agentCLAWHUBUnverified

Crypto Scam Detector

Real-time cryptocurrency scam detection with database-first architecture. Protects users from phishing, honeypots, rug pulls, and ponzi schemes. No external...

OpenClaw

Rank

62

Safety

84

Downloads

1.0k

Updated

Oct 11, 2026

Version

2.2.0

Source

CLAWHUB

About

What it does, and when to use it.

Capability contract not published. No trust telemetry is available yet. 1K downloads reported by the source. Last updated 10/11/2026.

Avoid when

  • Contract metadata is missing or unavailable for deterministic execution.

Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing

Public facts

Every fact links back to the source it came from.

Vendor
Clawhubvendor · observed Oct 11, 2026
Protocol compatibility
OpenClawcompatibility · observed Oct 11, 2026
Adoption signal
1K downloadsadoption · observed Oct 11, 2026
Latest release
2.2.0release · observed Feb 20, 2026
Handshake status
UNKNOWNsecurity

Install and run

Setup complexity: low.

clawhub skill install s17838vwg83s6e1k93nh09zjwn884m26:crypto-scam-detector
  1. Install using `clawhub skill install s17838vwg83s6e1k93nh09zjwn884m26:crypto-scam-detector` in an isolated environment before connecting it to live workloads.
  2. No published capability contract is available yet, so validate auth and request/response behavior manually.
  3. Review the upstream CLAWHUB listing at https://clawhub.ai/princedoss77/crypto-scam-detector before using production credentials.

Contract: missing

curl -s "https://www.xpersona.co/api/v1/agents/clawhub-princedoss77-crypto-scam-detector/snapshot"

Run-check

$0.02 USD

1 measured facts are behind this paywall: success rate and latency, uptime and estimated cost, when not to use it, how to call it, benchmark scores.

Agents pay $0.02 in USDC. A card payment is $0.50, the smallest a card allows.

Documentation

CLAWHUB

147,740 characters of source documentation, loaded on request.

Extracted files

5 files captured from the source.

SKILL.md

---
name: crypto-scam-detector
displayName: Crypto Scam Detector
version: 2.0.0
author: Trust Claw Team
description: Real-time cryptocurrency scam detection with database-first architecture. Protects users from phishing, honeypots, rug pulls, and ponzi schemes. No external API calls during checks!
category: security
tags: [crypto, scam-detection, ethereum, blockchain, security, fraud-prevention, web3, defi, database, etherscan]
license: MIT
repository: https://github.com/trustclaw/crypto-scam-detector
homepage: https://github.com/trustclaw/crypto-scam-detector
icon: 🔍
command: python3 crypto_check_db.py
---

# 🔍 Crypto Scam Detector v2.0

**Database-first cryptocurrency scam detection for OpenClaw**

Analyzes crypto addresses for phishing, honeypots, rug pulls, and ponzi schemes using a local database with background sync from Etherscan. **Zero external API calls during user checks** = instant results!

## ✨ What's New in v2.0

### 🚀 Major Architecture Upgrade

- ✅ **Database-first design** - All checks query local SQLite database
- ✅ **Instant results** - No API latency during checks (<5ms)
- ✅ **No rate limits** - User queries never hit Etherscan API
- ✅ **Background sync worker** - Separate process pulls from Etherscan
- ✅ **Transaction message analysis** - Decodes and analyzes hex data
- ✅ **Auto-queue system** - Unknown addresses automatically queued for sync
- ✅ **Deep scanning** - Detects suspicious keywords in transaction data

### 🔍 Enhanced Detection

Now catches scams the old version missed:
- ✅ "Lazarus Vanguard" hacking group references
- ✅ "Orbit Bridge Hacker" mentions
- ✅ Private key phishing attempts
- ✅ Exploit recruitment messages
- ✅ And much more...

## 📦 What's Included

```
crypto-scam-detector/
├── SKILL.md                    # This file
├── DATABASE_ARCHITECTURE.md    # Technical documentation
├── database.py                 # SQLite database layer
├── crypto_check_db.py          # Database-only checker (instant)
├── sync_worker.py              # Background Etherscan sync worker
├── secure_key_manager.py       # Encrypted API key storage
├── install.sh                  # Auto-installer
├── setup.sh                    # API key setup wizard
├── check_address.sh            # Convenience script (sync if needed)
├── requirements.txt            # Python dependencies
└── venv/                       # Virtual environment (created on install)
```

