Decentralized Finance Flow β built on BlockDAG
The DeFiFlow DeFi Protocol project built to demonstrate the power of BlockDAG's EVM & SDK for DeFi innovation. It enables users to lend, borrow, earn yield, and interact with synthetic real-world assets (RWA) in a single dApp.
Key innovations:
- β‘ Auto-Rebalancing Credit Pools β yield strategies rebalance dynamically.
- π Synthetic RWA Tokens β on-chain representation of assets (Treasuries, Real Estate).
- π Cross-Chain Bridge Integration β BlockDAG bridge SDK for future liquidity movement.
- π‘ Delegated Risk Control β enforce borrowing caps with BlockDAG signatures.
- π Multi-Network Support β BlockDAG, Sepolia testnet, and Ethereum mainnet
- π₯οΈ Cross-Platform β Web, Desktop (Electron), Mobile (Capacitor)
- π One-Click Deployment β Vercel, Electron, and Capacitor builds
This dApp now supports Delegated Signing using EIP-712 typed messages, allowing users to keep their private keys secure in their wallets while transactions are executed by a backend relayer.
- β No Private Keys in Codebase - Private keys remain in user wallets
- β EIP-712 Typed Messages - Structured, human-readable transaction data
- β Nonce-based Replay Protection - Prevents signature reuse
- β Signature Expiration - Messages expire after deadline
- β Backend Relayer - Secure transaction execution service
- User Action: User initiates action (e.g., lend dUSD) in frontend
- Message Creation: Frontend creates EIP-712 typed message with action details
- Wallet Signing: User signs the typed message with their wallet
- Backend Submission: Signed message sent to relayer service
- Signature Verification: Relayer verifies signature (optional, contract also verifies)
- Transaction Execution: Relayer submits transaction to blockchain
- Contract Validation: Smart contract verifies signature and executes action
- Replay Protection: Nonce tracking prevents signature reuse
- Expiration: Messages expire after configurable deadline
- Rate Limiting: API endpoints protected against abuse
- Input Validation: All inputs validated on both frontend and backend
- Deploy Contracts: Deploy updated LendingPool contract with EIP-712 support
- Setup Relayer: Configure and run the Node.js relayer service
- Update Frontend: Use EIP-712 signing for supported actions
- Test Integration: Verify end-to-end workflow functionality
- Connect Wallet: Link your MetaMask or compatible wallet
- Sign Messages: Approve actions by signing typed messages
- Automatic Execution: Transactions executed securely by relayer
- Gas-free Experience: No gas costs for message signing
- Private Key Security: Private keys never leave the user's wallet
- Message Clarity: EIP-712 ensures users see exactly what they're signing
- Expiration Protection: Messages expire to prevent stale approvals
- Nonce Management: Sequential nonces prevent replay attacks
- Rate Limiting: Prevents abuse of the relayer service
- Input Validation: Comprehensive validation on all inputs
- Error Handling: Graceful failure handling with user feedback
- Audit Trail: All transactions logged for monitoring
const domain = {
name: 'LendingPool',
version: '1',
chainId: 1043, // BlockDAG
verifyingContract: lendingPoolAddress
}const types = {
DepositAction: [
{ name: 'amount', type: 'uint256' },
{ name: 'nonce', type: 'uint256' },
{ name: 'deadline', type: 'uint256' }
]
}- Signature Verification: ECDSA recovery with domain separation
- Deadline Enforcement: Rejects expired signatures
- Nonce Validation: Prevents replay attacks
- Access Control: Only authorized users can execute actions
- Rate Limiting: 100 requests per 15 minutes per IP
- Input Sanitization: All inputs validated and sanitized
- Error Handling: No sensitive information leaked in errors
- HTTPS Only: All communications encrypted
- CORS Protection: Configured for allowed origins only
- AWS KMS/Azure Key Vault Integration: Enterprise key management
- Automated Key Rotation: 24-hour rotation cycle with grace period
- Real-time Transaction Monitoring: Comprehensive security dashboard
- Multi-signature Support: Large transaction approval workflow
- Automated Alerting: Email and Slack integration for security events
- Relayer Balance Monitoring: Automated funding alerts
- Security Event Logging: Complete audit trail for compliance
GET /api/security/status // Security dashboard
GET /api/monitoring/dashboard // Production monitoring
POST /api/admin/rotate-key // Manual key rotationπ See PRODUCTION_SECURITY_GUIDE.md for complete enterprise security implementation including:
- AWS KMS setup and configuration
- Automated key rotation systems
- Transaction monitoring and alerting
- Multi-signature implementation
- Incident response procedures
- Compliance and audit requirements
1. Smart Contracts (Solidity, BlockDAG EVM)
LendingPool.solβ deposits, borrowing, repayments, withdrawals.YieldRouter.solβ simulates auto-rebalancing yield strategies.RWARegistry.solβ mints synthetic RWA tokens.Governance.solβ lightweight DAO for parameter updates.
2. Frontend (React + TailwindCSS)
- Wallet connect (MetaMask + BlockDAG SDK).
- Unified dashboard with lending & borrowing flows.
- Live balances, yields, and governance interactions.
3. Backend Scripts (Node.js / Hardhat)
- Deployment, verification, and demo scripts.
- Mock oracle & RWA minting scripts.
function deposit(address token, uint256 amount) external;
function borrow(address token, uint256 amount) external;
function repay(address token, uint256 amount) external;
function withdraw(address token, uint256 amount) external;- Node.js 18+
- npm or yarn
- MetaMask wallet
- BlockDAG testnet account (optional)
# Clone repository
git clone <repository-url>
cd defiflow
# Install root dependencies
npm install
# Install frontend dependencies
cd frontend && npm install && cd ..
