Inspiration

Over 40 million Ethiopians rely on mobile money platforms such as Telebirr and CBE Birr. However, sophisticated SMS phishing, USSD transfer exploits, fake lottery claims, and AI-generated deepfakes are increasingly being used to target users and drain accounts. Local-language speakers are particularly vulnerable because many traditional cybersecurity tools do not understand Ge'ez scripts, Ethiopian languages, or locally specific social-engineering tactics.

What it does

BirrGuard is an Ethiopian-first AI cybersecurity platform designed to protect mobile money users in Amharic, Afaan Oromo, Tigrinya, and English. Powered by custom Ge'ez script normalization and multi-vector NLP analysis, BirrGuard detects credential harvesting, USSD-based scams, financial baiting, social-engineering attempts, and synthetic media. Its intuitive Living Shield interface provides real-time risk scoring, one-click test cases, direct reporting guidance, and Gash Birr—an interactive Amharic AI safety companion that provides instant, accessible security guidance. BirrGuard aims to bridge the digital security gap and make digital financial services safer and more accessible for Ethiopian users.

How we built it

I architected BirrGuard as a lightweight, full-stack application using: Next.js 16 (App Router) TypeScript Tailwind CSS Framer Motion Lucide React Gemini 1.5 Flash Custom local threat-detection heuristics

  1. Ge'ez Script Normalization Pipeline To defeat scam evasion techniques, I built a custom script harmonization function that converts incoming Ge'ez text into a standardized canonical format before analysis. Scammers frequently manipulate lookalike Amharic letters to bypass filters. My engine maps all phonetic variants into single canonical characters—such as normalizing ሐ, ኀ, and ኻ into ሀ; converting ሠ to ሰ; mapping ፀ to ጸ; and replacing ዐ with አ. This ensures that regardless of how a scammer alters Amharic orthography or spelling, the underlying semantic threat is preserved and evaluated correctly.
  2. Multi-Vector Cyber Risk Engine Threats are evaluated across four distinct vectors: Brand Impersonation: Detecting fake Telebirr or bank credentials. Credential Harvesting: Catching PIN request forms and suspicious link redirections. Social Engineering & Urgency: Identifying fake prize claims, holiday rush traps, and panic-inducing language. Financial Baiting: Detecting USSD transfer codes disguised as airtime bonuses or account updates. The platform calculates a composite Risk Score on a scale from 0 to 99 by combining localized weights for each detected threat signature across the normalized text. Risk Thresholds: Score under 25: Safe (status = "safe") Score from 25 to 54: Warning (status = "warning") Score 55 and above: Critical Threat (status = "danger")
  3. Key Core Modules Living Shield Dashboard (/): A dynamic threat visualization shield that pulses, scans, and morphs its state (emerald green, amber, or pulsing crimson) based on real-time risk severity. Scam & Phishing Detector (/check): Analyzes SMS messages, Telegram broadcasts, and USSD strings with instant translation and risk explanations across Amharic, Afaan Oromo, Tigrinya, and English. Deepfake Forensic Scanner (/deepfake): Scans uploaded video and photo media for visual lighting anomalies, frequency noise, and synthetic facial manipulation. Gash Birr AI (/chat): An interactive Amharic AI companion acting as a trusted older brother figure (ጋሽ) to guide non-technical users through financial security. ## Challenges we ran into
  4. Erratic Internet Connectivity & Late-Night Builds Building a complete AI platform single-handedly in Ethiopia presented a significant infrastructure challenge. Unpredictable internet latency and packet loss made downloading NPM packages, resolving build errors, and communicating with external APIs difficult during peak hours. ## Accomplishments that we're proud of The accomplishment I am most proud of is single-handedly designing, building, and deploying BirrGuard, an Ethiopian-first AI cybersecurity platform designed to protect mobile money users from financial scams.

What makes this achievement particularly meaningful to me is the combination of technical problem-solving, local impact, and persistence it required.

First, I tackled a low-resource NLP problem. Many existing security tools are built primarily around English and other languages with abundant training data, leaving gaps in their ability to understand Ethiopian languages, Ge'ez script, and locally specific social-engineering tactics. I built a custom Ge'ez normalization pipeline and multi-vector threat engine to identify patterns associated with phishing, financial baiting, impersonation, and USSD scams across Amharic, Afaan Oromo, Tigrinya, and English.

Second, building it in Ethiopia forced me to think about reliability differently. Unstable and slow internet made development difficult, especially when downloading packages, debugging builds, and working with external AI APIs. I adapted by often coding late at night, sometimes from 1 AM to 5 AM, when connectivity was more reliable. I also built a local fallback system so BirrGuard can continue analyzing threats when its external AI services are unavailable.

Building BirrGuard taught me that meaningful technology does not always require a large team or abundant resources. A single developer who understands a problem deeply can still build something from scratch to address it. That realization is what makes BirrGuard the accomplishment I am most proud of.

What we learned

  1. Local Context Matters A generic multilingual model does not automatically understand every local cybersecurity threat. Effective detection requires combining language normalization, localized threat patterns, prompt engineering, and knowledge of Ethiopian financial workflows.
  2. UI/UX Can Be a Security Tool For users who are unfamiliar with cybersecurity terminology, technical explanations alone are not enough. The Living Shield, visual status indicators, and simplified explanations allow users to understand the severity of a threat quickly, regardless of their technical background.
  3. Resilience Engineering Building software in a low-resource environment taught me that reliability cannot always depend on a constant internet connection. Designing offline fallbacks and local-first systems can be essential when deploying technology in regions where connectivity is inconsistent. ## What's next for BirrGuard USSD & Offline SMS Protection Explore Android-based protection mechanisms that can help identify suspicious USSD and SMS activity while minimizing dependence on constant internet connectivity. Expanded Regional Languages Extend support to additional Ethiopian languages, including: Sidama Wolaytta Somali Community Threat Network Build a community-driven threat database where users can submit confirmed scams and suspicious messages, creating a continuously expanding Ethiopian cybersecurity knowledge base. Stronger AI Forensics Improve the deepfake-analysis pipeline with larger datasets and more sophisticated multimodal detection techniques.

Built With

Share this project:

Updates

Submission history