filecoin-project / filecoin-project/devgrants
Proof of Audits
- Dominant language
- No language data
- Stars
- 409
- Forks
- 311
- PR merge metrics
- No merged PRs in 30d
Description
# Open Grant Proposal: Proof of Audits - Living Audit Passport for FVM
**Project Name:** Proof of Audits
**Proposal Category:** Developer and data tooling (primary) / FVM (secondary) - see https://github.com/filecoin-project/devgrants/blob/master/Program%20Resources/Open%20Grants%20README.md
**Individual or Entity Name:** Individual - MK Veerendra Vamshi, solo founder of Proof of Audits (100% owner). Will sign as individual; will incorporate Delaware if agreement requires entity.
**Proposer:** `@Proofofaudit`
**Project Repo(s)**
- Main app: `https://github.com/Proofofaudit/proofofaudits` (private beta, will open source under this grant)
- New repos to be created: `poa-fvm-analyzer`, `poa-filecoin-pinning`, `poa-fix-proof-cli` - all MIT/Apache-2
**(Optional) Filecoin ecosystem affiliations:** None. No existing work relationships with Protocol Labs / Filecoin Foundation / FFDW. First Filecoin grant application.
**(Optional) Technical Sponsor:** None yet. Open to sponsor introduction from Filecoin team.
**Do you agree to open source all work you do on behalf of this RFP under the MIT/Apache-2 dual-license?:** Yes
# Project Summary
Audited FVM contracts still get hacked because the PDF expires on the next commit. $3.4B stolen in 2025 from audited contracts; 68% of protocols change code within 30 days of audit; 41% of live bytecode != reviewed source (`docs/outreach/accelerator-answer-lock.md:45`). Filecoin FVM faces the same gap: Filecoin's 100+ FVM actors and storage actors ship with a static audit badge, but users have no way to verify which functions at which commit are still covered after an upgrade.
Proof of Audits is live 30 Jul 2026 public beta at https://proofofaudits.com - checker at /verify-contract, demo at /deployed/evidence/aave-v4 (public demo, not a customer), extension at /extension. It maps audits function-by-function across 4 layers (T4→T1) into a living Trust Passport: deployed-code match, unresolved gaps, and fix proof. Extension score + first gap map free. Paid model for sustainability: gap audits $8k-$150k by clusters + 3% fee + 5% on payouts; scorer $3.5k/$5k/$6.5k - but free for Filecoin pilot cohort under this grant.
This grant ports that engine to FVM: Solidity actors on FVM, FEVM storage deal actors, and IPFS-pinned audit artifacts. Audit reports and gap maps will be pinned to IPFS and onboarded to Filecoin storage deals, creating verifiable audit-to-deployment lineage that outlives the PDF.
## Impact
Pain points addressed: 1) FVM teams pay $80k-$150k for a full re-audit after a 50-line fix because no gap map exists. 2) Storage clients cannot verify if the `MarketActor` or custom `Deal` logic they interact with is still within audited commit. 3) Audit firms won't give away pre-sign wallet signal; contests won't turn coverage into living proof.
Benefits: FVM launches with proof, not badge. Teams sell the gap, not the whole repo. Users/wallets see coral/verified-mint Trust Passport before signing a deal or calling `invokeContract`. Risk of not getting it right: Filecoin repeats EVM's stale-badge failures as FVM TVL grows - trust debt compounds.
Ecosystem impact: Direct lift for FVM vertical (DeFi, storage marketplaces, data DAOs, bridges). Success = 10 FVM actors with public Trust Passport at `proofofaudits.com/fvm/*` with IPFS CID + Filecoin deal ID for each audit artifact. 40+ auditors already scored via Native v5 - ready to staff gap audits.
## Outcomes
**Final deliverables:**
1. `poa-fvm-analyzer` - Open source FVM/Solidity actor parser: builds function closures, T4→T1 clusters, maps audit report scope to clusters (human-verified). Supports FEVM + native actors.
2. `poa-filecoin-pinning` - IPFS pinning + Filecoin deal integration: every audit PDF, gap map JSON, and Trust Passport snapshot pinned to IPFS and sealed via Filecoin storage deal (via `w3up`/`lighthouse` or `lotus` client). CIDs + deal IDs stored in Passport provenance.
