Last updated 3 weeks ago
Insufficient Safeguards for Wallet Users on Cardano: A Critical Security Gap
Addressing the security challenge by implementing a robust and collaborative security mechanism to protect Cardano wallet users from phishing, low-trust websites, and wallet drainers
This is the total amount allocated to CardanoShield: Protecting Cardano Wallet Users. 4 out of 5 milestones are completed.
1/5
Milestone 1: Project Kickoff & Research (Months 1-2)
Cost: ₳ 50,000
Delivery: Month 3 - Jan 2024
2/5
Milestone 2: Development of AI/ML Model (Months 3-6)
Cost: ₳ 50,000
Delivery: Month 6 - Apr 2024
3/5
Milestone 3: API Development (Months 7-9)
Cost: ₳ 50,000
Delivery: Month 9 - Jul 2024
4/5
Milestone 4: Implementation of User Feedback System (Months 10-11)
Cost: ₳ 50,000
Delivery: Month 11 - Sep 2024
5/5
Milestone 5: Launch & Iteration (Month 12)
Cost: ₳ 50,000
Delivery: Month 12 - Oct 2024
shawn@gerowallet.io, kostas@gerowallet.io
No dependencies.
Project will be fully open source.
We aim to create a security application that integrates with non-custodial wallets in the Cardano ecosystem. The software will protect against common security threats such as phishing attempts, websites with low trust ratings, and wallet draining mechanisms. Our system will also implement a community-driven approach, where users can contribute to the security knowledge base by marking certain transactions or sites as potentially harmful.
Our proposed solution addresses the challenge by enhancing the security layer of non-custodial wallets in the Cardano ecosystem, employing a blend of advanced security mechanisms and AI-powered threat detection systems. These systems will learn from every interaction, consistently updating their knowledge base to identify and guard against ever-evolving threats such as phishing, low trust websites, and wallet draining tactics in real-time.
AI and Machine Learning models can analyze vast amounts of data, recognize patterns and predict possible threats with a speed and accuracy that are unattainable for manual processes. They can also learn from the behaviors of users, identifying abnormal activities that may indicate a security breach.
The benefits to the Cardano ecosystem are multi-fold. Firstly, the advanced wallet security will encourage more users to join and stay within the ecosystem, bolstering growth and diversity. Secondly, the communal contribution to the security knowledge base creates a decentralized, self-reinforcing system of threat detection and prevention, embodying the spirit of a blockchain-enabled world.
Lastly, by being open-source, the community can actively contribute to the evolution of the solution, fostering innovation, transparency, and trust. This will enhance the overall reputation of the Cardano ecosystem as a secure, user-centric platform for decentralized applications and transactions. The utilization of AI and machine learning will place Cardano at the forefront of advanced, secure blockchain platforms, setting a high standard for others to follow.
Success of the CardanoShield will be evaluated based on the following key metrics:
User Adoption Rate: The number of Cardano wallet users who actively use CardanoShield application. Increasing numbers indicate a successful solution that meets user needs.
User Satisfaction: Regular user feedback surveys will be conducted to gauge user satisfaction with the tool. High satisfaction scores would indicate that the project is successful in meeting user expectations for security.
Reduction in Security Incidents: A decrease in reported phishing attempts, scams, and other security incidents among users of CardanoShield would signal that the tool is effectively improving security within the Cardano ecosystem.
Communal Contributions: The number of user-generated inputs for threat identification, as well as contributions to the open-source code, will be tracked. A high level of community involvement shows that the tool is considered valuable and trustworthy by the community.
AI Model Effectiveness: The accuracy of the AI and machine learning models in predicting and preventing security threats will be closely monitored. Over time, we expect the model's effectiveness to increase as it learns from more data.
These metrics will be regularly monitored and analyzed to ensure that the project is on track for success and to identify areas where adjustments or improvements may be needed.
