# Overview

### Mission Statement

GoPlus is building the security layer for the AI era.

### What is GoPlus?

GoPlus is the open security layer that protects AI agents, Web3 transactions, and other high-risk digital actions before they execute.

AI agents are becoming active participants in digital economies. They browse the web, call tools, access files, manage credentials, write code, install packages, deploy software, and trigger transactions on behalf of users and organizations. As these agents scale, they will need security for runtime behavior, on-chain transactions, tool calls, credential access, code execution, package usage, plugin installation, and broader supply-chain dependencies.

Web3 remains one of the clearest examples of why execution-time security matters. Malicious signatures, phishing sites, scam contracts, rug pulls, wallet drainers, risky approvals, and irreversible transactions continue to threaten users, wallets, applications, and chains. The same execution risks will become more severe when AI agents can operate wallets, route trades, deploy contracts, and interact with dApps at machine speed.

GoPlus secures these environments through AI-powered risk intelligence, runtime protection, policy enforcement, verified security data, and open security services. Its mission is to make security a native layer of every autonomous action, whether that action is performed by a human user, an AI agent, a wallet, an application, or blockchain infrastructure.

Since 2022, GoPlus has grown from a Web3 user security infrastructure provider into a broad security network. Its security APIs process tens of millions of daily requests, cover more than 30 blockchain networks, protect millions of wallets, identify malicious assets and addresses at scale, and are integrated by wallets, dApps, exchanges, infrastructure providers, RPC services, rollups, and developer platforms. This ecosystem gives GoPlus a strong distribution foundation across supported networks, wallets, exchanges, DeFi protocols, launchpads, trading tools, data platforms, RPC providers, security partners, and infrastructure providers.

GoPlus will continue to support its Web3 security business while extending the same security-layer philosophy to the AI era. AgentGuard protects AI agent runtime behavior. GoPlus Intelligence powers risk analysis across agents and Web3. The GoPlus Security Network provides open security data, policy coordination, and verifiable security signals. Security RPC, on-chain firewall, wallet integrations, and infrastructure integrations protect Web3 transaction execution. DeepScan provides AI-powered token security audits. SafeToken Protocol standardizes secure asset issuance and liquidity protection. Together, these products form a unified security layer for AI agents and Web3.

### The New Security Problem

Security risks are increasingly appearing at the moment of execution.

Traditional security systems were designed for applications that followed deterministic workflows. They monitored endpoints, scanned code, checked access control, and detected suspicious activity after systems were already built. AI agents and Web3 interactions change this model. Both are action-driven environments where software can make high-impact decisions, compose multi-step workflows, and trigger irreversible operations.

AI agents introduce a new runtime attack surface:

{% hint style="warning" %}
**Tool-call risk:** Agents can invoke shell commands, MCP tools, browser actions, cloud APIs, and deployment systems. A single unsafe tool call can leak secrets, modify production resources, or execute malicious code.
{% endhint %}

{% hint style="warning" %}
**Prompt injection and context manipulation:** Agents can ingest untrusted web pages, files, repositories, messages, and tool outputs. Malicious instructions hidden in those inputs can redirect agent behavior or override user intent.
{% endhint %}

{% hint style="warning" %}
**Credential and data exposure:** Agents often operate near sensitive assets such as `.env` files, private keys, API tokens, databases, customer data, and internal documents. Without runtime controls, sensitive data can be accessed, copied, or exfiltrated before a human reviewer notices.
{% endhint %}

{% hint style="warning" %}
**Agent supply-chain risk:** Agents rely on skills, plugins, MCP servers, packages, templates, repositories, browser content, and third-party tools. A compromised dependency or malicious integration can become an execution path into the agent runtime.
{% endhint %}

{% hint style="warning" %}
**Agent transaction risk:** AI agents will increasingly prepare, sign, route, simulate, and submit transactions on behalf of users or organizations. Without transaction-aware security, autonomous agents can trigger irreversible Web3 losses at machine speed.
{% endhint %}

Web3 user security faces a parallel execution problem:

{% hint style="warning" %}
**Irreversible transaction risk:** Once a malicious transaction or signature is submitted, users often cannot stop the resulting asset loss.
{% endhint %}

{% hint style="warning" %}
**High user decision burden:** Wallet warnings and raw transaction details still require users to understand complex contract behavior, approval logic, signature payloads, and token risks.
{% endhint %}

{% hint style="warning" %}
**Fragmented security coverage:** Users, applications, wallets, chains, and AI agents need consistent security policies across networks, tokens, dApps, RPCs, and transaction flows.
{% endhint %}

### GoPlus Security Layer

GoPlus addresses these risks by placing a security layer before execution.

Instead of relying only on alerts after an action has already happened, GoPlus evaluates risky actions in real time, applies policy, routes sensitive operations through approval when needed, blocks dangerous behavior, and records an auditable security timeline. This creates a common security model for both AI agents and Web3:

* **Detect:** Analyze prompts, URLs, commands, packages, signatures, transactions, tokens, addresses, approvals, and dApps for risk.
* **Decide:** Evaluate each action against risk models, user intent, custom policies, and contextual security rules.
* **Enforce:** Allow, block, warn, or escalate high-risk actions before they execute.
* **Verify:** Use decentralized data contribution and validation mechanisms where transparency and trust are required.
* **Audit:** Produce clear records of actions, decisions, approvals, and security outcomes.

This security layer is open and modular. Developers can integrate GoPlus Intelligence through APIs and SDKs. AI agent users and teams can protect runtime behavior, transaction execution, and supply-chain exposure with AgentGuard and GoPlus Web3 Security. Wallets, dApps, RPCs, chains, and rollups can integrate GoPlus security capabilities through infrastructure integrations. Security developers and data contributors can participate through the GoPlus Security Network.

### Core Product Lines

**AgentGuard: AI Agent Security**

AgentGuard is GoPlus' runtime security product for AI agents. It provides local-first runtime protection, policy enforcement, approval workflows, audit timelines, and supply-chain scanning for agent actions. AgentGuard evaluates risky shell commands, file access, tool calls, URLs, package content, sensitive operations, and agent-to-Web3 actions before execution, helping users and teams protect agents from prompt injection, credential leakage, malicious commands, data exfiltration, transaction risk, supply-chain compromise, and permission abuse.

**GoPlus Intelligence**

GoPlus Intelligence is the risk analysis engine behind the security layer. It provides real-time security intelligence, automated analysis, transaction simulation, malicious address detection, token risk analysis, phishing site detection, approval and signature analysis, dApp risk information, and agent-oriented security detection capabilities.

**GoPlus Web3 Security**

GoPlus Web3 Security protects the full lifecycle of on-chain activity. Through APIs, browser extension, GoPlus APP, transaction simulation, Security RPC, wallet integrations, and on-chain firewall infrastructure, GoPlus helps users, wallets, dApps, chains, and RPC providers detect and prevent malicious on-chain actions before they execute.

**DeepScan**

DeepScan is GoPlus' AI-powered token security audit product. It combines static analysis, LLM-powered semantic audit, financial semantic modeling, and accumulated security rule patterns to detect smart contract vulnerabilities, rug pull risks, access-control issues, honeypot behavior, and scam patterns before token contracts reach users and markets.

**GoPlus SafeToken Protocol**

SafeToken Protocol provides standardized security for token issuance and liquidity management. It helps projects launch tokens with safer contract templates, risk controls, and liquidity protection, reducing malicious asset creation and improving trust across the token ecosystem.

**GoPlus Security Network**

The GoPlus Security Network turns security into an open, verifiable, and participatory infrastructure layer. Security data contributors, users, developers, security service providers, and governance participants collaborate to provide decentralized security services across AI agent and Web3 environments.

### Why GoPlus?

**Security before execution:** GoPlus focuses on the moment where risk becomes damage: before an AI agent runs a command, before a tool call reaches an external system, before an agent or wallet submits a transaction, and before a user signs a malicious payload.

**AI-era agent protection:** AgentGuard brings GoPlus into the AI agent runtime, where large-scale agents need policy enforcement, approvals, auditability, transaction protection, supply-chain checks, and real-time protection around every risky action.

**Proven Web3 security scale:** GoPlus has already built one of the most widely used Web3 user security infrastructures, with large-scale API usage, multi-chain coverage, wallet protection, malicious asset detection, and integrations across the ecosystem.

**Ecosystem distribution:** GoPlus works across supported networks, wallets, exchanges, DeFi protocols, launchpads, trading tools, data platforms, RPC providers, security partners, and infrastructure providers, giving the security layer broad distribution.

**Unified risk intelligence:** GoPlus combines AI-powered analysis, security data, transaction simulation, phishing detection, malicious address intelligence, token risk classification, and runtime risk detection into a common intelligence layer.

**Open and verifiable network:** Through decentralized data contribution, security service coordination, and governance, GoPlus makes security services more transparent, scalable, and aligned with the communities they protect.

### Conclusion

The AI era requires a new security layer. As agents and applications gain the ability to execute complex actions on behalf of users, security must shift from passive detection to real-time protection before execution.

GoPlus is building that layer. Starting from its proven Web3 security foundation and expanding through AgentGuard for AI agents, GoPlus provides the intelligence, runtime controls, transaction security, supply-chain protection, policy enforcement, and verifiable services needed to secure high-risk digital actions across AI and Web3.


# Architecture Overview

<figure><img src="https://2031722588-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F3j5GFgqQKWTX18n74ll7%2Fuploads%2FsigHCDNIkZMMIsKJSAfJ%2Fimage.png?alt=media&amp;token=a2b15317-5fef-47b0-8bc9-d17d08e83506" alt=""><figcaption><p>Architecture Overview</p></figcaption></figure>

GoPlus Security Network is the open and verifiable infrastructure behind the GoPlus security layer for the AI era. It provides the risk intelligence, verified security data, runtime protection, and ecosystem coordination needed to protect AI agents, Web3 users, applications, wallets, chains, and security developers.

The network started with Web3 user security, where GoPlus built real-time risk intelligence, transaction protection, malicious asset detection, and on-chain security infrastructure across multiple chains. As AI agents become a new execution environment, the same security layer expands to protect runtime behavior, tool calls, command execution, credential access, URL interaction, package supply chains, and agent-to-Web3 workflows.

### Core Architecture

The GoPlus Security Layer is organized around three connected layers:

* **Security Intelligence**
* **Runtime Protection**
* **Security Data Network**

Together, these layers create a system that can understand risk, enforce policy before execution, and continuously improve through verified security data.

#### Security Intelligence

Security Intelligence is the risk engine behind GoPlus products. It evaluates assets, addresses, URLs, signatures, approvals, transactions, dApps, packages, commands, prompts, and agent actions.

This layer includes token security analysis, malicious address detection, phishing site detection, transaction simulation, approval and signature analysis, dApp security information, prompt-injection detection, credential leak detection, malicious command detection, URL analysis, package risk analysis, and supply-chain risk detection.

Security Intelligence produces structured risk signals that can be consumed by AgentGuard, GoPlus Web3 Security, DeepScan, SafeToken-related workflows, wallets, applications, and third-party integrations.

#### Runtime Protection

Runtime Protection applies security decisions before risky actions execute.

For AI agents, Runtime Protection is represented by AgentGuard. AgentGuard evaluates shell commands, file access, tool calls, URLs, package content, sensitive operations, and agent-to-Web3 actions before they run. It can allow, block, warn, or require approval based on policy and risk analysis.

For Web3, Runtime Protection is represented by Security RPC, on-chain firewall, browser extension, GoPlus APP, wallet integrations, dApp integrations, and other infrastructure integrations. These components analyze signatures, approvals, transactions, tokens, dApps, and addresses before users or agents submit high-risk on-chain actions.

#### Security Data Network

The Security Data Network collects, verifies, and distributes security data through open contribution and validation mechanisms. It supports malicious address data, phishing data, token risk data, dApp data, transaction risk data, signature risk data, agent threat data, package risk data, URL risk data, and other security intelligence inputs.

This data network is critical because risk detection is only as strong as the security data behind it. By supporting data contribution, verification, and ecosystem feedback, GoPlus improves the coverage, freshness, and credibility of the signals used across its products.

### Product and Integration Components

#### AgentGuard

AgentGuard is the AI agent runtime security product of GoPlus. It protects agent actions before they execute, including commands, file operations, URLs, tool calls, package scans, approval flows, transaction workflows, and audit timelines.

#### GoPlus Intelligence

GoPlus Intelligence is the shared risk engine used across the GoPlus security layer. It powers token analysis, malicious address detection, phishing detection, transaction simulation, signature analysis, approval analysis, dApp risk information, and agent-oriented risk detection.

#### Web3 Security Products

GoPlus Web3 Security includes DeepScan, SafeToken Protocol, transaction protection, Security RPC, on-chain firewall, GoPlus APP, browser extension, and infrastructure integrations. These products protect token launch, token audit, wallet activity, user transactions, dApp interaction, and chain-level execution paths.

#### Ecosystem and Governance

GoPlus Security Network is supported by users, developers, data contributors, security service providers, governance participants, and ecosystem partners. This ecosystem gives GoPlus a broad distribution path across chains, wallets, exchanges, DeFi protocols, launchpads, trading tools, data platforms, RPC providers, security partners, and infrastructure providers.

### Conclusion

GoPlus Security Network is evolving from a Web3 user security network into a broader security infrastructure for AI agents and Web3. By combining security intelligence, runtime protection, and a verified security data network, GoPlus provides a scalable foundation for protecting high-risk digital actions before they execute.


