in

Harpie Review: Can This On-Chain Firewall Solve Web3’s Security Problem?

Key Takeaways

  • Harpie is the primary on-chain firewall product that protects customers towards frequent assault vectors in crypto.
  • It really works by monitoring customers’ wallets and intervening in case of an assault by frontrunning malicious transactions and shifting their funds to a safe non-custodial vault.
  • Whereas it is not good, it is some of the promising choices for safeguarding Web3 customers in existence right this moment.

Share this text

Harpie’s on-chain firewall lets crypto customers join their Web3 wallets and create a protected transacting setting and defend themselves towards crypto’s most typical assault vectors.

Crypto’s Safety Drawback

As crypto and decentralized finance have risen in reputation over the past couple of years, so have cryptocurrency-related assaults, together with focused person thefts and protocol exploits. In response to Chainalysis‘ mid-year crypto crime report, over $1.9 billion had been stolen in hacks of customers and providers from January by means of July 2022, up from just below $1.2 billion over the primary seven months of 2021. And whereas a lot of the exploits have been protocol-related, many customers have had their wallets drained thanks partially to the dangers related to utilizing Web3 right this moment.

For customers who frequently work together with DeFi protocols and NFT marketplaces, transacting in Web3 can virtually really feel like taking part in Minesweeper in actual life. Each transaction approval and on-chain interplay with a third-party software can doubtlessly result in pockets compromise and lack of funds. Sadly, there hasn’t been a easy or environment friendly resolution to this downside up to now. The most well-liked Web3 wallets, like MetaMask or Belief Pockets, do an abysmal job of conveying the character of every on-chain interplay to their customers. As an alternative of creating every transaction clear, the default descriptions of most in-wallet transaction confirmations learn like gibberish to most unsophisticated customers, leaving them successfully blind to even essentially the most primary safety threats.

MetaMasks description for a easy interplay with a Web3 software (Supply: MetaMask)

Past the same old protocol hacks, maybe essentially the most harmful kind of assaults affecting crypto customers are so-called “approve spend” exploits that trick customers into approving malicious transitions that permit the hackers to empty the customers’ wallets. One other frequent method Web3 customers lose their cash is by having their non-public keys compromised, which usually includes customers putting in malicious software program like keyloggers, storing their seed phrases in plain textual content on insecure gadgets, or falling for phishing scams.

Defending towards all of those assault vectors has all the time been attainable, but it surely requires vital technical data, sophistication, and sacrifices in person expertise. Harpie is hoping to resolve this downside. 

What’s Harpie?

Harpie is the primary on-chain firewall resolution that lets Ethereum customers create a protected transacting setting by whitelisting a set of addresses and Web3 purposes they deem protected. The service displays linked wallets for pending suspicious or unpermitted transactions to cease them once they floor. When it detects a suspicious transaction, it instantly strikes the person’s funds out of their pockets and right into a protected, non-custodial vault, defending the funds from potential theft.

Harpie does this by frontrunning malicious transactions by paying the next fuel payment. For instance, suppose a hacker has someway gotten maintain of a person’s non-public keys or fooled them into approving a malicious spending transaction and tried to switch funds from the sufferer’s pockets into his tackle. In that case, Harpie would detect the outgoing transaction from the sufferer’s pockets to an unapproved tackle, and mechanically broadcast one other transaction with the next fuel payment to maneuver the goal’s funds right into a protected vault earlier than the outgoing transaction is confirmed. 

Ethereum validators prioritize transactions with the best fuel charges, which implies they’ll decide up and ensure Harpie’s benevolent transactions earlier than any attackers, thus saving customers from theft.

After Harpie has intervened and moved the belongings to a protected place, the person can withdraw them to a brand new uncompromised pockets for a flat payment of 0.01 ETH, whatever the quantity that was saved within the process.

