RFP-13 Proposal: The CROPS Cyber-Range & Repository Emergency Room
Censorship-Resistance · Open-Source · Privacy · Security
Submitted by Web3Spell Developer Collective, in response to Devcon 8 India Community Hubs ![]()
1. Summary of Proposal
The CROPS Cyber-Range & Repository Emergency Room turns a Devcon Hub into a live diagnostic clinic and battle-simulation lab. Builders bring live codebases for 1-on-1 open-source security triages or drop into 15-minute attack/defense terminal challenges across Censorship-resistance, Open-source, Privacy, and Security. No slide decks; pure verifiable engineering.
2. Motivation and Rationale
How this Community Hub enhances the attendee experience
Most conference spaces default to passive consumption: an attendee sits through a 45-minute slide deck, retains roughly 10%, and returns home with the exact same vulnerabilities in their repository they arrived with.
The CROPS Hub converts passive attendees into active operators within 90 seconds of stepping inside. Whether an engineer has 15 minutes between main-stage keynotes or three hours during an open afternoon, they plug into a pre-configured terminal, attack a live sandboxed target, or sit down with an Attending Physician (a veteran security researcher or maintainer) to run automated static analysis, invariant tests, and threat modeling on their own production codebase.
How it complements Devcon 8 India & adds a unique dimension
Devcon 8 in India sits at a critical inflection point: India represents one of the largest software engineering pools in the world, yet thousands of builders transitioning into Web3 begin writing smart contracts without deep exposure to cypherpunk hygiene (running light clients, auditing dependencies, defending against RPC-level censorship, or designing for metadata privacy).
Main-stage talks deliver the protocol roadmap and research breakthroughs. This Hub provides the physical engine room where Indian builders, university hackers, and international core devs sit shoulder-to-shoulder to operationalize those principles at the code level.
Why a Community Hub is the best format (vs. a one-time talk or workshop)
- A 45-minute workshop serves 30–40 people once and disappears from the venue schedule.
- A Community Hub operates continuously across all 4 days (32+ active hours). It accommodates over 120+ structured 1-on-1 triage slots and hundreds of drop-in challenge attempts on a rolling, zero-friction basis.
- The format accommodates the erratic schedule of Devcon attendees: challenges are modular (10–15 minute sprints), self-paced, and reset automatically.
Supporting builders in creating a free, open, private, and verifiable future
A decentralized future cannot survive on centralized defaults. If decentralized applications rely on centralized RPC endpoints, leak user IP addresses to third-party node providers, or use opaque, proprietary off-chain components, their censorship-resistance is an illusion.
This Hub forces builders to confront these trade-offs directly by simulating:
- Censorship scenarios: Frontend censorship and RPC blacklisting bypass via Helios light clients.
- Privacy leaks: Extracting wallet metadata from standard Web3 RPC calls in real time.
- Open-source integrity: Flagging malicious dependencies and unlicensed closed-source libraries.
- Verifiable security: Writing invariant-based test suites using Foundry rather than trusting unit tests.
Past experience & lessons carried forward
Web3Spell has organized Core-Nexus (Central India’s largest 36-hour hackathon) along with regional security bootcamps and developer workshops.
Key operational lessons we are applying directly:
- Network Resilience: Conference Wi-Fi degrades during peak hours. All Cyber-Range challenges and triage scripts are pre-packaged into local Docker containers and local testnets (Anvil) running offline on dedicated mini-PCs.
- Strict Timeboxing: Open-ended “office hours” devolve into long queues. We use an automated queue board with 15-minute hard limits per triage slot.
- No Sound Bleed / No Lecture Noise: Sound bleed from adjacent hubs ruins informal talks. We eliminate traditional lectures in favor of 1-on-1 screensharing, visual whiteboard threat modeling, and self-guided terminal cards.
3. Implementation
Space Layout & Zones (48m² Footprint)
- Track A: The Cyber-Range (8 Hardened Terminals): High-throughput, self-paced battle simulation stations with pre-configured local testnets and automated exploit harnesses.
- Track B: Repository Emergency Room (3 Triage Pods): 1-on-1 consultation tables equipped with dual monitors for live code diagnosis, threat modeling, and PR generation.
- Async Peer Audit & Collaboration Bar (12-Person Capacity): High-top bench with dedicated power rails and Ethernet for attendees collaborating on fixes.
- Threat-Modeling Whiteboard Arena: 2 mobile whiteboards for live exploit deconstructions.
- 75" Live Leaderboard & Exploit Feed: Real-time visual telemetry of solved challenges and repo vulnerabilities diagnosed.
