Peter Jung - Fraud Prevention for {Smart} Wallets
ETHCluj Meetup·Tue, Oct 7, 2025, 12:00 AM
Speaker
AI in the Web3 space is experiencing a boom, primarily due to the rise of LLMs. However, a critical application of machine learning, which has long been utilized in centralized payment solutions, is fraud prevention. Each time we send money or pay using a credit card, state-of-the-art algorithms decide if the transaction should go through. But not on the chain. Let's change that.
Transcript
Hello everyone. So my name is Peter and I work at Nosis and today I will present a new project from Nosis AI that's aiming to like uh make safety and security on chain for everyone as easy as easy as possible especially for the end users. to the day-to-day users of onchain because nowadays the AI agent in web three are just booming right there are so many uh so many projects about using AI making it agentic everything from predicting the future with prediction market uh through governing those up to the some entertainment like streamers tweeters etc etc and this is great so I'm actually fan of many of these projects and working a lot with them as well while developing them as well. However, what we thought is a shame that there is not much news about the security point of view. So, usually when we hear about security in web 3, it's like z case and verify lm outputs and similar stuff and that's of course very important and I will also show later in the presentation why.
But here I will be talking about security from the daily user uh point of view because usually how it is when we are on boarding someone into the web three from the web three space then let's say the first wallet that you will find out on Google is metam mask. So just in install the meta mask, it will give you the seat phrase. You have right away your public key, private key and then uh there's a little bit of confusion because how it goes usually is like here's your private key, here is your receipt phrase and make a backup of it. So make a copy uh place somewhere where you can find it because if you lose this, if you don't have the access to this, there is no one who will help you and basically you lost all your funds. On the other hand, kind of contradictory actually perhaps don't make some so many copies and don't just leave it at home somewhere where everyone can see it because you have a malicious uh party.
You have like you have a party there is a lot of people someone will see it. If they get hands on it then you are like doomed again because uh with this there is no one who will actually stop them from draining all your funds doing whatever uh they want with it. And then there is safe. So the smart wallet like safe and they are great because they are solving many of those problems for sure. So with safes for example you can have multiple signers.
So if you are a team at the company uh then you can have a rule that your safe needs at least two signs from owners to execute the given transaction such that multiple people need to see it and no single micious party can do anything wrong even if single person is hacked or we have spending limits. So if you have like a life-saving account uh then perhaps you can spending limit and say that you can spend just some some small portion of the funds on day-to-day basis uh to somehow limit the possible loss uh that can be made uh from hack or something else and of course stuff like account recovery. So if you are on boarding a family member then for example family member or someone will retrust you that they can make you uh able to recover the account if it happens that they lost it that actually I guess happens a lot about how you guys uh but anytime I'm helping with something back home for my family there always lose the password never remember it we need to recover it etc and I think everything like this is heading in the right direction we also have Pectra uh and with Pectra like even AOAs can become a smart wallets. So again uh that's great and heading in the right direction. However, there is still a lot of stuff that's judged by the end user.
Uh so stuff like scam tokens uh if the user is going to buy some token it's up to him to judge if this will have any value tomorrow or stuff like signing. So even though you have multiple signers in your safe they need to manually verify what the transaction is going to do or or not to do. And nowadays I guess the average V3 user is quite technical. So perhaps it's not so big problem but still it happens that people are in hurry. Uh they just miss it and sign something that they shouldn't.
So with web three even a small like small potentially unimportant transaction like sending $1 to someone can have a disaster effect. If your computer is for example hacked and they will just visual transaction for something else then people will miss it sign it and everything everything is done which of of course something that happens well sometimes sometimes happens and the thing is that inver there is no centralized entity that could be blamed like hey you should have done something to prevent this so it's up to the end user and usually we just say like hey you should you should you should do better you will see the transaction, you will see what he's doing. Ah, so it's up to him and let's let's just let's just move on. However, and yeah, and that's kind of like it is. However, in the standard banking systems, there are bank centralized entities uh that usually do some kind of job uh to prevent this.
However, in web three, it's not the case so much. So in natively in web3 you have the private key the seed phrase and with that you can do whatever uh whatever you want. However, in the standard banking as I said uh there is the bank and if we assume that you have some like reasonably developed uh bank that uh that you are using some reason the develop bank then they are doing a lot of checks for every transaction login uh if you are looking from your computer from your location your credit card is suddenly being used from other part of the of the globe then they will most probably uh block such sex transaction. Or perhaps if you are going to pay at some ehop, there's a lot of fraudulent activity or like not fraudulent activity but a lot of uh like lot of complaints about them that the bank can stop the transaction and under an hour you will get a call from them that hey uh we bought this. Are you sure you want to do this?