# GoPlus Intelligence

## Introduction

GoPlus Intelligence is the risk analysis engine of the GoPlus security layer.

It provides real-time security intelligence for AI agents, Web3 users, wallets, applications, chains, and developers. Its purpose is to detect risk before execution and provide the signals needed for runtime protection, policy enforcement, user warnings, transaction blocking, approval workflows, and security audits.

GoPlus Intelligence began with Web3 security, including token risk analysis, malicious address detection, phishing detection, approval and signature analysis, dApp security information, and transaction simulation. As GoPlus expands into the AI era, GoPlus Intelligence also supports agent-oriented risk analysis such as credential leak detection, prompt-injection detection, malicious command detection, URL analysis, permission abuse analysis, package risk detection, and data exfiltration detection.

## GoPlus Intelligence Overview

### Key Features

* **Real-time risk signals:** Provides up-to-date security intelligence for runtime decisions.
* **Automated analysis:** Uses AI models, security rules, graph analysis, code analysis, transaction simulation, and threat intelligence to identify risk.
* **Cross-environment coverage:** Supports both Web3 execution and AI agent runtime security.
* **Scalable integration:** Offers APIs, SDKs, and product integrations for developers, wallets, dApps, chains, AI agent frameworks, and security platforms.
* **Policy-ready output:** Produces structured risk results that can be used by AgentGuard, Security RPC, GoPlus APP, browser extension, infrastructure integrations, and third-party products.

## GoPlus Intelligence Capabilities

### AI Agent Runtime Risk Analysis

Analyzes risky actions attempted by AI agents before execution.

* Features: command risk detection, file access evaluation, sensitive data access detection, tool-call risk analysis, permission abuse analysis, and runtime risk scoring.
* Applications: AgentGuard, coding agents, autonomous workflow platforms, AI agent frameworks, MCP tool routers, and enterprise agent governance.

### Prompt Injection Detection

Detects attempts to manipulate agent behavior through malicious or hidden instructions.

* Features: detection of role hijacking, system prompt extraction, obfuscated payloads, encoded instructions, and indirect prompt injection patterns.
* Applications: AgentGuard runtime enforcement, browser agents, coding agents, document-processing agents, and web automation agents.

### Credential Leak Detection

Identifies exposed secrets and sensitive credentials in files, commands, prompts, repositories, and agent-accessible content.

* Features: detection of API keys, private keys, tokens, database credentials, cloud credentials, and connection strings.
* Applications: agent runtime protection, developer workflow protection, repository scanning, and supply-chain security.

### Malicious Command and Data Exfiltration Detection

Detects command patterns and data movement behaviors that may cause system compromise or sensitive data leakage.

* Features: remote code execution detection, reverse shell detection, encoded payload detection, suspicious network transfer detection, sensitive path access detection, and exfiltration pattern analysis.
* Applications: coding agents, deployment agents, CI/CD assistants, local agent runtimes, and enterprise automation workflows.

### URL and Package Risk Analysis

Analyzes URLs, domains, packages, plugins, skills, and agent supply-chain inputs.

* Features: malicious domain detection, phishing URL analysis, suspicious TLD analysis, homograph attack detection, malicious package indicators, and advisory-based detection.
* Applications: AgentGuard supply-chain scanning, MCP security workflows, agent plugin review, and browser-agent protection.

### Multi-chain Token Security

Provides detailed security analysis of tokens across supported blockchain networks.

* Features: token contract security, liquidity analysis, holder distribution, permission risk, honeypot indicators, and malicious behavior signals.
* Applications: exchanges, wallets, DeFi platforms, token launch platforms, research tools, and trading applications.

### AI-Powered Token Audit

Powers DeepScan with token contract audit capabilities that combine static analysis, AI semantic review, financial risk modeling, and accumulated security rule patterns.

* Features: smart contract vulnerability detection, rug pull risk detection, access-control analysis, honeypot and scam detection, Graph-IR static analysis, LLM-powered audit, and financial semantic modeling.
* Applications: DeepScan, token projects, launchpads, exchanges, wallets, dApps, and AI-assisted Web3 development workflows.

### Malicious Address Detection

Provides a timely and comprehensive malicious address intelligence service.

* Features: identification of scam, phishing, drainer, exploit, laundering, and other malicious addresses.
* Applications: transaction screening, wallet warnings, compliance workflows, dApp risk management, and chain-level protection.

### NFT Security Assessment

Assesses NFT-related risks to help detect scams, suspicious contracts, or fraudulent activity.

* Features: origin analysis, transaction history review, contract security analysis, and suspicious behavior detection.
* Applications: NFT marketplaces, wallets, collectibles platforms, and digital asset services.

### Approval Security Analysis

Analyzes token approval requests to prevent unauthorized or high-risk asset exposure.

* Features: spender risk detection, unlimited approval risk analysis, known malicious contract detection, and approval behavior assessment.
* Applications: wallets, DeFi applications, browser extension, transaction protection, and user security dashboards.

### dApp Security Information

Aggregates and analyzes security information about dApps.

* Features: contract risk signals, audit status, malicious behavior indicators, phishing relationships, and historical security information.
* Applications: wallets, dApp browsers, security dashboards, ecosystem monitoring, and user warnings.

### Signature Data Decoding

Decodes and analyzes signature payloads for irregularities or malicious intent.

* Features: ABI signature decoding, permit and permit2 risk detection, malicious signature pattern recognition, and transaction intent interpretation.
* Applications: wallet protection, transaction confirmation flows, phishing prevention, and user-facing risk explanations.

### Phishing Site Detection

Detects and blocks phishing websites before users or agents interact with them.

* Features: real-time URL verification, phishing pattern detection, suspicious domain analysis, and malicious site intelligence.
* Applications: browser extensions, wallets, AI browser agents, security tools, and dApp front-end protection.

### Multi-chain Transaction Simulation

Simulates transactions across blockchain networks to assess expected results and detect potential risks before execution.

* Features:
  * Preview transactions in a secure environment.
  * Identify anomalies, risky token transfers, approval changes, and unexpected contract behavior.
  * Support multiple blockchain networks including Ethereum, BNB Chain, Solana, Sui, and others.
  * Provide reports on gas estimation, token movements, and contract interactions.
* Applications:
  * Wallet transaction protection.
  * dApp and DeFi risk management.
  * Chain-level and RPC-level security.
  * AI agents that prepare, review, or submit Web3 transactions.

### Conclusion

GoPlus Intelligence provides the risk intelligence foundation for the GoPlus security layer. By combining Web3 security analysis with AI agent runtime risk detection, it enables GoPlus to protect high-risk actions before they execute across agents, wallets, applications, chains, and decentralized security services.


# Security Data Layer

The Security Data Layer is the trusted data foundation of the GoPlus security layer for the AI era.

In the last few years, GoPlus Network has experienced exponential growth, with security data usage increasing by over 5000 times from what was recorded in 2022 and daily API calls reaching tens of millions, demonstrating high levels of ecosystem trust. As GoPlus expands from Web3 security into AI agent security, the integrity and reliability of security data becomes even more important. Agent runtime protection, transaction protection, policy enforcement, and decentralized security services all depend on accurate, timely, and verifiable risk data.

To address this need, GoPlus proposes a decentralized Security Data Contribution and Verification Layer that harnesses multi-party participation and automated verification processes. This foundational layer provides trustworthy, rich, and real-time security data for both Web3 and AI agent security. It supports the collection, verification, and utilization of token risk data, malicious address data, phishing data, dApp risk data, signature risk data, transaction risk data, prompt-injection indicators, malicious command patterns, credential leak patterns, URL risk data, package risk data, and other security intelligence inputs.

<figure><img src="https://2031722588-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F3j5GFgqQKWTX18n74ll7%2Fuploads%2Fd3uXfqU2SOsXfS9HouSv%2F%E7%99%BD%E7%9A%AE%E4%B9%A6.003.png?alt=media&amp;token=9da8e309-36d9-41a1-9129-44504fd20b23" alt=""><figcaption><p>Security Data Layer</p></figcaption></figure>

### Data Contribution

Security data contributors form the foundation of the entire system. They provide valuable information about potential security risks and threats through various channels, including but not limited to:

**End-users:** Users can report security issues they encounter, such as suspicious scam activities, phishing attempts, malicious websites, wallet drainers, rug pulls, and unsafe agent actions.

**Security researchers:** Professional security researchers can contribute findings on Web3 risks, AI agent threats, malicious packages, prompt-injection payloads, credential leakage patterns, and other in-depth security insights.

**Third-party security companies & organizations:** Specialized security firms can offer comprehensive threat intelligence and risk assessment reports.

Through incentivization and recognition mechanisms, GoPlus encourages broad participation to establish a comprehensive and diverse security database.

### Data Verification

To ensure the credibility and accuracy of the contributed data, we implement a multi-tiered decentralized verification mechanism. The Security Data Verification system consists of a Primary verification process and a Secondary verification process, working in tandem to validate the security data.

#### **Primary verification**

The Primary verification employs a multi-faceted approach to data verification, incorporating trusted third-party entities and automated computational methods:

**Third-Party Verification Nodes:** Reputable entities operate verification nodes that leverage their expertise and resources to assess the veracity of user-contributed information.

**Computational Verification Nodes:** Automated computational methods are used to verify specific types of security data through security scanning, advanced algorithms, and AI techniques.

**Auditors:** Independent auditors oversee the verification process, ensuring compliance with established protocols and maintaining the integrity of the system.

#### **Secondary verification**

The Secondary verification is triggered when disputes arise in the Primary verification. It is composed of highly specialized security teams and institutions that focus on resolving controversies in Primary verification:

**Elite Security Teams:** Renowned security teams with expertise in Web3 security, AI security, application security, and threat intelligence are enlisted to investigate and resolve complex disputes.

**Institutional Arbitrators:** Respected institutions, such as respected university labs and Web3 industry leaders, act as impartial arbitrators to settle disagreements and provide final verdicts.

The Secondary verification ensures that any contentious issues are thoroughly examined and resolved by the most qualified experts in the field.

By seamlessly integrating security data contributors and the multi-tiered verification mechanism, GoPlus creates a robust and resilient decentralized security data ecosystem. This approach enhances the diversity, professionalism, and accuracy of risk data while strengthening the risk models that protect users, AI agents, wallets, applications, and chains. By working together, the ecosystem can build a shared data foundation for protecting high-risk digital actions before they execute.


# Types of Risk Data

GoPlus has identified and prioritized a range of critical security data types. These data types serve as the backbone of our decentralized Security Data Contribution and Verification Layer, providing comprehensive insights into potential security risks and enabling mitigation strategies. Here's an overview of these data types:

#### **Token Security Data**

This category encompasses analyses of token contracts, highlighting potential risk assessments, and token holder distribution analyses. Additionally, we have introduced an open source [Token Risk Classification](/goplus-network/the-goplus-security-layer/security-data-layer/token-risk-classification) standard, a framework designed to categorize the various risks associated with tokens. Token security data plays a vital role in offering stakeholders a detailed understanding of the security aspects of token projects, aiding in the identification and mitigation of associated risks. This classification standard further enhances our ability to assess and communicate the nuances of token-related risks effectively.

#### **Malicious Address Data**

Malicious address data includes known blockchain addresses associated with scams, phishing, hacking and other fraudulent activities. By identifying and warning users about these addresses, this data type is crucial in preventing interaction with these malicious addresses and enhancing user security.

#### **NFT Security Data**

This category encompasses analyses of NFT contracts, highlighting potential risk assessments, and token holder distribution, NFT information analyses. NFT security data plays a vital role in offering stakeholders a detailed understanding of the security aspects of NFT projects, aiding in the identification and mitigation of associated risks.

#### Approval Risk Data

Approval risk data primarily focuses on potentially hazardous contracts that require user authorization, including contracts that have been compromised in hacker attacks as well as malicious contracts. When users authorize their assets to these contracts, they may face the risk of asset loss. This type of security data is crucial in helping users identify and revoke permissions to dangerous contracts, thereby preventing the authorization of their assets to these risky entities. Approval risk data serves as a vital tool in safeguarding user assets against unauthorized access and potential misuse by highlighting the risks associated with certain contract authorizations.

#### **dApp Security Data**

This category comprises security audit reports of smart contracts, known vulnerability lists, and community safety feedback. dApp security information provides a comprehensive safety assessment for dApp users, helping them avoid interactions with insecure dApps.

#### **Specific Malicious Signature Features Data**

Targeting anomalies and potential risks in blockchain transaction signatures, such as unauthorized transactions or suspicious contract calls, this data helps identify and prevent malicious activities, enhancing transaction security.

#### **Phishing Site Data**

Phishing site data involves characteristics of known phishing sites and user feedback, aimed at identifying potential phishing attacks. This data is vital in preventing users from accessing malicious websites and protecting them from data or asset theft.

### Conclusion

Together, these security data types form the core of our decentralized data contribution system. By integrating and analyzing this data, the network can more effectively identify and respond to security threats, ensuring the safety of users and their assets. This collective effort lays a solid foundation for the future of digital interactions, empowering all participants to navigate the Web3 world with confidence and security. Furthermore, we plan to enrich and expand the variety of security data categories through governance and voting mechanisms in the future. This approach will enhance the diversity and coverage of our security data, strengthening the overall robustness of our security data ecosystem.


