agentsvc.io

services / scam-message-check

financeoperational · 3002 ms

Crypto Scam Message Detector

Scam and phishing detection for crypto wallets, trading bots and social agents: check a DM, cast, tweet, email or comment before your agent or user acts on it. Returns a verdict safe, suspicious or scam, a 0 to 100 risk score, the scam type (wallet drainer, fake airdrop, phishing login, impersonation, seed phrase theft, fake support, giveaway doubling, investment fraud, pig butchering, malware), red flags with exact quotes, and advice. Every link is checked for real: domain age and registration via RDAP, look-alike domains of 40 known brands (uniswap-claims.xyz, rnetamask.io), punycode and link shorteners. Fixed checks can only raise the verdict, so a message that tries to talk the classifier into "safe" still gets flagged. Claude Haiku 5.5. Up to 8,000 characters; optional sender and channel.

Run free trial ↗3 free calls per day with the example input. Paid: $0.003 USDC, no limit.

Call it

import { wrapFetchWithPayment, x402Client } from "@x402/fetch";
import { registerExactEvmScheme } from "@x402/evm/exact/client";
import { privateKeyToAccount } from "viem/accounts";

const client = new x402Client();
registerExactEvmScheme(client, { signer: privateKeyToAccount(process.env.EVM_PRIVATE_KEY) });
const payFetch = wrapFetchWithPayment(fetch, client);

const res = await payFetch("https://agentsvc.io/api/v1/proxy/scam-message-check", {
  method: "POST",
  headers: { "Content-Type": "application/json" },
  body: JSON.stringify({"text":"gm! new LP rewards on https://rnetamask.io/rewards connect your wallet to claim before midnight","channel":"Discord DM"}),
});
const { data, payment } = await res.json();  // payment.status "settling"; header X-Payment-Settle: sync returns payment.transaction

Input

FieldTypeDescription
text *stringThe message to check, max 8,000 chars
senderstringOptional: sender name or handle as shown, max 200 chars
channelstringOptional: where it arrived, e.g. X DM, Telegram, Discord, email

Output

FieldTypeDescription
verdictstring
risk_scoreinteger
scam_typestring
red_flagsarray
evidencearray
explanationstring
linksarray
addresses_mentionedarray
pattern_hitsarray
advicestring
modelstring
checked_atstring

Example response (data)

{
  "verdict": "scam",
  "risk_score": 97,
  "scam_type": "wallet_drainer",
  "red_flags": [
    "rnetamask.io imitates metamask",
    "Domain rnetamask.io imitates metamask.io using a lookalike character substitution",
    "Domain registered only 384 days ago and is not the official MetaMask domain",
    "Unsolicited Discord DM promising rewards",
    "Urgency pressure with a claim-before-midnight deadline",
    "Asks the user to connect their wallet to a link to claim rewards",
    "asks to connect or verify a wallet"
  ],
  "evidence": [
    "new LP rewards on https://rnetamask.io/rewards",
    "connect your wallet to claim before midnight"
  ],
  "explanation": "This message links to a fake MetaMask lookalike domain that asks you to connect your wallet to claim rewards, which is a classic wallet drainer setup. Do not visit the link or connect any wallet, and never share your seed phrase.",
  "links": [
    {
      "url": "https://rnetamask.io/rewards",
      "domain": "rnetamask.io",
      "official_for": null,
      "imitates": "metamask",
      "shortener": false,
      "punycode": false,
      "domain_age_days": 384,
      "registered": true
    }
  ],
  "addresses_mentioned": [],
  "pattern_hits": [
    "asks to connect or verify a wallet"
  ],
  "advice": "Do not click the links, connect a wallet, sign anything or reply. Block and report the sender.",
  "model": "claude-haiku-5-5",
  "checked_at": "2026-10-10T19:09:55.666Z"
}