Last updated 2 months ago
Cardano's security knowledge is scattered across only 2 incomplete sources. No LLM-ready vulnerability database exists to train AI security agents for automated code analysis.
Create a comprehensive LLM-structured vulnerability database with exploit examples, fixes, and best practices. Enable AI agents to provide real-time security guidance to Cardano developers
This is the total amount allocated to No Witness - Common Vulnerabilities Patterns.
Please provide your proposal title
No Witness - Common Vulnerabilities Patterns
Enter the amount of funding you are requesting in ADA
87000
Please specify how many months you expect your project to last
4
Please indicate if your proposal has been auto-translated
No
Original Language
en
What is the problem you want to solve?
Cardano's security knowledge is scattered across only 2 incomplete sources. No LLM-ready vulnerability database exists to train AI security agents for automated code analysis.
Supporting links
Does your project have any dependencies on other organizations, technical or otherwise?
No
Describe any dependencies or write 'No dependencies'
No dependencies
Will your project's outputs be fully open source?
Yes
License and Additional Information
Fully open source with MIT license
Please choose the most relevant theme and tag related to the outcomes of your proposal
Developer Tools
Mention your open source license and describe your open source license rationale.
This project will be fully open source under MIT license from day one. We belive all developer tooling should be open source which helps teams build new products, but also improve and develop tooling by collaboaration
How do you make sure your source code is accessible to the public from project start, and people are informed?
Our project will be open source from day on at:
https://github.com/no-witness-labs
We will also be sharing all develpment and updates regularly on our X account:
How will you provide high quality documentation?
Jonathan, lead developer is taking all the lessons learned from creating Lucid Evolution library and applying them to this project to have high quality documentation having in mind developers transitioning to Cardano as well as those that have been building here for years.
Please describe your proposed solution and how it addresses the problem
Cardano's security knowledge lives in just two incomplete sources - a GitHub markdown file and MLabs documentation.
New developers, especially those using Aiken, have a hard time finding comprehensive vulnerability information that actually fits their development setup, leading to the same security mistakes happening over and over across projects. There's no structured format for building automated security tools either.
We're building a comprehensive vulnerability database designed specifically for Cardano developers, with a special focus on Aiken developers and newcomers. This resource brings together existing security knowledge while adding Aiken-specific vulnerabilities into one well-organized place that will be hosted on developers.cardano.org for maximum accessibility.
Each vulnerability entry gives you clear descriptions with Aiken-specific context, working exploit code that shows how attacks actually happen on Aiken contracts, step-by-step fixes with tested Aiken code, prevention best practices for secure Aiken development, and coverage of common Aiken misconceptions and edge cases that trip people up.
Our database covers all vulnerabilities from existing sources but expanded for Aiken, Aiken-specific vulnerabilities and development pitfalls, and smart contract security approaches tailored to how Aiken actually works.
Each example comes with Aiken code, making it practical for developers to actually learn and implement fixes. Content gets structured for both human reading and future AI tool integration.
The biggest chunk of work is Aiken-specific vulnerability research and verification, taking up 40% of our effort. Creating and testing Aiken exploit examples takes another 30%, while developing comprehensive Aiken fixes and prevention guides accounts for 20%. Quality assurance and peer review handles the remaining 10%.
Please define the positive impact your project will have on the wider Cardano community
The primary impact of this project centers on dramatically improving the onboarding experience for new Cardano developers while preventing costly security incidents across the ecosystem.
Currently, new developers entering Cardano face a steep security learning curve. They must hunt through scattered documentation, piece together incomplete information, and often learn security lessons the hard way through trial and error. This creates significant barriers to entry and leads to repeated vulnerabilities in new projects. Our comprehensive vulnerability database eliminates this friction by providing everything new developers need to build securely from day one.
For Aiken developers specifically, this resource addresses a critical gap. As Aiken becomes the preferred smart contract language for Cardano, new developers need security guidance tailored to this environment. Our database provides Aiken-specific examples, common pitfalls, and secure coding practices that help developers avoid mistakes before they happen.
The structured format of our database also enables the development of AI powered automatic tooling for code analysis. Future tools can be trained on our comprehensive vulnerability examples to automatically scan Aiken code, identify potential security issues, and suggest fixes in real time. This transforms security from a manual learning process into automated assistance that guides developers as they write code.
The cost savings potential is substantial. Smart contract vulnerabilities can cost projects significant funds in lost assets, damaged reputation, and recovery efforts. Even smaller security incidents can devastate early-stage projects that lack resources to recover from mistakes. Prevention through proper education and automated tooling is exponentially more cost effective than dealing with security breaches after they occur.
Beyond direct financial losses, security incidents damage the entire Cardano ecosystem's reputation and slow adoption.
The multiplier effect is significant. Each developer who learns secure practices from our database goes on to build better protocols, mentor other developers, and contribute to a culture of security first development.