# Token Risk Classification

Token Risk Classification(TRC) aims at identifying and cataloging scams like honeypots, and intentional backdoors that may be present in token smart contracts within the web3 ecosystem. This classification serves as:

* **A Shield against Malicious Smart Contracts:** By showcasing a defined list of malicious token contract patterns, it empowers users and project teams to recognize and steer clear of contracts with hidden intents, thereby ensuring safer interactions within the decentralized space.
* **A Testing Ground for Developers:** With a clear classification of malicious patterns and real-world examples, developers creating tools to detect these malicious token smart contracts can effectively evaluate their systems against a standardized classification.
* **A Catalyst for Research:** By clarifying the deceitful practices adopted in token smart contracts, we hope to drive more research towards crypto user safety, encouraging the community to devise strategies that deter such behaviors.
* **An Educational Asset:** This Github repository stands as an initiative to amplify awareness, serving as an informational storage hub, shedding light on potential contract pitfalls and deceitful patterns to the advantage of the community.

For more details, please visit our [TRC website](https://cryptousersecurity.github.io/token-risk-classification/).

### Contribute <a href="#contribute" id="contribute"></a>

Maintaining the relevance and comprehensiveness of this Github repository is a joint endeavor. We hope for and welcome community contributions. For details on how to contribute, kindly refer to our [Contribution Guidelines](https://github.com/cryptousersecurity/token-risk-classification).

<br>


# AgentGuard

## Overview

AgentGuard is GoPlus' runtime security product for AI agents.

AI agents are no longer passive assistants. They can browse, write code, read files, call MCP tools, execute shell commands, manage credentials, deploy applications, and trigger Web3 transactions. This creates a new security challenge: the most important security decision often happens at runtime, immediately before an agent performs a high-impact action.

AgentGuard protects agents at that moment. It sits between the agent and risky execution paths, evaluates actions against security detectors and policy rules, blocks or escalates dangerous behavior, and records an audit timeline for review. It is designed as a local-first runtime guard connected to a cloud control plane for policy, approvals, reporting, advisories, and team workflows.

## Why AI Agents Need Runtime Security

Traditional AI safety focuses heavily on prompts and model outputs. Agent security requires more. Once an agent can use tools, the attack surface expands from text generation to execution.

Key risks include:

* **Prompt injection:** Untrusted content can manipulate agent intent, override instructions, or attempt to extract system prompts.
* **Credential leakage:** Agents may access API keys, private keys, cloud tokens, database credentials, or `.env` files during normal workflows.
* **Malicious command execution:** Agents can be tricked into running destructive shell commands, encoded payloads, reverse shells, or supply-chain installation scripts.
* **Data exfiltration:** Sensitive files or credentials can be copied, uploaded, tunneled, or sent through external services.
* **Permission abuse:** Agents may request broad tool permissions, combine capabilities in unsafe ways, or exceed the intended scope of a task.
* **Malicious URLs and package supply chain:** Agents often consume web pages, install dependencies, load skills, and connect to MCP servers from external sources.

These risks cannot be solved only by asking the model to behave safely. They require policy enforcement at the boundary where the agent attempts to act.

## Core Capabilities

### Runtime Policy Enforcement

AgentGuard evaluates risky actions before shell, file, deploy, browser, URL, or tool execution. Based on policy, it can allow, block, warn, or require approval for an action.

### Local-First Protection

The guard runs close to the agent runtime so sensitive operations can be inspected before they leave the local environment. This reduces dependency on remote-only scanning and makes protection practical for developer machines and agent workflows.

### Security Detectors

AgentGuard includes detectors for credential leaks, prompt injection, malicious commands, data exfiltration, permission abuse, and URL risk. These detectors help identify both obvious malicious actions and subtle agent-specific attack patterns.

### Approval Workflows

Sensitive operations can be routed through human approval. This gives teams a practical way to supervise high-risk agent behavior without blocking all automation.

### Audit Timeline

AgentGuard records what the agent attempted, which policy was applied, what risk was detected, and whether the action was allowed, blocked, or approved. This creates the evidence needed for debugging, incident response, governance, and compliance.

### Supply-Chain and Advisory Protection

AgentGuard scans agent skills, plugins, packages, URLs, and related supply-chain inputs. It can also consume signed advisories for malicious skills, plugins, MCP servers, packages, phishing URLs, and prompt-injection payloads.

## AgentGuard in the GoPlus Security Layer

AgentGuard is the AI agent runtime enforcement layer of GoPlus.

It complements the rest of the GoPlus ecosystem:

* **GoPlus Intelligence** provides risk models, detection capabilities, and threat intelligence.
* **GoPlus Security Network** enables open security data, verifiable security signals, and decentralized security services.
* **GoPlus Web3 Security** protects transactions, signatures, approvals, tokens, dApps, wallets, RPCs, and chains.
* **AgentGuard** protects the agent actions that may lead to those same high-risk environments.

This connection is important because AI agents will increasingly operate Web3 wallets, manage on-chain assets, interact with dApps, deploy contracts, analyze tokens, and execute transactions. AgentGuard protects the agent runtime before the action reaches Web3, while GoPlus Web3 Security protects the on-chain execution path itself.

## Use Cases

**Developers using coding agents**

Protect shell commands, file access, dependency installation, repository changes, deployment scripts, and credentials during agent-assisted development.

**Teams adopting autonomous workflows**

Apply organization-level policy to agent actions, require approvals for risky operations, and keep audit records of agent decisions.

**AI agent platforms**

Integrate runtime security and action evaluation into agent frameworks, tool routers, MCP workflows, and cloud agent infrastructure.

**Web3 agent applications**

Protect agents that interact with wallets, contracts, dApps, tokens, transaction builders, and cross-chain workflows.

## Conclusion

AgentGuard brings GoPlus' security-layer philosophy into the AI agent runtime. It protects actions before they execute, gives users and teams control over agent behavior, and creates an auditable foundation for safe AI automation.


# DeepScan

## Overview

DeepScan is GoPlus' AI-powered token security audit product.

It helps projects, developers, launchpads, exchanges, wallets, and communities evaluate token contracts before users are exposed to risk. By combining static analysis, AI-driven semantic review, financial risk modeling, and GoPlus' accumulated security rule patterns, DeepScan produces professional token security reports with fast delivery.

DeepScan extends GoPlus Web3 Security from transaction protection into token-level pre-deployment and pre-listing security. It helps projects identify contract vulnerabilities, scam patterns, access-control issues, rug pull risks, and honeypot behavior before those risks reach users or liquidity markets.

## Why Token Audit Matters

Tokens are one of the most common entry points for Web3 users. A token contract can look simple from the outside while hiding privileged functions, transfer restrictions, minting risks, proxy upgrade risks, or mechanisms that can drain liquidity or prevent users from selling.

Traditional audits are often expensive, slow, and hard to access for early-stage projects. Simple automated scanners can catch basic issues but often miss deeper logic flaws and financial attack patterns. DeepScan is designed to make token security audit faster, more accessible, and more intelligence-driven.

## Core Capabilities

### Smart Contract Vulnerability Detection

DeepScan detects common smart contract vulnerabilities, including reentrancy risks, integer overflow or underflow, unchecked external calls, unsafe logic, and other structural flaws that may harm users or projects.

### Rug Pull Risk Detection

DeepScan identifies mechanisms that can be used to drain funds or undermine user trust, including hidden mint functions, ownership risks, proxy upgrade dangers, privileged liquidity controls, and unsafe administrative permissions.

### Access Control Analysis

DeepScan audits privileged functions, admin roles, multisig requirements, ownership status, and role-based access patterns to uncover centralization and abuse risks.

### Honeypot and Scam Detection

DeepScan detects hidden transfer restrictions, sell blockers, trading traps, malicious token behavior, and known scam patterns that may prevent users from exiting positions.

### AI-Powered Semantic Audit

DeepScan uses large language models to improve semantic understanding of contract logic, helping identify complex vulnerabilities and intent-level risks that basic static rules may miss.

### Financial Semantic Modeling

DeepScan applies financial scenario modeling for DeFi and tokenomics-specific risks, including fund flow risk, economic attack vectors, liquidity behavior, and token control design.

### Graph-IR Static Analysis

DeepScan performs deep static analysis using graph-based representations of smart contract control flow and data flow, enabling structural detection of vulnerabilities and risky logic paths.

## DeepScan in the GoPlus Security Layer

DeepScan is part of GoPlus Web3 Security and complements the rest of the GoPlus security layer:

* **GoPlus Intelligence** provides security data, rule patterns, AI analysis, and token risk intelligence.
* **SafeToken Protocol** helps projects create and manage tokens with safer templates and liquidity controls.
* **Security RPC, infrastructure integrations, and on-chain firewall** protect users when they interact with tokens and contracts.
* **AgentGuard** can protect AI agents that review, deploy, or interact with token contracts before they execute risky actions.

Together, these components form a lifecycle approach to token security: audit before deployment, safer issuance and liquidity management, real-time risk intelligence, and transaction protection during user interaction.

## Use Cases

**Token projects**

Audit token contracts before launch, identify high-risk design issues, and provide security transparency to users and partners.

**Launchpads and listing platforms**

Screen token projects before listing or launch to reduce rug pull, scam, and honeypot exposure.

**Wallets and dApps**

Use DeepScan reports and GoPlus Intelligence to provide clearer token risk information to users.

**Exchanges and market data platforms**

Evaluate token contract risks before listing, indexing, or surfacing token data.

**AI-assisted Web3 development**

Use DeepScan alongside AgentGuard when AI agents help write, review, deploy, or modify token contracts.

## Conclusion

DeepScan brings AI-powered audit capability into the GoPlus Web3 Security product line. It helps projects detect token risks before launch, gives platforms a faster way to screen assets, and strengthens the broader GoPlus mission of protecting high-risk digital actions before they execute.


# GoPlus SafeToken Protocol

### Overview

The GoPlus SafeToken Protocol represents a significant advancement in addressing fundamental security challenges in token creation and management within the DeFi ecosystem. Built upon GoPlus Security's extensive experience in token security analysis and risk detection, this protocol provides comprehensive solutions for secure token issuance and liquidity management.

### Background

The DeFi ecosystem has witnessed numerous security incidents related to token contracts and liquidity management, including:

* Malicious token contracts with hidden features
* Unauthorized minting capabilities
* Liquidity removal scams
* Rugpulls due to poor liquidity management
* Token contract vulnerabilities

Drawing from its extensive database of token security incidents and deep understanding of contract vulnerabilities, GoPlus has developed the SafeToken Protocol to address these challenges at their source.

### Key Components

#### 1. GoPlus SafeToken Factory

A revolutionary platform for secure token creation and deployment:

**Features:**

* Free and open-source token contract templates
* Pre-audited, security-first contract designs
* Standardized security implementations
* Quick and efficient token deployment process
* Automated security checks during creation

**Benefits for Developers:**

* Reduced development time and costs
* Elimination of common security vulnerabilities
* Enhanced trust from the community
* Standardized security best practices
* Seamless deployment process

#### 2. GoPlus SafeToken Locker

An advanced liquidity management solution designed to enhance project credibility and protect investor interests:

**Key Features:**

* Flexible lock-up period management
* Automated rewards distribution system
* Multi-signature security options
* Transparent lock tracking
* Cross-platform DEX compatibility

**Advanced Capabilities:**

* Customizable vesting schedules
* Emergency security measures
* Real-time monitoring and alerts
* Automated compliance checks
* Integration with major price websites

### Technical Implementation

#### [SafeToken Factory Implementation](https://docs.gopluslabs.io/page/goplus-safetoken-protocol)

#### [SafeToken Locker Implementation](https://docs.gopluslabs.io/page/goplus-safetoken-locker)

### Conclusion

The GoPlus SafeToken Protocol represents a significant step forward in securing the token creation and management process in the DeFi ecosystem. By providing comprehensive, security-focused solutions through the SafeToken Factory and SafeToken Locker, the protocol addresses critical vulnerabilities at their source while promoting standardization and best practices in the industry.


# Web3 Security Layer Overview

<figure><img src="https://2031722588-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F3j5GFgqQKWTX18n74ll7%2Fuploads%2FtoXjy5YNGKSQnkwoz9sQ%2Fimage.png?alt=media&amp;token=530c65ae-f36c-4a31-b5b9-241e0fbb81aa" alt=""><figcaption><p>Web3 Security Infrastructure Integration</p></figcaption></figure>

GoPlus Web3 Security protects on-chain actions before they execute. It extends GoPlus' security layer into wallets, dApps, RPC services, chains, sequencers, rollups, and other Web3 infrastructure.

Unlike the earlier architecture, Web3 infrastructure integration is now positioned as one product path within the broader GoPlus strategy. The strategic center is the security layer for the AI era, with AgentGuard, GoPlus Intelligence, DeepScan, Security Data Layer, and Web3 security products working together to protect high-risk actions.

The Web3 Security Layer uses GoPlus Intelligence and Security Data Layer to analyze transaction intent, signatures, approvals, token risk, dApp risk, malicious addresses, phishing sites, and simulation results. Infrastructure integrations can use these signals to warn users, block risky actions, escalate decisions, or provide clearer transaction explanations.

These integrations are especially important as AI agents begin to operate wallets, deploy contracts, evaluate tokens, and submit on-chain transactions. AgentGuard can protect the agent runtime, while GoPlus Web3 Security protects the on-chain execution path.


# On-chain Firewall

## Introduction to On-Chain Firewall

GoPlus introduces a groundbreaking security feature: the On-Chain Firewall. This innovative solution provides real-time transaction protection on the blockchain, automatically blocking malicious and dangerous transactions that could harm users. Unlike traditional pre-transaction warnings, our On-Chain Firewall implements seamless risk control and blocking capabilities, significantly enhancing the security of the blockchain environment.

