DEV Community

memeshe
memeshe

Posted on

My Mum Keeps Getting Scam Texts. I Built Her a Telegram Shield.

Hacktoberfest Weekend Challenge: Build for a Friend Submission 🤝

My Mum Keeps Getting Scam Texts. I Built Her a Telegram Shield.

This is a submission for the Hacktoberfest Weekend Challenge: Build for a Friend.

Live: t.me/scamsshield_bot · Dashboard · Repo

The friend

My mum gets parcel-scam SMSes in Thai almost weekly — "พัสดุถูกระงับ, ยืนยันตัวตนด่วน" with a bit.ly link, fake bank warnings, the works. She forwards them to me, I tell her "don't click that," and the cycle repeats. She's not going to learn to read headers. So I built the thing that reads them for her: ScamShield. She forwards any suspicious message to a Telegram bot, and in seconds gets back a verdict card — SCAM / SUSPICIOUS / LIKELY SAFE — with reasons in Thai first, English second, and what to do next.

What it actually does

Send anything — an SMS forward, a link, a wallet address — and the bot runs a triage pipeline:

  1. Signal extraction — links, crypto addresses, phone numbers, urgency phrases ("ด่วน", "airdrop", "verify now"), impersonation hits (banks, Binance, Shopee, "ตำรวจ"…).
  2. Live web grounding (SerpApi) — the suspicious domain gets searched for scam/fraud reports, so the verdict cites the web, not vibes.
  3. On-chain probe — wallet addresses are checked against public RPCs: contract code (drainer pattern) vs plain wallet vs fresh/empty.
  4. Score — transparent point rules, capped at 100. ≥70 SCAM, ≥40 SUSPICIOUS, else LIKELY SAFE.
  5. Explanation by an open-weight model (Gemma) — two short sentences, Thai then English, written for a non-technical reader. The model explains; the rules decide. If the model is unreachable, the verdict still lands, honestly labelled rule-based.

Real outputs from the pipeline (cards exactly as the bot sends them):

🚨 Thai parcel scam → SCAM 75

🚨 อันตราย: น่าจะเป็นมิจฉาชีพ (SCAM, 75/100)

เหตุผล / Why:
• pressure tactics: ด่วน, ระงับ, ยืนยันตัวตน
• impersonates: พัสดุ
• suspicious link (shortener / risky domain)

ลิงก์ / Links:
`http://bit.ly/kerry-th-99`

เว็บพูดถึง / Web:
• bit.ly url scan | Free Url Scanner & Phishing Detection — checkphish.bolster.ai/…

🤖 ข้อความนี้ดูน่าสงสัยเพราะใช้คำเร่งรีบและลิงก์ที่ดูไม่น่าเชื่อถือ อย่ากดลิงก์หรือกรอกข้อมูลส่วนตัวเด็ดขาด
This message is suspicious because it uses urgent language and an untrustworthy link. Do not click the link or enter any personal information.
_(model: gemma-4-26b-a4b-it)_

ทำอย่างไร / What to do:
• อย่าโอน อย่าให้ OTP — Do not send money or OTP
• ส่งมาให้ลูกดูก่อนเสมอ
Enter fullscreen mode Exit fullscreen mode

✅ Family check-in → LIKELY SAFE 0

✅ ดูปลอดภัย (แต่ยังระวังไว้) (LIKELY SAFE, 0/100)

เหตุผล / Why:
• no pressure tactics, links, or crypto addresses found

🤖 ข้อความนี้ดูปลอดภัยเพราะเป็นแค่การถามไถ่ทั่วไปและไม่มีลิงก์แปลกๆ ให้กดครับ
This message looks safe because it is just a casual question and has no suspicious links.
_(model: gemma-4-26b-a4b-it)_

ทำอย่างไร / What to do:
• ไม่มีสัญญาณอันตราย แต่ถ้าไม่แน่ใจถามลูกก่อน
• ส่งมาให้ลูกดูก่อนเสมอ
Enter fullscreen mode Exit fullscreen mode

There's also a live dashboard (latest verdicts stream in every 2 seconds, zero API credits burned on page views) and a /health endpoint the host watches.

Why open innovation is what makes this work

The prompt asks where open beats closed for this build. Three places, all load-bearing:

1. The explainer is an open-weight model behind a swappable plug. The verdict text my mum reads is written by Gemma through a plain OpenAI-compatible endpoint. This weekend that endpoint was, in turn: a big hosted Gemma (too slow, 35s+), a smaller one (fast, but it thinks out loud — it wraps everything in <thought> planning blocks), and finally the smaller one plus a 15-line answer-extractor that recovers the Thai/English sentences from inside the thinking. I could do that iteration in an evening because the model, the weights lineage, and the wire format are all inspectable and interchangeable. A closed black-box API gives you one behavior, take it or leave it. Next weekend the same code can point at Ollama on a laptop and nothing else changes — try that migration with a proprietary agent stack.

2. The score is readable by her kid. Every point comes from a named rule in one file (triage.py), and the card lists each reason. When the bot says 75, I can point at exactly which three signals added up. That transparency is the whole product for a family: trust isn't a brand, it's showing your work. Closed-scoring "AI fraud APIs" return a number and a shrug.

3. It costs $0 to run and nobody's data is the product. Free-tier hosting, 250 free SerpApi searches a month (only suspicious domains trigger one), public RPCs, an open model. A tool that protects your family shouldn't need a subscription or a data pipeline into someone's ad machine to survive.

What open didn't do: the score itself is still hand-written rules, and I'm saying so instead of dressing it up. The model explains; the rules decide; the receipts are real links and real RPC responses. A demo that fakes intelligence is worse than no demo.

How it's built

python-telegram-bot (polling worker inside the FastAPI lifespan) + FastAPI + httpx, on Render's free tier from a render.yaml. Telegram handlers have timeouts, an error handler, and a 120s triage budget so one slow provider can't wedge the bot. Every verdict is saved to SQLite and streamed to the dashboard. Sentry watches errors and performance. Nothing exotic — the exotic part is that it exists in my mum's chat app instead of a slide deck.

Built with: Render (hosting) · Gemma (open-weight explanations) · SerpApi (live search grounding) · Sentry (error + performance monitoring).

Repo: memeshee/scamshield — MIT, contributions welcome, especially Thai scam-pattern rules.

Handover

The bot is live in my mum's Telegram now. Her verdict on the verdicts lands here as an update — the real judging criterion was always whether she trusts it.

Disclosure: this write-up was drafted with an AI assistant; every verdict, link, and number in it was run and verified by the author against the live code.

Top comments (0)