# Wei Desk > Token decimals and Keccak-256 hashing, audited in off-chain EVM code (bots, backends, dashboards, > indexers, relayers). A free in-browser prescan, an exact unit converter and a selector calculator, > then a paid audit or patch run on gpt-terra. URL: https://wei-desk.skillsafe.ai/ API tutorial: https://wei-desk.skillsafe.ai/api.html ## What it does - Prescan (free, in the browser, no AI): flags hardcoded 18/6/8 decimals, parseEther/formatEther/toWei on ERC-20 amounts, floating-point math on token amounts, integers built from floats, Decimal built from floats, decimal tables keyed by token symbol, decimal caches keyed by address without the chain, silent fallbacks to 18, token code that never calls decimals(), USDC/USDT scaled by 6 where BNB Chain is in play, truncating down-scales and divide-before-multiply (ids D1..); and NIST SHA3-256 used where Ethereum needs Keccak-256, SHA-256 next to Ethereum work, web3.utils.sha3 on possibly empty input, hex strings hashed as UTF-8 text, packed encodings of two dynamic values and non-canonical signatures fed to selector or topic hashes (ids H1..). - Keccak-256 and SHA3-256 are computed in the page (same sponge, padding 0x01 vs 0x06). Signatures are canonicalised (no parameter names, no spaces, uint -> uint256, no keywords) and hashed to a 4-byte selector and a 32-byte topic. - Units: decimal amount <-> base units exactly (BigInt), rescale between decimal bases with the dust it drops, and the number a wrong-decimals read would show. ## Paid lanes (field `task`) - `decimals` - audit of every amount path: findings with line, verbatim code, problem, numeric impact and fix; amount_paths (decimals source, exact/float math, chain-aware); cache keying; tests. - `hashing` - audit of every hash site (algorithm, purpose, ok) and the signature table, with the selectors the browser computed; findings and tests. - `patch` - rewritten code (whole file or changed functions), changes mapped to findings, helpers; the browser re-runs the prescan on the patched code. Every reply is reconciled in the browser: each prescan flag answered, each confirmed high/medium flag carried by a finding, verdict (broken / at_risk / safe) no looser than the flags left standing, every quoted snippet present on the cited line, and no hex digest that the browser did not compute or the code does not contain. ## Reference decimals (read on-chain with decimals() on 2026-09-26) - USDC: 6 on Ethereum (0xA0b86991c6218b36c1d19D4a2e9Eb0cE3606eB48), Arbitrum One native (0xaf88d065e77c8cC2239327C5EDb3A432268e5831), Polygon PoS native (0x3c499c542cEF5E3811e1192ce70d8cC03d5c3359); 18 as Binance-Peg USDC on BNB Chain (0x8AC76a51cc950d9822D68b83fE1Ad97B32Cd580d). - USDT: 6 on Ethereum (0xdAC17F958D2ee523a2206206994597C13D831ec7); 18 as BSC-USD on BNB Chain (0x55d398326f99059fF775485246999027B3197955). - WBTC 8 and DAI 18 on Ethereum. The rule stays: read decimals() at runtime and cache by (chain id, token address). ## Sources Derived from the agent skills @affaan-m/evm-token-decimals (primary) and @affaan-m/nodejs-keccak256, affaan-m/everything-claude-code, MIT licence: - https://skillsafe.ai/skill/@affaan-m/evm-token-decimals - https://skillsafe.ai/skill/@affaan-m/nodejs-keccak256