## Key Features of On-Chain Firewall

* Real-time Protection: Monitors and analyzes transactions in real-time as they occur on the blockchain.
* Automatic Blocking: Instantly stops malicious or high-risk transactions before they can cause harm.
* Seamless User Experience: Operates invisibly in the background, providing security without disrupting the user experience.

## Implementation Strategy

To provide each blockchain with native risk control and security capabilities, GoPlus implements the security service through a three-step process:

#### 1. GoPlus Intelligence Integration

* Provide GoPlus Intelligence support tailored for the specific blockchain.
* Offer APIs and SDKs to wallets and various projects on the chain.
* Enable developers to easily integrate robust security features into their applications.
* Deliver real-time security insights and risk assessments for transactions and smart contract interactions.

#### 2. Secure RPC Service Provision

* Deploy secure, native RPC nodes for the blockchain.
* Allow users to directly utilize these secure RPC endpoints for enhanced protection.
* Implement additional security layers at the RPC level to filter and analyze transactions.
* Provide a trusted infrastructure layer for secure blockchain interactions.

#### 3. Native Blockchain Integration

* Collaborate with blockchain projects to integrate a User Security Module.
* Implement an additional security layer directly into the blockchain's architecture.
* Enable native risk control capabilities at the chain level.
* Ensure that security checks are performed as an inherent part of the transaction validation process.

## Conclusion

The On-Chain Firewall represents a significant leap forward in blockchain security. By providing real-time, seamless protection at multiple levels of the blockchain stack, GoPlus is setting a new standard for security in the decentralized world. As we continue to expand and refine this technology, we envision a blockchain ecosystem where users can transact and interact with confidence, knowing that advanced security measures are working tirelessly to protect their assets and interests.


# Security RPC

GoPlus Security RPC provides users, wallets, dApps, and AI agents with a seamless and secure way to interact with supported blockchains. By connecting to Security RPC endpoints, users and applications can access GoPlus security features before transactions reach the chain, helping protect on-chain activity against malicious signatures, risky approvals, scam contracts, wallet drainers, and other transaction risks.

With GoPlus Security RPC, developers can integrate security protection into existing infrastructure without complex setup or configuration. The RPC service leverages GoPlus Intelligence, transaction simulation, and risk analysis to deliver fast, reliable, and secure blockchain access.

Whether you're a developer building decentralized applications, a wallet protecting users, or an AI agent system preparing on-chain actions, GoPlus Security RPC provides a practical execution-time protection layer for on-chain activities. GoPlus will continue expanding RPC support across additional networks and security features.

Currently, we have launched Security RPC services for various blockchain networks, including:

* [Ethereum](/goplus-network/web3-security/on-chain-firewall/security-rpc/goplus-eth-rpc)
* [BNB Chain](/goplus-network/web3-security/on-chain-firewall/security-rpc/goplus-bnb-rpc)


# GoPlus BNB RPC

**Network name:** BNB GoPlus SecNet

**RPC URL:** <https://app.gopluslabs.io>

**Chain ID:** 56

**Currency symbol:** BNB

**Block explorer URL(Optional):** <https://bscscan.com>


# GoPlus ETH RPC

**Network name:** ETH GoPlus SecNet

**RPC URL:** <https://app.gopluslabs.io>

**Chain ID:** 1

**Currency symbol:** ETH

**Block explorer URL(Optional)**: <https://etherscan.io>


# Infrastructure Integration

GoPlus Web3 security capabilities can be integrated into wallets, dApps, RPC services, chains, sequencers, rollups, and other infrastructure. These integrations are not the center of the GoPlus strategy, but they remain an important way to bring GoPlus risk intelligence and transaction protection closer to users before risky on-chain actions execute.

{% hint style="success" %}
**Modular Integration**

GoPlus security capabilities are designed to be modular. Infrastructure teams can integrate transaction simulation, malicious address detection, token risk analysis, signature decoding, approval analysis, dApp risk information, and policy signals based on their product needs.
{% endhint %}

{% hint style="success" %}
**Multi-chain Support**

GoPlus Web3 security is designed to support multiple blockchain networks, helping wallets, dApps, RPC services, and infrastructure providers offer consistent protection across ecosystems.
{% endhint %}

{% hint style="success" %}
**On-chain Risk Management**

By leveraging GoPlus Intelligence and comprehensive security data, infrastructure integrations can identify and prevent potential security threats such as phishing, scam contracts, malicious approvals, wallet drainers, and risky token interactions before they cause harm.
{% endhint %}

{% hint style="success" %}
**Customizable Security Strategy**

GoPlus integrations can connect to user security policy and personal security hub experiences, allowing users or applications to customize security preferences based on risk tolerance and specific needs.
{% endhint %}

{% hint style="success" %}
**Seamless User Experience**

GoPlus infrastructure integrations help users receive security protection without needing to understand every technical detail of a transaction. Wallets, dApps, RPC services, sequencers, and chains can use GoPlus risk signals to warn, block, or escalate risky on-chain actions before execution.
{% endhint %}


# User Security Life Cycle

<figure><img src="https://2031722588-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F3j5GFgqQKWTX18n74ll7%2Fuploads%2FcheTFIieP51DmAv2UgLY%2Fimage.png?alt=media&amp;token=28ec50a4-6ae3-4662-b62b-1004f09931af" alt=""><figcaption><p>User Security Life Cycle</p></figcaption></figure>

To address the pressing security concerns in the Web3 space and guide users towards adopting optimal security practices, we have introduced the Web3 User Security Life Cycle (USLC). This framework outlines the necessary steps users should take to protect themselves before, during, and after interacting with Web3 applications and services.

• **Pre-Event Phase:**

At this initial stage, the focus is on equipping users with the knowledge they need to navigate the Web3 space safely. Before engaging with any Web3 applications or services, such as a Data Website, dAPP, or Dex, users should be presented with up-to-date and accurate security information and risk assessments. Ensuring users are informed about potential threats and equipped with best security practices is crucial. This preventative measure lays the foundation for a secure interaction with Web3 platforms.

• **During-Event Phase**

As the user progresses to actively engage with Web3 services, they generate and sign transactions in their wallet. After the signing, the security measures are actively at play, with on-chain firewalls and rigorous security protocols operating in real-time to shield the user's assets. This protection extends as the transaction is sent through RPC nodes to the mempool (Step 4), where it's validated in mempool or by validators (Step 5) before ultimately being broadcasted and recorded on the ledger.

• **Post-Event Phase**

Once the transaction has been broadcast and the ledger is updated (Step 6), post-event security becomes paramount. This phase tackles the risks that linger after the interaction has taken place. It involves steps such as revoking unneeded permissions, conducting ongoing monitoring for anomalous activity, and ensuring that robust recovery solutions are in place to respond swiftly in the event of a security breach. This ensures that even after the transaction is completed, the user's security posture remains strong and resilient against latent threats.

The USLC emphasizes that securing a user’s journey in Web3 is not a one-off event but a cyclical and ongoing process. By diligently addressing the unique challenges inherent at each phase, the GoPlus ecosystem aims to cultivate a safer and more reliable Web3 experience for all users.


# GoPlus Ecosystem

GoPlus has built one of the broadest security ecosystems in Web3 and is extending that distribution into the AI era. The ecosystem is not limited to a single product or chain. It spans supported networks, wallets, exchanges, DeFi protocols, launchpads, trading tools, data platforms, RPC providers, infrastructure partners, security companies, browser products, payment providers, NFT platforms, and other ecosystem participants.

<figure><img src="https://2031722588-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F3j5GFgqQKWTX18n74ll7%2Fuploads%2Fgit-blob-263a559e6c78799ab9cc13d6d65362570b1e2fd1%2Fgoplus-security-ecosystem-landscape-2026.png?alt=media" alt=""><figcaption><p>GoPlus Security Ecosystem Landscape</p></figcaption></figure>

## User Adoption and Security Scale

GoPlus' ecosystem is supported by large-scale real-world usage. Its security intelligence is called directly by wallets, dApps, infrastructure providers, analytics platforms, trading products, and other partners that need real-time risk signals.

Key usage and coverage indicators include:

* **Token API daily request volume:** 40M+ requests per day.
* **Detected token and currency coverage across public chains:** 20M+ token records across supported public chains.

These metrics demonstrate that GoPlus is not only building security products, but also operating a high-throughput risk intelligence layer used by a broad network of Web3 applications and infrastructure partners. This usage foundation is important for the AI era because large-scale AI agents will require the same real-time security signals when they analyze tokens, interact with dApps, prepare transactions, and execute on-chain actions.

## Multi-Chain Security Coverage

GoPlus Security Intelligence supports a wide range of blockchain networks, including major ecosystems such as Ethereum, Solana, BNB Chain, Sui, Optimism, Polygon, Fantom, zkSync Era, Arbitrum, Avalanche, Base, Tron, Scroll, Manta, Merlin Chain, Berachain, Mantle, Zircuit, Bitlayer, Linea, and more.

This multi-chain coverage is a core advantage of GoPlus. Users and developers increasingly operate across many networks, while AI agents will also need to evaluate, route, and execute actions across multiple chains. GoPlus provides the security data, transaction analysis, malicious address intelligence, token risk analysis, and phishing detection needed to protect these cross-chain workflows.

## Customers and Integration Channels

GoPlus security capabilities are used across many categories of Web3 products and services:

* **Wallets:** Wallet integrations bring GoPlus transaction protection, wallet scanning, token risk alerts, and phishing detection directly into user workflows.
* **Exchanges:** Centralized exchanges and trading platforms can use GoPlus intelligence for token screening, risk monitoring, and user protection.
* **DeFi protocols:** DeFi integrations help users detect risky tokens, malicious approvals, unsafe contracts, and transaction-level threats.
* **Launchpads:** Launchpad partners can use DeepScan, token risk intelligence, and SafeToken-related workflows to improve token launch security.
* **Trading tools:** Trading products can use GoPlus data to surface token risk, malicious address signals, liquidity risks, and dApp risk context.
* **Data and analytics platforms:** Market data and analytics partners can enrich asset pages, token dashboards, and risk reports with GoPlus security intelligence.
* **RPC and infrastructure providers:** Infrastructure partners can embed transaction risk analysis and security signals closer to execution.
* **Security companies:** Security partners contribute complementary intelligence, detection methods, and ecosystem coverage.

## Partnership Network

GoPlus' ecosystem includes partnerships and integrations across many layers of Web3. This gives GoPlus a strong distribution network for security intelligence and a large feedback loop for emerging threats.

The ecosystem covers:

* Supported blockchain networks and rollup ecosystems.
* Wallets and browser-based user security products.
* CEX and trading venues.
* DeFi, launchpad, trading, and token lifecycle platforms.
* Data, analytics, storage, RPC, and RaaS providers.
* Security companies and research teams.
* NFT, payment, browser, and other ecosystem products.

This broad partner network matters because security becomes more effective when it is embedded close to where users and agents act. GoPlus can distribute protection through the products users already use, while also bringing risk intelligence into the systems that AI agents will increasingly operate.

## From Web3 Ecosystem to AI Agent Security Distribution

The existing GoPlus ecosystem gives the company a strong foundation for AI agent security. As AI agents begin to manage wallets, analyze tokens, interact with dApps, deploy contracts, and execute transactions, they will need access to the same security intelligence and protection layer that GoPlus already provides across Web3.

AgentGuard extends this ecosystem from human-driven Web3 actions to agent-driven actions. DeepScan extends token security from real-time risk detection into AI-powered audit. GoPlus Intelligence connects these products through a shared risk engine. Together, the ecosystem allows GoPlus to protect both users and agents across the full lifecycle of digital execution.

## Conclusion

GoPlus' ecosystem demonstrates that security is not a standalone feature. It is a distribution layer across chains, wallets, applications, exchanges, infrastructure, security partners, and users. This broad coverage strengthens GoPlus' position as the security layer for the AI era and provides the foundation for serving large-scale AI agents, Web3 users, and high-risk digital actions before execution.


# GoPlus Security Governance

GoPlus Network Governance empowers the community by fostering transparency, inclusivity, and collaboration. It establishes a framework where participants, including data contributors, users, developers, security service providers, and ecosystem partners, help shape the GoPlus security layer.

GoPlus governance is designed to support the security layer for the AI era. As GoPlus expands from Web3 user security into AI agent runtime security, governance helps align incentives around verified security data, open security services, policy standards, and ecosystem growth.

### Ecosystem Contributors

Ecosystem contributors include **Data Contributors**, users, developers, security service providers, and ecosystem partners. These contributors empower the GoPlus ecosystem with security data, risk intelligence, product feedback, integrations, and governance participation. They can be rewarded with tokens from GoPlus Network Governance and can stake tokens to gain long-term governance influence.

{% hint style="success" %}

#### **Data Contributor**

* Data Contributors contribute high-quality security data, including Web3 risk data, AI agent threat data, malicious URL data, prompt-injection indicators, token risk data, and supply-chain risk signals.
* Data Contributors are incentivized through reward systems that recognize the value they bring to GoPlus Intelligence, AgentGuard, Web3 Security, and the broader security network.
  {% endhint %}

{% hint style="success" %}

#### **Developers and Security Service Providers**

* Developers and security service providers integrate GoPlus products, build security workflows, contribute threat intelligence, and help expand the GoPlus security layer across AI agents and Web3.
* Contributors are rewarded through ecosystem programs based on adoption, quality, and ecosystem contribution.
  {% endhint %}

{% hint style="success" %}

#### **Users and Ecosystem Partners**

* Users, AI agent operators, wallets, dApps, token projects, exchanges, launchpads, and infrastructure partners provide real-world usage, feedback, and security needs that guide product evolution.
* Ecosystem partners help expand GoPlus adoption by integrating services, contributing risk context, and supporting ecosystem standards.
  {% endhint %}

### Ecosystem Revenue

**Security Service Fees**

Users and business customers may pay tokens or supported payment methods when they use GoPlus security services, including AgentGuard, GoPlus Intelligence, transaction protection, DeepScan, SafeToken Protocol, and other security services. These fees support service providers, product development, ecosystem growth, and ongoing research.