What is your capability to deliver your project with high levels of trust and accountability? How do you intend to validate if your approach is feasible?
No Witness Labs is founded by seasoned blockchain developers with a proven track record of delivering high-quality, impactful open-source tools and protocols in the Cardano ecosystem.
Our co-founder, Jonathan Rodriguez, is the creator and lead maintainer of Evolution SDK—the next generation of the widely adopted Lucid—which has become a cornerstone for off-chain transaction building on Cardano. His work has enabled countless developers to rapidly build, test, and deploy Cardano dApps with improved developer experience and reliability.
Our team collectively has extensive experience building both open-source and production-grade blockchain solutions. Members have contributed to many ecosystem projects and several protocol-level designs including cross-chain bridges, staking systems, and Layer 2 frameworks.
No.Witness Labs operate with transparency and accountability as core principles and all significant of our work are developed open-source, ensuring community visibility, code review, and independent audit potential.
Our deep experience, combined with a proven history of delivering developer-focused infrastructure, ensures that No Witness Labs can execute this project with the highest standards of trust, transparency, and technical excellence.
Milestone Title
Research & Foundation
Milestone Outputs
Acceptance Criteria
Evidence of Completion
Delivery Month
1
Cost
20000
Progress
20 %
Milestone Title
Core Content Development
Milestone Outputs
Acceptance Criteria
Evidence of Completion
Delivery Month
2
Cost
20000
Progress
40 %
Milestone Title
Content Expansion & Quality Assurance
Milestone Outputs
Acceptance Criteria
Evidence of Completion
Delivery Month
3
Cost
20000
Progress
80 %
Milestone Title
Final Milestone — Launch & Closeout
Milestone Outputs
Acceptance Criteria
Evidence of Completion
Delivery Month
4
Cost
27000
Progress
100 %
Please provide a cost breakdown of the proposed work and resources
The total budget for the proposed project is estimated at 87,000 ADA, equivalent to 70,000 USD at the current ADA price of 0.81 USD. This plan is designed to efficiently deliver the project within 3 - 4 months, ensuring quality while addressing all cost considerations.
Senior Developers:
Hiring two senior developers is essential for the successful completion of this project within the specified timeframe. Their expertise will be crucial for delivering high-quality code.
Senior developers' rate: Range from 80-120 USD per hour.
Estimated Total Cost in ADA (3 months):
80 USD/hour: For two developers working full time (40 hours per week for 3 months), the total cost would be 76,800 USD, equivalent to 109,740 ADA.
However, since the total project budget is 87.000 ADA, the cost per developer will be split, bringing each developer's effective budget allocation down to 43,500 ADA for the duration of the project.
How does the cost of the project represent value for the Cardano ecosystem?
We’re delivering a shared, open source security knowledge base for Cardano exploits that any team, educator, auditor, or tool can use.
This database systematically removes common classes of mistakes for Aiken. Even a single prevented production bug is a huge benefit for the project and the ecosystem
On top of that we are looking for AI-readiness with LLM-structured entries which will be powering code assistants and CI bots that could flag vulns at PR time, training datasets for Cardano-focused security agents
This will lead to savings through shorter audits (auditors start from known pitfalls and patterns).
Terms and Conditions:
Yes
Jonathan Rodriguez - Senior Blockchain Developer
Jonathan Rodriguez is a distinguished Cardano Smart Contract Developer with a wealth of experience in auditing and optimizing key protocols within the Cardano ecosystem, including Minswap V2, IBC protocol (Cardano Foundation), Optim Finance, Lenfi V2, Genius Yield, and Wanchain Bridge.
His deep technical expertise in smart contracts is further evidenced by his development of the Lucid Evolution framework and his authorship of CIP-128. Jonathan is also a co-creator of the Cardano Design Patterns Libraries, which serve as valuable resources for the wider developer community.
Beyond his technical development work, Jonathan has made significant contributions to the Cardano network's resilience, playing a pivotal role in mitigating a DDOS attack.
His efforts in the Cardano community extend to delivering over five successful Project Catalyst proposals, which have added important open-source tools and innovations to the ecosystem.
Jonathan's role as a Smart Contract Developer and lecturer for the "Cardano Solutions Architect" course at Emurgo Academy demonstrates his commitment to shaping the next generation of blockchain developers.
Vu Dinh Hoang
Software and blockchain engineer with extensive experience building high-performance trading systems and decentralized applications.
Over the past several years, Vu contributed to the Cardano ecosystem through Catalyst-funded projects, governance features, and open-source contributions to libraries such as Lucid Evolution, Plu-ts, Cardano-js-sdk, and Aiken.
His work spans performance optimization for large-scale trading platforms, smart contract development in Plutarch, Haskell, and Helios, and security audits for protocols like Charli3 and USDA.
Vu has a proven track record in designing scalable, secure, and production-grade blockchain solutions, with a strong focus on Cardano innovation.