New Ethereum talks, every Monday. The week's conference uploads by event, in your inbox.

Loading player…

Oasis Workshop | ROFL 201 - Matevz Jekovec | ETHDam III - 2025

CryptoCanalTue, Oct 7, 2025, 12:00 AM

Welcome to the 3rd Edition of ETHDam, hosted May 9–11, 2025 in Amsterdam. This year, we brought together the brightest minds in privacy, security, and AI for a unique 48-hour hackathon + conference combo. 🌷 https://www.ethdam.com// 🌷 ------------------ Oasis Workshop | ROFL 201 - Matevz Jekovec | ETHDam III - 2025 Oasis is home to Sapphire, the world's first confidential EVM network using the Trusted Execution Environment (TEE), the Oasis Privacy Layer (OPL), a cross-chain privacy solution that can be used by any third-party EVM chain, and ROFL, a framework that adds support for confidential off-chain compute. Oasis is an L0/1 blockchain built to support confidential compute for applications at scale, with a unique layered architecture that presents the optimal building and execution environment for DeFi, AI, RWAs, Gaming, NFTs, DAO governance, and more. 𝕏 Follow: https://oasis.net/ https://x.com/OasisProtocol ------------------ About ETHDam & CryptoCanal ETHDam is powered by CryptoCanal, an education and events platform rooted in Amsterdam, expanding into Rotterdam and Zürich. Keep up with us to see updates on future events: https://www.cryptocanal.org/ Follow CryptoCanal on X: https://twitter.com/CryptoCanal Join CryptoCanal TG Community: https://t.me/CryptoCanalCommunity Join CryptoCanal Discord: https://discord.com/invite/XJVjpCqQBz CryptoCanal unites crypto enthusiasts committed to making a positive impact. Unapologetically political, we prioritize education, events, and services while championing cypherpunk values like privacy, sovereignty, and censorship resistance. ------------------ 🎥 Credits: Intro / outro by babyPRO - https://babypro.art/ ETHDam Photography by Paulus – https://concretestate.eu/ MC of ETHDam - James Campbell - he builds decentralized, end-to-end encrypted, privacy tools. Come and say hello on Farcaster https://farcaster.xyz/theref ------------------ Special thanks to our partners who made ETHDam possible: 🌹 Hackathon – Bouquet: Oasis Network https://oasisprotocol.org/ 🌷 Hackathon – Petal: Circles https://aboutcircles.com 💛 Conference – Gold: Zano https://zano.org/ Dash https://www.dash.org/ Bitvavo https://bitvavo.com/en 🩶 Conference – Silver: Igra Labs https://igralabs.com/hero 💛 Conference – Copper: Lido https://lido.fi/ DeTrip https://detrip.travel/ Cake Wallet https://cakewallet.com/ The Grid https://thegrid.id/ Calimero Network https://calimero.network/ 0xbow https://0xbow.io/ Mina https://minaprotocol.com/ JobStash https://jobstash.xyz/ Cyber Capital https://www.cyber.capital/ POAP https://poap.xyz/ Acronym Foundation (Supported our Top 10 Hackers) https://acronymfoundation.org/ 🌱 Sponsor: EF Ecosystem Support Program https://esp.ethereum.foundation ------------------ 00:00 Welcome & Workshop Recap 01:06 Raffle Overview & Architecture 02:11 Multi-Container Setup with Docker 04:38 LLaMA Integration Example 06:38 Persistent Encrypted Storage 07:55 Storage Configuration in Raffle 08:57 Sapphire Integration & Smart Contracts 10:27 Secure Key Generation & Signing 13:00 On-Chain Chatbot Architecture 17:13 Hackathon Tracks, Judging & Resources

Transcript

Welcome to East to E to E to E to Eas from Oasis. He's uh talking about Ruffle. He's giving the 2011 workshop. As he just said, he gave the 101 workshop a few days ago. Thank you very much.

