls, and ponzi schemes. No external API calls during checks! category: security tags: [crypto, scam-detection, ethereum, blockchain, security, fraud-prevention, web3, defi, database, etherscan] license: MIT repository: https://github.com/trustclaw/crypto-scam-detector homepage: https://github.com/trustclaw/crypto-scam-detector icon: 🔍 command: python3 crypto_check_db.py --- # 🔍 Crypto Scam Detector v2.0 **Database-first cryptocurrency scam detection for OpenClaw** Analyzes crypto addresses for phishing, honeypots, rug pulls, and ponzi schemes using a local database with background sync from Etherscan. **Zero external API calls during user checks** = instant results! ## ✨ What's New in v2.0 ### 🚀 Major Architecture Upgrade - ✅ **Database-first design** - All checks query local SQLite database - ✅ **Instant results** - No API latency during checks (<5ms) - ✅ **No rate limits** - User queries never hit Etherscan API - ✅ **Background sync worker** - Separate process pulls from Etherscan - ✅ **Transaction message analysis** - Decodes and analyzes hex data - ✅ **Auto-queue system** - Unknown addresses automatically queued for sync - ✅ **Deep scanning** - Detects suspicious keywords in transaction data ### 🔍 Enhanced Detection Now catches scams the old version missed: - ✅ "Lazarus Vanguard" hacking group references - ✅ "Orbit Bridge Hacker" mentions - ✅ Private key phishing attempts - ✅ Exploit recruitment messages - ✅ And much more... ## 📦 What's Included ``` crypto-scam-detector/ ├── SKILL.md # This file ├── DATABASE_ARCHITECTURE.md # Technical documentation ├── database.py # SQLite database layer ├── crypto_check_db.py # Database-only checker (instant) ├── sync_worker.py # Background Etherscan sync worker ├── secure_key_manager.py # Encrypted API key storage ├── install.sh # Auto-installer ├── setup.sh # API key setup wizard ├── check_address.sh # Convenience script (sync if needed) ├── requirements.txt # Python dependencies └── venv/ # Virtual environment (created on install) ``` ## 🚀 Quick Start ### 1. Install ```bash cd ~/.openclaw/workspace/skills/crypto-scam-detector bash install.sh ``` ### 2. Configure Etherscan API Key (Optional but Recommended) **Option A: Interactive Setup** (Encrypted storage) ```bash ./setup.sh # Follow the wizard to encrypt your API key ``` **Option B: Environment Variable** ```bash export ETHERSCAN_API_KEY="your_key_here" ``` Get free API key: https://etherscan.io/myapikey ### 3. Check an Address ```bash # Check address (instant, database-only) python3 crypto_check_db.py 0x1234567890abcdef1234567890abcdef12345678 ``` #
README.md
# 🔍 Crypto Scam Detector v2.0
**Database-first cryptocurrency scam detection for OpenClaw**
[](https://opensource.org/licenses/MIT)
[](https://www.python.org/downloads/)
[](https://openclaw.ai)
Protects users from cryptocurrency scams by analyzing addresses for phishing, honeypots, rug pulls, and ponzi schemes. Features a local database with background sync for instant, rate-limit-free checks.
## 🎯 Key Features
- ✅ **Instant Checks** - Database queries complete in <5ms
- ✅ **No Rate Limits** - User checks never hit external APIs
- ✅ **Deep Analysis** - Decodes and analyzes transaction messages
- ✅ **Auto-Queue** - Unknown addresses automatically queued for sync
- ✅ **Background Worker** - Separate process handles Etherscan sync
- ✅ **Encrypted Storage** - AES-256 encrypted API key storage
- ✅ **Multi-Source** - Combines Etherscan, ChainAbuse, and local data
## 🚀 Quick Start
### Installation
```bash
# Via ClawHub
clawhub install crypto-scam-detector
# Or manual
cd ~/.openclaw/workspace/skills/crypto-scam-detector
bash install.sh
```
### Setup
```bash
# Interactive setup (recommended)
./setup.sh
# Or set environment variable
export ETHERSCAN_API_KEY="your_key_here"
```
Get free API key: https://etherscan.io/myapikey
### Usage
```bash
# Check an address (instant)
python3 crypto_check_db.py 0x1234567890abcdef1234567890abcdef12345678
# Check with auto-sync if needed
./check_address.sh 0x1234567890abcdef1234567890abcdef12345678
# Run background worker
python3 sync_worker.py
```
## 📖 Documentation
- **[SKILL.md](SKILL.md)** - Complete usage guide
- **[DATABASE_ARCHITECTURE.md](DATABASE_ARCHITECTURE.md)** - Technical deep dive
- **[SECURITY.md](SECURITY.md)** - Security practices
## 🎨 Example Output
### Critical Risk Detection
```
🚨 Analysis for 0x098b716b8aaf21512996dc57eb0615e2383e2f96
Risk Score: 100/100 - CRITICAL RISK
Last Updated: 2026-02-20 07:14:32
🚨 KNOWN SCAM DETECTED!
