<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/">
    <channel>
        <title>koshik</title>
        <link>https://paragraph.com/@koshik</link>
        <description>🚀 BUIDLing ZenGuard  (https://zenguard.xyz) :shield:
✍️: https://x.com/rajkoshik
🔑 PGP: C4B9 729D B4AB 75BD 
PoW: https://koshik.info</description>
        <lastBuildDate>Sun, 14 Jun 2026 19:37:31 GMT</lastBuildDate>
        <docs>https://validator.w3.org/feed/docs/rss2.html</docs>
        <generator>https://github.com/jpmonette/feed</generator>
        <language>en</language>
        <image>
            <title>koshik</title>
            <url>https://storage.googleapis.com/papyrus_images/58c9a52e4787fd699fbde104bbc74a1d57ca845403ac297d91b07a25fdb326b6.jpg</url>
            <link>https://paragraph.com/@koshik</link>
        </image>
        <copyright>All rights reserved</copyright>
        <item>
            <title><![CDATA[ZenGuard is Now Brewit: Our Story and Vision Forward]]></title>
            <link>https://paragraph.com/@koshik/zenguard-is-now-brewit-our-story-and-vision-forward</link>
            <guid>20KJOWJkHUF6FyKPpo5Y</guid>
            <pubDate>Mon, 19 May 2025 11:15:37 GMT</pubDate>
            <description><![CDATA[At ZenGuard, we set out with a bold mission: to redefine how people enter and experience crypto - making it not just accessible, but secure, smart, and intuitive from day one. What started as a simple hackathon idea around EOA recovery quickly transformed into a deeper pursuit: building the next generation of onchain account infrastructure - modular, secure, and ready for real-world users.The ZenGuard JourneyZenGuard was born at a Safe hackathon, where we set out to build seamless recovery to...]]></description>
            <content:encoded><![CDATA[<p>At ZenGuard, we set out with a bold mission: <strong>to redefine how people enter and experience crypto</strong> - making it not just accessible, but secure, smart, and intuitive from day one.</p><p>What started as a simple hackathon idea around EOA recovery quickly transformed into a deeper pursuit: building the <strong>next generation of onchain account infrastructure</strong> - modular, secure, and ready for real-world users.</p><hr><h2 id="h-the-zenguard-journey" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">The ZenGuard Journey</h2><p>ZenGuard was <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://x.com/brewithq/status/1643867248782880768">born at a Safe hackathon</a>, where we set out to build seamless recovery tools for <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://safe.global/">Safe</a> accounts. That early work gave us a strong foothold in the Safe ecosystem and led us deeper into Safe modules - how they could be built, distributed, and adopted more easily.</p><p>We realized a critical missing piece: a <strong>public marketplace for Safe modules</strong>, with standardized onchain audit attestations. We explored this idea in depth <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://mirror.xyz/koshik.eth/PboTed857tHhIK5ypPaHm-bgYDmyeJVcrR9QPc_QH2Q">here</a>.</p><p>With support from a Safe grant, we built tools, dashboards, and dev workflows to improve module creation, verification, and adoption.</p><hr><h2 id="h-embracing-account-abstraction" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Embracing Account Abstraction</h2><p>As <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.erc4337.io/">ERC-4337</a> and account abstraction gained traction, it became clear that Safe accounts needed new adapters and infra. Teams like <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://rhinestone.wtf/"><strong>Rhinestone</strong></a> led the charge in standardizing account interfaces and making Safe compatible with the 4337 spec.</p><p>We took that momentum and pivoted toward the missing infrastructure focusing on <strong>recovery</strong>, <strong>session keys</strong>, and <strong>delegated account access</strong>. Our goal became clear: make Safe accounts more secure, flexible, and ready for real-world use.</p><hr><h2 id="h-the-inception-of-brewit" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">The Inception of Brewit</h2><p>At <strong>Devcon</strong>, during a presentation at the Ethereum Foundation’s Account Abstraction Hub with <strong>Vitalik in the room</strong> - we introduced our concept of session keys + delegated automation.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/34f55c2527b4fc7a1b9dc21115f80bdfa2fad88f9d78ea4e9976d8b84ce4591c.png" alt="Demo of Smart Session powering Brewit at AA Hub, DevCon 2024" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Demo of Smart Session powering Brewit at AA Hub, DevCon 2024</figcaption></figure><p>That moment sparked the beginning of <strong>Brewit</strong>.