A lot of users are complaining perhaps you shouldn't. And so that actually happened to me as well as well in the past. And so there is there is a lot of algorithms, hard-coded rules, uh machine learnings, basically AI uh that are taking care of this and escalating this to the humans in in the end. And with this in the mind, I would introduce an agent eosigner uh from GIS AI. So basically what it is is an agent.
It's running 24/7 on some server. It can be your computer, it can be cloud, it can be consist cloud uh whenever and it's monitoring your transactions 247 uh the wall day, the wall week, the volume uh war year. So it works in safe is that if you require multiple signers then when you create the transaction and you you are the first signer it goes uh to the queue and from this queue anyone can pick it up and add a sign if they are owner of the safe and that's exactly what the agent is doing. So as soon as you create a new transaction the agent will pick it up and will give you near instant feedback about about it. So it will check hey are you are you like interact with some potentially malicious addresses some addresses that are reported as that are being used by scammers or something similar or is there any odd behavior compared to your history.
So you have some history of transactions in your safe and in the case that the new transaction is somehow odd. Uh we will see how how odd as example later in the slide it can block it and there are many many more checks. I will uh show some of them later on but that's the idea uh on high level of view and in the end the agent will either approve or decline the transaction but in any case it will send you and side message to your safe such that you can do the final decision whether you want to go with this transaction or not. So how can it look like? Here is an example of a message sent to the safe uh from the agent for transaction that is to be okay.
So let me read the first line at least. It's saying everything is okay. The transaction involves a swap of €250,000 uh for USDC with no indication of malicious activity. All security checks and the trans is consistent with the previous legitimate operations. And then you also get the like the list of all the various checks uh that the agent did.
And in this case you can see that even though 250,000 is quite a lot of money so this it's not a small transaction. Uh however there is really no uh potential malicious stress in this because if we are just swapping uh one well-known stable cocons uh to another well-known stable cocon USDC and at the end of the day all those money are remaining in our safe uh there is not much that can be wrong about it. So agent can just uh approve it. And here you have an example of potentially malicious transaction where the agent is saying the transaction is flag is potentially malicious due to the large amount almost 12,000 being transferred to a new recipient address that has been not been observed in previous transactions. And so this is another clear example of when something can go wrong because when you are well €12,000 is much lower amount of money than the 250,000.
However, in this case, the agent has no idea who this other Arab recipient address is. So it can be your friend, it can be your new employee or maybe you have been hacked and someone is withdrawing all your money uh to their own safe. So who knows agent doesn't uh so he will decline the transaction and so this example I kind of black and white uh so swapping something is totally fine in that case uh this is uh potentially malicious but then of course there is this big gray area where well we uh it's hard to say it's hard to interpret and that also when the agent can came in and give you some details about uh about the transaction that you are going to do and this is how it looks like in the case he thinks the transaction is malicious so he will not approve and actually he will create an onchain rejection. So in safe when you create a transaction so basically propose a transaction uh you can also reject it afterwards by creating the transaction with the very same nons and this is how it looks like then in the interface if the agent created the rejection you have received the message and now you have the choice you can either confirm the rejection so you can say that okay agent is right I would rather not go through with this or uh you can say that hey that's a false positive I don't care agent I will approve it anyway anyway by some other owner of of the safe and so that means that the while the agent is there to somehow help you guide you and give you informations about transactions that you are doing he's not able to actually plug you out of your safe unless there will be some misconfiguration uh but he's he's not so to this up it's an identity cosigner that's completely open source and you can either go to the URL down there or scan the QR code. And so that means that while you can trust the agent that Gnosis is running, uh you can also just clone the repository and run your own agent as well.
However, in any case, it's good to mention that the agents permissions are limited. So even if you add it as a cosigner, it doesn't mean that he would be able to steal your money and or do any malicious activity there. And in the future, the well the access will be even more limited than is now. However, still it's kind of big ass to like a big ask to say to someone that hey at this age cosigner because well that's basically access to your to your safe. So for that reason before you actually do that you can also try it out either with APR or web application that's also in that QR code because saves are on the blockchain uh that's public so you are able to copy paste any safe address on either Ethereum or chain and verify any transaction that's currently cute or even the historical ones if you just want to check out how it looks like how it performs uh what kinds of things it says.
