Proofly
Privacy-first wallet proving humanity, securing AI
Created on 9th April 2026
•
Proofly
Privacy-first wallet proving humanity, securing AI
The problem Proofly solves
🚨 The Problem It Solves
The internet is facing a growing trust crisis.
- Bots and fake users can create unlimited accounts, exploit rewards, and manipulate platforms
- Wallets only prove ownership of keys, not whether the user is a real human
- AI agents can act autonomously without strict human control or limits
- Existing verification systems either leak personal identity or rely on weak, centralized trust
This leads to:
- Fake engagement and spam
- Exploited airdrops and marketplaces
- Uncontrolled AI actions
- Loss of trust in decentralized systems
💡 How Proofly Solves It
Proofly introduces a wallet-native trust layer that makes interactions verifiable, private, and secure.
🔐 Prove You're Human (Without Revealing Identity)
- Uses zero-knowledge proofs to verify real humans
- No personal data, no identity leakage
✍️ Secure Every Action
- Every action is wallet-signed and intentional
- Prevents spoofing, fake submissions, and unauthorized activity
🤖 Control AI Agents
- Define strict rules for AI:
- spending limits
- allowed contracts
- time restrictions
- AI cannot act beyond user-defined boundaries
📜 Verifiable Trust Trail
- Actions are backed by:
- human proof
- cryptographic signatures
- policy enforcement
- Anyone can verify trust without needing identity
🚀 What Can People Use It For?
- Airdrop protection → only real humans can claim rewards
- Marketplaces & gigs → prevent fake users and spam submissions
- AI automation → safely delegate tasks to AI with strict limits
- Content authenticity → verify human-created, signed content
- dApps & platforms → build trust without KYC or identity leakage
✅ Why It Matters
Proofly makes the internet:
- Safer → eliminates bots and fake users
- Private → no personal data exposed
- Trustworthy → every action is verifiable
- AI-ready → humans stay in control of AI systems
Challenges we ran into
Challenges We Ran Into
Building Proofly as a real, end-to-end trust system (not just a UI demo) came with several technical challenges:
🔌 Wallet + dApp Integration (EIP-1193)
Problem:
Making the Chrome extension behave like a real wallet provider was tricky. Injecting a custom provider and ensuring dApps could properly connect, request accounts, and sign messages caused inconsistencies.
Solution:
We implemented a proper EIP-1193-compatible provider and standardized request/response handling. Careful event management fixed connection issues.
🔐 Secure Key Storage in Extension
Problem:
Handling private keys securely inside a Chrome extension without exposing them to content scripts or external access.
Solution:
We encrypted all key material locally using a user-defined password and ensured keys never leave the extension context. Sensitive logic was isolated in the background service worker.
🧠 Integrating Human Proof (World ID)
Problem:
Managing the zero-knowledge proof flow and handling proof responses correctly, especially binding proofs to specific actions.
Solution:
We structured proof handling with proper nullifier tracking and stored verification state locally and in the backend, ensuring proofs are reusable only within valid scopes.
🤖 AI Policy Enforcement (Core Challenge)
Problem:
Designing a system where an AI agent cannot bypass user permissions and perform unauthorized actions.
Solution:
We built a policy engine inside the wallet, where every action request is validated locally before signing. Since the wallet is the signer, AI cannot act outside defined rules.
🔗 Sync Between Wallet, Backend, and Chain
Problem:
Keeping state consistent across:
- extension (local state)
- Supabase backend
- smart contracts on Base Sepolia
Solution:
We introduced structured event logging and clear state ownership:
- wallet → source of truth for decisions
- chain → enforcement & audit
- backend → indexing and UI sync
🎨 UI vs Real Functionality Trade-off
Problem:
Balancing between building a visually impressive demo and maintaining real, working functionality.
Solution:
We prioritized real implementations first, then iteratively improved the UI to match production-grade wallet experiences.
🧩 Key Takeaway
The biggest challenge was ensuring nothing is faked — every feature (wallet, proof, signing, policy) had to work end-to-end.
This forced us to think like real product engineers, not just prototype builders.
Technologies used
