OpenAI 2026 hackathon

ScamShield Pro

ScamShield Pro: local AI protection against scams, phishing links, fake login pages, and fraudulent job offers.

Solo project by Rehan Raza · 0 likes · 0 comments

Archive position — measured, not model output

0 likes on Devpost

2,264 of the 7,856 archived projects have more likes, and 5,592 share exactly 0 — so this project's #6,553 place in the like-ranked listing is a tie-break inside that group, not a ranking.

Projects (log scale)

1
10
100
1k
10k
05,592
11,758
2285
3–4132
5–975
10+14

Likes on Devpost. ▲ marks this project's group.

Show the figures
LikesProjectsShare of archive
05,59271.2%
11,75822.4%
22853.6%
3–41321.7%
5–9751.0%
10+140.2%
Devpost like counts for all 7,856 archived projects, captured when this archive was built.

Executive Summary

What the company appears to be

ScamShield Pro is a self-reported local-first Chrome extension designed to protect users from scams, phishing links, fake login pages, and fraudulent job offers. It combines machine learning (ML), explainable rules, OCR, and browser security inspection into a single tool that runs locally in the browser without requiring user data to leave their device.

What changed

The author states they built this as a solution to the increasing sophistication of scams, which now include professional-looking fake job offers and phishing pages. The project was developed using tools like DistilBERT, ONNX Runtime Web, Tesseract.js, and various APIs including Gemini and Tavily Search.

Single most important open question

Is there any evidence of user adoption or commercial traction beyond the author’s own development?

Note: All content is based on a self-reported project description. No external verification, revenue data, customer names, or independent sources are available.

Back to contents

What The Product Actually Is

The description states that ScamShield Pro is a local-first Chrome extension that performs multiple layers of scam detection:

  • Text-based detection: Uses a fine-tuned DistilBERT model to classify text as Safe, Risky, or Scam.
  • Image OCR support: Allows users to drag-select text from images on webpages and analyze it locally using Tesseract.js.
  • Link inspection: Detects lookalike domains, URL shorteners, punycode, hidden redirects, and visible-link mismatches.
  • Anti-phishing scan: Checks for fake login pages by inspecting claimed brand, current domain, password fields, and form destinations.
  • Company research feature: Enables manual or selected company name input to return public evidence with source links (via Tavily API and Node.js backend).

It uses:

  • Chrome Manifest V3
  • ONNX Runtime Web with WASM
  • Transformers.js
  • Tesseract.js
  • A Node.js backend hosted on Render for optional company research

Inference: The product is described as a browser extension, not a SaaS platform or API service. It is built to run locally and does not appear to be a commercial product yet.

Back to contents

Positioning & Claim Evolution

The author claims ScamShield Pro addresses the growing sophistication of scams, including:

  • Fake job offers
  • Phishing emails
  • Fake login pages
  • Shortened links
  • Screenshot-based recruitment scams

They state that people should not need to copy content into a chatbot to assess risk — instead, they want a fast safety layer directly inside the browser.

The positioning is local-first security, emphasizing:

  • Privacy (no data leaves the browser)
  • Speed (real-time detection)
  • Explainability (shows why something was flagged)

Claim vs Fact: The author positions this as a solution to modern scam trends, but no evidence of actual user feedback or market validation is provided.

Back to contents

Target Customer & ICP

The description states that ScamShield Pro targets:

  • Students
  • Job seekers
  • Everyday internet users

These are described as individuals who are increasingly fooled by professional-looking scams.

Inference: The target audience appears to be general consumers rather than enterprise clients. No segmentation beyond “internet users” is evident.

Back to contents

Business Model & Pricing Evidence

There is no mention of pricing, monetization strategy, or business model in the project description.

Not evidenced

Back to contents

Technical & Delivery Signals

Key technical elements:

  • Uses local inference via ONNX Runtime Web and Transformers.js
  • Implements Tesseract OCR for image text extraction
  • Runs on Chrome Manifest V3
  • Includes an offscreen document for model execution
  • Has a Node.js backend hosted on Render for optional company research
  • Integrates with APIs like Gemini, Tavily Search, and Codex/GPT-5.6

Inference: The architecture shows a focus on privacy, performance, and integration complexity — but no evidence of deployment scale or production readiness.

Back to contents

Traction & Maturity Signals

The project is described as a hackathon submission (OpenAI 2026) and was built by one person (Rehan Raza). There is no evidence of:

  • Users
  • Revenue
  • Customers
  • Adoption metrics
  • Product-market fit
  • Commercial traction

Not evidenced

Back to contents

Competitive Context

No competitive analysis or mention of existing tools is included in the description.

Not evidenced

Back to contents

Key Risks & Red Flags

  • Single-person development: The entire project was built by one individual, raising questions about scalability and long-term maintenance.
  • No commercial traction: No evidence of users, revenue, or market validation.
  • Local-first design may limit impact: While privacy-focused, local execution could reduce effectiveness if not widely adopted.
  • Dependency on AI accuracy: The system relies heavily on ML models that may miss nuanced scams or generate false positives.
  • Limited scope: The tool is focused on browser-based detection and lacks broader ecosystem integration.

Inference: The lack of any commercial or user-facing data makes it difficult to assess viability as a product or business.

Back to contents

Diligence Questions To Ask The Founders

  1. What is the current usage rate or adoption level among users?
  2. How do you plan to monetize this extension beyond its current open-source/hackathon state?
  3. Have you tested the model’s accuracy in real-world scenarios with actual scam content?
  4. Are there any plans for expanding beyond Chrome or adding mobile support?
  5. What are your long-term goals for product development and market positioning?

Back to contents

Investment/Partnership Verdict

There is no evidence of commercial traction, revenue, or customer base.

Not evidenced

The project is described as a hackathon submission built by one developer. It demonstrates technical capability but lacks any sign of product-market fit, user adoption, or business model.

Confidence Level: Low — based entirely on self-reported claims with no external validation or data points.

Back to contents

Source

Submitted to the OpenAI 2026 hackathon on Devpost. Project home on DevPost.

The analysis above was generated by a language model from the project's own one-line description. It is not independent research and contains no verified traction, revenue or customer data.