The way to Use Harpie

Customers should join their present Web3 pockets to Harpie to make use of the service. They’ll do that by clicking the “Enter App” button within the high proper nook of Harpie’s homepage after which clicking “Join” inside the applying. Customers additionally want to substantiate the connection inside their wallets individually to present Harpie permission to observe their wallets and transfer funds from them in case of an incident.

Connecting to Harpies service (Supply: Harpie)

After connecting, customers are requested to arrange their “Trusted Community” of purposes and addresses. These are purposes and addresses the customers deem protected and want to exclude from the firewall, which means Harpie received’t mechanically block any transactions with them.

Making a “Trusted Community” (Supply: Harpie)

 To do that, customers can select in the event that they use DeFi purposes, NFT marketplaces, or each and choose their trusted community of purposes from a preselected record of established protocols. The entire protocols that Harpie recommends by default have undergone in depth auditing, stood the take a look at of time, and are usually thought-about safe, which means customers ought to really feel protected about whitelisting all of them. After choosing the trusted set of purposes, customers should press “Proceed” within the backside proper nook and signal the transaction inside their pockets.

Upon signing, Harpie will begin integrating its firewall system with the person’s pockets, and after it’s completed, customers will likely be directed to their dashboard. There, they’ll navigate to the “My Trusted Community” tab and add all of the addresses they’re frequently interacting with beneath the “Mates” part. These could embody their very own private wallets, their mates’ wallets, and the deposit addresses of the centralized exchanges they use.

Customers should additionally allow Harpie to entry their pockets’s funds to have the ability to transfer them to a safe vault in case of an assault. They’ll do that by clicking “Shield” for every asset of their dashboard’s “Protected Property” part. If they’ll’t see all of the belongings they’re holding of their pockets, they’ll import them manually from the identical dashboard part. 

Defending Uniswaps UNI token (Supply: Harpie)

Clicking “Shield” for every asset is essentially the most essential process for each person utilizing Harpie. It is because whitelisting a trusted community of purposes and addresses solely tells Harpie what site visitors to observe, whereas allowing it to entry the pockets’s funds is what truly permits it to intervene and transfer the belongings to a protected place in case of an assault.

Lastly, customers have to arrange a withdrawal tackle that may have the flexibility to retrieve the funds moved to the protected vault in case Harpie has intervened throughout a safety breach. They’ll do that by clicking on the “Setup” button within the “Setup withdrawal tackle” part, coming into the tackle they wish to use for retrieving funds, clicking “Register,” after which approving the motion with their pockets.

It’s essential to make clear that Harpie can solely defend customers from dropping belongings they have already got of their wallets. If customers deposit or stake their belongings on a third-party crypto protocol and the applying will get hacked, Harpie received’t be capable to do something to guard the customers’ funds. 

Last Ideas

Whereas no single system or protocol can remedy crypto’s safety downside, Harpie’s on-chain firewall strategy provides a vital layer of safety to the every day operations of the extra energetic Web3 customers. Past protocol hacks and sure edge instances, Harpie can successfully defend customers towards virtually frequent crypto exploits with out severely impeding their person expertise.

With that mentioned, interacting with Web3 with Harpie’s firewall resolution nonetheless introduces some inevitable hindrances from a person expertise standpoint. For instance, customers could neglect to whitelist their pal’s tackle or their very own account on a centralized alternate and have their belongings mechanically moved to Harpie’s non-custodial vault after they try to make an intentional switch. Past that, Harpie additionally doesn’t present customers with a easy technique to revoke the firewall’s entry. As soon as enabled, customers want to make use of a third-party software like revoke.money to revoke the entry they’ve given to Harpie in the event that they want to opt-out of it.

Every part thought-about, Harpie offers a much-needed on-chain safety layer that customers presently can’t discover wherever else. Whereas Harpie isn’t good right this moment, its resolution is a transparent step in the precise route towards making Web3 safer for normal customers.

Disclosure: On the time of writing, the writer of this text owned ETH and a number of other different cryptocurrencies.

Share this text

Leave a Reply

Your email address will not be published. Required fields are marked *