Special Production Requirements (Requested from Devcon)
(Note: Subject to confirmation)
- Display: 1× 75" (or 65") 4K LED Screen with HDMI input (for live leaderboard and telemetry).
- Whiteboards: 2× Double-sided mobile magnetic whiteboards + markers/erasers.
- Power: 3× 16A dedicated floor drops distributed via 6 heavy-duty spike busters (supporting 30+ simultaneous machines).
- Network: 1× Dedicated high-speed wired Ethernet drop (1 Gbps) connected to a local switch for local testnet syncing.
- Furniture:
- 8× Stools for Cyber-Range stations
- 6× Ergonomic chairs for 3 Emergency Room triage pods (2 per pod)
- 1× High-top counter table (12-person capacity) for async peer audits
Equipment Sourced Directly by Web3Spell (BYOD & Cloud-Free Local Rig):
-
Local Mesh & Offline Anvil Gateway: 1× High-performance Web3Spell gateway laptop running a local isolated Wi-Fi hotspot broadcasting offline Anvil testnets, Slither/Aderyn diagnostic APIs, and local RPC proxies. Attendees connect their own laptops directly with zero installation friction.
-
Triage Stations: 3× Web3Spell Core developer workstations dedicated for 1-on-1 screenshare diagnostic reviews.
-
Digital Take-Home Toolkits: One-click offline executable bundles distributed via local Wi-Fi / QR code + GitHub release.
-
Physical Diagnostic Artifacts: 300× Printed CROPS Challenge Cards & physical “Clean Bill of Health” stamped audit cards.4. Programming
4-Day Daily Theme Structure
| Day | Focus Area | Core Competency & Hands-on Objective |
|---|---|---|
| Day 1 | Censorship-Resistance | RPC Sanitization, crLists, Helios Light Clients, MEV-Boost & Inclusion Lists |
| Day 2 | Open-Source Ethos | Dependency Auditing, Verifiable Builds, EIP Compliance, Licensing Firewalls |
| Day 3 | Privacy & ZK | Metadata Leakage Triage, Stealth Addresses, Private State & Client-Side Proofs |
| Day 4 | Protocol Security | Invariant Fuzzing, Storage Collisions, Reentrancy Labs, Live Exploit Dissection |
Daily Schedule Breakdown (9:00 AM – 6:00 PM, All 4 Days)
09:00 - 10:00 | MORNING BOOTSTRAP & ENVIRONMENT SETUP
- Terminal stations open; peer code reviews over morning coffee.
- Assisting developers with local tooling installation (Foundry, Helios, Slither).
10:00 - 12:30 | REPOSITORY EMERGENCY ROOM: MORNING CLINIC (SLOTS 1-10)
- 15-minute dedicated triage slots for open-source repositories.
- Parallel open access on all 8 Cyber-Range battle stations.
12:30 - 13:30 | COMMUNITY UN-CONFERENCE & WHITEBOARD THREAT-MODELING
- Open discussion circle around the central whiteboards.
- Live deconstruction of a notable historical exploit on the whiteboard.
13:30 - 16:30 | REPOSITORY EMERGENCY ROOM: AFTERNOON CLINIC (SLOTS 11-22)
- Afternoon 1-on-1 code triage and automated vulnerability sweeps.
- Cyber-Range challenge speedruns and leaderboard tracking.
16:30 - 17:30 | THE DAILY TEARDOWN (LIVE DEMO & AUDIENCE PARTICIPATION)
- Day 1: "Intercepting & Rewriting Censored Transactions in 10 Lines of Rust"
- Day 2: "Hunting Malicious Payloads in Upstream npm/Rust Dependencies"
- Day 3: "De-anonymizing a dApp User in Under 60 Seconds via RPC Logs"
- Day 4: "Live Invariant Fuzzing Battle: Breaking an ERC-4626 Vault on Stage"
17:30 - 18:00 | DAILY TRIAGE RETROSPECTIVE & LEADERBOARD RECOGNITION
- Announcing top vulnerabilities caught during the day's repo triage.
- Awarding top Cyber-Range solvers; distribution of offline diagnostic kits.
Possible Speakers, Maintainers & Collaborative Ecosystem Partners
To ensure the space is fully decentralized and collaborative, open-source maintainers and researchers will be invited to rotate as Attending Physicians:
| Community / Tooling Focus | Target Maintainer / Partner | Interactive Session / Triage Focus |
|---|---|---|
| Foundry / Invariant Testing | Paradigm / OpenZeppelin Contributor | Invariant-Driven Security Testing |
| Light Clients & Trustless RPCs | Helios (a16z crypto) / EF Portal | Running Trustless Local Frontends |
| Static Analysis & Lints | Trail of Bits / Crytic / Aderyn Team | Automated CI/CD Security Filters |
| Zero-Knowledge & Privacy | PSE (Privacy & Scaling Explorations) | Practical ZK Client-Side Proving |
| EIP & Standards Compliance | Fellowship of Ethereum Magicians | Clean Implementation of EIP-712 / ERC-4337 |
| Regional Security Vanguard | Web3Spell / Indian Security Auditors | Common Architectural Pitfalls in Indian Dev Cohorts |
5. Audience
Target Audience & Personas
- Full-Stack Web3 Engineers: Developers building user-facing applications who need to verify that their dApps do not leak private user metadata or depend on single-point-of-failure RPCs.
