Biometric proof of personhood verification in Worldcoin by Remco Bloemen | Devcon SEA
Devcon·Tue, Oct 7, 2025, 12:00 AM
Speaker
A one-day summit focusing on the theme of d/acc: emphasizing the values of decentralization, democracy, differential accelerated progress, and defensive tech including crypto security, public epistemics, bio defense, neurotech/longevity, decentralized ai and physical resilience. Speaker(s): Remco Bloemen Track: [CLS] d/acc Discovery Day: Building Towards a Resilient Utopia Follow us: https://twitter.com/efdevcon, https://twitter.com/ethereum, https://warpcast.com/devcon Learn more about devcon: https://www.devcon.org/ Learn more about ethereum: https://ethereum.org/ Visit the https://archive.devcon.org/ to gain access to the entire library of Devcon talks with the ease of filtering, playlists, personalized suggestions, decentralized access on Swarm, IPFS and more. Devcon is the Ethereum conference for developers, researchers, thinkers, and makers. Devcon SEA was held in Bangkok, Thailand on Nov 12 - Nov 15, 2024. Devcon is organized and presented by the Ethereum Foundation. To find out more, please visit https://ethereum.foundation/
Transcript
[music] Hello, DevCon. So, Remco from the World Foundation, and I'm going to be talking about a thing we're doing, which is proof of human, otherwise known as proof of personhood, but that's a bit of a misnomer. We'll get into that and how we do this in a private way using biometrics and why we need Ethereum to make that happen. So quickly, what is proof of personhood? The short version is it is a way to limit account registration to a few ideally one per human being.
Um that in itself uh doesn't give you any kind of privacy. In fact, it usually gives you the opposite. But you can add a layer of zero knowledge proofs on top of that to get a slightly richer primitive which is being able to sign messages as a unique anonymous human. For example, within some context, you can sign a message proving that you are a human being that has not signed a message in this context before. You could do let's say hey dear project please claim my airdrop to this address signed an anonymous human or dear DAO please allocate my voting shares to this particular vote signed an anonymous human or dear farcaster please register my handle as belonging to a unique human being and not a bot or dear farcaster and this is where it gets interesting please register this other handle as my alt because it doesn't necessarily mean that you're restricted to one account per human being.
You can have multiple accounts. It's kind of up to the application developer to specify what the desired behavior is. It is a programmable primitive that we're adding to the blockchain. What is it not? It is not very importantly a capture.
A proof of personhood does not prevent a bot from doing something. It just means that this action was initiated and kind of signed off by a specific human being. So you can still automate your accounts. Now why do we want proof of personhood at a high level? AI will make it impossible to distinguish on behavioral features alone, at least in the digital domain.
And AI fueled economic disruptions require us to get much better at creating humanoriented financial solutions to solve any economic hardship that might happen in the world. Therefore, we need to add individuals as a programmable primitive. It is also critical to get strong decentralization because the only way to make sure that many many people are involved in consensus making is through a form of proof of personhub. This in turn unlocks financial primitives with a concept of individuals and a lot of them have that insurance, loans, pensions, universal basic income. None of these we can currently do with programmable money because we do not yet have programmable individuals.
We're changing that. And that allows you to do cool things that kind of I didn't even expect when we started this. Like um the world chain L2 that we just launched has prioritized block space for humans. So if you're a human being, you get priority over the trading bots in the sequencer. And then of course there's the basics like civil resistance and preventing spam bots.
Now why would you not want proof of personhood? Unique human can often just be a proxy for something more precise. That is what you really want. Like when it comes to let's say underolateralized loans, you're not necessarily interested in a unique human being. You're interested in someone's creditworthiness.
And there might be better tests for that that you could use directly that would in the end create a system that abstracts better what it is aiming to do. Um you could also have a like you could also imagine a social media platform where you don't really care whether someone is a human or a bot as long as they make valid meaningful contributions to the discussion. So here again there is a trade-off for the app developers to make like is is proof of personhood actually what I need here and there's kind of like a an argument that you can make that um if you really aim for maximal anonymity not even the number of humans that are currently in your system should be transparent which is something that of course proof of person achieves okay now that we've covered what it is how do we build How is it constructed? Um, the main problem you're solving here is the Oracle problem. You're trying to build some information in the platonic ideal cryptographic trusted domain that it comes from the outside that comes in in this case from the physical real world of humans.