Project Blog Posts and Updates: We will maintain regular communication through blog posts and updates on the project's progress on platforms like Medium, the project's own website, and on social media such as Twitter. These posts will detail recent accomplishments, challenges overcome, and next steps.
Public GitLab Repository: As an open-source project, our codebase will be publicly accessible on GitHub, allowing any interested parties to follow the project's development, contribute to it, or use it as a basis for their own projects.
Quarterly Report: Every quarter, we'll publish a report summarizing the project's progress, milestones achieved, user feedback, and data on the key success metrics described earlier.
Community AMAs: Periodically, we'll host Ask Me Anything (AMA) sessions on platforms like Twitter or Discord. These AMAs will allow the community to engage directly with the project team, ask questions, give feedback, and suggest improvements.
Publication of AI Model Results: The effectiveness of the AI and machine learning models will be shared with the public, including improvements in the model over time. This will include anonymized and aggregated data to ensure user privacy.
Our team has a proven track record in the blockchain industry, particularly within the Cardano ecosystem. We have successfully developed and launched GeroWallet, which currently serves over 20,000 users worldwide across various platforms such as Chrome, Brave, iOS, and Android. This demonstrates our ability to deliver high-quality projects with complex requirements.
Our team’s expertise ranges from blockchain development to UX/UI design, and quality assurance, ensuring that we have all the necessary skills to undertake and successfully complete this project. Our members are highly proficient and certified in their respective fields, bringing in a wealth of experience from working on similar projects.
We have always prioritized transparency and accountability in our work. Throughout this project, we intend to maintain a high level of communication with the Cardano community. We plan to regularly share our progress, challenges, and victories through blog posts, updates on our website, and social media channels. We also intend to actively seek feedback from the community to ensure our work aligns with their expectations and needs.
We are one of the few Cardano wallets that have been audited by third parties. We have an active bug bounty on all of our applications, further indicating our commitment to security and transparency.
We have successfully managed similar translation projects in the past, translating our browser extension into 8 languages. This not only shows our experience in managing translation projects but also provides a solid base from which to expand the languages supported by our wallet.
We have successfully launched many milestones into production over the course of the last 2 years.
Notable but Non-exhaustive list of successful milestones
In conclusion, our proven expertise, past experiences, commitment to transparency, and active engagement with the Cardano community make us highly capable of delivering this project with a high level of trust and accountability.
Develop an AI/ML Model: To identify and block phishing attempts, websites with low trust, and wallet drainers, we need to create a robust AI/ML model. This model should be capable of learning from both predefined patterns and user inputs to continually improve its effectiveness.
Integration with Popular Cardano Wallets through API: Develop robust API endpoints that can be readily utilized by popular Cardano wallets. This will seamlessly integrate CardanoShield functionality into these wallets, improving security measures in real-time.
Implement User Feedback System: The development of a user-friendly system for users to report suspicious activity is crucial to the AI/ML model's learning process and the system's overall efficacy.
Feasibility of the approach will be validated through a series of steps:
Prototype Development and Testing: A prototype of the system will be developed to test the AI/ML model, integration with Cardano wallets, user feedback system, and interface.
Beta Release: After initial development and internal testing, a beta version will be released to a limited group of users. Their feedback and the system's performance during this stage will help us refine and improve the system.
AI/ML Model Testing: The effectiveness of the AI/ML model will be validated by its ability to accurately identify and block threats. This will be measured by the decrease in successful attacks on wallets protected by CardanoShield.
User Feedback: Continuous user feedback will be invaluable in validating the approach. If users find the system enhances their security and is easy to use, we will know our approach is successful.
Adoption Rate: Lastly, the adoption rate among Cardano wallet users will also be a major indicator of success and feasibility validation. High adoption rates will demonstrate that our solution is effectively addressing a real need in the Cardano community.