</p><p>We realized: the primitives already exist - Safe accounts, session keys, bundlers, modules. But there was no cohesive framework tying them together into a secure, usable system. Brewit is our answer to that.</p><hr><h2 id="h-brewit-today" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Brewit Today</h2><p>Last month, we launched the <strong>first version of the Brewit App</strong> a consumer-friendly crypto app built around the concept of delegated accounts.</p><p>The response has been amazing, especially from newcomers to crypto who want simplicity without compromising on control or security.</p><p>But that’s just the start.</p><hr><h2 id="h-why-were-rebranding" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Why We’re Rebranding</h2><p>With the rise of <strong>agentic workflows</strong> and <strong>AI integrations</strong>, we believe <strong>delegated account automation</strong> is the next frontier.</p><p>Most tools today don’t offer safe, self-custodial delegation - especially for agents handling complex tasks. That’s why we’re going all-in on the delegation and automation stack, and rebranding from <strong>ZenGuard to Brewit</strong>.</p><hr><h2 id="h-whats-coming-next" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">What’s Coming Next</h2><p>We’re building a full-stack <strong>account delegation and automation framework</strong> for the new wave of smart accounts. Our roadmap includes:</p><ul><li><p>🧠 A <strong>consumer crypto app</strong> built for secure, delegated experiences (Already live: Try now: <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://brewit.money">https://brewit.money</a>)</p></li><li><p>🤖 A <strong>verifiable agent delegation layer</strong> for controlled task execution for accounts</p></li><li><p>🔐 A <strong>verifiable automation layer</strong> enabling DeFi, security, and recovery flows for accounts</p></li><li><p>🛠️ <strong>Tooling for developers and users</strong> alike to build and adopt better crypto accounts</p></li></ul><hr><p>At <strong>Brewit</strong>, we’re not just building another app.We’re crafting the foundation for a new generation of secure, composable, agent-ready crypto accounts.</p><p>👉 <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://brewit.money">Try the Brewit App</a>👀 Stay tuned for our next big release - <strong>delegation and automation infra for onchain accounts</strong> coming soon.</p><p><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="http://brewit.money/">http://brewit.money/</a></p><p>🔗 Follow us for updates and assistance:</p><p>🌐 <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://brewit.money">Website</a>🐦 <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://x.com/brewitmoney">X</a>🛠️ <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://github.com/brewitmoney">GitHub</a>💬 <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://t.me/brewitmoney/19">Telegram</a></p>]]></content:encoded>
            <author>koshik@newsletter.paragraph.com (koshik)</author>
            <enclosure url="https://storage.googleapis.com/papyrus_images/9b74611bcf42c6cd17127d1b93d86b25627898b180152ce48201f3fde8f2741f.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Setting the stage for making Safe Modules safer]]></title>
            <link>https://paragraph.com/@koshik/setting-the-stage-for-making-safe-modules-safer</link>
            <guid>sMGXq9FESLJ8DBiFdfl3</guid>
            <pubDate>Fri, 09 Feb 2024 16:59:41 GMT</pubDate>
            <description><![CDATA[In the vibrant world of Web3, we&apos;re dreaming big – envisioning a future where everything, from our finances to our real-world assets, seamlessly resides on the blockchain. But here&apos;s the catch: while we&apos;re busy moving mountains, we&apos;ve overlooked a crucial piece of the puzzle – security. Sure, security audits are a non-negotiable part of the crypto world. They&apos;re what keep our users, communities, and investors feeling safe and sound. Countless tools, infrastructure, an...]]></description>
            <content:encoded><![CDATA[<p>In the vibrant world of Web3, we&apos;re dreaming big – envisioning a future where everything, from our finances to our real-world assets, seamlessly resides on the blockchain. But here&apos;s the catch: while we&apos;re busy moving mountains, we&apos;ve overlooked a crucial piece of the puzzle – <strong>security</strong>.</p><p>Sure, security audits are a non-negotiable part of the crypto world. They&apos;re what keep our users, communities, and investors feeling safe and sound. Countless tools, infrastructure, and auditing firms work tirelessly to beef up protocol security. But here&apos;s the snag: we&apos;re missing a standardized way to put all this vital audit info on-chain.