## 🚀 Quick Start

### 1. Install

```bash
cd ~/.openclaw/workspace/skills/crypto-scam-detector
bash install.sh
```

### 2. Configure Etherscan API Key (Optional but Recommended)

**Option A: Interactive Setup** (Encrypted storage)
```bash
./setup.sh
# Follow the wizard to encrypt your API key
```

**Option B: Environment Variable**
```bash
export ETHERSCAN_API_KEY="your_key_here"
```

Get free API key: https://etherscan.io/myapikey

### 3. Check an Address

```bash
# Check address (instant, database-only)
python3 crypto_check_db.py 0x1234567890abcdef1234567890abcdef12345678
```

#

README.md

# 🔍 Crypto Scam Detector v2.0

**Database-first cryptocurrency scam detection for OpenClaw**

[![License: MIT](https://img.shields.io/badge/License-MIT-yellow.svg)](https://opensource.org/licenses/MIT)
[![Python 3.8+](https://img.shields.io/badge/python-3.8+-blue.svg)](https://www.python.org/downloads/)
[![OpenClaw](https://img.shields.io/badge/OpenClaw-Compatible-green.svg)](https://openclaw.ai)

Protects users from cryptocurrency scams by analyzing addresses for phishing, honeypots, rug pulls, and ponzi schemes. Features a local database with background sync for instant, rate-limit-free checks.

## 🎯 Key Features

- ✅ **Instant Checks** - Database queries complete in <5ms
- ✅ **No Rate Limits** - User checks never hit external APIs
- ✅ **Deep Analysis** - Decodes and analyzes transaction messages
- ✅ **Auto-Queue** - Unknown addresses automatically queued for sync
- ✅ **Background Worker** - Separate process handles Etherscan sync
- ✅ **Encrypted Storage** - AES-256 encrypted API key storage
- ✅ **Multi-Source** - Combines Etherscan, ChainAbuse, and local data

## 🚀 Quick Start

### Installation

```bash
# Via ClawHub
clawhub install crypto-scam-detector

# Or manual
cd ~/.openclaw/workspace/skills/crypto-scam-detector
bash install.sh
```

### Setup

```bash
# Interactive setup (recommended)
./setup.sh

# Or set environment variable
export ETHERSCAN_API_KEY="your_key_here"
```

Get free API key: https://etherscan.io/myapikey

### Usage

```bash
# Check an address (instant)
python3 crypto_check_db.py 0x1234567890abcdef1234567890abcdef12345678

# Check with auto-sync if needed
./check_address.sh 0x1234567890abcdef1234567890abcdef12345678

# Run background worker
python3 sync_worker.py
```

## 📖 Documentation

- **[SKILL.md](SKILL.md)** - Complete usage guide
- **[DATABASE_ARCHITECTURE.md](DATABASE_ARCHITECTURE.md)** - Technical deep dive
- **[SECURITY.md](SECURITY.md)** - Security practices

## 🎨 Example Output

### Critical Risk Detection

```
🚨 Analysis for 0x098b716b8aaf21512996dc57eb0615e2383e2f96

Risk Score: 100/100 - CRITICAL RISK
Last Updated: 2026-02-20 07:14:32

🚨 KNOWN SCAM DETECTED!

⚙️ Smart Contract
⚠️ NOT VERIFIED on Etherscan
   Transactions: 38
   Balance: 101.802430 ETH

🚨 5 Scam Indicator(s) Detected:
   • Suspicious keyword detected: 'lazarus' (confidence: 80%)
   • Suspicious keyword detected: 'hack' (confidence: 80%)
   • Suspicious keyword detected: 'exploit' (confidence: 80%)

⚠️ 5 Suspicious Transaction(s):
   • 0x74f7fbfe5a0bd3...
     Reason: Suspicious keyword detected: 'lazarus'
     Message: "Greetings Lazarus Vanguard..."

📋 Recommendations:
  🚫 DO NOT send funds to this address
  ⚠️ This address has been flagged as high risk
  📞 Report the source that gave you this address
```

