Back to All Episodes
Season 2Episode 95

Blocksec

December 9, 2023
24m
1 Guest

Listen Now

About This Episode

In this episode of DevNTell, Narb welcomes Blessing Emah, a winning team member from the Chainbase x Developer DAO Hackathon. Emah presents Blocksec, a Web3 security tool designed to simplify the process of tracing hacks within the blockchain space. The project features a Chain Visual Explorer that allows users to enter a wallet address and visualize its transaction flow through a user-friendly tree diagram. One unique feature of Blocksec is its ability to flag and visually highlight addresses that have been linked to known hacks or exploits, such as the Cream Finance and Ola Finance hacks. Emah emphasizes the tool's accessibility, targeting not only developers and security auditors but also everyday Web3 users and companies. Future plans for Blocksec include adding more features, such as an incoming transaction alert system and a repository for blacklisted addresses, with the ultimate goal of enhancing security and awareness across various EVM and non-EVM chains.

Key Takeaways

1

Blocksec is a Web3 security tool designed to simplify tracing hacks and visualizing transaction flows on the blockchain.

2

The Chain Visual Explorer provides a user-friendly, tree-diagram visualization of wallet transactions, making it accessible to non-developers.

3

A key feature of Blocksec is the flagging and visual identification of wallet addresses previously linked to hacks or exploits.

4

Future developments for Blocksec include a blacklist repository, an alert system for potentially compromised transactions, and expansion to non-EVM chains.

5

The Blocksec team, composed of four members with extensive blockchain experience, aims to improve Web3 security awareness for both individuals and companies.

Featured Guest

BE

Blessing Emah

Founder @ Blocksec

Blocksec

Episode Transcript

Narb

GM GM everybody. Welcome to what's going to be a great DevNTell, brought to you by our great friends at POKT Network and Zerion. So if you didn't know, DevNTell is a 30-minute window for builders to showcase something they're passionate about or been working on in Web3. This could be an awesome project you've been working on, demonstrating testing best practices, automation goodies, smart contracts, how to structure projects, etc. Basically, if you've got a passion for something, this is your opportunity to share it with the Web3 community here. And today I am ecstatic to have Blessing on the show, who was one of the winning teams of the recent Chainbase cross Developer DAO hackathon. Welcome to the show, Blessing. Happy to have you on.

Blessing Emah

Thank you so much, Narb. Hello everyone, my name is Blessing Emah and I am happy to be here. So, this was our first hackathon as a team. Some of my friends and I just came together and were like, let's just build something, let's just get involved in hackathon spirit. And being a member of Developer DAO gave me that platform where I saw the hackathon that was happening. So we saw the Chainbase one and we were like, hmm, this is really cool. Let's get building. So what kind of product do we want to build? And that's where, it was just like a one-and-a-half-week ideation process and we came up with our product. And to our surprise, we won, we came like second runner up and we also won the best product in the openness track because of how we used the Chainbase API. So it was very interesting and I love the fact that this us winning basically is proof that we actually are solving a real problem. So I know that you guys are curious on oh, what did you build? What did you guys do? We want to know. So let me introduce you to, let me share my screen. Let me introduce you all to... let me know if you can see my screen.

Narb

Narb, can you see my screen? Uh, no, you haven't shared it yet. Okay, okay. Okay then. Just give me a minute then. Let me just... Sure thing. Right.

Blessing Emah

So what we basically built was a Chain Visual Explorer and we are a Web3 security tool. Sorry, just give me a minute. It's so much better when I share my screen so you guys can see it and understand. Certainly, yep. Okay. All right. Your screen is being shared. Okay, we're good. We're live then.

Blessing Emah

So we are working on the name and the name came to us as Blocksec, that means blockchain security. And we are a Web3 security tool which simplifies the process of tracing hacks in the Web3 space. Blockchain is less than 15 years old and it's a very, very new technology. Yes, there are different innovations coming on here and there. But then we all know about rug pulls, hacks that are happening, protocols are losing large sums of money and it just keeps on happening and happening. Right now, the solutions that are available in the space are tailored towards developer focus or basically they are security companies that are just focused on auditing smart contracts. But what about us, the everyday users, who are innocently trying to explore this technology? We are innocently trying to explore this technology and also how can we secure ourselves? How are we aware of hacks that are happening in the space? So that was what brought about Blocksec and our baby product, the MVP that we have is basically a Chain Visual Explorer.