Hello. Hello, dear hackers. Okay. So, uh on Tuesday, uh I held a 1-hour workshop on raffle 101. So, we discussed like what's all about raffle.

Um basically, Raffle is a offchain version of the confidential confidential computer we have on our blockchain. It's called Sapphire blockchain, the EVM compatible confidential uh I think it was the first one in production. Um and then we discussed this raffle thing which is basically the off-chain version of what you can do onchain. uh you can do off-chain it's still running inside a TE so we can trust the computation but you can do more you know comput intensive apps like AI gaming and and so on uh and we discussed how raffle app looks like the components you have this configuration file called the manifest file a raffle.coml um and then you need to register your raw app onchain you you need to pay some fees for that but basically you just stake your assets there and then once you dregister the app you get those assets back so this is basically just for for the spam spam protection.

Um, all right. And then you you build your raffle. There is a raffle bundle called the file and then you deploy that file to our decentralized sorry decentralized um cloud. So uh basically anyone can be a cloud provider uh and uh as long as it it has this TDX the Intel's uh TE version uh of hardware available. Uh right.

So today I'd like to point out more more powerful features. Um and let's get back to it. Uh for starters I will just take the telegram bot we we developed uh in the raffle 101 workshop. Um okay and the first feature I'd like to point out is that um back uh in the previous workshop we just had one Python script packed inside the Docker container. uh but you can have multiple Docker containers orchestrated running in parallel inside the same raw app.

So why do you want to uh have that for example you have a chatbot but basically you want to connect that chatbot to some um LLM model for example Olama and uh ideally you know it would run inside the same bundle and the conversation like never leaves the TE. So that that was the original uh motivation. Uh so how do we do it? This is standard uh compose syntax. So nothing new here.

Oasis specific. Uh basically inside inside your compose yaml file you just add another service. In this case I call it o llama and you define uh where this image lives and so on and you expose ports. So this ports uh section is mandatory. And it basically means that the port 11434 in this case will be exposed externally and you can have other containers connect to this Olama container and speak to it.

Um okay and in the um Python uh this is Python yeah in Python uh in this example. So this is snippet you have access to to these PDFs. I posted it on uh telegram and discord channels so you can copy and paste it. But basically uh I use this Olama Python package and you simply provide uh the URL. So uh the URL should be um Olama and the port.

So just a standard uh syntax. Um and basically you can connect this way to the other container. Um and the command here is that basically in the last workshop we had like /hello which just uh bongs you back the hello hello matosh and uh now I have another um command called clear to remove the history and uh what whatever else comes in it's uh conversation for your bot. So basically if you type what's the population of Amsterdam ano uh that will be redirected to a lama and returned back to you. Um so yeah this is the history here.

So it's per user history. So it's a very like a 50 lines of code uh chatbot speaking to llama like how cool is this? Um okay the second feature is persistent storage. Um so it's a decentralized uh system of um raffle providers that run your raffle app and uh one of the questions was like how do you do storage? So you have some data and you want that data to be shared among multiple instances of your application and the only the only you know proper way to do it is using blockchain.

So blockchain is a root of trust. Whatever is on blockchain inside the smart contracts for example that data is always available to any node out there. Um so this this clearly works. Um but if you take the amma example uh so the first thingama does is you need to download the model I don't know the deepseek model 1.5 uh gigs of tokens.

Uh it's needs quite some space and quite some bandwidth to to spin up. So uh we need some persistent storage on host that uh each time you for example restart your machine or restart your raw app it doesn't download again. So we have you need you need to have some some kind of persistent storage of course per per node uh per per machine it's it's not distributed it's just local. Uh but the problem now here is that we are doing TE right and when it comes to storage you basically need to encrypt everything. So we set up this Lux device and from the host point of view it's just a random blob on on his hard drive uh and inside this uh the TE is using the storage and decrypts it uh and actually to read the content.

So it's it's a TE still and the storage the persistent storage is is like uh safe to use. Um so how do how do you configure to use the persistent storage? Well, this slash storage folder is basically exposed to your containers. So you can just simply uh bind mount it. So this is again the compos file.

