Protect: Pre-Flight & Wallet Security

Xecute's Protect engine enforces two distinct layers of defense: Execution Protect (real-time pre-flight transaction guards) and Wallet Protect (live onchain permission and allowance audits).

Pillar 1 · Execution Protect

Deterministic Pre-Flight Safeguards

Before wallet signing, Xecute runs the applicable live execution safeguards:

  • Gas Reserve: Enforces ≥ 0.005 OKB buffer to prevent locked wallets.
  • Slippage Ceiling: Hard block on slippage > 5.0%.
  • Simulation: Real-time dry run via eth_estimateGas to detect likely failures; fails closed on revert.
  • Address Check: Validates 40-hex EVM recipient addresses and normalizes canonical format.
Pillar 2 · Wallet Protect

Live Onchain Allowance Auditing

Inspects discoverable ERC-20 approval permissions and active spenders using real-time contract reads without arbitrary AI risk scores:

  • Live RPC Reads: Queries allowance(owner, spender) directly onchain.
  • Unlimited Allowance Flags: Surfaces true maximum allowances (type(uint256).max).
  • Contract vs. EOA: Uses eth_getCode to verify whether a spender is a contract.
  • 1-Click Revocations: Prepares direct zero-allowance transactions.

Wallet Permission Audit Scope

When you ask Xecute “Scan my wallet for risky approvals”, it scans supported token contracts across X Layer, queries active onchain allowances, and outputs a focused audit summary. If no active approvals are discovered, it reports “No active ERC-20 approvals found within this scan's scope.”

Total Scanned

Supported Assets

Active Spenders

Onchain State

Unlimited Risk

Flagged Exposure

Remediation

1-Click Revoke

Current Implementation vs. Planned Expansion

Security FeatureStatusImplementation Detail
ERC-20 Allowance Audits✓ AvailableLive allowance(owner, spender) checks across token registry
Spender Bytecode Check✓ AvailableVerifies whether spender is a smart contract via eth_getCode
1-Click Revocations✓ AvailableGenerates approve(spender, 0) execution card
Permit2 Offchain ApprovalsPlanned (v2)Canonical Permit2 allowance tracking and expiration inspection
NFT Operator Approvals (ERC-721/1155)Planned (v2)isApprovedForAll scanning for digital collectibles
Proxy & Upgrade InspectionPlanned (v2)EIP-1967 implementation slot detection and admin checks