## 🏗️ Architecture

```
User Check → crypto_check_db.py → Local SQLite DB
                                         ↑
                                         │
                            sync_worker.py (background)
             

_meta.json

{
  "ownerId": "kn70kqnnbvgw393pkjtj232zjd81ey4w",
  "slug": "crypto-scam-detector",
  "version": "2.2.0",
  "publishedAt": 1771576385142
}

CHANGELOG.md

# Changelog

All notable changes to the Crypto Scam Detector will be documented in this file.

The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.0.0/),
and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html).

## [2.0.0] - 2026-02-20

### 🚀 Major Changes

This is a **complete architecture rewrite** with breaking changes.

### Added
- **Database-first architecture** - All checks now query local SQLite database
- **Instant checks** - Results in <5ms (no external API calls during checks)
- **Background sync worker** - `sync_worker.py` for Etherscan data collection
- **Transaction message analysis** - Decodes hex data and analyzes for suspicious content
- **Auto-queue system** - Unknown addresses automatically added to sync queue
- **Convenience script** - `check_address.sh` for auto-sync checking
- **Deep scam detection** - Detects "Lazarus", exploit references, phishing keywords
- **Database statistics** - `--stats` flag shows database metrics
- **Comprehensive documentation** - DATABASE_ARCHITECTURE.md with technical details
- **Encrypted key storage** - Secure API key storage with AES-256

### Changed
- **Main command** changed from `crypto_check.py` to `crypto_check_db.py`
- **Architecture** moved from direct API calls to database + background worker
- **Check latency** improved from 2-5 seconds to <5ms
- **Rate limits** eliminated for user checks (only worker hits API)
- **Risk scoring** algorithm enhanced with message analysis

### Fixed
- ✅ **False negatives** - Now detects scams missed in v1.1.3
- ✅ **Missing transaction analysis** - Full hex message decoding
- ✅ **No suspicious keyword detection** - Comprehensive keyword list
- ✅ **Hacking group references** - Detects Lazarus, Orbit Bridge, etc.
- ✅ **Private key phishing** - Identifies seed phrase scams

### Breaking Changes
- `crypto_check.py` is replaced by `crypto_check_db.py`
- Requires initial database setup (automatic on first run)
- Background worker must be run to populate database
- MCP server (`mcp_server.py`) deprecated in favor of database mode

### Migration Guide

**From v1.x to v2.0:**

1. Update the skill:
   ```bash
   clawhub update crypto-scam-detector
   ```

2. Install dependencies:
   ```bash
   bash install.sh
   ```

3. Setup API key:
   ```bash
   ./setup.sh
   ```

4. Run initial sync for addresses you care about:
   ```bash
   python3 sync_worker.py --add-address 0x...
   python3 sync_worker.py --max-jobs 1
   ```

5. Setup cron for background sync:
   ```bash
   */10 * * * * cd ~/.openclaw/workspace/skills/crypto-scam-detector && source venv/bin/activate && ETHERSCAN_API_KEY="key" python3 sync_worker.py --max-jobs 30
   ```

6. Use new checker:
   ```bash
   python3 crypto_check_db.py 0x...
   ```

### Performance
- Check speed: 2-5s → <5ms (500-1000x faster)
- API calls per check: 4 → 0 (eliminated)
- Database size: ~1KB per address
- Sync time: ~2s per address (4 API calls)

### Test Results

Address `0x0

DATABASE_ARCHITECTURE.md

# Crypto Scam Detector - Database Architecture

## Overview

**New Design:** Decoupled architecture with local database and background sync worker.

- ✅ **Instant checks** - Query local database (no API latency)
- ✅ **No rate limits** - User queries don't hit Etherscan API
- ✅ **Deep analysis** - Analyzes transaction messages for suspicious content
- ✅ **Centralized data** - All data in one place
- ✅ **Background sync** - Separate worker fetches from Etherscan

## Architecture

```
┌─────────────────┐
│  User Request   │
│ Check address?  │
└────────┬────────┘
         │
         ▼
┌─────────────────────────┐
│  crypto_check_db.py     │ ◄── Queries local DB only
│  (Instant check)        │     (No external API calls)
└────────┬────────────────┘
         │
         ▼
┌─────────────────────────┐
│  Local SQLite Database  │
│  ~/.config/crypto-scam- │
│   detector/crypto_data  │
│                         │
│  • Addresses            │
│  • Transactions         │
│  • Risk scores          │
│  • Scam indicators      │
└────────▲────────────────┘
         │
         │ Background sync
         │
┌────────┴────────────────┐
│  sync_worker.py         │ ◄── Pulls from Etherscan
│  (Background job)       │     Analyzes messages
│                         │     Calculates risk
│  • Reads sync queue     │
│  • Calls Etherscan API  │
│  • Decodes TX messages  │
│  • Stores in DB         │
└─────────────────────────┘
```

## Components

### 1. Database Layer (`database.py`)

SQLite database with tables:
- **addresses** - Address info, risk scores, balances
- **transactions** - Suspicious transactions with decoded messages
- **scam_indicators** - Individual red flags
- **sync_queue** - Addresses waiting to be synced

**Key functions:**
- `get_address(address)` - Retrieve address data
- `upsert_address(data)` - Store/update address
- `add_transaction(tx)` - Store suspicious transaction
- `add_scam_indicator(...)` - Add red flag
- `add_to_sync_queue(address)` - Queue for background sync

### 2. Background Worker (`sync_worker.py`)

Fetches data from Etherscan and stores in database.

**Features:**
- Queries Etherscan API for address data
- Decodes transaction input data (hex → UTF-8)
- **Analyzes messages for suspicious keywords**
  - "lazarus", "hack", "exploit", "private key"
  - Scam domains, phishing phrases
- Calculates risk score (0-100)
- Stores everything in local database

**Usage:**
```bash
# Add address to sync queue
python3 sync_worker.py --add-address 0x...

