Grub boots before you sign

Grub is a pre-signature shield for BNB Chain. Like the bootloader it is named after, it runs first: before your wallet signs, Grub reads what the chain would do and shows you its face. Unimpressed means safe. Side-eye means read the findings. Eyes shut means do not sign.
App: grubonchain.xyz · X: @grubonchain
What it does
| Chamber | Question it answers | How |
|---|---|---|
| Before you sign | What will this transaction or signature actually do? | Decode, replay on the live chain with eth_simulateV1, diff your assets and permissions |
| Token check | Is this token a honeypot? | Bytecode capabilities, owner, proxy, liquidity, then a real buy and sell replayed on the live state |
| Approvals | Who can spend my tokens right now? | Allowances against known spenders and Permit2, event scan, one-click revoke |
| Scam check | Is this message or link trying to eat me? | Wording rules, MetaMask and ScamSniffer blocklists, homoglyph and brand checks |
| Ask the grub | Explain this hash / address / calldata | A deterministic planner runs the tools; numbers come from tools, never from a model |
| $GRUB | The token | Fixed supply, Uniswap V4 pool on BNB Chain, stepped tax hook in BNB |
Principles
- Watch, never connect. No account, no sign-in, no wallet connection needed for any tool. Paste an address, a transaction, a token, a message. The only transactions Grub ever proposes are approval revokes, built as plain
approve(spender, 0)calls that you sign in your own wallet. - Execute, then judge. Calldata tells you the intent; only execution tells you the effect. Every transaction is replayed on the current chain state before Grub says anything.
- Judge the spender, not only the call. An approval does nothing today and everything next month. Every spender is profiled: known router, verified contract, plain wallet, delegated account, blocklist.
- Say what you do not know. Unknown selectors stay unknown. Partial scans say partial. Unreachable lists say unreachable. Nothing is invented to fill a box.
Where it runs
In your browser, against public BNB Chain RPC endpoints that accept cross-origin requests and support eth_simulateV1. Two small serverless helpers exist: a cache of the phishing blocklists (they weigh several megabytes) and an optional language-model rewrite of the agent's answer that only ever sees tool results. Read Privacy and data for the exact list of what leaves your machine.