</p><p>That&apos;s where the proposed onchain audit representation standard <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://github.com/ethereum/ercs/blob/master/ERCS/erc-7512.md">ERC-7512</a> steps in – it&apos;s the brainchild of some heavy hitters in the industry: <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://safe.global">Safe</a>, OtterSec, ChainSecurity, Ackee, OpenZeppelin, Hats Finance, and Omniscia. Their mission? To ensure audit reports have a home on-chain and are easy to verify across different platforms and protocols.</p><p>ERC-7512 isn&apos;t just a game-changer; it&apos;s a community effort to bring trustless security to the forefront of Web3. By setting clear guidelines for representing audit reports on-chain, this proposal aims to streamline the verification process of audits, and auditors, thus fostering transparency within our ecosystem.</p><h2 id="h-onchain-audits-for-safe-modules" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0"><strong>Onchain audits for Safe modules?</strong></h2><p>Here at <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://zenguard.xyz">ZenGuard</a>, we&apos;re pretty pumped about this! Security is our bread and butter, after all. In our Safe Module <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://explore.zenguard.xyz">marketplace</a> (Currently in the <em>Alpha</em> version), we&apos;ve got your back. Before you hit that enable module button on your Safe account, we will make sure every module&apos;s audit is verified on-chain and meets your security requirements. It&apos;s all about keeping things safe and sound for you because your security is our top priority!</p><p>At ZenGuard, we&apos;ve designed a solid on-chain report collection system that sticks to this standard. Whenever a verified auditor conducts an audit and gives an on-chain attestation through our user-friendly <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://dashboard.zenguard.xyz">dashboard</a>, we will make sure to gather all the relevant details and make it accessible to be verified across platforms.</p><blockquote><p>ℹ️ <strong><em>BACKGROUND: Safe Modules and ZenGuard:</em></strong> <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://docs.safe.global/smart-account-modules"><em>Safe Modules</em></a><em> enable Safe Accounts to add additional custom features in the form of standardized Smart Contracts. These smart contract logic can be anything from Social Recovery, Passkey Auth, Session Key to DeFi Automation, and much more. We have created a non-exhaustive list </em><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://notes.zenguard.xyz/module-research"><em>here</em></a><em>.</em></p><p><em>At ZenGuard, we have designed a marketplace for publishing, exploring, and enabling these modules. Understanding that the security of these modules is of utmost importance, we will be onboarding module auditors through our module dashboard.</em></p></blockquote><p>The Safe Module ecosystem is buzzing with growth, thanks to all the exciting innovations in modular smart accounts. Developers are constantly adding new modules to the mix. But, ensuring the safety of these modules through security attestations is crucial for our Safe users. It&apos;s not just about promising wonders; it&apos;s about building a trustworthy ecosystem together.</p><h2 id="h-audit-attestation-and-verification-via-eas" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0"><strong>Audit attestation and verification via EAS</strong></h2><p>In our initial implementation, we&apos;ve made this process simple by using the Simplistic Attestation Service -<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://attest.sh"> Ethereum Attestation Service</a> (EAS), which is open-source and comes with secure contracts and handy SDKs. ZenGuard will store these audit attestations securely on EAS with a predefined<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://base.easscan.org/schema/view/0x975ba45202b5e2f314cae0c0ae1e464a53abaed083b9b95248190b71c461ac36"> schema</a> that matches the ERC-7512 <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://github.com/ethereum/ercs/blob/master/ERCS/erc-7512.md#audit-properties">audit properties</a>.</p><p>Once the audit details are attested, they become accessible to any Safe account user through our marketplace Safe App (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="http://explore.zenguard.xyz/">https://explore.zenguard.xyz</a>). But here&apos;s where it gets exciting.