Yeah. And currently it's on Ether aggressive chain. However, uh it's just EV and compatible. So in theory you can run it on any uh chain where safe is deployed and it will be to totally fine. So that was kind of summary.
Now we can check out some details and perhaps future friends. So what attack vectors does the agent check for? Uh I would split into four groups. So the first group are hardcoded rules. uh so various checks that are just programmatic and hardcoded such as hash verification.
So does the hash of the transaction matches with the ones that coming from API versus where the one that agent creates by itself or some black list of addresses like public keys that are published by governments because they were related to some big scams hackers etc. Then the second group is not yet implemented but coming soon and there's a transaction simulation. So the agent will actually execute the transaction and sees what it actually did and make a decision based on that as well. And the third one are is LM analysis. So and I would say that the first three groups are either free or very cheap to run.
So the first and second is free and the LLM well the cost are going down every month and you can even run your own local LLM. So that means that the cost of running the check is very very low and you can verify the transaction under a few cents at at max. So unless you would be doing like thousands of transactions per day which is I guess unlikely uh it's very cheap to run and use. However then there is also the fourth group because the agent is meant to be uh very extensible. So it means you can implement any well any integration any check that would like to do as well and we have some integration with third party APIs as well.
So the go plus and cyers are companies uh we specialize in blockchain security and expose some APIs about other security NFT security uh safe transaction security etc. Uh so if you would like to you can also plug in some third parties or create your own module uh to check and the agent would use that as as well and that would be about uh what's possible right now. Uh let's check out what perhaps we will implement it in in the future and the first thing are circles. So this kind of looks like a slice from different presentation because it is but to quickly introduce you so I can get back to the agent. Circles is a new monetary protocol diagnosis.
It was launched a few week backs and if you didn't heard about it and perhaps too much information, but I encourage you to go and check it out because it's super cool. And how it works is that instead of the money like Bitcoin, Ether, etc. being issued by the miners, validators and so on. How it works here is that anyone can join the system and anyone can issue uh the circles. So basically tokens the money in in the system.
So if you join then every hour you are able to create one circle basically one token one kind of your money. However then the question is if anyone can join and anyone can issue uh the money. How you can make sure that there are no bots fake accounts some farm bots some malicious actors etc. So how can we assure that someone will just not create hundreds of accounts and basically become a circus billionaire over over the night and how it works is a trust network. So in circles in order to like in order to someone accept your money so in order to you to be able to pay to someone they need to give you a trust.
So if you give someone trust that means that you are accepting them as a real non-malicious person and you're accepting their circles because in the background every person has their own kind of circles. On high level there are just circles. So you can have three of circles but on the implementation level there are many kinds of circles. And how that works in this example is that we have the represents A, B and C and A and B is trusting each other and B and C is trusting each other. That means that B is willing to accept A circles and C circles but for example A is only accepting the B circles.
Uh so what does it mean in practice is that if let's say the person A wants to send circles to person C but they don't know each other, they never met. uh it can be just um a coffee owner, coffee shop owner or something similar. It doesn't mean they necessarily need to give each other trust right away because there is an intermediate person between them and we can create okay and we can create a pastor. So that means that if A is going to send circles to C, A circles go to B and B circles go to C and everyone is happy because everyone has the monetary trust and this is how the network is growing. So in the beginning there was few people but it's growing growing and growing and you can see that there is some dense graph but at the same time there are some small community small communities that we don't know if they are like fake accounts just trusting each other or perhaps some real small community.
Uh but it doesn't matter so much. The idea is that we could use the circus trust graph in order to verify the transaction. So if you are sending money to a completely new person to completely new public key instead of just saying hey we are not going to accept this because we don't know the person we can check the circus trust graph and see if there is some strong trust relations between you and the third party and if yes based on how strong it is uh we can either ac accept or decline or the second cool improvement would be once we have some data to train our small like smaller faster cheaper models that will be also verifiable because approving of the client transaction is certainly something where we want to verify the LM output. However, with big models provided by open API is not really possible. So if we train something for the data once we have them uh that will be pretty cool and very useful and scalable into the future and even more in the future what would be super nice is instead of asking you to add a cosigner to your safe to have some deeper integration because adding a cosigner yeah that's kind of scary and also people need to be introduced to the metam mask to the safe and now to the agent.