If you want for example to have this um root folder uh to be persistent, you do something like mount storage or lama to my root lama folder inside my inside my container. So this way um the first time the raffle app is spun up it will download the LM models uh the second time for examp if it's upgraded or restarted um the persistent storage will be there and it will just you know start immediately because the model will already be there. Uh when you upgrade your raw the persistent storage remains intact. Okay. And uh the third um very strong feature is slightly more uh complex.

Uh it's about integrating um your raw app with Sapphire. So Sapphire uh as I mentioned is our confidential uh EVM. Um and it basically so it it allows you to have smart contracts uh and the smart contract state is onchain. It's encrypted. So basically if you want to dump uh smart contract state you will just get random uh blobs or actually we even just return zero uh for the sake of um um yeah um right so um how do we do it um we set up a service called app d so it's a application demon uh it's a simple rest service and um it's you can use it uh by binding to this Unix socket.

So on a host it's called /runabd.sock and usually just you want you want to map it inside the same file. At least in in our examples that's how we do it. Uh and then you connect to that socket um and the HTTP request header should begin with HTTP/ localhost and then the endpoint you want to use. Okay.

Okay. Now, what are the endpoints? Um the first endpoint is the app ID. It just means that um give me the app ID I'm currently running and that's it. So, uh the app ID is the one starting with raffle one something.

So, it's a batch 32 encode encoding. Um and this is for example if the app wants to know of its identity, it's useful. Yeah. Okay. The second endpoint is if you want to generate a key pair, it can be either the ED25519 or the Sanders P256 uh key pair and it's generated inside the TE but it's not generated each time.

It's just derived from the key some some key ID you provide. So this is for example if you uh have some app specific uh key pair you need and if you will provide the same uh ID of that key like the myama key for example it will always derive the very same the very same key. So request here in our example is a demo key. Uh we define the kind. So it's a standard JSON and the response is the hex encoded um 32 byt long um private uh key.

You can then use meta mask or whatever. Um now why is this useful? Let's see. Um the third endpoint is called sign and submit. And um this endpoint you provide the standard Ethereum transaction and it signs you signs the transaction with the unique raw key and submits it onchain.

Um okay and this is useful because when you're running a smart contract you need to know whether the transaction originated from raw app. Okay, this is this is may not sound so complicated but it is because um if there's a transaction and you see the transaction was signed okay with some public key okay with some keeper okay uh how can you make sure that this keep pair never left the TE okay because the first thing is if you Say some account is allowed to to post transactions then you need to generate the key pair for that account and if you generated it some somewhere outside of the TE that's the game over right you cannot assure that the key is is hasn't been compromised yet so you must generate it inside the TE and then once you generate it inside the TE you need to make sure that that key was never exposed during the lifetime of the raffle because you can have upgrades you can have number of containers accessing that that that raffle. So you need to have a very strict uh policy to audit like all history of all the images all the raffle upgrades that ever you know was running inside that uh raffle. Uh so that's the second thing. So we we have this raffle upgrades and each upgrade is all the images are are signed.

So you can then verify the whole history uh and audit specific you know snapshots of those images. Okay. Um and then once you have that you you you still have just a single key and then inside a smart contract how can you verify um like which key is then the right one that originated inside raffle and for this reason we added a special call. It's called the raffle insure authorized origin and it works like this. Um so for example let's have um a simple smart contract that stores uh quotes um for example the rows USD uh prices on Binance and this contract would look like uh so so in this submit observation is something that's running inside um the raw fetches quotes and then wants to send it onchain store it onchain and this submit observation needs to have this um authorization its only o app um modifier and what it does is is make sure that the transaction originated inside raffle which app ID this one raffle app ID and where is this raffle app ID uh defined well inside the constructor so it's here it's public so once you make um once you deploy your contract you define which raffle app you want your smart contract to be linked with and then afterwards any transaction that is signed and submitted using this endpoint will pass this raw ensure authorized origin uh check, right?