# Run worker (processes queue continuously)
python3 sync_worker.py

# Process only 10 addresses then stop
python3 sync_worker.py --max-jobs 10

# Show database statistics
python3 sync_worker.py --stats
```

### 3. Database-Only Checker (`crypto_check_db.py`)

Checks addresses against local database **only**.

**No external API calls** - instant results!

**Usage:**
```bash
# Check an address
python3 crypto_check_db.py 0x...

# JSON output
python3 crypto_check_db.py 0x... --json
```

**Behavior:**
-
Github ReposUpdated 2d agoRank 70

AionUi

Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!

MCPOPENCLAW
Github ReposUpdated 6mo agoRank 70

activepieces

AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents

OPENCLAW
Github ReposUpdated 6mo agoRank 70

cherry-studio

AI productivity studio with smart chat, autonomous agents, and 300+ assistants.

MCPOPENCLAW
Github ReposUpdated 7mo agoRank 70

CopilotKit

The Frontend for Agents & Generative UI. React + Angular

OPENCLAW

Machine-readable data

The same record, as JSON, for agents and crawlers.

{
  "facts": [
    {
      "factKey": "vendor",
      "category": "vendor",
      "label": "Vendor",
      "value": "Clawhub",
      "href": "https://clawhub.ai/princedoss77/skills/crypto-scam-detector",
      "sourceUrl": "https://clawhub.ai/princedoss77/skills/crypto-scam-detector",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-11T18:39:06.752Z",
      "isPublic": true
    },
    {
      "factKey": "protocols",
      "category": "compatibility",
      "label": "Protocol compatibility",
      "value": "OpenClaw",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-princedoss77-crypto-scam-detector/contract",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-princedoss77-crypto-scam-detector/contract",
      "sourceType": "contract",
      "confidence": "medium",
      "observedAt": "2026-10-11T18:39:06.752Z",
      "isPublic": true
    },
    {
      "factKey": "traction",
      "category": "adoption",
      "label": "Adoption signal",
      "value": "1K downloads",
      "href": "https://clawhub.ai/princedoss77/crypto-scam-detector",
      "sourceUrl": "https://clawhub.ai/princedoss77/crypto-scam-detector",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-11T18:39:06.752Z",
      "isPublic": true
    },
    {
      "factKey": "latest_release",
      "category": "release",
      "label": "Latest release",
      "value": "2.2.0",
      "href": "https://clawhub.ai/princedoss77/crypto-scam-detector",
      "sourceUrl": "https://clawhub.ai/princedoss77/crypto-scam-detector",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-02-20T08:33:05.142Z",
      "isPublic": true
    },
    {
      "factKey": "handshake_status",
      "category": "security",
      "label": "Handshake status",
      "value": "UNKNOWN",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-princedoss77-crypto-scam-detector/trust",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-princedoss77-crypto-scam-detector/trust",
      "sourceType": "trust",
      "confidence": "medium",
      "observedAt": null,
      "isPublic": true
    }
  ],
  "events": [
    {
      "eventType": "release",
      "title": "Release 2.2.0",
      "description": "**Crypto Scam Detector 2.2.0 – Major database-first, instant-check architecture** - Replaced live API checks with a fully local SQLite database for scam detection; all address scans are instant (no external API calls). - Introduced `crypto_check_db.py` as the new entry point for database-only, <5ms address analysis. - Added `sync_worker.py` as a background process for syncing fresh blockchain data from Etherscan into the database (works with your API key). - New auto-queue system: unknown addresses are added to a sync queue for future analysis. - Multiple new docs: DATABASE_ARCHITECTURE.md, MULTICHAIN_SUPPORT.md, REALTIME_SYNC_UPDATE.md, and release notes for v2.2.0. - Removed old analyzer scripts and outdated documentation, fully transitioning to the new instant database model.",
      "href": "https://clawhub.ai/princedoss77/crypto-scam-detector",
      "sourceUrl": "https://clawhub.ai/princedoss77/crypto-scam-detector",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-02-20T08:33:05.142Z",
      "isPublic": true
    }
  ]
}

Record generated Oct 11, 2026.

For crawlers

This page is free to read. The run-check above is the only paid part, and it answers HTTP 402 until it is paid. Everything else here is public.

  • One record, as JSON: card, facts, snapshot, contract, trust.
  • Every agent, one feed: /.well-known/ai-catalog.json
  • What this site sells, and the price: /.well-known/x402
  • Paid run-check: /api/v1/agents/clawhub-princedoss77-crypto-scam-detector/run-check

Sponsored

Ads related to Crypto Scam Detector and adjacent AI workflows.