- Smart Contract Developers: Engineers looking to stress-test their protocols against reentrancy, oracle manipulation, and economic vulnerabilities using modern invariant fuzzers.
- Indian University Hackers & Student Builders: Junior developers transitioning from tutorials to production-grade security habits and verifiable engineering standards.
- Security Researchers & Whitehats: Competitive builders looking to test their skills against novel attack vectors on the Cyber-Range leaderboard.
Fostering Collaborations with India’s Growing Developer Community
India’s developer ecosystem is undergoing a massive shift from Web2 software engineering to protocol development. However, access to elite security auditing and protocol-level mentorship is often restricted to high-end consulting engagements.
Our concrete action plan:
- Pre-Event Open Triage Intake: 4 weeks before Devcon, we will open an intake form across Indian Web3 developer networks (Web3Spell, Regional Clubs, University Clubs) allowing local builders to submit their open-source repos for priority triage slots at the Hub.
- Pairing Global with Local: We pair visiting international security experts with Indian student maintainers during their 15-minute triage sessions, turning code review into a high-impact mentorship moment.
6. Team, Neutrality & Multi-Lingual Support
Organizing Team & Bios
| Name & Role | Background & Qualifications | Responsibility at Devcon Hub |
|---|---|---|
| Rythme Nagrani | ||
| (@rythmern02) | ||
| (Lead Hub Coordinator & DevRel) | Founder, Web3Spell; Lead Organizer of Core-Nexus (Central India’s largest 36-hour hackathon) and Arbitrum Ignite. Extensive background in developer ecosystem mobilization and high-throughput hackathon logistics. | Space operations, Participant Guidance, extensive learning, hardware management, Devcon production liaison, scheduling. |
| Rajeev | ||
| (@rajeevK07) | ||
| (Lead Security Architect & Range Master, Web3Spell Core) | Smart contract security auditor and invariant testing researcher with hands-on experience authoring CTF frameworks and leading developer security bootcamps across India. | Authoring CTF challenge containers, managing automated validation engines, leading Day 4 invariant fuzzing clinics. |
| Swarna | ||
| (@swarnasn29) | ||
| (Community, Designer & Triage Dispatch Lead, Web3Spell Core) | Lead Designers and experienced hackathon mentor with deep grassroots ties across Indian university developer cohorts and Web3 communities. | Managing 15-minute triage bookings, attendee onboarding, live leaderboard tracking, and pre-event repository intake. |
Neutrality Guarantee & Conflict of Interest Firewall
To guarantee that the CROPS Community Hub remains a credibly neutral, non-commercial public good:
- Strict Zero-Token / Zero-Commercial Policy: No tokens, token launches, proprietary paid services, or venture-backed promotional pitches are permitted within the space.
- 100% FLOSS Tooling: All diagnostic scripts, static analyzers, and range exercises use exclusively free/libre open-source software (Foundry, Slither, Aderyn, Helios, Anvil, Circom).
- Open Merit-Based Access: Triage slots and terminal access are 100% free and open on a first-come, first-served and verified-open-source basis. No VIP/paid fast tracks.
Multi-Lingual Accessibility
India is linguistically diverse, and technical concepts are often best understood in a builder’s native tongue. The on-ground Web3Spell organizing team and local contributors are fluent in:
- English (Standard global coordination)
- Hindi (Universal across North and Central India)
- Marathi & Gujarati (Prominent regional languages in Mumbai and Western India)
- Bengali, Telugu & Tamil (Via dedicated regional community volunteers)
All challenge cards and diagnostic summaries will be made available in clean English, with bilingual facilitators present at triage desks to ensure zero language barriers for regional Indian builders.
7. Proof of Work (POW) & Institutional Track Record
Web3Spell Labs is a high-performance developer laboratory, community organization, and engineering team specializing in applied zero-knowledge systems, smart contract architecture, and privacy infrastructure.
- Event Experience: Organized and hosted over 75+ local as well as national level ecosystem events, including the Ethereum Builder’s grimoire by EF, Arbitrum Ignite workshops, Core Nexus Hackathon, and various technical meetups targeting developers, creators and investors.