**Staking Requirements for Contributors**

To maintain credibility and long-term alignment, qualified contributors may be required to stake tokens. Staking can support governance participation, contributor accountability, and incentive alignment across data contribution, integrations, and security service provision.

**Staking-Based Voting Weight Mechanism**

In GoPlus Network governance, users can stake tokens to acquire voting weight. Voting weight is correlated with the number of tokens staked, ensuring that voters are committed to the ecosystem and responsible for its long-term development.

Through these mechanisms, GoPlus Network Governance supports a vibrant ecosystem while giving contributors and users a clear path to participate in the growth of the security layer for AI agents and Web3.

## Conclusion

GoPlus Network Governance enables community proposals, voting, and open discussion so that the governance framework can reflect the interests and values of the ecosystem. By coordinating data contributors, users, developers, security service providers, and ecosystem partners, governance strengthens the reliability, sustainability, and openness of the GoPlus security layer.


# Data Contributor

Data Contributors are pivotal members of the GoPlus Ecosystem and the broader GoPlus Security Network. They supply the on-chain, off-chain, agent-runtime, and supply-chain security data that powers GoPlus Intelligence, runtime protection, transaction security, and decentralized security services.

### **Responsibilities of Data Contributors**

{% hint style="success" %}
**Data Provision**

Data Contributors are tasked with sourcing and supplying high-quality, relevant security data to the Security Data Layer. This can include malicious addresses, phishing sites, token risks, dApp risks, transaction patterns, prompt-injection payloads, malicious packages, unsafe MCP servers, risky URLs, and other threat intelligence.
{% endhint %}

{% hint style="success" %}
**Data Verification**

Data Contributors also bear the essential duty of verifying the accuracy and legitimacy of the information they provide. Rigorous checks and validation processes are a standard part of their workflow, serving to maintain the security data's integrity.
{% endhint %}

{% hint style="success" %}
**Incentive Acquisition**

When the data provided by Data Contributors is successfully submitted and verified by the data layer, GoPlus Network Governance can facilitate incentive distribution in the form of tokens. This reward system acknowledges the significant contributions Data Contributors make to the ecosystem.
{% endhint %}

### Conclusion

Data Contributors are the linchpins of GoPlus security services, with their commitment to accuracy and validation upholding the integrity and reliability of the system. Through incentives offered by GoPlus Network Governance, their critical input is recognized and rewarded. Their work is fundamental to the success of AI agent security and Web3 security. For more specific security data types, see [Types of Risk Data](/goplus-network/the-goplus-security-layer/security-data-layer/types-of-risk-data).


# Users

Users are at the heart of the GoPlus Ecosystem, playing a critical role in its functionality and growth. They include Web3 users, developers, AI agent operators, wallet users, token projects, and teams that rely on GoPlus to protect high-risk digital actions before execution. Their real-world usage drives the continuous evolution of the network.

**Role and Impact of Users**

{% hint style="success" %}
**Engagement with Security Services**

Users are the primary consumers of GoPlus security services. They can use tokens or supported payment models to subscribe to security services, protect transactions, secure AI agent actions, and access risk intelligence. During service usage, value can flow back to ecosystem contributors who provide data, threat intelligence, integrations, and security capabilities.
{% endhint %}

{% hint style="success" %}
**Feedback and Community Interaction**

The feedback provided by users is invaluable in the continuous development cycle of the GoPlus Ecosystem. Through forums, social media, and direct interactions with developers, users voice their experiences, suggestions, and concerns. This feedback is crucial for identifying usability issues and improving user interface and experience across GoPlus products and integrations.
{% endhint %}

{% hint style="success" %}
**Participation in Security Campaigns on GoPlus APP**

Users are encouraged to engage in diverse campaigns run by GoPlus products. These campaigns are structured to simulate real-world threats in controlled environments, allowing users to practice safe Web3 navigation, agent runtime protection, transaction review, and security decision-making. By actively participating, users improve their own security skills and contribute to the collective security intelligence of the GoPlus Ecosystem.
{% endhint %}

{% hint style="success" %}
**Rewards and Incentives**

Active participation in campaigns on GoPlus APP is incentivized with various rewards, including ecosystem points and tokens. These rewards serve not only as a motivation for users to engage more deeply with the security features of the network but also as a means of acknowledging their contributions to the ecosystem’s resilience.
{% endhint %}

{% hint style="success" %}
**Stake to Vote**

Users can stake tokens to gain voting rights in the GoPlus Network’s governance. This staking not only signifies a user's commitment to the ecosystem but also grants them the power to influence decision-making processes. The amount of tokens staked directly correlates with the weight of their vote, emphasizing the principle that those who are more invested in the network have a greater say in its governance.
{% endhint %}

## Conclusion

Users are not just participants but fundamental drivers of the GoPlus Ecosystem. Their active involvement, feedback, campaign participation, voting, and advocacy shape the network's development, ensuring that it remains responsive to the needs of Web3 users, AI agent operators, developers, and security teams. By engaging with the ecosystem, users protect their assets and agents while contributing to a broader movement toward a more secure, transparent, and user-focused digital environment.


# Tokenomics

The $GPS token is the cornerstone of the GoPlus Security Network, aligning incentives across decentralized security data, runtime protection, governance, and open security services. As GoPlus evolves into the security layer for the AI era, $GPS is designed to support both AI agent security and Web3 security.

## **Our Vision: A Decentralized Security Network** <a href="#id-7bae" id="id-7bae"></a>

$GPS launched through GoPlus' token generation event on **January 16, 2025**. The introduction of $GPS marks a new chapter in our journey, transforming GoPlus from a security provider into a decentralized network where everyone can contribute to and benefit from open security. We envision a future where security is open, permissionless, transparent, and user-driven. Through GoPlus Network, protection can be available before every high-risk digital action, from AI agent tool calls to Web3 transactions.

With a proven track record since 2020, GoPlus has established itself as a crucial security infrastructure provider for Web3. Every day, we process over **30 million** security detection requests, actively combat emerging scams and threats across more than **30 blockchains**, and protect **billions** in user assets. Our security intelligence technology has been integrated by leading platforms including major price websites, DEXs, and wallets, with over **10,000+** projects and developers relying on our services.

GoPlus security services cover the entire Web3 transaction lifecycle and are now expanding into AI agent runtime protection through AgentGuard. This coverage, combined with a sustainable business model, demonstrates both our technical capabilities and operational execution.

As we move toward a more decentralized future, $GPS aligns incentives across the ecosystem and supports the expansion of GoPlus from Web3 security into the broader security layer for the AI era.

## **$GPS Token Launch and Market Access**

The GoPlus Security token uses the ticker **GPS**. GPS has a maximum supply of **10,000,000,000 GPS** and is deployed on Base, with market data tracked by major crypto data platforms including CoinMarketCap.

GPS began trading on **January 16, 2025**, with initial market access through centralized exchanges and Web3 trading venues. Early exchange support included **KuCoin**, **Bitget**, **MEXC**, **Bybit**, **Gate**, **CoinW**, and other trading platforms. Binance later listed GPS on **March 4, 2025** through its HODLer Airdrops program, opening spot trading pairs including GPS/USDT, GPS/USDC, GPS/BNB, GPS/FDUSD, and GPS/TRY.

GPS market access has continued to expand across major centralized exchanges, including platforms such as Binance, OKX, Bithumb, KuCoin, Bybit, Gate, MEXC, Bitget, BingX, and others, improving liquidity and accessibility for users, contributors, developers, and ecosystem participants.

## **Product Lines** <a href="#f8c5" id="f8c5"></a>

Business Solutions:

* AgentGuard: Runtime security for AI agents, including policy enforcement, action evaluation, approval workflows, audit timelines, and supply-chain scanning.
* Security Intelligence: Comprehensive security APIs powered by AI, security data, transaction simulation, and advanced analysis capabilities.
* DeepScan: AI-powered token security audit for detecting smart contract vulnerabilities, rug pull risks, access-control issues, honeypots, and scam patterns.
* Web3 Infrastructure Integrations: Security integration capabilities for chains, RPCs, wallets, sequencers, and rollups.
* SafeToken Protocol: Standardizing secure token issuance and providing professional liquidity management tools to enhance token ecosystem security.

Consumer Products:

* GoPlus APP: A one-stop security hub protecting users' Web3 activity with wallet security scanning, transaction protection, and real-time risk alerts.
* Browser Extension: Real-time wallet and transaction protection for users.

### **Tokenomics Overview**

With a total supply of **10,000,000,000 $GPS** tokens, GoPlus tokenomics are designed to prioritize ecosystem growth and community participation while ensuring proper alignment with initial contributors.

<figure><img src="https://2031722588-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F3j5GFgqQKWTX18n74ll7%2Fuploads%2FTnJF4cV0fMg4sM6kdt4F%2Fimage.png?alt=media&amp;token=417e38fa-0e62-408d-b5ab-e8b4a8e07bb6" alt=""><figcaption></figcaption></figure>

60.67% for Ecosystem & Community Growth

* Community & Development (24.67%) For incentivizing community participation, rewards
* Ecosystem Growth (10%) Allocated to grow network adoption and enhance security service
* Marketing & Growth (6%) Supporting ecosystem expansion and market development
* Airdrop (10%) Rewarding early adopters and active participants
* Liquidity (7%) Ensuring market stability and trading efficiency
* Advisors (3%) Supporting strategic guidance and ecosystem development

39.33% for Initial Contributors and Private Investors

* Team (20%) 20% of the supply has been allocated to the initial team of contributors, who have been building GoPlus since 2021 and will continue leading the development of the GoPlus security layer for years to come. Initial contributors have a **6-month lockup** (cliff) after the January 16, 2025 TGE, followed by **2 years of monthly linear vesting**, demonstrating our long-term commitment to the project’s success. *🏋️ For these early contributors, it will take **7 years** to receive all the tokens from the beginning.*
* Early backers from 2021–2024 (19.33%)
* GoPlus has allocated 19.33% of the supply to early backers across different investment rounds. These partners have supported our vision of making Web3 safer and expanding GoPlus into the security layer for the AI era. Their allocation follows cliff and vesting schedules designed to align long-term ecosystem incentives.

### **Summary Unlock Schedule** <a href="#dff5" id="dff5"></a>

<figure><img src="https://2031722588-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F3j5GFgqQKWTX18n74ll7%2Fuploads%2FpWDt0vohfhngMz3qg1Cj%2Fpic%20(2).png?alt=media&amp;token=1bb04bf4-a826-4d01-9eae-19080fbae8c3" alt=""><figcaption></figcaption></figure>

**$GPS Utility**

> $GPS Token — Powering the GoPlus Security Layer

GoPlus Network is building comprehensive security infrastructure covering four critical aspects:

* AI Agent Security: Runtime protection, policy enforcement, approvals, audit trails, and supply-chain scanning.
* Secure Asset Issuance: Standardizing token creation and deployment
* Secure Asset Management: Professional liquidity and token management
* Secure Trading: Protected transactions and risk prevention

The $GPS token is designed to power every aspect of this security lifecycle:

1. **Security Service Fees**

* End users pay security gas in $GPS when using transaction protection services
* Business users pay in $GPS to access security intelligence
* Agent users and teams pay in $GPS or supported payment models to access AgentGuard protection and security services
* Token projects and platforms pay in $GPS or supported payment models to access DeepScan audit services
* Projects pay in $GPS to utilize SafeToken Protocol for liquidity management

2. **Staking Ecosystem**

Ecosystem contributors may stake $GPS to become security data providers, governance participants, or other qualified security service participants and earn rewards for their contributions.

3. **Security Trading Fees**

As GoPlus expands transaction protection and secure trading services, $GPS can be used to align incentives among users, security service providers, liquidity partners, and ecosystem contributors.

### Conclusion <a href="#id-537a" id="id-537a"></a>

The January 16, 2025 launch of $GPS marks a new era for GoPlus Security. As GoPlus expands from Web3 security into AI agent security, $GPS helps coordinate incentives across security data, runtime protection, governance, and open security services.


# Automated Security Testing

<figure><img src="https://2031722588-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F3j5GFgqQKWTX18n74ll7%2Fuploads%2F7OaBbhMVEl09G5hhxv1P%2Fimage.png?alt=media&amp;token=bab40e1e-0df7-49c3-af75-d2de6eac1652" alt=""><figcaption><p>SecScan</p></figcaption></figure>

## Introduction

In the world of blockchain, Token is a concept symbolizing different assets that drive decentralized finance. When tokens are implemented as smart contracts, they follow specific standards to ensure unified manipulation, such as making token transfer between addresses. The well-known established standards include ERC-20, ERC-721. However, adhering to a token standard never guarantees the "merit" of a token. Some token owner would insert some malicious behaviors in the token implementations, resulting in token holders being unable to enjoy their rightful asset benefits.

