# Introducing Verifier Alliance (VerA )| Kaan Uzdoğan (April 2024)

- Speakers: Kaan Uzdoğan
- Channel: [Berlin Ethereum Meetup](https://streameth.org/berlin-ethereum-meetup)
- Date: 2024-10-07
- Duration: 32:59
- Watch: https://streameth.org/watch/yt-NUbIRtGeg8Y
- YouTube: https://www.youtube.com/watch?v=NUbIRtGeg8Y

## Description

Join us on Meetup to keep track of our events in Berlin: 
https://www.meetup.com/berlin-ethereu...

See you at the next one!

---

Apply to speak at our future meetups:
https://forms.gle/5y9Y5ywZC7pSEqpV9
---

Twitter: @BerlinMeetup

## Transcript

all right hello everyone um as I introduced my name is Khan uh I'm working at eum foundation on the project called sourcify and today I'll be mostly speaking Yeah I think half and half I I'll speaking about sourcify and mainly the Veri Alliance it is the new brand new thing we found recently we haven't been talking about it that much so now I'm starting to we are starting to talk about it more and more yeah I'm also so glad I'm back in a crypto Meetup I was I was in a corporate Meetup last last week in too Bank BTC no it's not Bitcoin Berlin Technology Center and yeah typical typical corporate Meetup innovation technology and I found like and I found out in DOA Bank technology centered there are 1,300 people working like what are you doing with 1,300 people it's almost number of developers in our ecosystem so yeah anyways it's it's good to be talking to people of Our Kind let's say my M right um so verify um before I begin uh maybe a couple of questions who knows what a smart contract is great um very small group so don't be shy uh who has ever looked at a contract source code on ether scan cool who has ever verified a contract on ether scan nice and who knows what sourcify is okay not bad thanks um yeah sourcify uh is a decentralized and open source smart contract verification service in short terms but if you ever listen to my talks before or um another Francis talks or maybe even our websites oh I confused the ordering so we are three people um I'm and another team member recent team member is Manuel and we have Marco from Italy we have three people building this yeah but as I said if you were if you were to listen to my other talks or look at our websites you will see many other things you will see uh solid metadata you'll see human friendly contract interactions you'll see npec ipfs whatever all these things but these were also our goals in the in the uh recent years but recently we are more focusing on one thing and that is this decentralized and open source smart contract verification but um what exactly mean by this if we focus on the two value propositions let's say we have being decentralized on open source comes for an assumption that something is centralized and something is Clos s right and this is the current uh def facto standard in the in the ecosystem yeah currently it's not decentralized or open source and we are talking about these guys ether scan so now I don't want to throw fingers at any anyone like when I usually when I talk about stuff it it is as if like I'm a e scan enemy or something of course like they bring a lot of value to the ecosystem and I know thean guys they are really cool people but at the end of the day this where we end up is not perfectly aligned with our values like we don't want to we don't want to have contracts all all the ethereum contracts own by a single entity um if it goes down everything stops like you you you most of the consumers won't be able to get to know what's happening on the chain and Beyond its values it has a lot of risks as I said when it goes down it goes down if it's lost the contracts are lost one thing I keep bringing it up and that bothers me is when the rink B and robone test Nets were shut down or they deprecated they were gone with their ether scan instances so you can say so what like they were T tests yes but that means also part of the whole knowledge in the internet about ethereum is also gone when I go to a forum click a link on robst rink be it's not there anymore so I don't have the context I don't know what's going on so they were gone this is this partly actually has happened and also you have to if you're a chain and you want a n scan instance you have to pay millions to R scan instance which yeah is quite much money um before we dive let's recap a bit what smart contract verification is what we are actually talking about in the technical terms not going too much into detail um in short smart contract verification exists because the contracts on blockchain or any chain lives as bite codes like here and this is what you see when you look at a code and when you at a contract if you don't verify it and we humans cannot read the bite code we don't understand and it's for machines and you can't make sense of it what we want is something readable at least in n in human language in so in wiper or in any other language but what if I come to you and show this show you this code on GitHub and claim that this is the this is the code of a contract like how do you know this is actually this contract that that that is powering this contract at the end of the day you are um giving your money to this piece of program and how do you know how can you make sure this is actually what it's made what it's doing and not it's not that it's stealing your money what we have right now is the this this thing this is how we see on each scan as I said it's the most popular uh blog Explorer and the contract verier and what you want this actually this this screen check mark you see green check mark you see Source C you're happy and in technical terms this is how it works so we have the the contract files let's say we have three files then we have some compil compiler settings then we feed these into compiler in this case Sol compiler this could be wiper F haveu other languages as well then this gives us a bite code of the contract um then we take this bite code from what we got get from the user when they give us the source code and the user wants to verify a contract on a blockchain let's say at this address and from the chain we get the onchain by code and then we compare it with the compiled