⚙️ Smart Contract
⚠️ NOT VERIFIED on Etherscan
Transactions: 38
Balance: 101.802430 ETH
🚨 5 Scam Indicator(s) Detected:
• Suspicious keyword detected: 'lazarus' (confidence: 80%)
• Suspicious keyword detected: 'hack' (confidence: 80%)
• Suspicious keyword detected: 'exploit' (confidence: 80%)
⚠️ 5 Suspicious Transaction(s):
• 0x74f7fbfe5a0bd3...
Reason: Suspicious keyword detected: 'lazarus'
Message: "Greetings Lazarus Vanguard..."
📋 Recommendations:
🚫 DO NOT send funds to this address
⚠️ This address has been flagged as high risk
📞 Report the source that gave you this address
```
## 🏗️ Architecture
```
User Check → crypto_check_db.py → Local SQLite DB
↑
│
sync_worker.py (background)
_meta.json
{
"ownerId": "kn70kqnnbvgw393pkjtj232zjd81ey4w",
"slug": "crypto-scam-detector",
"version": "2.2.0",
"publishedAt": 1771576385142
}CHANGELOG.md
# Changelog All notable changes to the Crypto Scam Detector will be documented in this file. The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.0.0/), and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html). ## [2.0.0] - 2026-02-20 ### 🚀 Major Changes This is a **complete architecture rewrite** with breaking changes. ### Added - **Database-first architecture** - All checks now query local SQLite database - **Instant checks** - Results in <5ms (no external API calls during checks) - **Background sync worker** - `sync_worker.py` for Etherscan data collection - **Transaction message analysis** - Decodes hex data and analyzes for suspicious content - **Auto-queue system** - Unknown addresses automatically added to sync queue - **Convenience script** - `check_address.sh` for auto-sync checking - **Deep scam detection** - Detects "Lazarus", exploit references, phishing keywords - **Database statistics** - `--stats` flag shows database metrics - **Comprehensive documentation** - DATABASE_ARCHITECTURE.md with technical details - **Encrypted key storage** - Secure API key storage with AES-256 ### Changed - **Main command** changed from `crypto_check.py` to `crypto_check_db.py` - **Architecture** moved from direct API calls to database + background worker - **Check latency** improved from 2-5 seconds to <5ms - **Rate limits** eliminated for user checks (only worker hits API) - **Risk scoring** algorithm enhanced with message analysis ### Fixed - ✅ **False negatives** - Now detects scams missed in v1.1.3 - ✅ **Missing transaction analysis** - Full hex message decoding - ✅ **No suspicious keyword detection** - Comprehensive keyword list - ✅ **Hacking group references** - Detects Lazarus, Orbit Bridge, etc. - ✅ **Private key phishing** - Identifies seed phrase scams ### Breaking Changes - `crypto_check.py` is replaced by `crypto_check_db.py` - Requires initial database setup (automatic on first run) - Background worker must be run to populate database - MCP server (`mcp_server.py`) deprecated in favor of database mode ### Migration Guide **From v1.x to v2.0:** 1. Update the skill: ```bash clawhub update crypto-scam-detector ``` 2. Install dependencies: ```bash bash install.sh ``` 3. Setup API key: ```bash ./setup.sh ``` 4. Run initial sync for addresses you care about: ```bash python3 sync_worker.py --add-address 0x... python3 sync_worker.py --max-jobs 1 ``` 5. Setup cron for background sync: ```bash */10 * * * * cd ~/.openclaw/workspace/skills/crypto-scam-detector && source venv/bin/activate && ETHERSCAN_API_KEY="key" python3 sync_worker.py --max-jobs 30 ``` 6. Use new checker: ```bash python3 crypto_check_db.py 0x... ``` ### Performance - Check speed: 2-5s → <5ms (500-1000x faster) - API calls per check: 4 → 0 (eliminated) - Database size: ~1KB per address - Sync time: ~2s per address (4 API calls) ### Test Results Address `0x0