Worse, the malicious tokens deliberately disguise themselves by employing various tricks to conduct their maclious behaviors. Even a seasoned contract security engineer would require significant time to distinguish such issues. In reponse to the severe situation, we introduces **SecScan**, an automatic solution based on cutting-edge static analysis techniques. Overall, **SecScan** accepts ERC-20 tokens of any solidity versions and detects malicous behaviors. The detection process is both efficient, completing in under three seconds per token, and effective.

Next, we delve into the inner operations of **SecScan**. For each input program, we first construct our Intermediate Representation (GIR) from the solidity compiler. Our IR namely GIR, shares the same spirit as program dependence graph. It not only encompasses various dependency information such as data-, control-, and order dependencies, but also provides a comprehensive depiction of these dependencies. Specifically, our data dependence analysis is enhanced with static single assignment form and field sensitive alias analysis, And we have further captured the implicit control dependencies introduced by features such as revert statements, and function modifiers. Subsequently, we employ value flow analysis on the ERC-20 interfaces of the contract to identify different financial concepts, such as balance variables, to enhance GIR. Such financial concept identification enables us to comprehend token behaviors at a high level.

On this powerful GIR, we conduct various kinds of detection for malicious token behaviors, such as abnormal tax modification, minting, and blacklist. A portion of the malicious behaviors is modeled as value flow reachability problem. In this case, we have developed a highly productive value flow engine that abstracts many program details, such as deep function call chains, enabling users to describe malicious behavior at its core. To further enhance productivity, we leveraged Large Language Model (LLM) to help us in writing these checkers. As for the malicious behaviors involving numerical values, we address them strictly with constraint solving. Specifically, the behaviors of a token is encoded into symbolic constraints, while the malicious behaviors are encoded as predicates to check. This crucially guarantees our high precision.

**SecScan** has identified a significant number of malicious behaviors across various aspects and is continuously ensuring the security of users in investment contracts.


# Fuzzing Testing

**Paper Link:** <https://arxiv.org/abs/2312.04512>

## Background

Smart contracts have emerged as the cornerstone of blockchain technology, enabling the automation and execution of agreements without the need for intermediaries. It has revolutionized the way agreements are executed in decentralized environments, offering transparency, efficiency, and trustlessness.

However, smart contracts, like any software, are susceptible to vulnerabilities that can be exploited by malicious actors. Common vulnerabilities include reentrancy attacks, integer overflow, authorization flaws, and logic errors. These vulnerabilities can result in financial loss, privacy breaches, and disruption of services. While the potential benefits of smart contracts are vast, ensuring the security of users who interact with them is paramount. By focusing on user security, we aim to foster a safer and more resilient ecosystem for smart contract adoption and usage.

**Example.** Imagine a scenario where a token contract allows users to buy tokens but not sell them, resulting in the token price continuously rising due to the inability to sell. This setup attracts more users to invest, believing they will benefit from the increasing value of the tokens. However, if the contract owner withdraws all funds at this point, the users' funds are drained from the contract, causing significant financial losses to investors. This is a classic example of a honeypot contract, deployed with malicious intent to exploit the trust and naivety of users in the blockchain ecosystem. To mitigate the risks associated with honeypot contracts, users must exercise caution and conduct thorough due diligence before interacting with smart contracts, especially those offering high returns or incentives that seem too good to be true. In addition, developers have a responsibility to prioritize security and transparency when deploying smart contracts. By adhering to best practices and conducting thorough security audits, developers can help prevent the creation of honeypot contracts that pose a threat to unsuspecting users.

Towards smart contract user security, we propose a novel fuzzing paradigm MuFuzz, which can dynamically test smart contract and expose potential vulnerability in the contracts. Fuzzing has been proven to be a practical technique in the field of smart contract security for uncovering vulnerabilities. Users can utilize MuFuzz to preemptively detect smart contracts on the blockchain, allowing them to identify potential pitfalls in the contract beforehand and mitigate possible risks associated with the contract.

## Methodology

In the following, we present the specific technical details of MuFuzz, which consists of three key components, namely sequence-aware mutation, mask-guided seed mutation, and dynamic-adaptive energy adjustment. Figure 1 shows the high-level architecture and analysis pipeline of MuFuzz.

#### A. Sequence-Aware Mutation

MuFuzz begins by taking the contract source code as inputs, which is then compiled into three types of representations, i.e., bytecode, application binary interface (ABI), and abstract syntax tree (AST). Bytecode is disassembled into EVM instructions for fuzzing. Meanwhile, MuFuzz captures the data dependencies of all state variables in the contract. By analyzing the ABI and AST, MuFuzz is able to figure out which state variables are defined and which functions contain state variables. Since smart contracts are stateful programs, MuFuzz ignores functions that do not contain any state variables because they cannot affect the persistent state. MuFuzz then tracks each state variable and its read and write operations, such as assignments and comparisons.

Afterwards, MuFuzz derives a transaction sequence based on the information gathered from the data dependency analysis of the state variables. Put succinctly, MuFuzz approximately determines a sequence of transactions in which transaction T1 is executed before transaction T2 only if T1 writes a state variable V where T2 reads it. As a result, MuFuzz is able to estimate the invocation order of each transaction in the sequence.

#### B. Mask-Guided Seed Mutation

MuFuzz then determines the inputs of the transaction sequence. A trivial way is to randomly generate the test inputs of transactions. However, due to the randomness, it suffers from inherent difficulties in satisfying complicated branch conditions. To address these challenges, MuFuzz introduces a seed evolution paradigm that iteratively refines the test inputs of transactions. MuFuzz first adopts a branch-distance-feedback seed selection strategy, guiding the fuzzer to select high-quality seeds. Furthermore, MuFuzz employs a mask-guided seed mutation strategy, which allows the fuzzer to identify the certain parts of the test inputs that should not be mutated, thus guiding the seed mutation to hit target branches more efficiently. MuFuzz starts by creating an empty seed queue and a set of seeds as inputs, followed by performing seed selection and seed mutation, respectively.

**Branch Distance Feedback.** MuFuzz tracks the seed execution and records the branches that each test case covers. Whenever a test case covers a new branch, it is added to the seed queue. While this strategy has been shown to quickly traverse most of the branches, it still has difficulty in covering those branches that are guarded by strict conditions.

**Mutation Masking.** To further bias test input generation towards target branches, MuFuzz incorporates a mask-guided seed mutation into MuFuzz. The mutation masking strategy derives from the observations that: (1) certain parts of a test input that hits a deeply nested branch are critical to satisfying the necessary conditions for reaching that branch; (2) certain parts of a test input that makes the distance to cover a branch smaller play a key role in approaching that branch. Therefore, to generate more mutated inputs hitting target branches, the crucial parts of the test inputs should not be mutated. Inspired by this, MuFuzz first customizes the selection of test inputs to mutate from the seed queue. It selects the inputs that either hit the deeply nested branches or make the branch distance smaller. We say that a branch *br* is a nested branch if and only if *br* contains at least two nested conditional statements. Each nested branch is associated with a nested score, which is set to the number of nested conditional statements. After filtering out which seeds need to be mutated, MuFuzz introduces a mutation mask computation algorithm, aiming to approximate the critical parts of the test inputs that are not allowed to mutate. MuFuzz engages a set of mutation operators, including byte flipping, replacing bytes with interesting values, byte insertion, and byte deletion.

#### C. Dynamic Energy Adjustment

In practice, after reviewing a large number of real-world smart contracts, we empirically observe that the updating of state variables tends to be protected by strict branch conditions or hidden in deeply nested branches. Unfortunately, conventional fuzzers may waste massive resources in fuzzing common branches, while the allocated energy is insufficient for the deeply nested branches or branches that are likely to contain bugs. To address this problem, MuFuzz adopts a dynamic-adaptive energy adjustment mechanism, which enables the fuzzing resource allocation for each branch more balanced and flexible.

MuFuzz is equipped with a pre-fuzz phase that executes a test input on an instrumented EVM to collect the exercised path. Given the path *P*, MuFuzz initializes the fuzzing resources. After that, it analyzes all split points (i.e., branch instruction) in *P*. During the pre-fuzz phase, MuFuzz will set a weight value for each exercised branch. Note that the nested branches are assigned different weight values based on the value of nested score, and the branch covering a vulnerable instruction is assigned an additional weight value. It is worth mentioning that the pre-fuzz phase yields little impact on the overall runtime overhead of the fuzzer.

In subsequent fuzzing rounds, MuFuzz dynamically adjusts resource allocation according to the weight value of each branch. This suggests that the higher the weight value of a target branch, the more fuzzing resources will be allocated along the path to that branch. Moreover, MuFuzz also leverages the energy allocation feedback to guide seed mutation, namely the seeds that reach branches covering the vulnerable instructions are preferentially selected and fuzzed. With the assistance of the dynamic-adaptive energy allocation strategy, MuFuzz is able to take care of these target branches, making the fuzzing process more balanced for each branch.

## Result Analysis

#### A. Effectiveness

| Bug Type                  | True Positives |
| ------------------------- | -------------- |
| BLOCK DEPENDENCY          | 15             |
| UNPROTECTED DELEGATECALL  | 17             |
| ETHER FREEZING            | 14             |
| INTEGER OVER-/UNDER- FLOW | 62             |
| REENTRANCY                | 16             |
| UNPROTECTED SELF-DESTRUCT | 23             |
| STRICT ETHER EQUALITY     | 19             |
| TRANSACTION ORIGIN USE    | 2              |
| UNHANDLED EXCEPTION       | 27             |
| Total                     | 195            |

Table 1 The nine types of smart contract vulnerabilities can be detected by MuFuzz

MuFuzz now is able to detect nine types of smart contract vulnerabilities. On 155 vulnerable smart contracts, MuFuzz uncovers 195 true positives, which are summarized in Table 1.

#### B. Real-World Case Study

| Bug Type                  | Reported Bugs | True Positives |
| ------------------------- | ------------- | -------------- |
| BLOCK DEPENDENCY          | 21            | 20             |
| UNPROTECTED DELEGATECALL  | 0             | 0              |
| ETHER FREEZING            | 0             | 0              |
| INTEGER OVER-/UNDER- FLOW | 42            | 42             |
| REENTRANCY                | 10            | 7              |
| UNPROTECTED SELF-DESTRUCT | 1             | 1              |
| STRICT ETHER EQUALITY     | 2             | 2              |
| TRANSACTION ORIGIN USE    | 0             | 0              |
| UNHANDLED EXCEPTION       | 10            | 9              |
| Total                     | 86            | 81             |

Table 1 Real-World Case Studies of MuFuzz

We randomly select 100 real smart contracts from Etherscan, where each contract contains more than 30,000 transactions in Ethereum. We manually check the bug detection results and classify them into true positives. In addition, we present the overall branch coverage (i.e., the average of the 100 contract runs) of MuFuzz. Table 2 summarizes the experimental results. From the table, we can see that MuFuzz reports a total of 86 bug alarms. Out of the 100 contracts, 39 contracts are flagged as having at least one of these alarms. We manually verify the alarms and confirm that 94% of them are true positives.

## Conclusion

Overall, user security is a fundamental consideration in the design and deployment of smart contracts. By actively addressing prevalent vulnerabilities, we can establish a more secure ecosystem conducive to the widespread adoption and utilization of smart contracts. As the smart contract landscape continues to evolve and expand, it is critical to place a strong emphasis on strengthening user security to foster trust in decentralized systems. MuFuzz, with its integration of advanced technologies such as sequence-aware mutation, mask-guided seed mutation, and dynamic adaptive energy adjustment, is a critical tool for dynamically testing smart contracts. By enabling users to proactively identify potential security risks in advance, MuFuzz serves as a critical safeguard for protecting their interests from potential violations.


# Phishing Site Detection

**Paper Link:** <https://arxiv.org/abs/2311.12372>

## Background

Phishing detection is an increasingly critical area in the realm of cybersecurity, addressing the pervasive threat that phishing attacks pose to users' privacy, data security, and trust in digital communications. Phishing, a form of social engineering attack, typically involves deceiving individuals into revealing sensitive information, clicking malicious links, or performing actions that compromise their security. The evolving sophistication of these attacks underscores the urgent need for robust detection mechanisms that can adapt to the changing tactics of adversaries.

The importance of phishing detection extends beyond protecting individual users; it is vital for maintaining the integrity and security of entire digital ecosystems. Effective detection tools help safeguard personal and financial information, preserve the reputation of businesses, and ensure the trustworthiness of online platforms. As we transition into the era of Web3.0, characterized by decentralized networks, blockchain technologies, and a greater emphasis on user sovereignty and data privacy, the landscape of phishing attacks and the strategies for their detection must evolve correspondingly.

Machine learning-based phishing detection technologies, with their robust data processing and learning capabilities, are increasingly supplanting traditional rule-based and signature-based detection methods. Conventional web features, such as page behavior, content, and HTML code, can be harnessed to construct efficient phishing detection models. However, phishing links often have a short lifespan, rendering a vast archive of phishing web page records inaccessible. This scenario limits researchers' ability to retrieve and utilize information related to web content, behavior, or HTML code. Consequently, utilizing URLs to train machine learning models has become a predominant method for phishing detection. Given that URLs serve as gateways to web pages and contain a wealth of information, machine learning models can effectively identify phishing sites by analyzing and learning from these details, even in the absence of additional supportive data.

