Madar TxCheck
Most people sign transactions they cannot read. Madar TxCheck reads a Substrate / Polkadot SDK transaction before it is signed, explains in plain words what it will really do, and stops the classic traps — fake sites, scam addresses, hidden full-control permissions and transactions disguised as harmless messages.
Try it
Pick an example or paste your own call / signer payload. The check runs on our public API.
Full answer (JSON)
🎣 Fake & scam sites
Sites on the community scam list, and look-alikes such as polkadot-js.org or po1kadot.network.
🚩 Scam addresses
Any account in the transaction that has been reported for fraud — even inside batches.
🔑 Full control
“Any” proxies that hand someone your whole account, unlimited asset approvals, ownership transfers.
🎭 Disguised transactions
A “sign this message to log in” request that is really a transfer.
📦 Hidden in batches
Every action inside batches, proxies and multisigs is unpacked and explained one by one.
⚙️ Wrong network & traps
Payloads for another chain, transactions that never expire, large tips, admin-only calls, raw XCM.
API
POST https://madar-network.com/api/txcheck/v1/check — JSON in, JSON out. Free; fair-use rate limit per IP.
curl -s https://madar-network.com/api/txcheck/v1/check \
-H 'content-type: application/json' \
-d '{"chain":"polkadot","call":"0x0503…","origin":"https://app.example.com","lang":"en"}'Request
chain—polkadot,polkadot-asset-hub,kusama,kusama-asset-hub,madar. Optional when the payload has agenesisHash.payload— polkadot.jsSignerPayloadJSON, exactly what a wallet receives insignPayload.call— or just the call as hex.raw—{"address","data"}fromsignRaw.origin— the site asking.lang—enorar.
Answer
verdict—ok,cautionordanger, with a ready-to-showheadline.actions— what will happen, in plain words.findings— each risk:level, stablecode,message.calls— the fully decoded call tree.call_hash— BLAKE2-256 of the call, so a verdict cannot be reused for another transaction.
Verify the signature
Every answer is signed with Ed25519 over the exact response body. Headers: X-Madar-Signature, X-Madar-Key. Pin our key: loading…
const res = await fetch(API, { method: "POST", headers: { "content-type": "application/json" }, body });
const bytes = new Uint8Array(await res.arrayBuffer());
const hex = (h) => Uint8Array.from(h.slice(2).match(/../g), (b) => parseInt(b, 16));
const key = await crypto.subtle.importKey("raw", hex(PINNED_KEY), "Ed25519", false, ["verify"]);
const ok = await crypto.subtle.verify("Ed25519", key, hex(res.headers.get("X-Madar-Signature")), bytes);
if (!ok) throw new Error("answer was not signed by Madar TxCheck");
const verdict = JSON.parse(new TextDecoder().decode(bytes));For wallets
Call the API inside your signPayload / signRaw handler and show headline, actions and findings above the confirm button. On danger, make the user type or hold to continue. If the API cannot be reached, show your normal screen — the check is advice, never a gate you depend on.
Privacy
- No keys, no seeds — only the unsigned transaction, which becomes public on-chain anyway.
- We do not store requests or answers, and we do not log their contents.
- Prefer to keep even that in-house? Run your own instance — same binary, same answers.
Self-host
One static binary. It reads networks through their own RPC (any Substrate / Polkadot SDK chain you add) and signs answers with a key created on first start.
./madar-txcheck init # writes madar-txcheck.toml (add your [[chain]] entries) ./madar-txcheck serve # API on 127.0.0.1:9630 — put TLS + a rate limit in front ./madar-txcheck check req.json # one check from the command line
| System | File | SHA-256 |
|---|---|---|
| Loading… | ||
FAQ
Does “ok” mean the transaction is safe?
It means none of our checks found a known risk. It cannot know your intentions: always read the plain-words actions and make sure they are what you want.
Which chains?
The public API reads Polkadot, Kusama, their Asset Hubs and MADAR. A self-hosted instance reads any Substrate / Polkadot SDK chain you configure — it learns each runtime from the chain itself and follows upgrades automatically.
Where do the scam lists come from?
The community list maintained at polkadot-js/phishing, refreshed every 6 hours, plus our own look-alike detection.
How much does it cost?
It is free.