Testudo

Protect your wallet from malicious EIP-7702 delegations. Real-time bytecode analysis warns you before signing dangerous contracts.

As of June 2026, Testudo has users in the Developer Tools category.

Usersno change0%
Ratingno change0%
— reviews
Reviewsno change0%
Version
0.2.0
Manifest V3

History

5 snapshots

Tracking since Apr 1, 2026.

3.1620.8399999999999999Apr 1, 2026Jun 5, 2026
View as table
DateUsersRatingReviewsVersion
Apr 1, 202620.2.0
Apr 21, 202630.2.0
Apr 26, 202630.2.0
May 3, 202620.2.0
May 26, 202610.2.0
Now0.2.0

Permissions & access

Permissions
storagealarms
Host access
https://testudo-api-production.up.railway.app/*, https://eth.blockscout.com/*, https://pub-76c6347fe0fc49d7b1497bc741c11d24.r2.dev/*, https://eth.llamarpc.com/*

Screenshots

Testudo screenshot 1Testudo screenshot 2Testudo screenshot 3Testudo screenshot 4

About

Testudo protects your Ethereum wallet by analyzing smart contract interactions before you sign them. It intercepts transaction and signature requests in real time, runs bytecode-level analysis, and warns you about dangerous patterns — all before any damage is done.

WHAT IT DETECTS

- EIP-7702 delegation attacks (auto-drainers, metamorphic contracts)
- Malicious token approvals (ERC-20 approve, increaseAllowance)
- Dangerous NFT approvals (setApprovalForAll to unknown operators)
- Permit signature phishing (EIP-2612, Permit2)
- Blind signature risks (personal_sign with suspicious content)
- eth_sign abuse (full transaction signing with typed confirmation gate)
- Known malicious addresses (real-time threat intelligence lookups)
- Suspicious contract deployers (fresh wallets, low nonce)

HOW IT WORKS

1. Testudo intercepts wallet requests (eth_sendTransaction, eth_signTypedData_v4, personal_sign, eth_sign) on any webpage.
2. Contract addresses are checked against a threat intelligence database and analyzed for dangerous bytecode patterns (auto-forwarding, DELEGATECALL, SELFDESTRUCT, metamorphic deployment).
3. If a risk is found, a warning modal appears with a clear explanation of what the contract can do. You decide whether to proceed or cancel.
4. Safe interactions pass through without interruption.

KEY FEATURES

- Pre-signature protection: warnings appear before you sign, not after
- Human-readable intent: translates raw contract data into plain English (e.g., "Approve 1,000 USDC to 0xabc...")
- Bytecode capability analysis: detects what a contract CAN do, even without source code
- Threat intelligence: checks addresses against aggregated malicious address databases
- Deployer risk scoring: flags contracts deployed by fresh wallets with no history
- Phishing detection: scores personal_sign messages for social engineering patterns
- Fail-open design: if analysis fails, your transaction still goes through — Testudo never breaks dApps
- No tracking: zero analytics, zero telemetry, zero cookies

Technical

Version
0.2.0
Manifest
V3
Size
713KiB
Min Chrome
116
Languages
1
Featured
No

Metadata

ID
gpidnceilfbhhcpheagjpkdioohmkpmb
Developer ID
u0ebbece7b5d9c40b161fde2d12da89cb
Developer Email
[email protected]
Created
Feb 20, 2026
Last Updated (Store)
Feb 20, 2026
Last Scraped
Jun 5, 2026
Website
Support URL

Similar extensions

Alternatives to Testudo, ranked by description similarity.

Data sourced from the Chrome Web Store · last verified Jun 5, 2026.