## Solution

We introduce a pre-trained model-guided phishing webpage detection framework utilizing a multi-layer attention mechanism. This framework starts by extracting subword and character-level URL information using a pre-trained network. It then incorporates three pivotal modules: hierarchical feature extraction, layer-aware attention, and spatial pyramid pooling. Hierarchical feature extraction leverages pyramid feature learning to derive multi-level URL embeddings from CharBERT's various Transformer layers. The layer-aware attention module discerns and weights interconnections across hierarchical feature levels. Spatial pyramid pooling further processes the weighted feature pyramid through multiscale downsampling, capturing both local and global feature nuances. Our approach achieves near-perfect detection accuracy in real-world tests.

#### Backbone Network

We utilize the pretrained CharBERT model as our backbone network, primarily for its ability to focus on both subword and character-level features simultaneously. CharBERT is an enhancement of the BERT model, incorporating the Transformer architecture with a novel dual-channel framework. This framework is specifically designed to capture information at both the subword and character levels. The key advancements in CharBERT consist of two main components: (1) the Character Embedding Module, which encodes character sequences derived from input tokens, and (2) the Heterogeneous Interaction Module, which facilitates the integration and encoding of these character sequences.

#### Hierarchical Feature Extraction

In deep pre-trained models, even though the output features of one layer serve as the input for the next, the intricate computations within each layer could lead to the degradation of low-to-mid level features, impeding the comprehensive feature learning process. This understanding underscores the necessity of integrating output information across all layers. In this module, we leverage the pretrained model to amalgamate aspect features from every layer during the large-scale, self-supervised URL information learning process. Contrasting with methods that solely rely on the final layer's classification features, our approach significantly enhances detection performance by utilizing the distinct features learned at each layer.

#### Layer-Aware Attention

To effectively discern and highlight the importance of specific features across various layers, we develop a Layer-Aware Attention mechanism, drawing inspiration from channel attention principles. This mechanism empowers the model to independently discern and assign differentiated weights to feature maps at different layers, thus boosting both processing efficiency and precision. In particular, we consolidate spatial data from pyramid feature maps, extracted via the Hierar-chical Feature Extraction Module, using both average and max pooling. This yields two unique spatial context descriptors.

#### Spatial Pyramid Pooling

We apply Spatial Pyramid Pooling (SPP) to the weighted feature results. Originally utilized in computer vision tasks and convolutional neural networks, SPP segments feature maps into locally spatial partitions from fine to coarse levels, aggregating local features and thus becoming a key component in classification and detection systems. We innovatively combine SPP with Transformer technology, applying it to the weighted features extracted by our Layer-Aware Attention module. In the final stage of our network, we perform mean pooling along the concatenated feature map and fixed sequence length dimension. This is followed by processing through a standard dropout layer and a fully connected layer, transforming the URL features into a binary class representation for prediction. This methodology enhances the representational capability of features and improves the model’s adaptability to different scale features, thereby increasing overall predictive accuracy.

## Competitive Advantage

Our approach outperforms the current best methods across a range of challenging real-world scenarios, including class imbalance, few-shot learning, multi-classification, non-independent and identically distributed (non-IIdD) settings, and adversarial attacks. It also achieves near-perfect detection accuracy in online tests.

<figure><img src="https://lh7-us.googleusercontent.com/JOB_bLIHDhg5AOpDTC4jc1AP_UscsRHT3BoJVPPp0of5Ul2OjVNn_H-OZ1SoyHk5x74POajKrxAJA4iAjfzd6-RcpL7hKAKIJE4VnAGGREYC-e4y0CWT45TLzrBHwUosab87eruaPK1MNDY-nykvQ6Q" alt=""><figcaption><p>Fig.1 Comparison of small sample learning capabilities</p></figcaption></figure>

<figure><img src="https://lh7-us.googleusercontent.com/UiWpqv5ZwJKF-L3qzuCprCo8vKpWKUWqgaGsGuVQ_4Q3RoTmYyLbs-Vv8LZLRLv9NZLUCfa1gj6KAjKH8kYckJSi86H9b0snSwjfnuTEZy_JggTFVT7S6NdkPTUwZZk2Cq4LT8VQnJIzG0N-y7IwKPM" alt=""><figcaption><p>Fig.2 Comparison of multi-classification capabilities</p></figcaption></figure>

<figure><img src="https://lh7-us.googleusercontent.com/lvi05tuIXULy03PMtlCF_yd0KW2iNghjAy_b0fSo4Dg5U1_MRgJWYuUMqnjfcB4XSqnI59d8MFoxMVfAebYq-gZPPvosGnAk05R7fKWb0fnE07mtNMisUGyOCjw_CPFdeQo3rJISAuf4d7CX8TxhdgY" alt=""><figcaption><p>Fig.3 Performance comparison under adversarial sample attack</p></figcaption></figure>

\ <br>

<br>


# Phishing Address Detection

**Paper Link:**[ https://dl.acm.org/doi/abs/10.1145/3650400.3650499](https://dl.acm.org/doi/abs/10.1145/3650400.3650499)

## Background & Motivation

The rapid growth and adoption of blockchain technology, particularly Ethereum, have paved the way for decentralized finance (DeFi) applications. These applications enable peer-to-peer transactions and financial services without the need for traditional intermediaries, offering users increased financial sovereignty and efficiency. However, this technological advancement has also attracted malicious actors who exploit the system for phishing scams, costing users substantial financial losses.

Phishing scams on the Ethereum platform are sophisticated and adaptive, often employing tactics such as giveaway scams and fraudulent investment schemes to deceive users into interacting with malicious accounts. These scams can involve complex smart contracts and transaction patterns that are difficult to detect using traditional anti-phishing methods. The transparent and immutable nature of Ethereum's transaction records, while a boon for security and trust, also presents challenges for scam detection, as attackers continually evolve their strategies to evade existing security measures.

Given the evolving threat landscape, there is an urgent need for advanced detection methods that can identify and mitigate phishing attacks on the Ethereum network. Such methods must be capable of analyzing the intricate patterns of transactions and user interactions within the blockchain ecosystem, taking into account both the spatial relationships between transactions and the temporal sequences in which they occur.

## Methodology

<figure><img src="https://2031722588-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F3j5GFgqQKWTX18n74ll7%2Fuploads%2FVqeshXV4Ofn0uCtTGk17%2Fimage.png?alt=media&amp;token=1e450352-89bd-47a8-838a-8c93b8f6233c" alt=""><figcaption><p>Figure 1. Overview of the STFN workflow</p></figcaption></figure>

The Spatio-Temporal Fusion Network (STFN) is a sophisticated approach designed to detect phishing scams on the Ethereum network by analyzing both the spatial and temporal aspects of transactions. The methodology is divided into several key steps:

1. **Data Collection**: The initial step involves gathering comprehensive Ethereum transaction data from Etherscan and GoPlus Security. This data includes transaction details such as sender and recipient addresses, transaction amounts, timestamps, and other relevant attributes. This dataset forms the foundation for subsequent analysis.
2. **Transaction Subgraph Construction**: Each Ethereum address is treated as a node in a graph, and transactions between addresses are represented as edges. This constructs a transaction subgraph for each address, capturing the spatial relationships between transactions and the addresses involved. These subgraphs are dynamic and reflect the actual flow of funds within the Ethereum network.
3. **Temporal Sequence Formation**: Concurrently, transaction sequences are formed for each Externally Owned Account (EOA). Transactions are ordered chronologically based on their timestamps, creating a timeline that reflects the temporal progression of an account's activity.
4. **Feature Extraction**: The spatial features are extracted using a Graph Convolutional Network (GCN) encoder. The GCN processes the transaction subgraphs to identify patterns such as transaction direction, amount, and frequency. These features provide insights into the structure and behavior of the transactions around each address.

   Similarly, the temporal features are captured using a BERT encoder. The BERT model, pre-trained on Ethereum transaction sequences, is fine-tuned to generate representations that are sensitive to the order and timing of transactions. This allows the model to identify temporal patterns indicative of phishing activities.
5. **Feature Fusion**: The spatial and temporal features extracted by the GCN and BERT encoders are fused to create a comprehensive representation of each transaction and address. This fusion process is crucial as it allows the model to consider both the 'who' and 'how' of transactions (spatial) as well as the 'when' (temporal).
6. **Machine Learning Classification**: The fused features are then used as input for a machine learning algorithm, specifically a Multilayer Perceptron (MLP), to classify Ethereum addresses into phishing and non-phishing categories. The MLP learns to distinguish between benign and malicious transaction patterns based on the integrated spatial-temporal features.
7. **Evaluation and Optimization**: The performance of STFN is evaluated using standard metrics such as Area Under the Curve (AUC), Precision, Recall, and F1-Score. The model is optimized through techniques such as cross-validation to ensure its robustness and generalizability.

This methodology represents a holistic approach to phishing detection on the Ethereum network, combining the strengths of graph analysis and sequence modeling to effectively identify and mitigate phishing threats. The integration of spatial and temporal features within STFN is a novel contribution to the field of blockchain security, offering a robust solution to protect users from the evolving landscape of cyber threats.

## Results

**Results of STFN for Ethereum Phishing Detection**

The Spatio-Temporal Fusion Network (STFN) has been thoroughly evaluated through a series of experiments to measure its effectiveness in detecting phishing scams on the Ethereum network. STFN's performance was assessed using a range of metrics, including Area Under the Curve (AUC), Precision, Recall, and F1-Score. These metrics provide a multi-faceted view of the model's accuracy, with AUC offering an overall measure of the model's ability to distinguish between phishing and legitimate transactions, and Precision, Recall, and F1-Score providing insights into the model's performance in terms of false positives, false negatives, and overall accuracy.

STFN was compared against several state-of-the-art baseline methods to demonstrate its effectiveness. These baselines included traditional machine learning approaches using handcrafted features, as well as advanced graph-based methods such as DeepWalk, Node2Vec, and Trans2Vec. Additionally, the performance of STFN was compared with more recent methods like Graph Attention Networks (GAT), GraphSAGE, and Temporal Transaction Aggregation Graph Network (TTAGN). STFN achieved an AUC score of 93.26%, indicating a high level of discrimination between phishing and non-phishing transactions. This score is significantly higher than the AUC scores of the baseline methods, showcasing STFN's superior ability to correctly classify transactions. The model also demonstrated excellent Precision, with a score of 91.08%, suggesting that it rarely misclassifies legitimate transactions as phishing attempts. STFN's Recall score of 94.53% indicates its strong capability to identify actual phishing transactions without missing many positive cases. The F1-Score, which harmonizes Precision and Recall, was 92.77%, further confirming the model's overall effectiveness in balancing the detection of phishing transactions while maintaining low error rates.

## Conclusion

To conclude, the results of the experiments conducted on STFN indicate that it is a highly effective tool for detecting phishing scams on the Ethereum network. The model's integration of spatial and temporal features, combined with its ability to outperform several state-of-the-art baselines, positions it as a leading solution in the field of blockchain security and phishing scam detection.


# Get Started

GoPlus is the security layer for the AI era. You can use GoPlus to protect AI agents, Web3 users, wallets, applications, chains, and high-risk digital actions before they execute.

### For AI Agent Developers 🤖

Protect agent runtime behavior with AgentGuard:

* **AgentGuard Runtime Protection:** Evaluate risky shell commands, file access, URLs, package content, and tool calls before execution.
* **Policy Enforcement:** Allow, block, warn, or require approval for sensitive agent actions.
* **Audit Timeline:** Review what agents attempted, which policies were applied, and why an action was allowed or blocked.
* **Supply-Chain Scanning:** Detect malicious skills, plugins, MCP servers, packages, URLs, and prompt-injection payloads.

Key resources:

* AgentGuard: [**https://agentguard.gopluslabs.io**](https://agentguard.gopluslabs.io)
* GoPlus Website: [**https://gopluslabs.io**](https://gopluslabs.io)

### For Developers 🛠️

Integrate GoPlus security capabilities into your product:

* **Integrate GoPlus Intelligence:** Use APIs and SDKs for risk intelligence, transaction simulation, token analysis, phishing detection, malicious address detection, signature analysis, and agent-oriented security signals.
* **Integrate AgentGuard:** Add runtime protection and policy enforcement to AI agent workflows.
* **Integrate Web3 Security:** Add GoPlus transaction protection, Security RPC, risk intelligence, or infrastructure integrations to chains, RPC services, wallets, dApps, or rollup infrastructure.
* **Use DeepScan:** Run AI-powered token security audits to detect contract vulnerabilities, rug pull risks, access-control issues, honeypots, and scam patterns.
* **Use SafeToken Protocol:** Apply secure token standards and liquidity protection.

Key resources:

* Documentation: [**https://docs.gopluslabs.io**](https://docs.gopluslabs.io)
* DeepScan: [**https://deepscan.gopluslabs.io**](https://deepscan.gopluslabs.io)
* Token Risk Classification: [**https://cryptousersecurity.github.io/token-risk-classification/**](https://cryptousersecurity.github.io/token-risk-classification/)
* GitHub: [**https://github.com/GoPlusSecurity**](https://github.com/GoPlusSecurity)

### For Users 🛡️

Protect your Web3 activity:

* [GoPlus Browser Extension](https://chromewebstore.google.com/detail/goplus/nfmppnghnhlfnfnhfnahilhfaiahmhfj)
  * Multi-chain wallet scanner
  * Real-time smart risk alerts
  * Personal security dashboard
  * AI security assistant
* [GoPlus Web APP](https://app.gopluslabs.io)
  * Personal security dashboard
  * Multi-chain wallet scanner
  * Security service marketplace
  * Security tasks and rewards

### For GoPlus Ecosystem Developers 🔧

Build with the GoPlus security layer:

* Integrate GoPlus risk intelligence, AgentGuard, DeepScan, Security RPC, or transaction protection into your products.
* Contribute security data, threat intelligence, and product feedback to improve ecosystem protection.
* Participate in governance and ecosystem initiatives as GoPlus expands across AI agent security and Web3 security.