And solving Oracle problems always means some form of compromise. And the question is what is the best tradeoff for the specific problem you're trying to solve. The three main approaches for proof of personhood are authority based where you use some existing authority like a government or a email provider or a bank as a trusted entity to have a list of all the humans. Others are graph based. um these are decentralized and here you have humans essentially verifying other humans or you take some approach to pairwise distinguish humans from each other and then turn that into a larger graph.
I'll get into more details on each of these um in a moment. Biometric based is recognizing that humans have a physical body and doing measurements on that body to distinguish it from other bodies. Now the authority based this is the conventional solution. This is what the whole web tool world the noncrypto world uses when they need anything remotely resembling proof of personhood. For example when they issue you a loan they will ask you to KYC yourself using your governmentisssued ID and so on.
Um this is an advantage because this means that the average person is familiar with them that a lot of people have access to these means of uh these modalities. They're easily scalable and easy to implement. The downside is that um they are imperfect when it comes to uniqueness. Passports are relatively good, but still people have multiple passports and definitely over lifetime people renew their passports. They also have weak inclusivity.
A lot of people don't have access to these means. And of course, there is this central authority problem. We've all heard of SIM swapping. Phone numbers kind of suck in general for any kind of authentication. It's also active.
Um, you need to go through this process. You need to actually make sure that the person presenting you the passport matches the document. Um, you also need to make sure that the document itself is a valid passport and not some copy. And this becomes substantially harder in the digital domain. And a lot of the current solutions could do a better job on on on these steps.
And if we don't deploy any kind of zero knowledge proof methods in here, of course, it's enormously revealing in terms of privacy. Fortunately, the RZK solutions for all of these and you can get them to a very high standard, which is great. Now, the graph-based ones, the main strength is it's decentralized. That is the the superpower of this particular class of solutions. The downside is that uh the main downside is a so-called click attack where you have a group of bots that keep verifying each other as real humans.
So you get a lot of signals on these bots that they're real humans. And once you have a network like that, it's very hard to get this out of your graph-based system. Um there's a couple of different approaches here. Social graphs is an easy one where you just go to your friends and provide proof to each of your friends that they're all real humans and you collect it from your friends and this body of evidence builds up over time. Other solutions that don't require you to reveal your circle of friends um are based on video calls where you either post a video of yourself online show showing that you're a real human and then have other people uh accept or reject that or you go into Zoom calls with people crossverifying each other that they are indeed in the Zoom call and indeed are are real humans and building the graph that way.
Um, I think both of these are are very flawed ultimately because we have deep fakes. It's very easy to nowadays create realistic video calls. Um, it's also just an awkward non-scalable process. Um, one that I do want to highlight because I just think this is such a clever solution is um, simultaneous capture solving. So, the captas I mentioned before are designed such that only humans can solve them.
Now if you through a blockchain or some other means trigger um let's say five people to solve a capture simultaneously. Now you know that there's at least five different people there. Biometric based this is the um the strongest approach. It gives you near perfect uniqueness. It is non-transferable.
You know that it is um this human and this human cannot give this modality away to some other human or sell it or so on. The weakness is it's immutable. It sort of sticks to you for your entire life which might not necessarily be desirable. You might want to have like some ability to reset. It also relies on trusted sensor if you need a way to capture this biometric information and and it requires physical interaction.
The other thing is the um so-called false match non-match rates where faces with the current algorithms are only unique up to maybe a million individuals and after that the algorithms will not be able to distinguish them anymore. Um same thing with fingerprints. They're not as unique as you would want them to be. Irises however have an enormous amount of entropy in them. So they work at a world population scale and that is the main reason uh world went in this direction.
Now two common mis misconceptions about biometrics I do want to address. A biometric is not a private key. Your fingerprint is in in a sense not a secret like you you leave it on every glass of every restaurant you've ever been to. And this fingerprint is not what is you. The thing that authenticates you is the fact that you have this fingerprint on a real life finger attached to a living breathing body.
