Devcon VIII India banner
devcon community hub proposal

LeakDetect AI: Cross-Layer Ethereum Security and Resilient Communication Hub

A community-led security research and education initiative focused on understanding and measuring security, privacy and communication risks across the Ethereum stack, from wallets, dApps, agents and tooling to Ethereum's underlying P2P networking infrastructure.

LeakDetect AI is supported through the EF DAO Fund via Giveth, has been invited to the 1 Trillion Security initiative of Ethereum, and is supported by Wintermute, with advice and technical input from members of the libp2p, IPFS and Filecoin communities.

01: what attendees get

A four-day, community-led security research and hands-on engineering hub.

Rather than treating smart contracts, wallets, agents and P2P networks as isolated layers, the hub demonstrates how information can leak or attacks can propagate across these layers, and how measurement, secure communication protocols and resilient infrastructure reduce these risks.

01
Build threat models for Ethereum users, wallets, agents, dApps and infrastructure.
02
Work with public Zcash and Tornado Cash datasets to investigate privacy, metadata leakage and transaction-graph patterns.
03
Explore how wallets, agents, RPC providers and developer tooling communicate, and identify weaknesses in those channels.
04
Understand how P2P attacks (Sybil, eclipse, network partition) affect higher-level Ethereum applications and users.
05
Experiment with Luminar as a measurement and observability layer for identifying and mitigating P2P attacks.
06
Explore post-quantum signatures and their integration into libp2p specifications using PKIX-compatible approaches.
07
Discuss interoperability of post-quantum authenticated communication with Ethereum L1 and L2 networks.
08
Rethink Ethereum P2P communication from the perspective of post-quantum light clients.
09
Connect researchers across the Ethereum, libp2p, IPFS, Filecoin and decentralized-systems communities.
02: program outline

Four days, four layers of the Ethereum security stack.

LeakDetect AI is the continuous research and measurement thread across all four days, connecting individual sessions into one broader investigation of Ethereum's attack surface.

day 1
Leak Detect AI, Privacy Leakage & Cross-Layer Threat Modeling

Establishes a common security framework for thinking about Ethereum beyond smart contracts.

topics
  • Introduction to LeakDetect AI and the cross-layer security problem.
  • From smart-contract security to user, wallet, dApp, agent, RPC, Ethereum and P2P network.
  • Information leakage versus direct compromise.
  • Metadata leakage, transaction timing, network observations and correlation risks.
  • Privacy-preserving analysis of public Zcash and Tornado Cash datasets.
  • What transaction graphs can and cannot reveal.
  • Legitimate security research and privacy analysis versus deanonymization.
  • Reproducible datasets and measurement methodologies.
hands-on
Small groups map what information is visible at each layer of the stack.
outcome
A practical understanding of cross-layer security and privacy leakage, plus a threat model reused across the remaining three days.
day 2
Secure Communication for Ethereum Wallets, Agents & Tooling

Can we trust the communication channels through which wallets, agents, dApps and developer tools exchange security-sensitive information?

topics
  • Wallet to dApp, wallet to RPC, agent to wallet, agent to agent and agent to tool communication.
  • Secure discovery and authentication.
  • Identity, authorization and capability boundaries.
  • Message integrity, authenticity, replay and downgrade risks.
  • Metadata leakage through communication channels.
  • Compromised front ends and malicious infrastructure.
  • How P2P communication differs from centralized RPC architectures.
  • Where libp2p, IPFS and decentralized networking primitives strengthen Ethereum tooling.
hands-on
Participants model six communication scenarios and use LeakDetect AI to identify observable signals and leakage points.
outcome
Communication threat models and concrete requirements for secure, authenticated and privacy-preserving channels.
day 3
P2P Resilience: Sybil, Eclipse, Network Partition & Luminar

The security layer that is often invisible to application developers: Ethereum's underlying P2P networking infrastructure.

topics
  • libp2p threat models and why P2P security is application security.
  • Sybil, eclipse and network-partition attacks.
  • Peer discovery manipulation, routing and topology attacks.
  • Connection diversity, peer selection and GossipSub security.
  • Network observability, measurement and abnormal peer behaviour.
  • Using Luminar for security measurement and attack detection.
  • Correlating network observations with application-level events.
hands-on
A Luminar workshop on scaling measurement and detection for decentralized networks: Sybil clusters, eclipse-like connectivity, partitions, peer diversity and reproducible experiments.
outcome
Measurement-driven approaches to detecting and mitigating Sybil, eclipse and network-partition risks.
day 4
Post-Quantum Ethereum: libp2p, L1/L2 Interoperability & PQ Light Clients

How should Ethereum's networking layer evolve for a post-quantum future?

topics
  • Limitations of existing public-key assumptions.
  • Post-quantum signatures and authenticated communication.
  • Integrating quantum-resistant signatures into libp2p.
  • PKIX-compatible approaches to post-quantum identity and authentication.
  • Key exchange versus signatures, migration and algorithm agility.
  • Backward compatibility with existing libp2p deployments.
  • Interoperability with Ethereum L1 and L2 environments.
  • PQ-secure wallet and agent communication, long-lived identities and migration.
hands-on
A research discussion on post-quantum light-client architectures, trust models, network-level verification and bandwidth, computation, latency and security trade-offs.
outcome
A community working roadmap for post-quantum-ready Ethereum communication infrastructure.
day 1 exercise: what is visible at each layer
User
  ↓  Wallet
  ↓  dApp / Agent
  ↓  RPC / API
  ↓  Ethereum L1 / L2
  ↓  libp2p / P2P Network
  ↓  Peers / Relays / Observers
03: four-day theme at a glance
DayThemeLeakDetect AI focusPractical output
Day 1Privacy & Cross-Layer Threat ModelingZcash/Tornado Cash datasets, metadata leakage, threat modellingCross-layer threat models
Day 2Secure Wallet & Agent CommunicationCommunication-channel leakage and authenticationSecure communication models
Day 3P2P ResilienceLuminar, Sybil, eclipse and partition detectionP2P measurement experiments
Day 4Post-Quantum EthereumPQ signatures, PKIX, L1/L2 and PQ light clientsPQ networking research roadmap
04: workshops so far

Road to Devcon India: libp2p and Ethereum Network Observability Study Group.