Blessing Emah

So this is how it looks like. I'm going to show you a demo of it all. Basically what it does is that you can bring up on any... you can get any address on any of these blockchains and you can put it on our Chain Visual Explorer and we basically are going to visualize the transaction that happens on the chain. That means that we are tracing the transaction and any address that has been flagged with a hack or has been identified with a hack before, that address will be turned into... will be flagged red. That means that you'll be able to see that oh my god, this address has been associated with a hack, that means it's not a safe address, that means it's not something that you should allow. Right now, what we have is like the baby... let me just present. Okay. Can you see my screen?

Narb

Uh, yes. Uh, but it's still your PowerPoint. Okay, sorry. Yeah. Or your presentation rather. Yeah. Okay, sorry.

Blessing Emah

Okay, let me just stop sharing that individual then. Sure. Okay. How about now?

Narb

Uh, yes. Now we can see it. We can see it now, yeah.

Blessing Emah

All right, so this is the demo of our product here, the Chain Visual Explorer. And what this means is that you can get any address that you want and you can put it into here and we will check if the address has been hacked before. So we can just check the most popular... I'll say the most popular man in Web3, vitalik.eth. And you should be able to see the transactions that have happened on his address. One thing that we're trying to address... one thing we're trying to address is the fact that when we look at the flow of transactions on the blockchain, it isn't visually appealing in terms of if you're not a developer you may not understand what's happening. So we're looking at how can we approach visualizing all the flow of transactions in a more friendly way, a user-friendly way, and that's why we have a tree diagram. So we are tracing the transaction using a tree diagram.

Blessing Emah

So now, this is Vitalik's transaction and this is like basically everything that has happened recently and you can see it here, it literally happened yesterday by 8:00 AM. So this is literally live. Everything that has happened here and we see where the addresses go to. So this also happened yesterday also. Any and then you get to see further what the flow of the transaction. Anything that happens we get to see it. This is another one again. This all happened yesterday, the transaction hash, the block number, transaction fee, the date, every information that you need and it just keeps going and going like that. So this is how, you can see, we're expanding. So let me zoom out a bit so you guys can see. So this is basically... sorry... So that's basically how everything works in terms of any address that you want, just put it on our Chain Visual Explorer and then you get to see every transaction that has taken place, the flow of each one of them.

Blessing Emah

So that's majorly our MVP product right now but we have so much more in store. Now you guys are saying oh this is nice and all, what about hacks? How do you use this to trace hacks? Now let me show you guys how we do that. So this is like a document that contains different hacks that have happened. This is the Cream Finance hacker, the hacker address. And now we're just going to put that here and what you're going to see is this. Basically, we... it has been... the address has been flagged red because of it has been associated with a hack. Now look at what it says here, reported to be associated with the Cream Finance and undefined exploit/hack. And this is what happened. And every other thing that has happened, every other transaction that has happened you will be informed about them.

Blessing Emah

So this is basically our baby MVP right now and that's just one... yes, a hacked account can also be linked to other transactions that are not hacked. But nevertheless, there's still... since it's like connected, there's still a slight chance of vulnerability. And this is how you see issues like oh a smart contract is good and all and it's secure but then they connected to a protocol and the protocol probably has been hacked. But through this way you get to see the flow of it all. So let's just say this is your address here, you are innocently just sending money, transacting, but then you don't know that the base contract is hacked. So this is just generally how we're doing it, we're trying to visualize how hacks happen in the Web3 space or in different protocols.

Blessing Emah

So right now we support different chains, Ethereum, Optimism, Polygon, Fantom, that means that any hack that has happened in these spaces we will be able to see it. And this is something that anyone and everyday user can use. A Web3 company can use it, a security company can use it, even a smart contract auditor can use it. And that's just... let me just go and try one more this... let me try the Ola Finance hack and it's basically like the same thing. It's very easy for anyone to understand. Yeah, it's very, very easy for anyone to understand. It's the same thing, this address has been associated with an Ola Finance exploit, address that has been linked to it. And this one happened, this was happened like third during March. This was a March that it happened. And every other address that is linked to it. So this is generally how the platform works right now. And we are really excited and this meant a lot for us for us to have won the hackathon shows that we are actually onto something here.

Blessing Emah

And right now we are... okay I can stop sharing my screen now. So that's generally the basics of how Blocksec works as a company that's like as the product. Right now that the feature that we showed you now is the Chain Visual Explorer. And right now we're so excited that it actually worked and this winning this hackathon is like a validation of oh this is actually a product. What we see what you should expect from us moving forward is that we want to add more features. With the money that we won, we want to really set up this product, like get a domain name, basically looking to get into incubators and adding more features. Something we're working on that we're working on right now that I can tell you guys that you should watch out for is that we're creating a repository of blacklisted addresses.