The second thing is um irises and retinas are not the same thing. So please get that right if you criticize world. Um world's approach at a high level uh we have a tiered system. We recognize that there's different trade-offs to these um different modalities and we offer a tier list of what we think covers the whole spectrum of what you might want. We have the the ORB, you see one right there, which is a um hardwarebased biometric iris based system that gives you super high guarantees, but um you need to go uh find an orb in order to sign up.
We're now rolling out um a ZK NFC passport-based system that gives you high privacy and can leverage existing national ID system. And then we have a very low tier system that uses the TEES in your mobile phones to prove that you have a unique mobile device. Now with that last tier, you can obviously see the issue there. Uh you can just buy more phones. Um and that is kind of the thing with a tiered system.
you want to make your tradeoffs as an application developer based on what your needs are and how you want the onboarding experience to be. How did we implement this? So, we make use of um modern cryptography. Um generally when state is local or global or public or private um there's different things we can do but we now have a full set of solutions here. we can kind of take any kind of problem and come up with a very adequate solution.
The high level strategy is we take our modality. Uh this always starts with some form of um trusted sensors. Either the trusted sensors are other humans in the network or the trusted sensor is an u um sorry the the trusted sensor is an NFC chip in your passport or it is the orb. The orb uh orbs are manufactured. They're registered on chain which is how you can verify that they are authentic through their public key.
These then produce uh these then interact with the user's wallet to produce uh secret shares in zero knowledge. So we know that all of this is done correctly and we now have secret shares of the modality that we can then send to a private uniqueness solution. This is implemented using multi-party computation uh which also runs in tees which also goes through onchain governance and that verifies the uniqueness. Critically it does this without ever seeing the raw modality. It only sees encrypted and processes encrypted data in the encrypted domain which gives you a tremendous amount of privacy here.
Um it really sets a new standard. Then we have um as a second layer of defense for your privacy. We don't issue you some sort of Ethereum address that is now blessed. We issue you an anonymous credential. You become a member of an onchain set that you can zero knowledge proof membership of.
And this makes it such you cannot track the behavior of any human that signed up through the system. You cannot um associate them to the modality that they signed up with and so on. Now already covered the orb. This is our um very sophisticated device. There's other talks about this that I recommend go in depth on how it works.
I do want to highlight a little bit about the challenges of doing this biometric uniqueness check in in multi-party compute. The scale is enormous. We're talking about a 24 Nvidia H100 GPU cluster that uh requires almost a terabyte of GPU memory and terabits of communication bandwidth just s to sustain the 8 million users that have signed up at a rate of 10 new users per second. Multi-arty as you may know has trust assumptions. It is important that the nodes are operated by non-oluding um entities.
For that we are working with reliable third parties. We found they operate the notes for us. The world organizations do not have access to these systems and as a further layer of defense we have uh or we have developed technology that allows us to run these CUDA MPCs on GPUs in TEES. So inside trusted execution environments so that they can prove that they're all running the proh protocol honestly and they crossverify each other before they even initiate the protocol. Then the question is okay what protocols are they allowed to run?
Can they do a uniqueness check? Yes. Um maybe in the future we want other functionality. We want have people the ability to recover their accounts through a biometric for example. that requires some form of governance that can then onchain sign off on what are the allowed protocols to run which protocols meet the criteria for privacy and the commitments made to the users.
So this is where modern cryptography and Ethereum specifically programmable consensus are critical in making all of this work. Now to summarize, World ID offers biometric passport and device-based proof of personhood tiers. You as an app developer can integrate this depending on your needs. We implemented all of these such that the modality, the actual underlying information never leaves the user. No one outside of the user learns about the passport, learns about the iris or anything else.
And then we have this additional layer of zero knowledge based anonymization on each use. So even if you have a DAO where you have a one person one vote you will not be able to track voting patterns of users. Each vote is individually unique by default. But of course as an application developer you can ask the user if you want different behavior here. Now covering some next steps um that we've recently rolled out mini apps which is a good way for people that have a a a use case that requires proof of personhood to immediately reach an audience of millions.