Milestone 1: Project Kickoff & Research (Months 1-2)
Assemble the project team, define roles and responsibilities
Conduct a detailed landscape analysis of existing phishing threats, scams, and risks in the Cardano ecosystem
Begin research and development of AI/ML models for threat detection, gathering and analyzing threat data
Milestone 2: Development of AI/ML Model (Months 3-6)
Develop the initial AI/ML model, based on research findings
Iterative testing and refining of the model
Define APIs necessary for integration with Cardano wallets
Milestone 3: API Development (Months 7-9)
Design and develop robust API endpoints for integration with Cardano wallets
Conduct thorough testing to ensure seamless integration and functionality
Milestone 4: Implementation of User Feedback System (Months 10-11)
Design and develop a feedback system to gather data from users
Integrate the feedback system with the threat detection model, allowing it to learn and improve over time
Test the feedback system to ensure it operates as expected
Milestone 5: Launch & Iteration (Month 12)
Release the CardanoShield solution to Cardano wallets
Collect feedback from wallet developers and users to refine and improve the solution
Iteratively improve and update the AI/ML model based on real-world data and feedback
Milestone 1: Project Kickoff & Research (Months 1-2)
Deliverables: Assembled project team, detailed research report on the landscape of existing threats in the Cardano ecosystem.
Outcomes: Clear understanding of the project's direction, identified potential risks, and challenges. A detailed understanding of the threats landscape to guide the development of the AI/ML model.
Milestone 2: Development of AI/ML Model (Months 3-6)
Deliverables: AI/ML model for threat detection, testing reports for the model.
Outcomes: A functional AI/ML model capable of identifying and flagging potential threats, contributing to enhanced wallet security.
Milestone 3: API Development (Months 7-9)
Deliverables: Fully developed and tested API endpoints for integration with Cardano wallets, API documentation.
Outcomes: Secure, functional APIs that Cardano wallets can utilize for real-time threat detection and user protection.
Milestone 4: Implementation of User Feedback System (Months 10-11)
Deliverables: A functional user feedback system integrated with the threat detection model, testing reports for the feedback system.
Outcomes: A system capable of learning from user-provided data, contributing to the continuous improvement of the AI/ML model.
Milestone 5: Launch & Iteration (Month 12)
Deliverables: Final CardanoShield solution, reports on feedback collected, and updates made post-launch.
Outcomes: A fully functional and robust solution for threat detection and user protection in the Cardano ecosystem, with capabilities for continuous learning and improvement.
Project Kickoff & Research (Months 1-2):
Personnel Costs (including Project Manager, Researchers): 30,000 ADA
Administrative & Other Costs: 10,000 ADA
Total: 40,000 ADA
Development of AI/ML Model (Months 3-6):
Personnel Costs (including AI/ML Engineers, Data Analysts, Quality Assurance): 70,000 ADA
Infrastructure and Development Tools: 20,000 ADA
Total: 90,000 ADA
API Development (Months 7-9):
Personnel Costs (including Backend Developers, QA): 50,000 ADA
Infrastructure and Development Tools: 10,000 ADA
Total: 60,000 ADA
Implementation of User Feedback System (Months 10-11):
Personnel Costs (including UI/UX Designers, Frontend Developers, QA): 30,000 ADA
Infrastructure and Development Tools: 10,000 ADA
Total: 40,000 ADA
Launch & Iteration (Month 12):
Personnel Costs (including Project Manager, Developers for Iteration, Marketing): 15,000 ADA
Marketing and Outreach: 5,000 ADA
Total: 20,000 ADA
Total project cost: 250,000 ADA
Development (55%) - 137,500 ADA: This is the most significant part of the budget, covering the actual development of the libraries and back-end system. It includes the cost of developers' time, any necessary software licenses, and other related expenses.
Design (15%) 37.500 ADA - Prior to development, successful user journeys will be created, UX design with foundational research, wireframing, prototyping, and testing. Consulting during development and work towards continual alignment with the dev team and Cardano community to provide a user friendly and successful design for the community to utilize.
Project Management (10%) - 25,000 ADA: This will cover the time and effort required to manage the project, including task allocation, progress tracking, and team coordination.