</p><p>Our ZenGuard Module Marketplace will also rely on the proposed<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://github.com/safe-global/safe-core-protocol-specs"> Safe {Core} Protocol</a><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://github.com/safe-global/safe-core-protocol-specs/tree/main/registry"> registry</a> to verify modules before they&apos;re enabled on a user’s Safe account. In our setup, the ZenGuard registry will check audit information against the ERC-7512 standard. Only when the security requirements are met can a module be activated on the Safe account; otherwise, the transaction gets rejected.</p><p>This showcases the power of on-chain audit verification, ensuring that Smart Accounts stay clear of extending them in accidental or intentionally malicious ways.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/73f6b17726c7713eb3ead424ba326eaa9ff5c53c8a5b9bad666a199197fdb7b8.gif" alt="Audit attestation via ZenGuard Dashboard (Alpha version). The attestations are just mocks for demonstration and do not guarantee actual audits." blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Audit attestation via ZenGuard Dashboard (Alpha version). The attestations are just mocks for demonstration and do not guarantee actual audits.</figcaption></figure><h2 id="h-the-initial-responses-and-feedback" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0"><strong>The initial responses and feedback</strong></h2><p>During our initial demos and onboarding on our alpha version to seek early reviews, we had some great chats with auditors and security advocates, including Shay Zluf from Hats Finance and Michael Lewellen from OpenZeppelin, who happen to be authors of ERC-7512. Their feedback has been highly encouraging and useful during the design of this initial implementation of this ERC in the Safe module ecosystem.</p><p>As we prepare to onboard the final versions of our modules onto our marketplace, we are actively engaging auditors who can conduct module audits and provide on-chain attestations. The responses we&apos;ve gotten about the onboarding process have been really promising. We&apos;re hashing out the details as we chat with more auditors and brainstorm integration strategies.</p><h2 id="h-things-to-improve" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0"><strong>Things to improve</strong></h2><p>So, this is just our first crack at on-chain audit representations. We&apos;re still ironing out all the kinks, especially when it comes to syncing up with the signature standard for verification and interoperability. Right now, we&apos;re relying on the EAS attestor information to verify attestors but we need to update our signature verification to standardize and guarantee interoperability as proposed by the standard.</p><p>But hey, since we&apos;re still getting the hang of it, there are a few things we need to sort out to make sure our on-chain audits are rock solid.</p><ol><li><p>Developing a standardized way to maintain and fetch the on-chain addresses associated with a verified auditor. It is also important to ensure there are good practices of key management and a way to revoke and add secondary addresses in case of auditor key compromises.</p></li><li><p>Mapping the correct version of the module code base to the deployed module and providing the on-chain attestation will still require manual verification from the auditor&apos;s part.</p></li><li><p>A better strategy is needed to provide updated audit attestations for newer versions of the module.</p></li></ol><h2 id="h-the-end-game" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0"><strong>The end game</strong></h2><p>We see this as the start of something major, aiming to set the bar for security verification not just in Safe, but across the whole Web3 space. Our initial rollout and efforts are just the tip of the iceberg, meant to spark ongoing discussions and momentum until this becomes the norm.</p><p>Sure, there&apos;ll be plenty of stuff to rethink and tweak along the way, but hey, we&apos;ve taken that first leap to get the ball rolling. We&apos;re totally open to feedback, collaborations, and yeah, even criticism. Feel free to<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://t.me/koshikraj"> shoot us a message</a> or jump on a<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://calendly.com/zenguard/greet"> call for a demo</a> and some good ol&apos; discussion. Let&apos;s make this happen together!</p><blockquote><p>⚠️ <strong>NOTE and DISCLAIMER</strong> <em>Our current platform is in the alpha stage, and while the published modules have undergone thorough testing, they have not yet undergone full audits. The attestations added are just mocks and do not guarantee actual audits.</em></p></blockquote>]]></content:encoded>
            <author>koshik@newsletter.paragraph.com (koshik)</author>
            <enclosure url="https://storage.googleapis.com/papyrus_images/2377a8cd06562e43f928b58253953e432fb0acf514263c085a477412220879ed.png" length="0" type="image/png"/>
        </item>
    </channel>
</rss>