Understand every Tri-Proof Guard decision.
Tri-Proof Guard helps Web3 teams review campaign wallet lists, reduce reward leakage, and protect users before risky wallet signatures. This guide explains the full product layer: Sybil analysis, ScamGuard, evidence scoring, admin intelligence, exports, and API integration.
Sybil review
campaign wallet lists
ScamGuard
pre-sign protection
API ready
partner integrations
Decision map
From raw input to operational output
1. Upload or paste campaign wallets
Start with a CSV, manual wallet list, or public mini audit sample from an airdrop, quest, testnet, allowlist, loyalty campaign, or rewards program.
2. Normalize and validate rows
The engine removes duplicates, separates invalid rows, detects chain context, and keeps parse issues visible so teams know exactly what was accepted.
3. Collect provider evidence
When providers are configured, Tri-Proof Guard enriches wallets with account age, balances, token activity, signatures, owner programs, and contract context.
4. Score behavior and reputation
Signals are weighted through strict, balanced, or conservative policy modes instead of relying on a single weak rule.
5. Build the evidence graph
Funding origins, referrers, referral codes, timing, and known-service context are joined into explainable campaign components.
One security story for campaigns and wallet actions.
Web3 teams face two related problems: fake or low-quality wallets can drain campaign rewards, and users can be pushed into unsafe claim, mint, approval, or wallet-signing flows. Tri-Proof Guard connects both surfaces into one review layer so the team can make better decisions before value moves.
The product is built around explainability. Every warning should answer five questions: what was scanned, what evidence was available, what risk drivers appeared, what the system recommends, and what would make the action safer.
How a wallet list becomes a decision list.
The workflow is designed for campaign operators: upload, enrich, inspect, decide, export, and keep enough evidence to defend the decision later.
Risk is built from layers, not one shortcut.
A good security product should avoid both extremes: calling every unknown project dangerous, or trusting every branded page blindly. Tri-Proof Guard weighs wallet evidence, domain evidence, transaction evidence, and reviewer context separately.
Input quality
Duplicate rows, invalid addresses, chain mismatch, CSV parsing errors, and row-level exclusions.
On-chain account state
Age, balance, token holdings, owner program, transaction count, and sampled historical activity.
Behavioral signals
Funding concentration, campaign-only usage, low diversity, similar timing, and repeated wallet patterns.
Graph evidence
Typed funding and referral edges, connected components, confidence, service neutralization, and corroborated coordination findings.
Reputation intelligence
Trusted project domains, suspicious surfaces, known bad counterparties, verified mints, and admin overrides.
Transaction semantics
Human-readable interpretation of approval, transfer, authority, and contract interaction intent.
Reviewer context
Primary reason, confidence, risk drivers, next action, and limitations behind the decision.
Pre-sign protection for the moment users are most exposed.
ScamGuard is the user-facing risk layer. It can scan the current page, every visible link, token mints, wallets, EVM contract targets, and transaction payloads. URL scans add an SSRF-safe passive sandbox and cross-domain Scam DNA comparison without executing page JavaScript.
1. Classify the surface
URL, wallet, token mint, contract address, serialized transaction, or wallet request JSON is routed to the right scanner.
2. Check source context
Domain patterns, trusted registries, suspicious TLDs, and project intelligence are evaluated together.
3. Open URLs passively
The URL Sandbox validates every DNS answer and redirect, pins the public destination IP, limits time and bytes, and never executes page code.
4. Compare Scam DNA
DOM, scripts, copy, styles, behavior, redirects, and wallet targets are compared with prior cross-domain campaign evidence.
5. Decode intent
The engine explains what the request appears to do before the user signs it.
6. Score and explain
The result includes risk level, confidence, security score, primary reason, and recommended actions.
7. Protect where users act
The same engine powers the public scanner, Chrome extension, Telegram Bot, and B2B API endpoint.
Decision outputs
Simple labels for complex evidence
No major risk pattern was detected from the available evidence. The wallet can be considered a candidate for automatic inclusion, subject to project policy.
The wallet or interaction needs human review because one or more signals require context. This is the right bucket for uncertain but not clearly malicious cases.
The wallet is high-risk, inactive, protocol-owned, unreadable, clustered, or otherwise unsuitable for automatic reward distribution.
ScamGuard uses this for dangerous pre-sign situations such as known scam domains, unlimited approvals to risky spenders, or authority-changing transactions.
The score prioritizes review; the explanation guides action.
A numeric score is useful for sorting, but it is not enough for an operator. Tri-Proof Guard pairs every result with a primary reason, confidence level, risk drivers, and next step so the reviewer understands why the score exists.
Use it as a dashboard, scanner, extension, or API.
Different teams need different surfaces. The product keeps the same decision language across public demos, full analyses, browser protection, and partner integrations.
Common product questions.
These are the questions a project team, grant reviewer, wallet partner, or security reviewer is most likely to ask first.
Ready to test the product?
Start with the public mini audit, open the ScamGuard scanner, or contact the team for a project-specific campaign review.