Blessing Emah

That means that every blacklisted address on the blockchain, basically just go there and you search an address there, you see information about the address, the hack it was involved in. And it's it has it's a lot of work so we have to scrape a lot of information off Twitter, different different products and everything. But it's something that we are adding and we feel like it's something that every and everyday user can make use of. It's not just focus we're not just targeting developers, we're not just targeting oh Web3 people in terms of oh the founders. We want people that want to get onboarded into blockchain and they people that are security conscious, we want them to basically understand that oh I'm not sure about this whether this address has been hacked, let me just go search. What about this address I came across, let's just go search. So that's something that we are working on and by next year, I've told Narb we'll be coming back up here to present to you a better product. We have so much more in store in terms of like we said, we want to simplify tracing hacks and that's the center and that's the vision. So everything we're going to be doing is going to be simplified in tracing tracing hacks in the Web3 space and even presenting it to everybody. We want our product to be used by the everyday Web3 people and even by Web3 companies. So I look forward to showing you guys what we have built what we are building next year and also thank you very much Narb for this opportunity, thank you very much Developer DAO, thank you so much to everyone, thank you Chainbase for this opportunity also because if not of this hackathon we wouldn't know what's possible. But I feel really excited about this and thank you and see you all guys next year.

Narb

Thank you, but just before we leave off, I wanted to ask you a couple of questions because this project is very, very interesting and very... it's something like you said can be used by not only developers and security auditors but Web3 companies, maybe even like the average user as well. When you're when the product is able to detect a flagged address, is do you have to go and do that research to see which smart contracts and wallet addresses have been compromised and you update your project with that or can your can the Chain Visual Explorer itself go and figure out that a smart contract has been made vulnerable?

Blessing Emah

Okay, so right now what we can just do is give you information about it like as you saw the smart contract I put in there it showed you the hack that it was related to. So that's generally what you can do right now. But in the future we're looking at a way whereby if we basically what we are doing is that we're going to be alerting projects about the smart or users about the smart contract hack. So it's just like now you input an address and then you can see that this address is hacked so you can we're basically alerting you before. And if it's like a protocol you can choose to reject the transaction. So let's say like an incoming transaction wants to is coming into your into incoming transaction is coming on and then what they are doing is similar to basically a hack, you have the choice to reject the transaction and just basically safeguard yourself. So that one is for companies and for Web3 companies and for everyone that's just trying to build stuff. The everyday users we will educate you about these hacks, better ways to secure yourself, things like that.

Narb

Gotcha. And on the demo you showed when when the search results first came up, it was a tree of I believe 9 or 10 nodes. Is there a reason why you limited it to that or is it just because if you did like everything it'll be too unmanageable to see, right?

Blessing Emah

Yeah, our core one of our core principles is that we want something to be visually appealing, that means a better UI and UX. And when you look at hacks that are happening in the space, the way they are given to the everyday users are probably in a GitHub repo or like in a note like maybe a note markdown format. And we wanted a way that was a way that was easier for people to understand how an hack was related. So like what you saw was the hack, the body hack then there from there we broke it down into a tree. We're using a tree diagram for just easier just for easier reference. And when I try to expand, you saw how the screen and everything expanded. So that was just for like our baby project but definitely we are working on improving it and making it more visually appealing. That's it.

Narb

Gotcha. And how many people did you work with in your in your team?

Blessing Emah

Okay, we are a team of four. We have Chris, we have Raman, we have Preshy. Chris and Raman are the developers, I am like the product manager, Preshy is also like the project manager. So we all just came together and then we are building this. So we are and then we have all been in the blockchain space all together. Our experience is like going to like eight years. I've been in this space for like six years since 2017, yeah. And then Chris is a full-stack blockchain engineer so he has built protocols and all. Raman is a full-stack developer and Preshy is also in the blockchain space. So it's just like bringing all our different experiences together as a team to build this product. And I know we have what it takes because of we have the technical talent, we have used product ourselves, we have built product ourselves. So it's just like a case of coming together and actually putting our head down. And that's what we plan on doing. This hackathon is a validation for that and we are working on that.

Narb

Excellent. Yes, and then the end product even the the baby product looks very promising so I can't wait to see what the evolved version of it is next year. But I guess in saying that, your whole team's experiences like you said kind of came together to make this to make your vision come true. Now, what would you say was the most challenging part when you all were building this initial MVP together? Like I'm sure there was lots of moments where you're like oh no this is maybe harder than we thought. Could you speak to that?