Research, Testing and Quality Assurance (10%) - 25,000 ADA: This ensures the product is reliable and performs as expected. It involves thorough testing and the time of quality assurance specialists.
Maintenance and Support (5%) - 12,500 ADA: This allocation is for the time and resources needed to provide ongoing support and maintenance of the CardanoShield after it is launched.
Contingency (5%) - 12,500 ADA: This is a buffer for any unforeseen expenses or challenges that may and often arise during the development. This can include events outside of the team's control such as illness, unexpected technical restrictions.
Total 250000 ADA
Answer:
The cost of this project, totaling 250,000 ADA, is an investment into fortifying the security and user experience of the Cardano ecosystem. Here's why it represents substantial value for money:
Improved Wallet Security: By leveraging AI and Machine Learning to identify and mitigate potential threats, we significantly enhance the security for users of the Cardano blockchain, thus fostering trust in the ecosystem.
Reducing Scams and Fraud: By allowing users to report suspicious activity, we can help decrease instances of scams and fraud. The cost of such malicious activities is often much higher than the investment required for this project, hence providing a significant return on investment.
Ecosystem-Wide Utility: This solution is not limited to a single project but will benefit all Cardano wallets and, therefore, all users interacting with them. The value delivered is spread throughout the ecosystem, thereby multiplying the effect of the initial investment.
Innovation and Attraction: Implementing AI and Machine Learning in the security landscape of Cardano will place the platform at the forefront of innovative blockchain security measures. This can help to attract new users, developers, and enterprises to the ecosystem, further increasing its value.
Scalability: The system, once developed, can be scaled to accommodate growth in the Cardano ecosystem with minimal additional costs. This means that as the user base grows, the cost per user decreases, thus offering even more value for money.
NB: Monthly reporting was deprecated from January 2024 and replaced fully by the Milestones Program framework. Learn more here
Lead Developer- Kostas Bastas Kostas has over 29 years of experience in IT duties across a broad spectrum of team sizes varying from Technical Support, Domain Administrator, DBA, and Full stack Developer. He is a hands-on, technical team leader with experience in designing, developing, and engineering dynamic web and intranet applications for a wide variety of financial institutes. After being introduced to blockchain Kostas quickly realized how the future will be defined by DeFi and he is currently using his vast experience to develop and lead the new generation of decentralized Web3 wallets.
Lead Design- Jason Forrest Hogg Jason aims to articulate principal values and develop creative ideas enveloping film, vfx, and motion graphics. I enjoy expressing these ideas through experimentation as well as rational theory, and believe that culture requires a strong visual voice which draws from modernist tradition and contemporary aesthetics. Jason has prior experience Working for Coinbase, Charli3, Apple, and many more.
Founder/UX/Operations- Shawn Roller Shawn has a master’s of science with a background in applied psychological research, as well as professional UX experience working on site for Google and NASA. In 2015, he discovered bitcoin mining. Since then he has contributed to the crypto community by combining his psychology background, user experience expertise, and passion for blockchain. Today, Shawn is focused on bringing decentralized finance to the masses for both new users and experts.
Security/Operations- Chris Chiras Chris is a cyber security engineer with more than 8 years of professional experience. He has a master’s degree in Information Security and in Business Administration. Through his career, Chris was involved with large scale enterprise projects and trading platforms with focus on security hardening and countermeasures. He is a strong believer and supporter of blockchain technology and is applying his innate passion for security to the blockchain and DeFi space.
Advisory:
Advisory- Andrew Westberg Andrew has over 20 years experience in the software development industry. In the past, he has worked for fortune 500 companies like Caterpillar, Nike, and Walmart. Today, he works on or provides technical guidance to projects in the Cardano ecosystem.
Advisory- Dylan Todd Dylan was on the ground for the blockchain reformation in Wyoming, functioning as an integral part of the WyoHackathon and Wyoming Blockchain Stampede. He was previously a member of the strategy division at IOHK, and brings experience in digital marketing, market research, and product strategy.