one if it's a match we say okay the source code of this contract at this address are these ones let's say my contract ownable ERC these are the uh solty files soty contract that make this contract so this is how it looks in technical terms um and how does cify solve the decentralization and the open source issue so mainly the obvious one is the we are open source um so this means anyone can run their own sourcify indeed people do in the next slide I'll show about this and yeah you can you can see how Source bu works and how our verification works that's the main thing and we want open source code that's another thing um and indeed as I said people run their own source spice for example has scan is the header Chain's main block Explorer if you're familiar with header chain it's evm chain and dat block Explorer is for example powered by sfy right now they had their own sortify fork and in the next weeks hopefully we will start using one single s like they originally for it but in the next weeks we will start using one instance customize for their own needs ours customize for our own needs um that's one thing so we anyone can their own sourcify and it's decentralized in the sense that all the data is public and available and uh also available on ipfs so there are other features that we use for ipfs so I don't want to get too much in detail about that but at the end of the day it's not really easy or possible to um download all contracts from E scan or another block Explorer but in our K it's possible to dump and download everything and do whatever you want with all these contracts um yeah right now we support 144 evm chains um these include the main chains that we know ethereum optimism uh the popular ones from to the ones that you never heard of um so we also kind of yeah helping out those chains or let's say we try to capture those people and on board them to sourcify before they're gone and you can verify the contracts through the soury UI the API or you can also import from leer scan you can enable you can verify contracts through hard hat so we have hardat verify support now that's with the hardat verify command you can also enable sortify and with the same same verification command you can also verify your contract on soury with hardhead is there a question okay um you can also verify with Foundry uh similarly foundaries verification module also support SFI uh you can pass the contract address chain ID and also even provide a custom sourcify instance to verify your contract and lastly you can verify uh your contract on remix source file plugin um right now this is only for source5 uh so it has a separate module than E stand you can also see in this view coincidential um but what we are working towards is more having more parallel verification between different verifiers so what we want actually is not to have separate modules for each verifier e scan soury block Scout you name it but we want to have a single verification module and then users being able to par parall verify everywhere so you don't so all the workload should be handled by the plug-in and as a user you should just click verify and it should go everywhere because we don't want a contract to be uh at a single place ideally unless you of out so this is what we are building next for remix and uh we also are trying to push hard that and Foundry in this direction to allow parallel verification but yeah we we do our best but this is a big problem and we can't really solve this by ourselves as souri so we have so many resources it is difficult to push develop ERS in one direction and change their habits it's also difficult to talk to tooling change their habits all um even though everyone's quite welcome but when it comes to action it's falls falls short so yeah we can't do it by ourselves the mission of let's say decentralized and open source verification easy and easy and unified access to contracts so for that we recently formed something called rare fire Alliance uh with the familiar people you know from the ecosystem uh yeah this happened uh last last summer I think in the etcc in a rather random random uh encounter with these people and yeah once we started talking there come the idea actually led by Sam Sam CC if you know him actually led by them uh to have something like an alliance between the us to share data and push the whole ecosystem in this Direction that's what I want what that's what I find the conference is valuable such encounters don't happen everywhere and yeah we we found that this Alliance recently and we are now working towards this um in short uh the alliance is an ecosystem Collective for easy unified and open access to the source code of evm source contract so not only ethereum not only ethereum ecosystem but all the evm smart contracts also not limited to solidity only we also um have wiper in different verifiers or maybe in the future the other uh evm languages and it's actually quite simple it's not uh rocket science what we are are doing in in the uh surface let's say but behind the scenes there are a lot of coordination work that has to go on and a lot of things to align between all the stakeholders but yeah the the idea is quite simple the idea is like what if took all the contracts and put somewhere this is in one sense it's really simple in short we just take everything from everyone and put in a database that's it so but I mean it's simple but it hasn't happened so far but that's what we are trying to do now um if I explain it with the idea so what would happen if you want to use verifier Alli or if you want your contract to be on the verify Alliance database is you go one of the verifiers or data providers here for now and you verify your contract there and at the end your contract will end up in the database uh um yeah the database has a schema a specific schema for our needs um you can find out schema spec here it's an SQL SQL database um the diagram looks like this so in general we have we have partitioned uh the different uh parts of the contract in different tables let's say in in general we have the difference of compile contracts and the deployments so we don't have a single row or single table of everything together