Blessing Emah

Yeah sure. So I think like the most challenging part was trying to I know was trying to maybe get information. Like we're trying to look at what libraries that we can use to display like what you saw our selling point making it visually appealing. So we're trying to look for the libraries and we had to explore a a lot of libraries till we settled on one. And another one was the case about addresses, trying to find addresses. I know of a website if not of my knowledge of a website that basically talks about hacks that happen in the Web3 space. It was really hard to like find add like maybe hacked projects and things like that because you see them online on Twitter but there isn't a repository where you can just find every single thing together as one. So that was something that was very, very hard. And I think it was just like if not of the Chainbase API we had to like bring all these different pieces together as one. And we had a very tight deadline. It was not easy. We submitted on the day like a few hours to the deadline. I think like about two hours or one hour to the deadline because of we were on it trying to make sure that the product was working, linking to different chains and everything. I think all together it's just how a a founding team works. There will always be hard like obstacles on the way but at the end we have we overcome and we did, we submitted.

Narb

Excellent. Yes, yes it worked out very well. And yes that's typically how these these things work. Uh, and do you foresee Blocksec kind of sticking with the Ethereum ecosystem for for the foreseeable future or do you see yourself expanding to also trace like Bitcoin and Solana and other other non-EVM chains?

Blessing Emah

Okay, so right now for the for this stage that we are we will be focused on EVM. But definitely as we grow we want to explore more chains because of blockchain is for everyone, it's not just limited to one chain. And we want to secure the let's say the whole blockchains. It's not just for one blockchains but definitely you have to start with one. So right now we're EVM compatible and we'll be focusing on growing there but later on in the future we will move on to non-EVM chains.

Narb

Excellent. And when you're building this product or at least the new version of it in the future, are you going to make it open source? Are you going to build in public or are you going to keep it kind of private so that you can you and the team can focus on building things without outside noise?

Blessing Emah

They'll be parts of it that will be open source because of we want contributions from from the public, from people that are eager to build. But then there will be parts of it that will be private because of as much as we want everything to be open source, we literally need to put our head down and build a product that actually works. If everything is open source and people are not contributing, it could just be a case of it could die. So definitely some parts will be open source for the general public who are interested to contribute, but then there are some parts that will be private.

Narb

Totally understandable. And any any plans to have like a a social handle around the product or anything like that so we can share with the crowd after the fact?

Blessing Emah

Yeah definitely, we will have we are going to create like a Twitter account where we'll be keeping you guys updated on the product. Right now we're just in the early stage of formulating everything like once we get our domain, once we set up our landing page and everything thanks to hackathon money, yes! Once we get all those things with you we definitely like link all our social media handles here and be dropping updates. Expect a Medium blog from us also that will show probably our roadmap for next year and just 2024 watch out for us. It will be awesome.

Narb

Oh yeah, looking forward to it. And yeah, I guess thank you so much for coming on Blessing, especially last minute. It was a pleasure having you on and I really looking forward to all the great things you and the team are going to be building on Blocksec. So yeah, watch out gang, they'll be back here next year with a new evolved version of it. So but before before everybody leaves today, I just want to show the QR code for you to scan to be able to claim your NFT for being an attendee today. So what you'll want to do is scan this QR code, fill out the form, and you'll be airdropped a attendee NFT for being in attendance today for DevNTell. So you'll have an hour and a half from now to fill out that form and get yourself on the airdrop list for your NFT that will be coming to your wallet within a couple of days. So again, scan this code, fill out the form, which you'll have an hour and a half to do, and you'll get airdropped your NFT. And with that, I want to wish everybody a very happy Friday, happy weekend, and we'll catch you back here next week for DevNTell. All right? Cheers.

Blessing Emah

Wait Narb before everyone goes, if anyone would like to reach out if you'd like to connect with me further or you'd like to contribute to the product, you can reach out to me on Twitter at @DBlessingEmah and also that's my mail also dblessingemah@gmail.com. If you'd like to reach out to me and talk more about the product in terms of accelerator and incubator program, anything that you feel will really help us in growing our product, whether you want to fund the product also. You can reach out to me at @DBlessingEmah and on Twitter and also my mail, DBlessingEmah. T-H-E Blessing Emah is E-M-A-H. Thank you very much.

Narb

And we'll have that information on the description of the YouTube channel. So you won't miss that. And yes, with that, thank you again Blessing for coming on and we'll see everybody here next week. All right? Cheers. Bye. Cheers.

Listen On

Share This Episode

Share on X

Watch Episodes Live!

Subscribe to our event calendar and never miss a live episode.

View Event Calendar