Most attacks don’t start with malware. They start with trust.
Sentrii started as a transaction-level threat detection tool, catching risky instructions and malicious wallet drainer programs.
A strong last line of defence.
But the deeper we went into the security landscape,
Your wallet showed you one thing.
The blockchain executed something else.
And by the time you realize it, your assets are already gone.
This is called transaction simulation spoofing and it's one of the more dangerous phishing techniques targeting crypto users today. 🧵
Most attacks don’t start with malware. They start with trust.
Sentrii started as a transaction-level threat detection tool, catching risky instructions and malicious wallet drainer programs.
A strong last line of defence.
But the deeper we went into the security landscape,
Your wallet showed you one thing.
The blockchain executed something else.
And by the time you realize it, your assets are already gone.
This is called transaction simulation spoofing and it's one of the more dangerous phishing techniques targeting crypto users today. 🧵
or other attack vectors.
Sentrii investigates the dApp and interaction flow in isolation before you touch it, helping you understand what it's actually doing behind the interface.
The biggest mistake people make is assuming that if a website looks professional, it must be safe
But attackers can still set delegates, approvals, or permissions and lie in wait for activity to build over time.
And sometimes the real danger isn't the transaction at all.
The website itself may be trying to compromise you through malicious scripts, phishing flows, redirects,
3/
The consequences can be devastating.
→ SOL drained
→ Tokens transferred
All within seconds.
And because you signed the transaction yourself, there is usually no recovery.
2. Treat every "free claim", airdrop, reward, or surprise opportunity as guilty until proven innocent.
These are some of the most common lures attackers use.
3. Use @Sentrii_io before connecting to unfamiliar dApps.
A burner wallet helps limit damage.
4/
How to mitigate the risk.
1. Use a burner wallet for every new dApp interaction.
@solflare makes this easy. You can spin up a burner wallet in seconds and fund it with only what you need for that interaction.
If something goes wrong, your primary wallet stays isolated.
2/
The problem is that a simulation is only a prediction.
It shows what your wallet expects will happen based on the information available at that moment.
In some attacks, what ultimately executes may not match what the user believed they were approving.
1/
You land on what looks like a legitimate website.
The branding looks right.
The UI looks right.
You connect your wallet.
A transaction prompt appears.
The simulation looks clean.
Small fee.
Expected outcome.
Nothing suspicious.
So you approve it.
Today let's talk about the risks, consequences and ripple effects of getting hit by a social engineering attack as a founder or builder.
Because the damage doesn't just stop with you personally.