# Install relayer dependencies
cd relayer && npm install && cd ..# Copy environment template
cp .env.example .env
# Edit .env with your configuration
# Add Infura API key (already configured)
# Private key is optional and only needed for contract deploymentImportant: Your private key is NOT stored in .env by default for security reasons.
Only add your private key when deploying contracts:
# Temporarily add your private key for deployment
echo "PRIVATE_KEY=0xyour_private_key_here" >> .env
# Deploy contracts
npm run deploy:all
# Remove private key immediately after deployment
sed -i '/PRIVATE_KEY/d' .envAlternative secure deployment methods:
- Use Hardhat with encrypted keystore
- Deploy via hardware wallet interface
- Use deployment services with secure key management
The relayer service is configured to work without a private key for development/testing:
# Relayer will start with read-only mode when private key is not configured
cd relayer && npm start
# Output:
# β οΈ Relayer private key not configured - some features will be disabled
# Relayer server running on port 3001To enable full relayer functionality:
# Add relayer private key to relayer/.env
echo "RELAYER_PRIVATE_KEY=0xyour_relayer_private_key" >> relayer/.env# Compile contracts
npm run compile
# Deploy all contracts to BlockDAG testnet
npm run deploy:all
# Or deploy to specific network
npx hardhat run script/deploy-all.js --network sepolia# Start frontend (port 5173)
npm run frontend:dev
# Start relayer service (port 3001)
npm run relayer:start
# Open http://localhost:5173 in browserThe dApp supports multiple networks:
- BlockDAG Testnet (Primary)
- Sepolia Testnet (Ethereum)
- Ethereum Mainnet
Switch networks using the dropdown in the header. Contract addresses are automatically loaded for each network.
# Development
npm run desktop:dev
# Production build
npm run build:desktop
# Creates: .exe (Windows), .dmg (macOS), .AppImage (Linux)# Build web assets
npm run frontend:build
# Generate mobile projects
npm run build:mobile
# Open in Android Studio
npx cap open android
# Open in XCode
npx cap open ios# Deploy to Vercel
vercel --prod
# Or use Vercel CLI
npm run frontend:build
vercel deploy --prebuilt/contracts # Solidity smart contracts
βββ LendingPool.sol # Main lending protocol
βββ YieldRouter.sol # Yield farming strategies
βββ RWARegistry.sol # RWA tokenization
βββ Governance.sol # DAO governance
βββ ...
/frontend # React + Vite application
βββ src/
β βββ components/ # React components
β βββ lib/ # Utilities & configs
β βββ ...
βββ dist/ # Built assets
βββ ...
/desktop # Electron desktop build
βββ main.js # Electron main process
βββ package.json # Desktop dependencies
βββ ...
/mobile # Capacitor mobile build
βββ capacitor.config.json
βββ ...
/relayer # Backend relayer service
βββ server.js # Express server
βββ ...
/scripts # Deployment & utility scripts
βββ deploy-all.js # Full deployment script
-
Network Switching Demo
- Show network selector dropdown
- Switch between BlockDAG, Sepolia, Ethereum
- Demonstrate automatic address loading
-
Lending/Borrowing Flow
- Connect MetaMask wallet
- Deposit RWA tokens as collateral
- Borrow dUSD stablecoins
- View real-time balances
-
Yield Farming
- Lend dUSD tokens
- View APY calculations
- Demonstrate yield strategies
-
Governance
- Create proposals
- Vote on proposals
- Execute approved proposals
-
Cross-Platform
- Show desktop app
- Demonstrate mobile responsiveness
- Highlight Vercel deployment
- β Multi-network support with automatic switching
- β EIP-712 delegated signing for security
- β Cross-platform compatibility (Web/Desktop/Mobile)
- β Real-time balance updates
- β Comprehensive error handling
- β TypeScript-ready architecture
- β Test token integration for demo purposes
// Your test token addresses are configured in:
frontend/src/lib/addresses.js (BlockDAG network)
// Main test tokens: 0xdE5F720670C02e5542376bD3e7163529ef5c958c
// Test token 1: 0x7679C988FFb52F7B513AE22d7845e7BAA38Bdd93
// Test token 2: 0x7679C988FFb52F7B513AE22d7845e7BAA38Bdd93
// Test token 3: 0xc95961Daa5581fd7C184CDB2Cb1B35f471E0710A
// Test token 4: 0x073Fc0d656B3714B3087ac24d283f9d05fd819b8# Full development setup
npm run dev # Start all services
# Individual services
npm run frontend:dev # Frontend only
npm run relayer:start # Relayer only
# Build commands
npm run frontend:build # Build frontend
npm run build:desktop # Build desktop app
npm run build:mobile # Build mobile app
# Deployment
npm run deploy:all # Deploy all contracts
vercel --prod # Deploy to VercelAfter deployment, addresses are automatically saved to:
frontend/src/lib/addresses.js(Frontend config).env(Environment variables)
Example deployed addresses:
LENDINGPOOL_ADDRESS=0x1234...
YIELDROUTER_ADDRESS=0x5678...
RWAREGISTRY_ADDRESS=0x9abc...
GOVERNANCE_ADDRESS=0xdef0...
- Fork the repository
- Create feature branch (
git checkout -b feature/amazing-feature) - Commit changes (
git commit -m 'Add amazing feature') - Push to branch (
git push origin feature/amazing-feature) - Open Pull Request
This project is licensed under the MIT License - see the LICENSE file for details.
For questions or issues:
- Create an issue on GitHub
- Join our Discord community
- Check the documentation
Built with β€οΈ for BlockDAG Hackathon