3. Trust Passport for FVM: `https://proofofaudits.com/fvm/{address}/{commit}` - shows coverage %, T4→T1 gaps, deployed bytecode == reviewed commit (FEVM `eth_getCode` match), freshness, IPFS/Filecoin provenance. API: `GET /api/fvm/{chainId}/{address}/passport`.
4. `poa-fix-proof-cli` - Differential verifier: takes fix commit, checks if critical/high findings are closed, runs invariant regression. Open source CLI for CI.
5. Docs + demo: 10 pilot FVM actors scored, Contract Shield extension updated for `Filecoin`/`Calibration` chainIds.
**Specification:** When finished, any user can paste an FVM address, see which functions were NOT reviewed, verify the IPFS CID of the audit report is sealed on Filecoin, and check if live bytecode matches the audited commit - without trusting our server.
**Success metrics:**
- 10 FVM actors with public Passport + IPFS CID + Filecoin deal ID
- Analyzer maps >90% of functions correctly on 2 baselines (validated by 2 auditors from 40+ pool)
- 3 fix commits verified with CLI
- 200+ Passport views + extension demo working on Calibration testnet
- All repos have CONTRIBUTING.md, pass CI, MIT/Apache-2
## Data Onboarding
All audit artifacts onboarded to IPFS + Filecoin (not just IPFS pin). Projections for this project:
- Month #1: ~0.5 GB (20 audit PDFs + gap JSONs for baselines)
- Month #3: ~2 GB (5 pilot Passports x ~400MB with source snapshots + CIDs sealed)
- Month #6: ~5 GB (10 pilots + fix snapshots, 3 deals per project avg)
- Month #12: ~10 GB (if post-grant adoption continues at 2-3 new FVM projects/month)
Tooling will use `w3up` / `web3.storage` + Filecoin deal maker - modular so teams can use own deal client. Not a large raw-data onboarding play, but high-value provenance data permanence.
## Adoption, Reach, and Growth Strategies
Target audience: FVM teams (DeFi, storage marketplaces, data DAOs, bridges) deploying on Filecoin mainnet/Calibration. Audience size: 100+ live FVM contracts today, growing with FEVM. Existing engagement: 40+ auditors scored, outbound to EVM teams post-upgrade with free gap map -> paid gap audit (same playbook `docs/outreach/accelerator-answer-lock.md:49`).
Onboarding: Founder outbound to FVM teams with stale audit or post-upgrade. First 10: free gap map (IPFS-pinned) -> they pay only to close holes (not in grant scope, shows sustainability). First 100 path: publish Passports, co-marketing with Filecoin Foundation, list Passports in FVM explorer so users demand proof pre-sign. Wallet/extension gives distribution beyond B2B. No paid ads.
## Development Roadmap
Solo founder MK Veerendra Vamshi (100% owner) + on-call auditors from 40+ pool for reviews. Pre-revenue per lock, solo. Infra credits: Google for Startups (Cloud), Google Workspace for Startups, MongoDB for Startups (Atlas for Passport store) - credits cover compute/storage, not cash per `docs/outreach/accelerator-answer-lock.md:23`.
**Milestone 1 - FVM Analyzer + Baselines (6 weeks) - $15,000 - Due 2026-10-31**
Functionality: Port EVM clustering to FEVM Solidity + FVM actor interface. Deliverables: `poa-fvm-analyzer` public, gap maps for 2 baselines (1 FEVM DeFi actor + librust-style baseline) drafted. People: Founder eng full-time. Funding: $12k compensation + $3k infra (Cloud/Atlas beyond credits).
**Milestone 2 - IPFS/Filecoin Pinning + Passport Infra (6 weeks) - $15,000 - Due 2026-12-15**
Functionality: Pin audit PDFs + gap JSONs to IPFS, seal to Filecoin, build Passport site/API with provenance (CID + deal ID + freshness) per `DESIGN.md:85` Evidence Panel. Deliverables: 5 pilot FVM Passports live at /fvm/*. People: Founder eng. Funding: $12k comp + $3k services (deal fees, pinning).
**Milestone 3 - Fix-Proof CLI (6 weeks) - $14,500 - Due 2027-01-31**
Functionality: `poa-fix-proof-cli` differential + invariant regression for fix commits. Deliverables: CLI public + 3 fix commits verified for pilots + CI docs. People: Founder + 1 auditor review. Funding: $12k comp + $2.5k auditor reviews.