Um, as I mentioned, we have WorldChain, which is our L2 that users by default get an account on, and it it is um experimenting with ways that we can integrate individuals and humanness in how sequencers prioritize uh the transactions and how fees are allocated. We're currently working hard on improving the technology of client side proving to get really fast client side proving. So on device on on your mobile device producing zero knowledge proofs and we want this because there is a big future in doing programmable zero knowledge identity meaning that not only can you prove that you're a unique person but you can prove things about yourself. You can prove that you're of a certain nationality you can or not of a certain nationality or um of a certain age and so on without revealing anything else about yourself. Um, and with that I want to open the floor for any questions.
Thank you. [applause] All right. Thank you guy. Thank you so much for the amazing talk. We do have five minutes to go over some of the questions that people submitted.
So it would be [music] great if you can come here in the center. Yes. So let's go from the very first one at the top. What if human creates a proof and sells it to AI? As there is no identity attached and it's zero knowledge proof, there is no consequence to sell the proof or keys associated with it.
That is correct. Um and that is intentional. Like I said, this is not a capture. This is uh you're still allowed to have a bot operate your account, but if you were to do this um you cannot bypass rate limits, for example, you would still be a single account on whatever system you're running it on. So if you want to bless your if you want to run a Twitter bot as a unique human, you can.
But if it starts spamming the system, it is obvious that it is one account. Cool. And what if world ID system gets hacked or becomes hostile on its own aka evil orb? [laughter] So world ID as a system is a set of smart contracts and a self-custodial wallet. Um that doesn't mean it's unhackable but it means it's subject to the same assumptions as hacking an Ethereum hacking the Ethereum network and hacking a self-custodial wallet.
Um but the other question about the orb itself is a good one. Um, and the way we tackle that is, uh, like I said, through transparency in how the orb itself operates onchain. So, first of all, the orb is fully open source, u, open hardware, open firmware, um, it has a removal SD card, so you can verify the build and so on. They're all, um, registered on chain. And while the process of users and the user signing up is entirely anonymous, the behavior of the orb is not.
So it is public like how many um signups a certain orb does and if there is any suspicious behavior that can be flagged and the multi-party compute setup can actually revert these fraudulent signups. Uh another question is Iris photo hard to capture? Can it be scanned when I'm sleeping? No, it cannot. It's actually um surprisingly hard.
Uh the orb um despite being open hardware unfortunately contains um custom optics uh that you can't really get off the shelf. You need to find someone specialized in making lenses to get this done. It's it's it's a hard problem of getting a high resolution picture of of something the size of a sugar cube that is bouncing around a meter and a half in front of you. Uh and the ARP does it. It's quite amazing.
Um this is a good thing though uh because this means that there is a strong form of uh consent um cons yeah yeah kind of consent in getting your Iris pictures taken. It's very hard to take Iris pictures of someone who doesn't actively and willingly participate in the process. How does world earn income? I pass. No really um this is we we currently don't have any uh any issues uh here um everything is everything is in production everything is running and this is such a the space of identity is such a gigantic opportunity that goes way beyond the entire current crypto space.
Um and then itself the world project will onboard already onboarded tens of millions of people into into blockchain but will onboard many many more. Um how about artificial fake irises? The award could theoretically think it registers real humans. Yeah, I think I haven't covered enough how important it is for any kind of biometric sensor to verify that it is act it's not enough to just take a picture of a iris or a fingerprint. You need to make sure that this is from a real life living breathing human body because otherwise it could just be someone holding on an iPad or someone trying to squish a silicon mold on a fingerprint scanner.
The the hard part in designing any kind of biometric system is not so much the capturing of the raw data but it is in validating that it is actually came from a real human being. Cool. Uh we have 30 seconds to go through one more question. Can someone with an orb produce IDs for non-existent irises? No.
The um even if you have an orb in physical possession, it is um near impossible to to make it do those kinds of things. it it has like a very strong amount of physical security in it and temper protection and so on. All right, cool. So, I think that concludes our talk today from Rimco.
Automatic transcript — names and jargon may be misspelled.