And um now if you consider why what this brings um maybe just okay um here's also the example how you uh use this uh endpoint with Python. Um so it's just a HTTP local host and then slash and then the the endpoint address. Uh this is the sign and submit example. So this is the complete Ethereum transaction. Um what this allows us is we can so in in in the previous workshop we had this uh chatbot which is uh telegram specific.

Uh so we have decentralized telegram service. Now what we can do with this um powerful sapphire feature that uh you can rest assured that all the conversation is kept secret uh you can get rid of telegram and just store all the conversation history onchain. So you you only have two components. Your raffle app which is audited and provably like verified that it's safe and you have the sapphire smart contract storage which is uh like yeah it's also provably uh working as as it should. You can audit it at any time.

All the upgrades are also audited and uh you know you can check the history and uh yeah maybe just a proof of concept. Uh I'm not sure why it doesn't want to go full screen but basically this is um something what we did um it's a chatbot which runs completely onchain. So when you want to um send some some prompt you need to sign. Okay. So question here was uh can can you explain the public private cryptography and then you sign the prompt with um metam mask and then raw on the other side listens to uh events on going on for that smart contract on sapphire and uh when when something happens now the transaction will be verified.

Okay. And then when the transaction is verified, when the block is verified, um it contacts the Olama service local inside locally inside raffle, generates the response and sends it back to the Sapphire smart contract and then there's the user uh yeah so this is the answer and then the user pulls the smart contract and gets the answer. Okay. So there is no like third party service involved whatsoever. Everything is completely um traceable and auditable all the history.

Uh maybe can just pause and then the end you can ask me. Yeah. And uh the architecture I don't know it went off full screen. I don't know why. Uh so the architecture looks like this.

So um the user sends a prompt to the blockchain. uh and then the Oracle uh pulse if there's any event uh when the event comes when there's a new uh prompt uh it relays the question to the um service Olama does the computation this is done everything inside raffle inside a TE the answer is returned and then stored back to the blockchain yeah uh so this is the basis note uh this is Ronald runtime onchain logic it is this sapphire EVM chain and then multiple raffles can connect to this uh onchain uh T component. Um okay, maybe just a few words about the hackathon. Um so these are our tracks and our prizes. So deliberately um we have two tracks.

Uh the one we encourage you to to to attend is u well build your off raffle app. Um so this can be just a pure raffle app without any blockchain communication whatsoever or you can do a sapphire integration as well to get some extra points. Uh okay so the sapphire integration means that you use this um insure where is it? Yeah, that you use this raffle insure authorized origin sub call for authentication for example or to do some some other stuff that you would have relied on some third party services otherwise. Okay.

Um, so this is track number one. And for other DABs that are really purely, you know, EVMish that don't require any off-chain uh services, offchain logic to be used whatsoever, we have a special um second track, but the bounties here are are much lower. Um, and this track number two is basically a copy paste from the last year's EVM when we just try to encourage people to build on on Sapphire. a pure confidential EVM uh chain without any off-chain uh components. Um okay.

And then we also had some I have some other pools. One is for uh developer feedback. So if you um join our communication, join our channels uh Discord and Telegram and help out others, post important questions. Uh also if you open issues at our repositories um either docs or oasis SDK or sapphire um yeah you you will get uh award for this uh and then there's a general pool which is just distributed equally among all uh bounty hackers. Okay.

When it comes to judging criteria I just like to point out the um innovation. So it's not just we have bunch of examples um and we encourage you to try to integrate some other technologies we didn't think of. So yeah, AI agents, LLMs, this is pretty, you know, obvious. Can we do something completely else, you know, I don't know, like uh Raspberry Pies, sensors, uh video image processing, I don't know, whatever. Uh so there are these technologies, number of the one one is the real time uh databases, I don't know.

