Inspiration

Every day, millions of people across Southeast Asia fall victim to online scams — fake bank SMS, phishing links, job fraud, and romance scams. In Vietnam alone, the State Bank reported over $400 million in losses from online fraud in 2024.

The most heartbreaking part? Most victims are ordinary people — elderly parents who trusted a fake "Vietcombank" message, students who fell for a "work from home" offer, families who lost savings because a link looked real.

We asked ourselves: what if anyone could verify a suspicious message in 3 seconds, for free, without needing technical knowledge? That question became ScamShield AI.

What it does

ScamShield AI uses a 3-layer detection system:

Layer 1 — AI Pattern Recognition

We use Claude AI (Anthropic) to analyze the psychological tactics behind scam messages:

  • Artificial urgency: "Your account will be locked in 30 minutes"
  • Authority impersonation: "This is Vietcombank Security Team"
  • Sensitive data requests: OTP, national ID, bank passwords
  • Unrealistic reward claims: "You've won 50 million VND"

Layer 2 — Link Intelligence

When a URL is detected, we run:

  • VirusTotal API — cross-check against global malware/phishing blacklists
  • Domain age heuristics — newly registered domains are a major red flag
  • URL structure analysis — detecting lookalike domains like vietcombank-secure.xyz

Layer 3 — Phone Research

When a phone number is pasted:

  • AI-powered automated web search across Vietnamese scam-warning communities
  • Aggregation from forums like OtoFun, community Facebook groups, and crowdsourced scam databases
  • Results summarized in plain language

How we built it

The entire stack was designed to be lightweight, fast, and deployable without a backend server.

Frontend — React + Tailwind CSS for a clean single-page interface. The core UX decision: one input box that accepts everything. No dropdowns, no mode switching — the app auto-detects whether the user pasted a message, a URL, or a phone number and routes it to the right pipeline automatically.

AI Core — Claude AI (Anthropic) via the /v1/messages API. We engineered a structured prompt that instructs Claude to act as a scam forensics expert, returning a JSON object with riskScore, category, reasons, and action. This structured output approach made the frontend rendering deterministic and reliable.

Link Intelligence — VirusTotal Public API for blacklist lookups, combined with client-side URL parsing to detect lookalike domains, suspicious TLDs (.xyz, .top, .click), and abnormal subdomain structures.

Phone Research — Claude's built-in web search capability aggregates mentions of a phone number across Vietnamese scam-warning communities, summarizing findings in plain language without requiring us to scrape any site directly.

Risk Scoring — A weighted combination of all three layers produces a final score from 0–100%, with thresholds at 70% (dangerous) and 40% (suspicious). The weights were tuned manually against a test set of 30 real scam cases collected from Vietnamese news and community reports.

No database. No backend. No login. The entire app runs client-side — making it trivially deployable on Vercel or Netlify and accessible from any device, including low-end smartphones.

Challenges we ran into

1. No single reliable scam database exists There's no free, comprehensive API for Vietnamese scam phone numbers or messages. We solved this by combining Claude's built-in knowledge of scam patterns with real-time web search — no proprietary database needed.

2. Avoiding false positives Early versions flagged legitimate bank messages as dangerous. We refined our prompting strategy to distinguish actual urgency signals from routine notifications.

3. Multi-input type detection Handling text, URLs, and phone numbers with a single input field required building an auto-detection layer that routes each input to the right analysis pipeline.

4. Speed vs. accuracy tradeoff Deep multi-source research takes time. We optimized by running AI pattern analysis first (instant) and enriching with link/phone checks in parallel.

Accomplishments that we're proud of

** Zero false negatives on our test set** We tested ScamShield against 30 confirmed scam cases from Vietnamese news outlets and community reports. Every single one was flagged as Suspicious or Dangerous. The system also correctly cleared all 10 legitimate URLs we tested — no over-blocking.

** Sub-3-second analysis with no backend** The entire detection pipeline — AI analysis, URL parsing, and risk scoring — completes in under 3 seconds on average, running fully client-side. No server infrastructure means zero latency from routing, and zero cost to scale.

** Multilingual by design, not by translation** Because Claude understands scam psychology across languages natively, ScamShield detects Vietnamese, English, and mixed-language scam messages with equal accuracy — without any language-specific training or rule sets.

** Accessible to non-technical users** We tested the interface with users aged 50+ who had never used a security tool before. Every tester successfully analyzed a message on their first try, without any instructions. One tester said: "This is the first tech thing that actually makes sense to me."

** A working product in under 12 hours** From idea to fully functional demo — including UI, AI integration, and risk scoring — the entire build took less than 12 hours of development time. This proved that AI-powered security tools no longer require large teams or long timelines.

What we learned

  • Prompt engineering is a core engineering skill — the quality of Claude's analysis depended entirely on how precisely we described scam taxonomy in the system prompt.
  • Scam psychology is universal — urgency, authority, and greed are the same tactics across every language and culture. This makes ScamShield inherently multilingual.
  • Simplicity wins — the most impactful design decision was a single paste box. No forms, no steps, no friction. Anyone can use it

What's next for ScamShield AI

| v1.0 (now) | Web app · Text, Link & Phone analysis · Claude AI · VirusTotal | | v2.0 (Q3 2026) | Browser Extension · Telegram Bot · Community reporting | | v3.0 (Q1 2027) | Bank API integration · Mobile app · EN / VN / TH / ID support |

Built With

Share this project:

Updates

Submission history