in this case we have the code separate from the compilation and the compilation separate from diplomes and a verification essentially is a is a linking of a compilation and a deployment so this allows us to D duplicate uh most of the contracts as well as uh being able to play around with other things such as looking at the code trying to find contracts that are similar to this code Etc so um right now this serves our needs but over the time as the use cases probably will develop and we will see if if this is a fitting schema or not yeah as I said we decouple the compilations from deployments uh we also have a separation between the Run time and creation code match so runtime code is if you're not familiar runtime code is the actual code that is running uh of your contract and creation code is the code that that is executed when you're creating the contract so it's executed once then it turns into a rtime code and we have matches for um both cases so you can have um yeah you have a creation match you a runtime match and Transformations you also have the concept called Transformations so when we are verifying verifying a bite code we have to leave out some of the fields from the bite code that are let's say deployment specific or contract specific but is not affected by the compilation these are uh Library addresses link libraries um immutables and the C Ox data if you know what it is it is maybe you have heard of it as the metadata hash as well so these parts uh don't don't directly influence the function of the contract let's say so that means before uh verifying contract we leave out these and we put them in a uh transformation so one example is this one I think this is a creation code transformation yeah um that's a creation code because it's a construct it has a Constructor transformation in this case we say okay when this contract was being verified the Al data is replaced with this one and these Constructor arguments were inserted at the end of the contract so next time when when we are verifying the same contract if maybe with different Constructor arguments we can take the all existing things and then just throw a different uh Constructor argument and call it a match really easily and in case of a runtime match for example we have a Library linking here the first one is a library a place this is a placeholder in the bite code and then this by this placeholder is replaced by this address this is the library that is being used as as the um this is the onchain address of the contract and then again the C transformation and the the immutable transformation immutable values are the uh variables that are uh put inside bite code which which the name suggest they are immutable once they're deployed so yeah um right now I just checked we have around 605,000 contracts 650,000 contracts and it's growing um I mean it's a big number but it's compared to the all existing contract it's not that big right now because we are syncing with each other but we don't have the historical contracts so we have to at some point all the data providers have need to go back and get all the historical data to the database um but also the alliance is not only a database so yes the main artifact is database it is the main outcome it's simple uh but it's also a knowledge base for all everything about verification right now both the code is close source and the knowled is close St and we're hoping this to change um with this Alliance and in general push the whole ecosystem in this direction um yeah and on top of that there might be tooling build uh because this effectively becomes a standard to represent verified contracts and taking this standard people can start building the standard toolings on top of that for example you can build tools that um let you verify locally the contracts really easily without trusting anyone else and yeah well as I mentioned you can do for example B code similarity search so if you have a b code that is not verified you can do certain similarity search on top of that and see okay this contract can be this it's similar to this I don't know what so once we give the data set to people there I'm quite sure there will be a lot of interesting applications that we haven't heard about it but like it's really a Pity right now it's the data set is not there so no one's working on the verified contract data set um yeah coming talking about the data sets we are planning to share this regularly in uh paret format uh dumps database dumps uh maybe daily or uh on another basis um and we are thinking about maybe giving an API or application access so that for example your the contracts you are seeing on your blog Explorer will come from this database but but this is just an igation phase right now so this because a public API public AP um app is a let's say different Endeavor yeah so yeah that's it from my side uh you can go to the verifier l.org this is our website to have more info follow us on Twitter we also have a public telegram uh chat if you're interested about uh contributing or even about the data sets right now as I said it's not open but if you want to play around we are Starly we are slowly giving out uh read access to people um also if you're interested in sourcify these are our contacts so yeah thanks for [Applause] listening are there any questions yes please so this verifier Alliance um what's the incentive for the uh people company there incentive or just like um you mean the participants of the alliance right yeah um so for us for example this is our mission like The Source by the public good we are another company but we are working towards this so this perfectly aligns with what we want but if you think about other block explorers block Scout um Dora rout scan Etc so they are kind of fighting a monopoly right the the E scan as the Monopoly and they Al of course want this Monopoly to be broken and at least on the verification side the block Explorer has really Network effects anyways but at least the verification side of things will be broken so they are of course incentivized to participate in so this is like um we are trying to pull them in this direction maybe if this wasn't there they wouldn't be they wouldn't