Inspiration

RugGuard AI was inspired by the growing number of scams, rug pulls, phishing websites, and fraudulent crypto projects that cause significant losses for investors, especially beginners. Many users struggle to understand complex blockchain data and security risks before investing. Most existing "scam checkers" also stop at reading verified source code from a block explorer — they don't actually test whether a token can be sold, and they don't work at all on unverified contracts. We wanted to build something that goes further: a simple, AI-powered solution backed by real on-chain verification, so users can make safer decisions in the Web3 ecosystem regardless of whether a project bothered to verify its source.

What it does

RugGuard AI analyzes crypto tokens and projects using blockchain intelligence, live on-chain simulation, and AI. It gathers data from Etherscan, CoinGecko, and DexScreener, then goes a step further than most tools by actually simulating a real buy-and-sell of the token against the live Uniswap router via eth_call, calculating real buy/sell tax and flagging honeypot behavior (like transfers that silently revert) directly from blockchain state — not just from what a project's source code claims. For contracts that aren't verified, it inspects the raw EVM bytecode instruction-by-instruction, walking the actual opcodes to catch hidden backdoors like SELFDESTRUCT, DELEGATECALL, or disguised blacklist/mint functions that source-only tools would miss entirely.

Gemini and Groq are then used to translate all of this — AI risk scoring, on-chain simulation results, and bytecode findings — into a single, easy-to-understand risk score with plain-language red flags, so non-technical users get a clear verdict instead of a wall of technical data.

The platform also includes a community-driven scam registry: users can connect their wallet and publish scam reports that are optionally recorded immutably on-chain via a Solidity smart contract we wrote, compiled, and deployed live on both Ethereum Sepolia and Base Sepolia testnets — giving the community layer real, verifiable, tamper-resistant backing rather than just a database entry that anyone could edit.

How we built it

We built RugGuard AI using React, TypeScript, Vite, and Tailwind CSS for the frontend, with an Express backend and Firebase Firestore for community data storage. Blockchain and market data are collected from Etherscan, CoinGecko, and DexScreener APIs. Gemini serves as the primary AI engine for analysis, with a multi-tier fallback chain (Mistral, Cohere, then Groq) to keep the platform reliable even if one provider is down or rate-limited.

For the on-chain layer, we used ethers.js to connect directly to public Ethereum, Base, BSC, and Arbitrum RPC endpoints, querying live Uniswap V2, PancakeSwap V2, BaseSwap, and Camelot router/factory contracts to simulate real trades and detect honeypots at the current block. We wrote a RugGuardScamRegistry.sol smart contract in Solidity, compiled it, and deployed it via Remix and MetaMask to Ethereum Sepolia and Base Sepolia, wiring wallet connect (MetaMask/EIP-1193) into the frontend so users can sign and submit reports directly to the deployed contract.

Challenges we ran into

One of the biggest challenges was transforming complex blockchain metrics into clear and actionable insights for non-technical users. Another was combining data from multiple APIs and generating a consistent risk assessment that is both accurate and easy to understand.

On the blockchain side, simulating an actual honeypot check correctly was harder than expected — early attempts at bytecode inspection using naive substring matching on hex data produced false positives on almost every contract, since compiled bytecode is high-entropy and coincidentally contains most 1-2 byte patterns somewhere. We rebuilt this as a proper linear EVM disassembler that walks the bytecode instruction-by-instruction, correctly skipping PUSH1–PUSH32 operand bytes so opcodes are only flagged when they appear at true instruction boundaries. We also had to handle RPC failures carefully — early versions defaulted to reporting a token as "safe" when an on-chain check simply couldn't run, which we fixed to explicitly report "unknown" instead of a false negative, since silently defaulting to "safe" is far more dangerous than admitting uncertainty. Getting testnet ETH across two chains, deploying via Remix/WalletConnect on mobile, and independently verifying every deployment on Etherscan/Basescan before trusting it was also a real logistical challenge worth mentioning.

Accomplishments that we're proud of

We're proud of building a platform that goes beyond reading pre-existing web APIs and actually reaches into live blockchain state — simulating real trades and disassembling real bytecode — rather than just wrapping an LLM around static data. We successfully deployed and independently verified a real Solidity smart contract across two separate testnets (Ethereum Sepolia and Base Sepolia), giving our community scam registry genuine on-chain backing. We're also especially proud of the beginner-friendly explanations that translate all of this technical depth into plain language, making crypto security more accessible to everyone, not just people who can already read Solidity or EVM bytecode.

What we learned

Through this project, we learned how blockchain intelligence platforms work end-to-end, how to integrate multiple APIs into a unified workflow, and how to reason correctly about EVM bytecode at the opcode level rather than relying on shortcuts that look right but produce false results. We learned the importance of designing for honest failure — an on-chain check that can't run should say "unknown," not quietly default to "safe." We also learned a lot about the practical side of deploying and verifying smart contracts across multiple testnets, including the friction of doing so from a mobile-first workflow. Most importantly, we learned that making security information understandable is just as important as detecting the risks in the first place — and that a hybrid of AI reasoning and verifiable on-chain execution is far more trustworthy than either one alone.

Built With

Share this project:

Updates

Submission history