Two community workshops delivered across 29 centers with roughly 750 attendees, covering protocol analysis, interop testing and observability-driven research.

Workshop 1 title slide: Road to Devcon India, libp2p and Ethereum Network Observability Study Group
Workshop 1 title slide: Road to Devcon India, libp2p and Ethereum Network Observability Study Group
Workshop 1 session across 29 centers with 750 attendees
Workshop 1 session across 29 centers with 750 attendees
Workshop 2 title slide: Charting the Unexplored Frontier
Workshop 2 title slide: Charting the Unexplored Frontier
Workshop 2 session across 29 centers with 750 attendees
Workshop 2 session across 29 centers with 750 attendees
Expedition goals: protocol analysis, interop testing and observability-driven research
Expedition goals: protocol analysis, interop testing and observability-driven research
Looking ahead: libp2p 2035 research horizons
Looking ahead: libp2p 2035 research horizons
04b: four new workshops

Data curation and annotation for LeakDetect AI with libp2p, IPFS and IPLD.

Four additional two-hour workshops delivered in collaboration with MeitY's India AI Mission as part of Road to Devcon. Every session keeps LeakDetect AI as the central theme: building, curating and annotating the datasets that power leakage detection across Ethereum.

libp2p workshop session on secure communication channels with participants across NIELIT centers
libp2p workshop in reference to secure communication channels: participants across centers explore how P2P networking primitives strengthen wallet, agent and tooling communication for LeakDetect AI.
Workshop session with participants across NIELIT centers
workshop 03 · 2 hours · Data curation for leakage-signal datasets
Security curation for LeakDetect AI
  • Curating timing, gas and error-code traces as LeakDetect AI training data
  • Privacy-preserving log packaging on IPFS with IPLD content addressing
  • Threat taxonomy for observability-derived leakage in Ethereum clients
Workshop session on libp2p observability with remote centers
workshop 04 · 2 hours · Annotation of network-level leakage traces
libp2p observability and research
  • Instrumenting libp2p transports to capture metadata for LeakDetect AI
  • Annotating peer-level traces: labelling benign vs leakage-indicative behaviour
  • Building reproducible research pipelines from annotated corpora
Workshop session covering kad-dht and peer discovery
workshop 05 · 2 hours · Discovery-layer leakage signals
kad-dht and peer discovery improvements
  • Query-pattern leakage in kad-dht routing tables
  • Labelling discovery events for LeakDetect AI model training
  • Proposed improvements evaluated against leakage-aware metrics
Workshop session on py-ipfs-lite and universal connectivity
workshop 06 · 2 hours · Curated storage and transport for detection pipelines
py-ipfs-lite and universal connectivity
  • py-ipfs-lite as the ingestion path for LeakDetect AI log corpora
  • Universal connectivity across browser, native and relay transports
  • IPLD schemas for versioned, verifiable annotation datasets
05: who organises the hub
LeakDetect AI Core Team
Hub leadership, research direction and security methodology
LeakDetect AI Security Researchers
Dataset analysis, threat modelling and cross-layer leakage research
libp2p Community Contributors
P2P security, networking, protocol design and interoperability
IPFS / Filecoin Community Contributors
Decentralized networking, storage and infrastructure security
Ethereum Security Researchers & Builders
L1/L2, wallets, agents and application-layer security
P2P Networking / Luminar Contributors
Network measurement, observability and resilience experiments
Community Facilitators
Workshops, participant support and documentation
Devcon Community Hub Coordinator
Daily scheduling, logistics and coordination with Devcon
06: equipment and production needs
core equipment
  • LED TV or large display with HDMI for live demonstrations
  • Projector or large screen where available
  • 2 to 3 whiteboards for threat modelling and protocol architecture
  • Multiple tables for collaborative security research
  • Power outlets and extension boards for laptops and test devices
  • Reliable high-bandwidth Internet and Wi-Fi for network experiments
  • HDMI and USB-C adapters, power strips and charging facilities
technical requirements
  • Participant laptops
  • Local test network or isolated networking environment
  • Test Ethereum L1/L2 environments and libp2p test nodes
  • Preconfigured Luminar demonstration environment
  • Prepared Zcash and Tornado Cash datasets
  • Data-analysis notebooks and reproducible research environments
  • Wallets, test accounts and test agent environments
  • Software for network visualization and threat modelling
security and research requirements
  • Isolated test environment for P2P experiments
  • Safe simulation of Sybil conditions and eclipse scenarios
  • Network partitions and peer-discovery manipulation
  • Communication failure scenarios
  • Post-quantum authentication experiments
  • All demonstrations run against controlled infrastructure only
07: why this hub matters to devcon

LeakDetect AI brings together security research that is often fragmented across Ethereum's application, wallet, agent and networking layers.

The hub gives Devcon attendees an opportunity to move beyond purely smart-contract-centric security and examine how privacy leakage, insecure communication, P2P attacks and cryptographic assumptions interact across the complete Ethereum stack. By combining real-world datasets, hands-on threat modelling, network measurement with Luminar, libp2p engineering and post-quantum research, the hub creates a practical environment where researchers and builders can identify vulnerabilities, test defensive approaches and develop ideas that continue beyond Devcon.

Join the expedition: map the dark matter and secure the foundation of Ethereum