Local-first wallet-security prototype with a working Arbitrum Sepolia policy-commitment demo. Controlled browser tests allow matching requests and block approval, recipient and policy mismatches.
TetraHelix Guard is an existing cross-browser, multichain wallet-security prototype. Its private provider-interception core, authenticated bridge and supported unsigned EVM inspection predate this Buildathon and are reused, not claimed as new work. Guard explains supported requests locally; the wallet remains the final signer.
The focused Arbitrum Sepolia module verifies that the local policy matches its versioned onchain commitment before a supported request reaches wallet review. PolicyRegistry is deployed at 0x4e05929f68dc9c433c7cbdf5120bd1dd527fbfaf on chain 421614, with confirmed policy version 1. Canonical, salted, domain-separated commitments bind policy version, owner, registry and chain. The registry receives commitments, not private policy rules or inspected transaction content. Public account/version/timing metadata remains visible; salt disclosure permits dictionary guesses. A commitment does not prove that a policy is safe.
Controlled Brave/MetaMask extension tests observed a matching zero-value self-transfer reaching wallet review, then cancellation without broadcast. Approval, diverted-recipient and policy-mismatch requests were blocked before a signing prompt; the valid policy was restored. Coverage is limited to the controlled local page after bootstrap, not startup, arbitrary hostile sites or all wallets. RPC/client integrity, registry selection and the gap between verification and signing remain trust assumptions. Live version-2 rotation and a signed self-transfer receipt are not claimed.
The public MVP and repository contain only the authorized standalone Arbitrum demo, registry, public receipts, new demo-only decoder and reproduction code. Guard's private core, extension source, PRIVATE policy and private repository history remain excluded. The public page is not an extension download. The unlisted narrated video shows the public demo and describes earlier private-extension observations separately. Independent audit completion, mainnet readiness, complete fraud protection, consensus authentication of intent, escrow and transaction recovery are not claimed.
Pre-existing work: Guard's private provider-interception core, authenticated bridge, supported unsigned EVM inspection and broader multichain product. These are reused and are not claimed as newly authored during the Buildathon.
Organizer clarification supplied September 14 permits private-core reuse with clear prior/new-work disclosure. Official start: September 14, 2026 at 01:01 SGT (September 13 at 12:01 CDT). Implemented/modified after that start: Arbitrum Sepolia PolicyRegistry; canonical salted/versioned policy commitments; current-policy and runtime verification; isolated demo UI; Arbitrum adapter for the existing authenticated Guard bridge; explicit wallet selector; receipt verifier; tests; limited public reproduction package with a new demo-only decoder. Material private-integration commits b22b1d23, d71ebd20, aee8c764 and e8d03c12 and public root 680dfec postdate the start.
Saved verification: 22 private-integration tests and 21 separate public-package tests passed. These are distinct suites, not additive full-product coverage. Existing receipts/runtime verification are reused; no redeployment. Registry: 0x4e05929f68dc9c433c7cbdf5120bd1dd527fbfaf, Arbitrum Sepolia 421614. Deployment transaction: 0xad2491fc511ea87135cb505423d1b0efaf7ac317d6ab82f2eef91dfacef423ef. Policy-v1 transaction: 0xeb3de6f4ca1491e425f1ed73f20eae0a31d2bcefb90d0368c4f35fd409325674. Receipt inclusion and exact runtime matching are not L1-finality claims.
Actual loaded-extension observations: matching zero-value self-transfer ALLOW to MetaMask review, canceled without broadcast; approval BLOCK; diverted-recipient BLOCK; changed-policy BLOCK; valid policy restored. No real funds or mainnet use. Live v2 rotation remains unobserved.
Public MVP: https://guard-arbitrum-demo.lucasz80.chatgpt.site
Public demo-only source: https://github.com/11elevyngroup-png/guard-arbitrum-demo
Video: https://www.youtube.com/watch?v=Jc6SISkQEvk — approximately 3:55, TESS-narrated public demo/receipt/source recording. Earlier private-extension observations are described separately, not presented as live extension footage. Private Guard core and PRIVATE policy remain excluded.
Any future grant exclusivity would require a separate, expressly agreed scope limited to the Arbitrum-specific funded module. No exclusivity over Guard, TESS or the broader multichain core is offered or accepted here, and this project update accepts no grant agreement. Independent audit completion, universal protection and production readiness are not claimed.