**Milestone 4 - Ecosystem Rollout + Extension (8 weeks) - $15,000 - Due 2027-03-31**
Functionality: 10 total FVM Passports, extension updated for Filecoin/Calibration, final report. Deliverables: Extension build, demo video, forum report, maintenance handoff. People: Founder. Funding: $13k comp + $2k services.
## Total Budget Requested
| Milestone # | Description | Deliverables | Completion Date | Funding |
|---|---|---|---|---|
| 1 | FVM Analyzer + Baselines | `poa-fvm-analyzer` repo + 2 baseline gap maps | 2026-10-31 | $15,000 |
| 2 | IPFS/Filecoin Pinning + Passport | 5 pilot Passports with CID+dealID + API | 2026-12-15 | $15,000 |
| 3 | Fix-Proof CLI | `poa-fix-proof-cli` + 3 fixes verified | 2027-01-31 | $14,500 |
| 4 | 10 Pilots + Extension + Handoff | 10 Passports + extension + final report | 2027-03-31 | $15,000 |
| **Total** | | | | **$59,500** |
Breakdown: Compensation $50k + Hardware/Software $4.5k (net after Google/MongoDB credits) + Services $5k (auditor reviews, pinning/deal fees). Raised cash $0, credits only.
## Maintenance and Upgrade Plans
1-year commitment to support FVM Passports on Filecoin mainnet/Calibration. Plan: keep analyzer + pinning + CLI version-tagged, handle FVM upgrade compat, respond to issues within 1 week, quarterly deal renewal check for pinned artifacts. After grant, sustain via gap-audit fees ($8k-$150k by clusters) - Filecoin pilots get free Passport, pay only for gap audits if they choose. All code MIT/Apache-2 with CONTRIBUTING.md for community PRs.
# Team
## Team Members
- MK Veerendra Vamshi - Founder - Proof of Audits - Built living audit infra (checker, T4→T1 clustering, Native v5 for 40+ auditors, Trust Passport, extension) live 30 Jul 2026. Leads all eng, FVM port, FVM/Filecoin integration, auditor staffing, reporting.
## Team Member LinkedIn Profiles
- https://www.linkedin.com/in/veerendravamshi/
## Team Website
- https://proofofaudits.com
- Checker: https://proofofaudits.com/verify-contract
- Demo: https://proofofaudits.com/deployed/evidence/aave-v4
- Extension: https://proofofaudits.com/extension
- Deck: https://new.express.adobe.com/publishedV2/urn:aaid:sc:AP:1fcbcae7-dce7-5cdb-8a58-44ddf38effc2
## Relevant Experience
Solo founder built Proof of Audits from 0 to live beta with deployed-code matching, authority controls, and Passport - same engine proposed for FVM. 40+ auditors scored. No invented revenue/customers per lock. Selected for Google for Startups + Google Workspace for Startups + MongoDB for Startups (credits, not cash) - covers infra for this grant.
## Team code repositories
- https://github.com/Proofofaudit (will open source `poa-fvm-analyzer`, `poa-filecoin-pinning`, `poa-fix-proof-cli` under this grant)
- Prior EVM checker + analyzer (private until open source milestone M1)
# Additional Information
How did you learn about the Open Grants Program? Filecoin docs + GitHub `filecoin-project/devgrants` Open Grants README.
Best email for grant agreement: `v@proofofaudits.com`
Additional info: Project live and pre-revenue, solo founder 100% owner, Raised $0 cash. Credits from Google for Startups / Workspace / MongoDB for Startups are infra credits only.
Contributor guide
No contributing guide indexed for this repository
Research direction
No public implementation files or ready-to-edit repository are identified; the proposal instead plans new repos named poa-fvm-analyzer, poa-filecoin-pinning, and poa-fix-proof-cli. Start by reviewing the milestone deliverables, docs/outreach/accelerator-answer-lock.md, and DESIGN.md:85, then confirm the repositories and interfaces exist before contributing. Done means the planned analyzer, pinning integration, Passport API, CLI, pilots, and CI documentation are delivered.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- google-cloud, mongodb, rust, solidity
- Domain
- blockchain, databases, devtools, security, web-dev
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Active
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100