Webpage: https://web3spell.fun
Host Profiles
Host Profile: Rythme Nagrani
-
Role: Full-stack blockchain developer specializing in zero-knowledge proofs (Circom, Noir), Account Abstraction, and EVM architectures.
-
Global Hackathons: Track prize secured at the Token2049 Origins Hackathon in Singapore (2025).
-
Grants & Research: Recipient of a Compound Protocol Grant for developing “Chainpot” (a decentralized savings protocol/on-chain ROSCA).
-
Relevant ZK Experience: Authored the technical whitepaper and developed Civitas, a zero-knowledge confidential payroll protocol, directly validating the capacity to teach the Selective Disclosure and Privacy frameworks proposed for this event. Have also mentored at major blockchain programs including Arbitrum Ignite Bootcamp, Paris Blockchain Week (PBW), GSSOC, and Core Nexus Hackathon.
-
X (Twitter): https://x.com/RythmeNagr64107
-
Portfolio: https://rythmastic.vercel.app
Host Profile: Swarna Nagrani
-
Role: Co-founder, Design Head, and CMO leading strategic operations at Web3Spell Labs and its affiliated ventures.
-
Ecosystem Experience: Spearheaded design, operations, and co-founding initiatives for high-impact technical protocols including ZK confidential payroll and SoulPass.
-
X (Twitter): https://x.com/swarnasn29
-
Portfolio: https://swarn.framer.website
Host Profile: Rajeev Kalra
-
Role: Principal Systems Engineer and Protocol Infrastructure Developer at Web3Spell Labs.
-
Core Technical Expertise: Protocol infrastructure, mobile-to-EVM resolver architectures, contract automation, and invariant security testing.
-
Open-Source Infrastructure: Author of RNS Java Resolver, Mobile RNS Portfolio Manager, Refuel Kit, and WebZen.
-
GitHub: https://github.com/rajeevK07
I. Live Protocols & Grant-Backed Projects
-
ChainPot Protocol (chainpot.fun): Decentralized savings and coordination protocol awarded an official grant from the Compound ecosystem. (Source Code)
-
Civitas Protocol (meetcivitas.xyz): Zero-knowledge decentralized payroll and privacy protocol. (Source Code)
II. Core Open-Source Repositories & Tooling
-
Identity & Privacy: SoulPass Identity · Solynx · Liveness Vault
-
Smart Contract & Gas Optimization: Permit Wizard · Fee Radar · RBTC/USDT Lending Boilerplate · Labelo
-
Mobile & Infrastructure Tooling: RNS Java Resolver · Mobile RNS Portfolio Manager · Refuel Kit · WebZen · RSK Deployer Action
-
Zero-Knowledge & Game Mechanics: Liars Poker SOL · Cards Against Humanity
III. Proven Event Execution (75+ Developer Events Hosted)
-
Core Nexus Hackathon: Central India’s largest 36-hour hackathon (powered by Web3Spell).
-
Arbitrum Ignite: India’s largest 12-day Web3 bootcamp serving 250+ active developers in Bhopal.
-
Build Stations & Hackathons: Radar Build Station, Breakout Build Station, AI Hackathon (Jaipur) and many more.
-
Community Meetups & Protocols: EthGlobal Co-working Bhopal, Berachain bhopal meetup, Shardeum Mainnet Launch Party Bhopal, XDC BlockMeet, Dev Day & Founders Connect Jaipur, Ascendia India AMA.
-
Ethereum Foundation Alignment: The Ethereum Grimoire by Ethereum Foundation.
IV. Global Recognition & Ecosystem Partnerships
-
TOKEN2049 Origins Hackathon Track prize secured (Singapore).
-
Official Community Partner: Consensus Hong Kong and TOKEN2049 Singapore 2025.
-
Mentorship Leadership: Paris Blockchain Week 2025, GirlScript Summer of Code (GSSoC), Winter of Blockchain, and Web3camp.
V. Official Portals & Media
-
Web3Spell Main Hub: web3spell.fun
-
SpellCast Podcast: YouTube Playlist
-
Lead Architect Portfolio: rythmastic.vercel.app
-
ChainPot App: chainpot.fun
-
SkyScreen Project: skyscreen.site
8. Forum Discussion & Community Co-Signatures
We invite open-source tool authors, security firms, and protocol researchers to join this initiative as Visiting Attending Physicians and co-contributors.
Please drop your repository, tooling suggestions, or interest in taking a 1-hour triage shift in the thread below.
Let’s make Devcon 8 India the most battle-tested, secure, and verifiable Devcon in Ethereum history. ![]()
![]()