be incentivized to share it share their data share their contract data but if enough people share it we hope to push the whole ecosystem and maybe maybe it scan themselves to open up as well yes sure so you said that um on top of this so You' selected all these smart contract 50,000 and on top of that maybe later on you put like apis or some some tooling so that means that any person have that developer they can like for example I'm just thinking out maybe they provide a parameter that I want Allen contracts let's say and they get it what kind of use cases do you think just for enable like what other than for analysis or uh statistical purposes what other use case would you have in mind for yeah the immediate thing for example I have in mind and this was also discussed is when there's an um vulnerability for example and if you have such a data set you can just go to data set and see where this vulnerability is in which contract like it's just would be simple search and if you want to extend your search you can even search more things like this is for example one immediate case yeah that's a good one other questions yes please do you what do you do differently than ether again so for the developer where is the use piece from yeah the new kind yeah the ux part is the most difficult part I would say because all the users are accustomed uh to the E scam verification and now I'm talking about more about sourcify um and what we also do differently is we support something called full verification um which means we verify both um you know I talked about the ca here for example we verify both the bite code plus this part and if you verify this part this gives your this gives you cryptographical guarantees that what you're are seeing is exactly uh what the contract was originally is because we are basic clarifying a hash of the whole compilation and this gives you higher guarantees plus this c o is actually a ipfs hash so the whole completion plus the contracts are um available on ipfs but again this is another a ux um ux positive so I would say the ux is the most difficult part for us so we have other value propositions being decentralized open source a different verification um but yeah in terms of ux I can't say im anything that's why actually we are trying to push for the parallel verification because we can't obviously step ahead of the ux so at least we say okay if we can't um stop them use ether scan let's at least have it verified everywhere yes please so since you mentioned that you know if you're F scan there team um have you talked to them about it so what was their response did they laugh at it did they sounds like worried like can you share more about it yeah no they're they're real nice people as I said um and I tried I talked about this open many times and uh so yes I said e scan people are different than eer scan as an entity and a c c company right so the compan is obviously not incentivized to do this but I was say people if I put it correctly people are aligned with this but of course they like they give Vance they can't they don't tell me anything completely but my my general uh sense is that yes these people want this to happen uh what what what is that it's opening up the data but the compan is of course not not incentivized to do that so someone has to push them in this direction so where is this database it is not decentralized I'm sorry it is on cloud it's on Google Cloud right now it's a postal database working on Google because um yeah coordinating on this is already quite difficult but um I think it's a good enough compromise as long as we do the regular dumps and we share all the data maybe on the future we can work on the more decentralization aspect if you have other ideas without compromising decentralization I'm happy to hear yeah um just for my understanding you mentioned that if a new chain wants to create like this stand chain it cost them you say a million dollars there was a discussion about this on Twitter I'm just speculating but they were saying so that that's there the the main uh business model of e scan is Explorer as a service and since everyone is familiar with the E scan people just want e scan and you have to give them money for E scan instance recently GIS actually also do that for example like gnosis main block explorer was block Scout but everyone wants ether scan so now we have gnosis Scan as well so yeah that's the main business model block Scout also has the same business model but block Scout is open source so you can run your own block Scout if you want to but you can also go to block Scout and tell them okay can you run a block Scout for us and they will do it I don't know for how much but I suppose for much less I I don't know why I thought if this can would be yeah yeah that's the problem now so like the whole ecosystem is built on top of these values being open source and decentralized and it's closed source and the data is closed um do you have a soal b strategy for the impant course uh border strategy budget budet strategy yeah for the impant course um yeah the the general idea right now the costs are quite low like not so high because the databas is small and we don't have Public Access but the idea is to share among the data providers so this we don't have a business model or anything the idea is just to keep this as a public good let's say yeah I'm just thinking about because like maintaining public uh production grade database that for the globally effable and like for the over the 100 Chains would cost a B in the end yeah so the there the main cost of verification is uh born by the verifiers let's say sourcify block Scout we are the doing the main work of verification and we just wri to the database that's not nothing big but that's why I had a question mark here API app access like we might think about giving API and app access but as you said it's not an easy Endeavor so the first step is have the public access and regular database dumps and then we can see how much of the public access we can manage any other questions okay then thanks again and as I said if you want to learn more um just join these channels or just approach me around the uh me of thank you
