hackquest logo

DemocraFund

What if public money could only move with public agreement? DemocraFund is a fully working, deployed system for transparent public tendering. It puts the whole lifecycle of a public project on the blockchain: the bids, the votes, the award, and every payment. Money only leaves the system in stages, and only when the right people cryptographically sign that the work is actually done. Not the committee alone, not the builder alone, not even the administrator alone. Everyone can see every decision the moment it happens, and nobody can move a token without the system's approval. It runs today on Arbitrum Sepolia, piloted with Humewood Golf Club, with 151 automated tests behind it. The result is simple to state: the oversight is no longer a report written after the money moved. It is the machine that moves the money, and it only accepts the public's agreement as the key.

ビデオ

テックスタック

Next
Solidity

説明

The problem

In South Africa, public tenders are awarded through paper trails that almost nobody sees. A department announces a project, a contractor is chosen, and a lump sum is transferred. Whether the money reached the work, whether the winner was chosen on merit, and whether the work was actually done are questions answered, if at all, months later and behind closed doors. Corruption in this system is not mostly about bad people. It is about a structure where no single decision can be checked by anyone who isn't inside it.

The idea

DemocraFund puts the entire lifecycle of a public project on a public blockchain. The bid, the vote, the award, the milestone approvals, and every payment run through smart contracts that enforce the rules automatically. Nobody can be trusted and nobody needs to be, because the system enforces transparency and multi-party approval at every step.

We built and deployed a working MVP on Arbitrum Sepolia, piloted with Humewood Golf Club, where club members play citizens, the club committee plays government, and club improvements play public projects. The architecture is deliberately built so the jump from golf club to municipality is configuration, not a rewrite.

How a project flows through the system

  1. A tender goes on-chain. An authorised committee member creates a tender with a budget ceiling, a department tag, a specification, and supporting documents hashed to IPFS. The tender is public from the first second.

  2. Companies bid. Registered companies submit priced proposals broken into milestones. Each milestone has its own payment amount, and the contract enforces that the milestones sum exactly to the bid. Bids are public, so everyone sees who bid and for what.

  3. Citizens vote. Members vote for the proposal they want. One person, one vote, recorded permanently on-chain. The voting window is time-enforced in the contract, so it can neither be extended by convenience nor closed early to rush a decision.

  4. The award is bound to the votes. The top proposals by vote count form a shortlist, fixed on-chain. The committee can choose any shortlisted bidder, preserving legitimate discretion, but it cannot award a proposal the citizens didn't put in the running. An unvoted choice is structurally impossible.

  5. The money goes into a vault that pays in stages. The moment a proposal is awarded, a new escrow contract is deployed for that specific project and funded with the exact budget. This is the heart of the design. Instead of a lump sum, the money sits in a contract that only releases each milestone when the right people cryptographically sign that the work for that stage is actually done: a committee administrator, the builder, and at least one randomly selected community member drawn via Chainlink VRF. No single person, not even the administrator, can move a single token alone.

  6. The community is drawn, not appointed. Members opt in to a committee pool. If enough opt in, a verifiable random draw (Chainlink VRF) selects the three community members and two alternates who approve milestone releases. The committee is never chosen by the administrator. It is chosen by randomness and public opt-in.

  7. Work is released stage by stage, against evidence. The builder submits proof of completion (photos, invoices, hashed on-chain) and the signers independently verify it before approving. Payment happens in the same transaction as the final approval. No second step, no stalling point.

  8. Off-ramp leaves a permanent receipt. The builder redeems their tokens for real money through a redemption contract that burns the tokens and mints a transferable receipt NFT. A paying authority marks the receipt paid once the fiat transfer lands. The result is a permanent, public chain that runs from the original tender, through the vote and award, through every milestone signature, to the bank payout.

Why this is different

The normal way to fight corruption is oversight after the fact: audits, inspectors, investigations. DemocraFund makes the oversight the mechanism itself. Every decision is public at the moment it happens, and the money physically cannot move past a stage that the required people have not signed. It isn't a report about where the money went. It is the machine that decides where the money goes, and the machine only accepts the public's agreement as the key.

The transparency is also automatic. Every vote, every signature, every payment is on a public block explorer, linked in a plain-language app view. Anyone can verify any claim about any project in minutes.

The components

  • PaymentToken (HZAR): the project currency, an ERC-20 that behaves like a stablecoin, minted exactly when a project is awarded and burned when money leaves the system, so supply tracks real money 1:1.

  • CompanyRegistry: permissionless company self-registration. Each company has one on-chain identity wallet, and only that wallet can bid.

  • ProjectFactory: the single entry point for creating tenders. It holds platform policy (minimum durations, fee caps) and the shared VRF configuration.

  • ProjectGovernance: one per tender. It runs the lifecycle state machine, collects votes, fixes the shortlist, and triggers the random committee draw.

  • ProjectEscrow: one per awarded project, deployed as a minimal proxy clone. It holds all the money and is a multisig that verifies EIP-712 signatures, so approvals work with regular wallets and future smart wallets alike. All fund movement happens here, and a strict accounting invariant is fuzz-tested continuously.

  • Redemption: the off-ramp where tokens are burned and receipt NFTs are minted as proof, then certified paid by a paying authority.

Built properly

151 automated tests cover the release rules for every committee size, signature correctness including ERC-1271 smart wallets, cancellation paths, the accounting invariants under random action sequences, and full end-to-end journeys. The contracts are formatted, documented, and verified on the testnet block explorer. The system runs on a public chain with the exact deployment configuration used by real Chainlink VRF.

ハッカソンの進行状況

Went well, happy with it.

資金調達の状況

No funding
チームリーダー
GGareth Larkan
プロジェクトリンク
業界
SocialFiDeFiDAO