***

Join our community to connect with GoFam and stay updated on the latest developments:

* [Discord](https://discord.gg/goplus)
* [Twitter](https://x.com/goPlusSecurity)
* [Telegram](https://t.me/goplussecurity)

For technical support or questions, reach out to our team at <service@gopluslabs.io>


# API & SDK Integration Guide

GoPlus Security offers a wide range of user security solutions, designed to provide real-time protection against a variety of Web3 threats such as phishing, malicious tokens, and fraudulent activities. These solutions have been widely adopted across the industry, trusted by leading platforms, wallets, and dApps to ensure a safer and more secure blockchain environment.

If you're interested in integrating GoPlus Security's advanced features into your own platform, we provide an easy-to-use suite of APIs & SDK that deliver automated security intelligence. These tools are designed for scalability and seamless integration, empowering developers to protect their users with reliable security insights.

For full documentation and step-by-step integration instructions, visit our [API Overview](https://docs.gopluslabs.io/docs/getting-started).


# Roadmap

GoPlus is building the security layer for the AI era. The roadmap reflects a continuous path from Web3 user security infrastructure to AI agent runtime security, with Web3 security continuing as a core business line and AI agent security becoming the main exploration and growth direction for 2026 and 2027.

Our roadmap is focused on four connected goals:

* Build AgentGuard into a full-stack AI agent security platform for runtime security, transaction security, and supply-chain security.
* Continue scaling GoPlus Web3 Security across users, wallets, dApps, tokens, chains, and infrastructure.
* Connect AI agent security and Web3 security into one execution-time protection layer for large-scale autonomous agents.
* Expand the GoPlus Security Network into an open, verifiable, data-driven security ecosystem.

{% hint style="info" %}
The roadmap will be updated as products, ecosystem needs, and security threats evolve. Completed items reflect delivered milestones, while future items indicate planned direction and may be adjusted according to technical progress and market demand.
{% endhint %}

**2024 Q2-Q3: Web3 Security Network Foundation**

* [x] **Security RPC Services - GoPlus SecNet:** Launched Security RPC coverage for Ethereum and BNB Chain, allowing GoPlus APP users to access real-time on-chain risk control.
* [x] **Personal Security Center Launch:** Introduced a user security center, allowing users to configure risk preferences and personalized security strategies.
* [x] **Security Service Ecosystem:** Expanded the GoPlus Network developer ecosystem and enabled additional security services to serve users through GoPlus APP.
* [x] **Solana Support:** Extended GoPlus Stack to Solana, providing Security Intelligence for Solana users, applications, and wallets.

**2024 Q4: Product Expansion**

* [x] **SafeToken Protocol:** Released secure token issuance and liquidity management solutions.
* [x] **Sui Support:** Extended GoPlus Stack to Sui, providing Security Intelligence for Sui users, applications, and wallets.
* [x] **Browser Extension:** Released the GoPlus Browser Extension with real-time smart risk alerts, wallet scanner, and security assistant integration.

**2025 Q1: $GPS Launch and Ecosystem Activation**

* [x] **Token Generation Event:** $GPS launched on January 16, 2025, with initial market access across centralized exchanges and Web3 trading venues.
* [x] **Initial Exchange Listings:** GPS began trading on exchanges including KuCoin, Bitget, MEXC, Bybit, Gate, CoinW, and other platforms.
* [x] **Binance Listing:** GPS was listed through Binance HODLer Airdrops on March 4, 2025, expanding market access and liquidity.
* [x] **Staking:** Enabled GPS staking mechanisms for network participants.
* [x] **Browser Extension Open Source:** Released the source code of the GoPlus Security browser extension to the community.
* [x] **Cross-Chain Bridge:** Supported token bridge to BSC and Solana networks.
* [x] **Transaction Security Upgrade:** Enhanced transaction security risk control features.

**2025 Q2: Security Data and AI-Assisted Audit**

* [x] **Security Data Layer Test Version:** Introduced the Security Data Layer, allowing users and contributors to submit security data to the network.
* [x] **Official Security Data Layer Release:** Launched data contribution nodes, staking-based contributor participation, and data verification mechanisms.
* [x] **Security Engine Partial Open Source:** Opened the developer platform and Playground for community engagement and development.
* [x] **AI Agent Audit Exploration:** Launched AI-powered smart contract audit functionality and began expanding GoPlus security capabilities toward AI-assisted security workflows.
* [x] **Token Risk Intelligence Upgrade:** Improved token security detection, risk classification, and malicious asset intelligence.

**2025 Q3: Chain-Level Security and Simulation**

* [x] **Web3 Infrastructure Integration:** Released infrastructure-level Web3 security integration capabilities for chains, wallets, and RPCs.
* [x] **Multi-Chain Transaction Simulation:** Expanded GoPlus Intelligence with transaction simulation support across multiple chains.
* [x] **Chain-Level Collaborations:** Established collaborations with EVM chains and rollup projects to integrate GoPlus security capabilities into infrastructure.
* [x] **Expanded Chain Support:** Extended security coverage with new integrations, including Sui and additional EVM ecosystems.
* [x] **Security BNB Node Open Source:** Released the open-sourced Security BNB Node as a reference implementation for security integration at chain and RPC levels.

**2025 Q4: Security Layer Consolidation**

* [x] **Secure Transaction Standardization Exploration:** Advanced work on secure transaction standards and chain-level protection mechanisms.
* [x] **Governance Portal Planning:** Completed governance portal planning for $GPS holder participation in proposals and voting.
* [x] **Third-Party Security Service Onboarding:** Began onboarding third-party security services such as AML, KYT, transaction monitoring, and risk analysis into the GoPlus ecosystem.
* [x] **Expanded Chain Integrations:** Continued integration of GoPlus security capabilities with additional EVM chains and L2 ecosystems.
* [x] **AI Agent Security Product Definition:** Completed the initial product direction for AgentGuard and defined AI agent runtime security as a major strategic track.

**2026 Q1-Q2: AI Agent Security Product Launch**

* [x] **AgentGuard Launch:** Released AgentGuard as GoPlus' AI agent runtime security product for protecting high-risk agent actions before execution.
* [x] **DeepScan Launch:** Released DeepScan as GoPlus' AI-powered token security audit product for fast professional token contract reports.
* [x] **Runtime Policy Engine:** Built policy-based allow, block, warn, and approval decisions for shell commands, file access, URLs, package scans, deploy actions, and tool calls.
* [x] **Agent Security Detectors:** Expanded detection for prompt injection, credential leaks, malicious commands, data exfiltration, permission abuse, malicious URLs, and package supply-chain risk.
* [x] **Audit Timeline and Reporting:** Added action-level audit records for agent sessions, policy decisions, approvals, and risk outcomes.
* [x] **Threat Intelligence Advisories:** Began building advisory workflows for malicious skills, plugins, MCP servers, packages, phishing URLs, and prompt-injection payloads.

**2026 Q3-Q4: AI Agent Security Expansion**

* [ ] **MCP and Tool-Call Security:** Extend AgentGuard protection to MCP servers, tool routers, and agent framework integrations.
* [ ] **Agent Transaction Security:** Connect AgentGuard with GoPlus Web3 Security to protect AI agents that prepare, sign, simulate, route, or submit on-chain transactions.
* [ ] **Team Policy Management:** Add team-level policies, approval workflows, webhook notifications, and organization-level runtime controls.
* [ ] **Enterprise Audit and Reporting:** Expand redacted audit logs, policy reports, incident review workflows, and security dashboards for production agent usage.
* [ ] **Agent Supply-Chain Protection:** Improve scanning for agent skills, plugins, packages, MCP servers, templates, repositories, browser content, and third-party tool integrations.
* [ ] **Large-Scale Agent Runtime Controls:** Improve policy evaluation, action gating, approval routing, and audit pipelines for high-volume agent workloads.
* [ ] **DeepScan Product Expansion:** Improve token audit coverage, sample reports, dashboard workflows, and integration with GoPlus Intelligence.
* [ ] **Web3 Security Continuity:** Continue transaction simulation, token risk intelligence, Security RPC, and chain integration upgrades.

**2027 Q1-Q2: Agent Security Network and Developer Ecosystem**

* [ ] **Agent Security Developer Platform:** Provide APIs, SDKs, policy templates, and integration guides for agent frameworks, coding agents, browser agents, and MCP ecosystems.
* [ ] **Agent Security Services:** Introduce additional services for AI agent risk detection, prompt-injection analysis, malicious package detection, URL risk analysis, and runtime policy evaluation.
* [ ] **Decentralized Agent Threat Intelligence:** Expand the Security Data Layer to support verified agent threat data, malicious skill reports, package advisories, and prompt-injection datasets.
* [ ] **Agent Runtime Verification:** Explore verifiable risk validation for agent actions that require independent security review.
* [ ] **Cross-Environment Policy Layer:** Build unified policy models across local agents, cloud agents, Web3 agents, wallets, trading agents, and transaction flows.
* [ ] **Agent Supply-Chain Intelligence Network:** Build shared intelligence for malicious skills, compromised packages, risky MCP servers, suspicious repositories, and unsafe agent templates.
* [ ] **Agent Trading and Wallet Security:** Extend simulation, approval analysis, malicious address detection, token risk analysis, and signature decoding to agent-driven trading and wallet operations.
* [ ] **Partner Integrations:** Expand integrations with agent platforms, developer tools, wallets, dApps, exchanges, launchpads, and infrastructure providers.

**2027 Q3-Q4: Unified AI + Web3 Execution Security**

* [ ] **Unified Execution Security Layer:** Connect AgentGuard, GoPlus Intelligence, DeepScan, SafeToken Protocol, Security Data Layer, Security RPC, and Web3 integrations into one coherent execution-time protection framework.
* [ ] **Agent-to-Chain Security Standard:** Work with AI agent and Web3 ecosystems to standardize risk evaluation, policy enforcement, approvals, and audit records for agent-initiated on-chain actions.
* [ ] **Autonomous Workflow Security:** Extend protection from single actions to multi-step agent workflows, including planning, tool selection, data access, package use, transaction execution, and post-action audit.
* [ ] **Large-Scale Agent Security Operations:** Support security operations for fleets of AI agents with runtime observability, policy orchestration, incident review, risk analytics, and automated response.
* [ ] **Agent Supply-Chain Standardization:** Work with developer and agent ecosystems to standardize skill, plugin, MCP server, package, and tool metadata for security scanning and trust evaluation.
* [ ] **Security Service Ecosystem:** Expand the ecosystem so security developers and service providers can contribute modular services for AI agent security and Web3 security.
* [ ] **Governance and Incentive Expansion:** Strengthen $GPS-based governance and incentive mechanisms for data contributors, developers, users, and security service providers.
* [ ] **Global Security Layer Adoption:** Drive adoption across large-scale AI agent platforms, Web3 infrastructure, developer ecosystems, trading systems, and enterprise security workflows.

GoPlus will continue to update the roadmap as the AI agent security landscape evolves and as new execution risks emerge.


# Community & Support

At GoPlus Network, we are committed to fostering a vibrant and engaged community of users, developers, and ecosystem partners. We believe that building a strong community is essential to the success and growth of our project.


# Community

### Join our community

* 🔗 [Official Website](https://gopluslabs.io)
* 🐦 [Official Twitter](https://twitter.com/goplussecurity/)
* 🏠 [Official Discord](https://discord.gg/goplus)
* 🌍 [APP Website](https://app.gopluslabs.io/)
* 🔧 [API Documents](https://docs.gopluslabs.io/)


# Glossary

### Glossary of Terms

| Term                       | Definition                                                                                                                                                                                                                |
| -------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| GoPlus Security Layer      | The GoPlus security infrastructure for the AI era, protecting AI agents, Web3 transactions, and high-risk digital actions before execution.                                                                               |
| AgentGuard                 | GoPlus' AI agent runtime security product for policy enforcement, action evaluation, approvals, audit timelines, transaction security, and supply-chain protection.                                                       |
| DeepScan                   | GoPlus' AI-powered token security audit product for detecting smart contract vulnerabilities, rug pull risks, access-control issues, honeypots, and scam patterns.                                                        |
| GoPlus Intelligence        | The risk analysis engine behind GoPlus products, providing token analysis, transaction simulation, phishing detection, malicious address detection, signature and approval analysis, and agent-oriented security signals. |
| Security Data Layer        | The GoPlus data foundation for collecting, verifying, and distributing security data across Web3 and AI agent security scenarios.                                                                                         |
| Security RPC               | RPC endpoints with GoPlus security protection for on-chain transaction analysis and risk prevention.                                                                                                                      |
| Infrastructure Integration | GoPlus Web3 security capabilities integrated into wallets, dApps, RPC services, chains, sequencers, rollups, and other infrastructure.                                                                                    |
| $GPS                       | GoPlus Security token, launched on January 16, 2025, used to support governance, ecosystem incentives, and security service coordination.                                                                                 |
| RaaS                       | Rollup as a Service, enabling developers to deploy scalable rollup-based blockchain infrastructure.                                                                                                                       |
| Sequencer                  | A component in rollup architectures responsible for ordering transactions and providing them to the execution engine.                                                                                                     |
| Energy Block / EB          | Points on the GoPlus APP platform, representing an important asset of GoPlus.                                                                                                                                             |


