Inspiration
Most financial scams don't hack a bank. They trick a person. A text says your account will be blocked, a "police officer" says to stay on the call, or a refund requires you to approve a UPI request. In each case the victim is under pressure, alone, and has seconds to decide.
Existing tools don't help much at that moment. Spam filters miss messages sent over WhatsApp and SMS, and warnings are often vague ("this may be dangerous") without explaining why. Reporting is also risky, because people paste full messages containing their card numbers, OTPs and ID numbers into forms and chats, which creates a second data leak.
We wanted a tool that works in the moment of doubt, explains itself in plain language, and protects the user's private data while doing it.
What it does
ScamShield lets you paste any suspicious message or link and instantly returns:
- A risk score (0-100) with a clear verdict: Low risk, Suspicious, or Likely scam.
- Explainable red flags. Each flag says what was found and why scammers use it, such as urgency, requests for OTP/PIN, threats of arrest, fake refunds, secrecy demands, or requests to install remote-access apps like AnyDesk.
- A link inspector that catches shortened URLs, raw IP addresses, look-alike domains (e.g.
paypa1-secure-login.top), brand names stuffed into unrelated domains, punycode tricks, and unencrypted links. - Highlighted text, so users see exactly which words triggered the warning.
- A privacy-safe sharing mode that automatically hides card numbers, OTPs/PINs, Aadhaar-style ID numbers, PAN, phone numbers, emails and UPI IDs, so the message can be reported without leaking more data.
- A "what to do now" plan with reporting steps, including India's cybercrime portal and 1930 helpline.
Everything runs in the browser. Nothing the user pastes is uploaded or stored.
How we built it
ScamShield is a single-page web app written in plain HTML, CSS and JavaScript, with no backend and no dependencies. We designed the detection engine to be rule-based and explainable, so every verdict can be justified.
Risk scoring. Each detected signal has a weight wi (0-100) based on how strongly it indicates fraud. Signals are combined so that several moderate signals add up, but the score never exceeds 100:
$$S = 100\left(1 - \prod_{i=1}^{n}\left(1 - \frac{w_i}{100}\right)\right)$$
Look-alike domain detection. We normalize common character swaps (\(0 \to o\), \(1 \to l\), \(5 \to S\), \(rn \to m\)) and compare each part of the domain to a list of well-known brands using Levenshtein edit distance. A distance \(d \le 1\) to a trusted brand name, on a domain that isn't the real one, is flagged.
Smart redaction. Card numbers are only masked if they pass the Luhn checksum, which avoids hiding random numbers. OTP/PIN/CVV values are masked based on the words around them.
AI. We used Claude as a pair-programmer to explore real scam patterns, draft and refine the detection rules, write test messages, and iterate on the interface and copy. The detection itself is deterministic, which keeps it fast, private and explainable.
Challenges we ran into
- Balancing false positives and false negatives. Words like "KYC" or "bank alert" appear in genuine messages too, so we gave weak signals low weights and let strong signals (asking for an OTP, installing remote-access apps) dominate.
- Look-alike links. Catching
amaz0n-refund-support.xyzwithout flagging the realamazon.inneeded domain normalization, registrable-domain extraction and careful edit-distance limits. - Redacting without breaking the message. Phone numbers, card numbers and ID numbers all look similar, so we validate cards with Luhn and order the redaction steps carefully.
- Keeping it understandable. Security tools are often too technical. We wrote every explanation for a non-expert and designed the verdict as a clear stamp instead of a wall of numbers.
What we learned
- Scams share a small set of psychological levers (urgency, fear, reward, secrecy, authority), and naming them for users helps them recognize new scams on their own.
- Privacy and safety can reinforce each other: a tool that processes data locally is easier to trust, especially in finance.
- Explainability matters. Users act on warnings when they understand the reason.
What's next
- Add an optional LLM layer for unfamiliar scam wording and multilingual messages (Hindi, Gujarati and more), with redaction applied before any text leaves the device.
- Ship as a browser extension and a mobile share-sheet action, so users can check a message directly from WhatsApp or SMS.
- Expand brand and scam-pattern coverage with community-reported data, and publish anonymized scam trends.
- Add a short "scam awareness" quiz for families and older adults, who are frequent targets.
Disclaimer: ScamShield is a safety aid, not a guarantee. When in doubt, contact your bank using the number on your card.
Built With
- ai-assisted-development
- anthropic
- claude
- client-side
- clipboard-api
- conic-gradient
- css3
- cybersecurity
- dark-mode
- explainable-ai
- fintech
- fraud-detection
- github
- google-fonts
- html5
- javascript
- levenshtein-distance
- luhn-algorithm
- phishing-detection
- privacy-by-design
- regex
- render
- responsive-design
- upi
Log in or sign up for Devpost to join the conversation.