We scan Solana multisig transactions before you sign them.
Durable nonces, authority transfers, withdrawal guard manipulation, known attack patterns — flagged before your Ledger prompt appears.
Free tier. No login. https://t.co/RIm8nCGsBC
@afscott We built a pre-sign threat scanner for multisig teams. We're looking for protocols to start using it.
This is what signers would have seen before signing the firsst Drift exploit transaction. No manual or ad-hoc editing of the report:
https://t.co/ulAlcXGVDH
This is the right long-term direction. But protocols are running on Squads today with billions at risk right now.
TxScope solves blind signing today without new primitives. We read the pending proposal from chain, simulate it, and give signers a plain-language report before they approve:
https://t.co/p6tr2YtxR5
New multisig primitives + external verification like this aren't competing approaches — you want both.
Great to see this. STRIDE and SIRN cover evaluation, monitoring, and incident response, but there's still a gap at the signing layer.
We built https://t.co/pfd5z0TEfZ to fill it: plain-language threat reports for every pending Squads proposal, before any signer approves.
Here's what it looks like on the Drift exploit tx:
https://t.co/p6tr2Yt01x
Yes, that's the core problem we're solving. Instead of signing blind, every pending proposal gets a report like this before anyone approves:
https://t.co/p6tr2YtxR5
That's the actual Drift admin transfer tx. Durable nonce flagged, authority change decoded, proposer history pulled, "DO NOT SIGN" recommendation: all before any signer opens the multisig UI.
We're working on this.
TxScope decodes every pending Squads multisig transaction into a human-readable threat report before any signer approves: durable nonce detection, authority transfers, oracle manipulation, instruction-level trace, risk scoring.
Built it because the Drift hack was preventable. We ran both exploit TXs through the engine: every red flag caught: durable nonce, admin transfer to a 1-day-old wallet, withdrawal guards raised 100,000x, 98% match to known attack patterns.
https://t.co/p6tr2Yt01x
Not hardware-level yet (that's a different problem) but we cover the pre-sign verification layer for multisig governance, the gap that actually got exploited.
This is exactly why pre-signing transaction verification needs to be automated, not left to human judgment under social pressure.
We built https://t.co/pfd5z0TEfZ to solve this. It scans every pending Squads multisig proposal and generates a plain-language threat report before any signer approves.
We scanned both Drift exploit transactions. Every red flag was detectable: durable nonce, authority transfer to a new wallet, known attack pattern match.
The reports are public: https://t.co/pfd5z0TEfZ
@DrPayFi You can prevent this by using pre-signing scanner. Have at the report the signers would have seen had they used the scanner: https://t.co/ulAlcXGVDH
@DriftProtocol Our transaction scanner shows you the problems before you sign with Squads. See the report that one of the two transactions would have produced before signing: https://t.co/ulAlcXGVDH
Can we show you how to integrate it?
@ariel__sol@P3b7_ That's what we did and this is what one of the two transactions would have shown them before signing: https://t.co/ulAlcXGVDH
Do you know anyone at the team so we can show it to them?