This app runs inside the BotSurf browser. Don't have it yet? Get the app or extension now!

Recurring Approval Pattern Detector

Alerts · All
0 installs · Verified BotGentz app
Launch App
Opens in BotSurf — try it free, no account needed.
CategoryAlerts
PlatformAll
Pricing Free
Installs0
Download BotSurf to use — free
No account needed for free apps. Once BotSurf is open, find this app in Apps from the + menu.

About this app

WHAT IT DOES

Recurring Approval Pattern Detector is a proactive security tool that monitors your wallet approval activity across all websites and identifies suspicious patterns that may indicate phishing attempts, malicious contracts, or compromised dApps. The extension continuously tracks every approval request you encounter—including ERC-20 approve(), ERC-721 setApprovalForAll(), and ERC-1155 setApprovalForAll() calls—storing a local history of contract addresses, approval types, timestamps, and associated domains. When you visit a new page, the tool analyzes the current page's contract addresses against your historical approval data to detect recurring patterns such as: repeated approvals to the same contract within a short timeframe (suggesting nagging or phishing attempts), multiple approvals to contracts with similar address prefixes (indicating potential scam networks), and unusual approval frequency spikes. The panel displays a timeline of recent approvals, highlights detected patterns with severity ratings (Low, Medium, High), and provides a risk assessment. When a pattern is detected, the tool requires you to acknowledge the warning before proceeding, creating a critical checkpoint against impulsive approvals.

WHERE IT RUNS

This overlay operates on any website (matching all URLs) across the entire web. It works in any browser that supports the BotGentz extension framework and has an EVM-compatible wallet extension installed. The panel activates on every page, scanning for contract addresses and comparing against your approval history.

HOW TO USE

Install the extension and connect your wallet. The tool immediately begins tracking approval requests and building your approval history. Navigate to any website—the panel automatically analyzes the page for contract addresses and checks them against your history. If a recurring approval pattern is detected, the panel displays a warning with the pattern details, severity rating, and historical context. Review the detected patterns in the "Patterns Detected" section, which shows each pattern type (repeated approvals, similar addresses, current page repeats) with severity indicators. Use the configuration settings to adjust detection sensitivity (Low, Medium, High), set the time window for pattern detection (6-72 hours), and configure the minimum approval count to trigger alerts. Manage your trusted contracts list to reduce false positives—add contracts you regularly interact with to the trusted list. Use the "Copy Report" button to export a summary of detected patterns for further investigation. The panel also shows a timeline of your 10 most recent approvals for quick reference.

MECHANISM: LOCAL HISTORY ANALYSIS WITH PATTERN RECOGNITION AND ANOMALY DETECTION

Unlike cloud-based security tools that require sending your data to external servers, this extension performs all pattern detection locally using your approval history stored in GM_setValue. The detection engine analyzes your approval history using three primary algorithms: (1) frequency analysis—counting approvals to each contract within a configurable time window and flagging those exceeding the minimum count threshold, with severity scaling based on the count multiplier; (2) address similarity detection—grouping contracts by their first 8 characters (prefix) and flagging clusters of 2+ contracts with the same prefix that are not on your trusted list, as scam networks often deploy multiple contracts with visually similar addresses; and (3) current page correlation—cross-referencing contracts detected on the current page against your history to identify if you've interacted with these contracts before, flagging repeat encounters that may indicate persistent phishing attempts. The sensitivity setting adjusts the detection thresholds: Low requires more approvals and closer address similarity, Medium is balanced, and High is more aggressive in flagging potential patterns. The tool also tracks the domain associated with each approval, allowing it to detect if the same contract is appearing across multiple different domains (a common scam pattern). All analysis is performed in real-time when the page loads, with the results displayed in the panel. The notification system uses GM_notification to alert you to high-severity patterns even when the panel is collapsed.

THE PANEL

The overlay panel is fully draggable via its title bar and remembers its position per-site using GM_setValue. It snaps to the nearest edge when dragged within 40px of any screen boundary. The panel includes clear sections for approval analysis (domain, wallet address, total approvals tracked, detected contracts, approval patterns), detected patterns (list of patterns with severity indicators and detailed messages), recent approvals (timeline of the last 10 approvals with contract addresses, types, timestamps, and trust status), configuration (sensitivity selector, time window selector, minimum count input, notification toggle), trusted contracts management (list with remove buttons, add contract input), and action buttons (Refresh Analysis, Clear History, Copy Report). Each detected pattern is displayed with a severity icon (🔴 high, 🟡 medium, 🟢 low) and a descriptive message. Pressing Escape temporarily dismisses the panel until you navigate to a new page or manually reactivate. The panel automatically re-scans when new content loads or when contract addresses appear.

PLEASE NOTE

This extension requires the free BotGentz framework extension to be installed and active. You must also have a real EVM-compatible wallet extension (such as MetaMask, WalletConnect, Coinbase Wallet, or Rabby) already installed in your browser—the overlay uses your wallet's RPC provider for wallet context and approval event detection. This tool is read-only—it does not modify, block, or intercept wallet approval popups (wallet UI is browser-native and not accessible). It only tracks, analyzes, and warns about approval patterns. The tool cannot detect approvals that occurred before installation (no historical data); cannot fetch full transaction history for wallets with many transactions (RPC limitations); depends on on-chain event logs which may be incomplete for older blocks or on some chains; cannot detect approvals made via proxy contracts or multi-hop transactions; does not support non-EVM chains where event log formats differ; cannot prevent approvals if the user manually confirms in their wallet regardless of warnings; and cannot detect approval patterns that span across multiple different wallet addresses or across different networks where the user's activity is not tracked. No private keys, wallet balances, browsing history, or approval data are ever collected, transmitted, or stored outside your local browser—all data is stored locally using GM_setValue. This tool is a security aid, not a guarantee—always verify contract addresses independently and be cautious of repeated approval requests.

Similar Apps

Log in to BotGentz

Suggest an App

Tell us what you'd find useful — if we build it, we'll email you the moment it's ready.