EPISODE · Jan 27, 2026 · 1H 9M
Web3 Security Podcast: DC Builder, Research Engineer at World Foundation
from The Web3 Security Podcast · host TheWeb3SecurityPodcast
World Foundation's proof of personhood system defended against an iris spoofing attack where users verified multiple times by pairing their left eye with someone else's right eye—exploiting uniqueness checks that operated on eye pairs rather than individuals. DC Builder, Research Engineer at World Foundation, explains the multimodal defense they deployed: continuous 3D heat mapping, time-of-flight sensors, anomaly detection models trained on contact lens datasets across manufacturers, and checks for glasses that alter iris patterns.This represents one attack surface in a system protecting 38 million verified humans. World became Nvidia's largest security partner for Jetson NX embedded chips, filing more CVSS reports than any other customer after discovering edge cases from production deployment that Nvidia's internal teams hadn't encountered. DC's current focus: building Proofkit, a Noir backend optimized for client-side ZK proving on constrained mobile devices, because the 99th percentile of World's users operate phones with minimal memory and CPU headroom.The technical architecture spans layers most Web3 teams never touch. Trusted execution environments and secure enclaves depend on vendor supply chains. Private keys etched into Orbs during manufacturing get destroyed after provisioning. Groth16 proofs require trusted setups from both PSE and World's own ceremony. Multiparty computation encrypts iris codes, but compromise would expose biometric-derived data. Open-source firmware on ejectable SD cards enables independent verification against GitHub repos—an auditability model DC walks through in detail.Topics discussed:Iris spoofing via eye permutation attacks: left-eye/right-eye combinations bypassing uniqueness checksMultimodal biometric defense: 3D heat mapping, time-of-flight sensors, contact lens detection across manufacturersFiling majority of Nvidia Jetson NX CVSS reports through production edge cases undiscovered internallyBuilding Proofkit: Noir backend optimized for ZK proving on memory-constrained Android devices at 99th percentileFormal verification pipeline: automatic GNARC-to-Lean circuit extraction developed with RayLabsGroth16 trusted setup dependencies: PSE ceremony plus World's own setup and associated compromise risksMPC protocol security: encrypted iris codes and what exposure means for biometric-derived sensitive dataHardware auditability: ejectable SD cards enabling firmware verification against open-source repositoriesSupply chain trust model: secure enclave vendors, TEE implementations, manufacturing key provisioningAttack surface inventory: hardware TEEs, Linux-based custom OS, biometric ML pipelines, MPC protocols, ZK circuits
Embed this episode
Ready to play
Web3 Security Podcast: DC Builder, Research Engineer at World Foundation
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.