This report updates on what WEFUZZ, Coinbase Crypto Group Fund grant recipient, has been engaged on over the primary a part of their year-long Crypto growth grant. This particularly covers their work on a decentralized, crowdsourced safety audit and bug bounty resolution.
By WEFUZZ, Coinbase Crypto Group Fund grant recipient
WEFUZZ implements a totally decentralized, crowdsourced safety audit and bug bounty resolution: a set of sensible contracts that enable builders and firms to get their sensible contracts, blockchains, web sites, and so on., audited by the auditors and hackers group. With this work, WEFUZZ goals to grow to be the *Hacker DAO*.
Crowdsourcing is a sourcing mannequin through which people or organizations get hold of items or companies — together with concepts, voting, micro-tasks and so on., from a big, comparatively open, and quickly evolving group of members. Firms like Uber, Gitcoin and GoJek already use this mannequin. Crowdsourcing mannequin gives improved prices, pace, high quality, flexibility, scalability, and variety.
The standard crowdsourcing system consists primarily of three roles: requesters, employees (auditors in our case), and a centralized system. Requesters submit duties to be accomplished by means of the crowdsourcing system. A set of auditors full this process and submit options to the crowdsourcing system. Requesters will then choose a correct resolution (normally the primary or the perfect one which solves the duty) and reward the corresponding employee
This makes centralized methods susceptible. Consumer’s delicate info (e.g. identify, e-mail deal with and so on.,) and vulnerability reviews are saved within the database of those centralized methods, which has the inherent danger of privateness disclosure and knowledge loss. Centralized choke factors usually are not solely assault vectors for leaks and hacks, but additionally for outages.
Crowdsourcing corporations are eager on maximizing their advantages and require requesters paying for companies, which in flip enhance person’s prices. Most crowdsourcing methods demand a ten–25% service payment.
All these points add as much as the already current considerations of sensible contract and multi-chains homeowners and builders (the audit requesters), freelance auditors’ and moral hackers’ considerations. A few of these considerations are:
- Guaranteeing their property are secure from cyber theft, knowledge hacks or every other danger that may end up in a lack of funds and compromised knowledge
- With the ability to get audits carried out in an economical approach — be it personal or public safety audits
- Ensuring the sensible contracts are audited by a number of auditors
- Hackers don’t wish to share delicate private knowledge
- Hackers and auditors and builders want full transparency
WEFUZZ is a totally decentralized, crowdsourced audit and bug bounty platform aiming to be the Hacker DAO. WEFUZZ goals to offer reliability, equity, safety and low service charges by design.
The decentralized platform has many benefits corresponding to greater person safety, service availability, and decrease prices. Sensible contracts operating on a selected blockchain are used to carry out the entire means of crowdsourcing duties which comprises posting audit and bounty campaigns, submitting audit and bug reviews, bounty project, and so on.
WEFUZZ resolution gives quite a few added advantages to customers:
- Information Safety: Studies are encrypted with auditors’ and goal builders’ public key, in order that the bug reviews solely will get learn by who it’s supposed for. Recordsdata are encrypted and saved on the decentralized community storage. No extra knowledge breaches, hacks, password leaks or every other danger affecting current cloud based mostly audit and bug bounty platforms.
- Price Effectiveness: Permitting sensible contract builders, multi-chain builders, and firms to get audits carried out in an economical approach immediately by the auditors and hacker crowd on the WEFUZZ platform. This helps the builders and firms keep away from big charges and congestion points affecting the normal bug bounty platforms.
- Versatile anonymity: Auditors and hackers can select to stay nameless whereas submitting reviews, defending their privateness, and nonetheless getting paid.
- Communication Safety: No centralized knowledge storage, full anonymity, no knowledge transfers, no moderators and full end-to-end encryption. All the info resides encrypted on the Solana blockchain and all of the recordsdata reside on the IPFS blockchain.
Audit Requestors: Builders, corporations or any particular person can request audits or begin a personal/public bug bounty marketing campaign.
Auditors: Auditors could be anybody from moral hackers to audit corporations who can carry out the requested audits or take part in bug bounty campaigns.
Judges: Judges are group members who’re both elected by the group or have been raised to the Choose class by means of popularity.
Presently, we’re engaged on the conceptualization, technical structure, and system design of WEFUZZ, moreover constructing our MVP on Solana and Polygon blockchains, and testing the optimum chain for our challenge.
Please be part of our Discord and comply with us on our Twitter and Medium to maintain observe of the progress. We’re going to launch the code and different instruments we construct as a part of the analysis and growth on this Github account.