DATABASE_ARCHITECTURE.md
# Crypto Scam Detector - Database Architecture
## Overview
**New Design:** Decoupled architecture with local database and background sync worker.
- ✅ **Instant checks** - Query local database (no API latency)
- ✅ **No rate limits** - User queries don't hit Etherscan API
- ✅ **Deep analysis** - Analyzes transaction messages for suspicious content
- ✅ **Centralized data** - All data in one place
- ✅ **Background sync** - Separate worker fetches from Etherscan
## Architecture
```
┌─────────────────┐
│ User Request │
│ Check address? │
└────────┬────────┘
│
▼
┌─────────────────────────┐
│ crypto_check_db.py │ ◄── Queries local DB only
│ (Instant check) │ (No external API calls)
└────────┬────────────────┘
│
▼
┌─────────────────────────┐
│ Local SQLite Database │
│ ~/.config/crypto-scam- │
│ detector/crypto_data │
│ │
│ • Addresses │
│ • Transactions │
│ • Risk scores │
│ • Scam indicators │
└────────▲────────────────┘
│
│ Background sync
│
┌────────┴────────────────┐
│ sync_worker.py │ ◄── Pulls from Etherscan
│ (Background job) │ Analyzes messages
│ │ Calculates risk
│ • Reads sync queue │
│ • Calls Etherscan API │
│ • Decodes TX messages │
│ • Stores in DB │
└─────────────────────────┘
```
## Components
### 1. Database Layer (`database.py`)
SQLite database with tables:
- **addresses** - Address info, risk scores, balances
- **transactions** - Suspicious transactions with decoded messages
- **scam_indicators** - Individual red flags
- **sync_queue** - Addresses waiting to be synced
**Key functions:**
- `get_address(address)` - Retrieve address data
- `upsert_address(data)` - Store/update address
- `add_transaction(tx)` - Store suspicious transaction
- `add_scam_indicator(...)` - Add red flag
- `add_to_sync_queue(address)` - Queue for background sync
### 2. Background Worker (`sync_worker.py`)
Fetches data from Etherscan and stores in database.
**Features:**
- Queries Etherscan API for address data
- Decodes transaction input data (hex → UTF-8)
- **Analyzes messages for suspicious keywords**
- "lazarus", "hack", "exploit", "private key"
- Scam domains, phishing phrases
- Calculates risk score (0-100)
- Stores everything in local database
**Usage:**
```bash
# Add address to sync queue
python3 sync_worker.py --add-address 0x...
# Run worker (processes queue continuously)
python3 sync_worker.py
# Process only 10 addresses then stop
python3 sync_worker.py --max-jobs 10
# Show database statistics
python3 sync_worker.py --stats
```
### 3. Database-Only Checker (`crypto_check_db.py`)
Checks addresses against local database **only**.
**No external API calls** - instant results!
**Usage:**
```bash
# Check an address
python3 crypto_check_db.py 0x...
# JSON output
python3 crypto_check_db.py 0x... --json
```
**Behavior:**
-AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/princedoss77/skills/crypto-scam-detector",
"sourceUrl": "https://clawhub.ai/princedoss77/skills/crypto-scam-detector",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-11T18:39:06.752Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-princedoss77-crypto-scam-detector/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-princedoss77-crypto-scam-detector/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-11T18:39:06.752Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "1K downloads",
"href": "https://clawhub.ai/princedoss77/crypto-scam-detector",
"sourceUrl": "https://clawhub.ai/princedoss77/crypto-scam-detector",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-11T18:39:06.752Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "2.2.0",
"href": "https://clawhub.ai/princedoss77/crypto-scam-detector",
"sourceUrl": "https://clawhub.ai/princedoss77/crypto-scam-detector",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-02-20T08:33:05.142Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-princedoss77-crypto-scam-detector/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-princedoss77-crypto-scam-detector/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 2.2.0",
"description": "**Crypto Scam Detector 2.2.0 – Major database-first, instant-check architecture** - Replaced live API checks with a fully local SQLite database for scam detection; all address scans are instant (no external API calls). - Introduced `crypto_check_db.py` as the new entry point for database-only, <5ms address analysis. - Added `sync_worker.py` as a background process for syncing fresh blockchain data from Etherscan into the database (works with your API key). - New auto-queue system: unknown addresses are added to a sync queue for future analysis. - Multiple new docs: DATABASE_ARCHITECTURE.md, MULTICHAIN_SUPPORT.md, REALTIME_SYNC_UPDATE.md, and release notes for v2.2.0. - Removed old analyzer scripts and outdated documentation, fully transitioning to the new instant database model.",
"href": "https://clawhub.ai/princedoss77/crypto-scam-detector",
"sourceUrl": "https://clawhub.ai/princedoss77/crypto-scam-detector",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-02-20T08:33:05.142Z",
"isPublic": true
}
]
}Record generated Oct 11, 2026.
For crawlers
This page is free to read. The run-check above is the only paid part, and it answers HTTP 402 until it is paid. Everything else here is public.
- One record, as JSON: card, facts, snapshot, contract, trust.
- Every agent, one feed: /.well-known/ai-catalog.json
- What this site sells, and the price: /.well-known/x402
- Paid run-check: /api/v1/agents/clawhub-princedoss77-crypto-scam-detector/run-check