So not great. So if there will be some deepro integration by default into the safe or blockchain uh that will be pretty cool and the users would have some kind of feedback about about the transactions and hopefully I got the one really right. Uh so that's about it. Again the QR code for the for the save watch agent and if you have any questions I'm here for you. Thank you so much Peter.
Everybody give a hand for Peter. So safety in everything is so much needed at this time especially when we have everybody. I have one small question. When you talk about circle of trust and you sent between people and those are the ones that validate you. What happens when one of them might become malicious?
That is a good question. So you should watch out for that. So if someone becomes malicious, you should just entrust them and minimize your losses. But ideally, you should trust people that you already know that won't become malicious. But it's a great question.
It's a big deal how to do this because either you can be very like very pessimistic and just trust your best friends, but then we won't have this trust connections with the world or you can trust everyone but you will end up with bunch of fake circles and no one really wants. So you need to find the right. Well, why I'm asking is many times the people you think you can trust the most are the ones that's going to backstab you first, right?
Yeah, that's true.
That's the thing. So, you think people are close and actually the ones that you think is the ones you bad is actually ones that you could trust more than the others. The world has become a weird place.
Yeah. Well, yeah, that's true.
Um, so we have two questions on board. First, I want to ask, do anybody from the audience in here have any questions for Peter today? Else we're going to jump directly into the questions. So let's go with the first one down here. Why is fraud prevention still so underdeveloped in web 3?
Yeah, that's what I'm asking since I am web three. So I have no idea. And even this was super simple to start with. So it started as a simple experiment like hey let's try to build this and it actually worked. That's why we are here and perhaps it will take some place in the future.
Perhaps not. We will see. But why it's underdeveloped? I don't know. It would be super cool if it wouldn't, right?
So maybe this will spike the interest. The strange thing uh fraud has even become bigger in web too even even the banks and everybody because everything becomes smart use and sign on phone and all of a sudden your bank account oops
basically
yeah that's true
so the other one is goes very much into who should take the lead in bringing fraud detection to web free dabs wallets or protocols
I think it would be very nice if some like perhaps etherum foundation someone who's actually developing the blockchain take some lead in is to somehow go big.
Go big or go home.
Uh like no go home. We can start small. Why not? But actually, yeah, going big and put a lot of ah yeah a lot of effort there. Put some motivations for people to actually build it to actually use it.
It would be nice. Right now it's kind of if you buy sign it's your fault. Sorry. Go home. But hey, we can actually do something about it.
So why not? And it's not so hard in the end. The reason why I think this is good is because many times you see the people with the best intentions in the space
are the first ones to get completely grilled because they're trying to do this and really do better for everybody else and they're like no we want to be anonymous 100% right
yeah well I think we can skip anonymotry and zar and have some safety protocols in place like why not it's not going against each other of course with centralized banks it's much easier to do some flow detection But hey, we can do at least something, right?
Yeah. So, audience, you have one last There we go. I think it just went down and in again.
Yeah. Yeah.
Hey, uh I have one question. You said you said earlier that you can uh give to the uh agent the cosigner possibility to a safe wallet.
Mhm.
Uh let's say we have a safe wallet with two out of three and I have myself and two agents with different wallets. they can take their own actions right and they
uh yeah that's true so ideally don't do that so that was I was also talking about like some deeper integration into save into blockchain somewhere because right now yeah you have a cosigner and what could also happen is that you are the signer cosigner the agent and there's just two of you so you can be blocked out so there is still some stuff that you need to pay attention to while configuring this uh so ideally we can do better in the future Right now we have this. Yeah.
All right. So they can call they can throw me out. I was thinking of I don't know give them a free will to trade or something or use a wallet for
Yeah. But the question is why would you add a second agent if you have the first one? Uh so hopefully the first one should be good enough.
Yeah. I just I just wanted to see if you say that they'll throw me out of the party.
Yeah. So permissions are very limited. So they cannot steal for you. They cannot be malicious. Uh they cannot just create a cooperation between them to take all your funds.
However, if you misconfigure this, yes, you can be blocked out and that needs to be improved. Yeah.
I'm going to laugh once he loses wallets to agents. All of a sudden, AI is taking over all his wallets. Well, for this time, Peter, we want to say thank you for coming. Please, everyone, give a major hand for Peter.
Thanks a lot.
Automatic transcript — names and jargon may be misspelled.