MADAR NetworkDeveloper services
Free · open source · v0.1.0

Madar TxCheck

Most people sign transactions they cannot read. Madar TxCheck reads a Substrate / Polkadot SDK transaction before it is signed, explains in plain words what it will really do, and stops the classic traps — fake sites, scam addresses, hidden full-control permissions and transactions disguised as harmless messages.

< 1 sper check
Signedevery verdict (Ed25519)
0keys involved, nothing stored

Try it

Pick an example or paste your own call / signer payload. The check runs on our public API.

🎣 Fake & scam sites

Sites on the community scam list, and look-alikes such as polkadot-js.org or po1kadot.network.

🚩 Scam addresses

Any account in the transaction that has been reported for fraud — even inside batches.

🔑 Full control

“Any” proxies that hand someone your whole account, unlimited asset approvals, ownership transfers.

🎭 Disguised transactions

A “sign this message to log in” request that is really a transfer.

📦 Hidden in batches

Every action inside batches, proxies and multisigs is unpacked and explained one by one.

⚙️ Wrong network & traps

Payloads for another chain, transactions that never expire, large tips, admin-only calls, raw XCM.

API

POST https://madar-network.com/api/txcheck/v1/check — JSON in, JSON out. Free; fair-use rate limit per IP.

curl -s https://madar-network.com/api/txcheck/v1/check \
  -H 'content-type: application/json' \
  -d '{"chain":"polkadot","call":"0x0503…","origin":"https://app.example.com","lang":"en"}'

Request

  • chain — polkadot, polkadot-asset-hub, kusama, kusama-asset-hub, madar. Optional when the payload has a genesisHash.
  • payload — polkadot.js SignerPayloadJSON, exactly what a wallet receives in signPayload.
  • call — or just the call as hex.
  • raw — {"address","data"} from signRaw.
  • origin — the site asking. lang — en or ar.

Answer

  • verdict — ok, caution or danger, with a ready-to-show headline.
  • actions — what will happen, in plain words.
  • findings — each risk: level, stable code, message.
  • calls — the fully decoded call tree. call_hash — BLAKE2-256 of the call, so a verdict cannot be reused for another transaction.

Verify the signature

Every answer is signed with Ed25519 over the exact response body. Headers: X-Madar-Signature, X-Madar-Key. Pin our key: loading…

const res = await fetch(API, { method: "POST", headers: { "content-type": "application/json" }, body });
const bytes = new Uint8Array(await res.arrayBuffer());
const hex = (h) => Uint8Array.from(h.slice(2).match(/../g), (b) => parseInt(b, 16));
const key = await crypto.subtle.importKey("raw", hex(PINNED_KEY), "Ed25519", false, ["verify"]);
const ok = await crypto.subtle.verify("Ed25519", key, hex(res.headers.get("X-Madar-Signature")), bytes);
if (!ok) throw new Error("answer was not signed by Madar TxCheck");
const verdict = JSON.parse(new TextDecoder().decode(bytes));

For wallets

Call the API inside your signPayload / signRaw handler and show headline, actions and findings above the confirm button. On danger, make the user type or hold to continue. If the API cannot be reached, show your normal screen — the check is advice, never a gate you depend on.

Privacy

  • No keys, no seeds — only the unsigned transaction, which becomes public on-chain anyway.
  • We do not store requests or answers, and we do not log their contents.
  • Prefer to keep even that in-house? Run your own instance — same binary, same answers.

Self-host

One static binary. It reads networks through their own RPC (any Substrate / Polkadot SDK chain you add) and signs answers with a key created on first start.

./madar-txcheck init            # writes madar-txcheck.toml (add your [[chain]] entries)
./madar-txcheck serve           # API on 127.0.0.1:9630 — put TLS + a rate limit in front
./madar-txcheck check req.json  # one check from the command line
SystemFileSHA-256
Loading…

FAQ

Does “ok” mean the transaction is safe?

It means none of our checks found a known risk. It cannot know your intentions: always read the plain-words actions and make sure they are what you want.

Which chains?

The public API reads Polkadot, Kusama, their Asset Hubs and MADAR. A self-hosted instance reads any Substrate / Polkadot SDK chain you configure — it learns each runtime from the chain itself and follows upgrades automatically.

Where do the scam lists come from?

The community list maintained at polkadot-js/phishing, refreshed every 6 hours, plus our own look-alike detection.

How much does it cost?

It is free.