So up to you. This is probably the the strongest part we're we're we're looking for like combine fancy new ideas with the technology that we built. Um, okay. And yeah, the the bonus point is if you if you use both Sapphire and Raffle together. Um, okay.

The resources uh so our documentation is at docs.io and then you have this build section where it covers both raffle and sapphire topics. So just go through maybe check some examples um and you'll you'll get your hands dirty quickly right um the OPPL is privacy layer uh this these are the tools for making bridges uh between um other uh chains usually how it's used is that you you have the original DEP running on some non-confidential chain and then just want to have specific features to be exposed to be running on on Sapphire. So yeah, these are the tools here. Uh it's called OPPL OS privacy and then the playground.

io collects um all projects we are that should be noted uh from previous hackathons. Um so it's a good you know collection to to check them out. Uh and then there's this uh cheat sheet uh which Danna printed and it's spread across this floor. Um you can also check it out here. uh if you don't like the paper version.

Um and I also have some some prints here at my backpack, so feel free to poke me. Um okay, and I think this is it. Cool. Thank you very much. Are there any questions?

I saw a hand go there. Yeah. Hold on. Hold on. Yeah.

In your example, is the answer of the LLM stored anywhere? Yeah. And this one here. Yeah. And the slide after that like Yeah.

So uh the LLM is running inside Olama inside raffle. So you need to download a few gigabytes of data and put them in this persistent storage. Context gets saved. Context uh there is no I mean there are prompts. So for the history you need to always put you know the the whole history along.

That's that's a standard but uh the model is just the original DeepS5. It's not strained on anything else. But you could I mean this is not the privacy issue. This is just a technical engineering you could you need to train on whichever app you want to build, right? Yeah.

Cool. Thanks. There's another question. Oh yeah. Thanks for the talk.

Uh I wonder if u we could run a publicly exposed web server inside the roof. Is it possible or is it discouraged somehow? Yes, it is possible. So uh inside the um Oasis node config file, you can specifically say this raw app ID has these ports exposed externally. Um but the issue here is that the node operator then needs to give you you know the public address and the port which you connect to.

So it's not automated. you need to contact the node operator and say hey can you open that and that port and uh make it uh yeah publicly available uh but it's not so the idea in the next few months we're trying to okay so when you want to deploy your raw you um find appropriate plan because you actually that's similar to what we have in cloud providers you rent some machine and x amount of memory storage CPUs. And here the fourth parameter would be the number of external ports um you are going to to to rent as well. So uh once you decide which offer is uh good for you at which provider then you submit this rent transaction onchain and you also pay for this rent and the the plan is for like a month or an hour or so in in our test net is just one hour for your hackathoners. So the default test net at endpoint is one hour plan and I think two CPUs and four gigs of RAM.

Um right and and at that point in time when you register when you uh rent uh an offer you get the machine back and that machine should also then contain okay I assigned you that and that and that port go ahead and use it for your app. So that's the that's the design we're having in mind to implement it in the next uh month or so. Yeah, but yeah, it's it's it's a great question because we have a decentralized network and now you want suddenly to to bind some centralized DNS records to that swarm of um nodes each having its own IP address and exposed port. Uh but yeah, so it it is possible but currently it's really rudimentary. So yeah, you can ping me and then I can open ports for you, but it's not automatic yet.

Yeah. Oh yeah, time for one more. Yeah. Is it somehow possible to run a scheduled task? So, so say let's say once every hour or well something like that.

the service must run all the time. But basically what you're asking is yes smart contracts don't allow you to have this chron job right and in our case if you set up raffle yes you can have exactly services chron jobs running all the time uh but then would you have to pay it continuously or you only pay currently yes yes currently the the plans are like fixed like hour month and so on you don't pay just by the um amount of you spend time running like CPU time executing your still I mean it will be possible and it will be implemented someday but it's currently yeah just a fixed plan so if you don't use it well tough luck yeah amazing thank you very much thank [Applause]

Automatic transcript — names and jargon may be misspelled.