VeraCred — Hackathon Submission Pitch

Inspiration

Academic credential fraud is a billion global problem. In Kenya alone, over 1,200 fake certificates were uncovered in a single government audit. Across Africa and emerging markets, employers waste weeks sending emails to registrar offices — emails that often go unanswered. Meanwhile, fake degrees circulate freely, undermining meritocracy and damaging institutions that worked hard to build their reputation.

We asked a simple question: what if you could verify a degree the same way you verify a crypto transaction — instantly, publicly, and without trusting any single authority?

That question became VeraCred.

We were also inspired by the W3C Verifiable Credentials standard and the promise of Self-Sovereign Identity (SSI) — the idea that individuals should own their data, not governments or corporations. Combining this with Polygon's low-cost, high-speed L2 blockchain gave us the perfect foundation to build something genuinely useful.


What It Does

VeraCred is a decentralized academic credential wallet built on Polygon. It replaces the broken, paper-based verification process with a cryptographically guaranteed, blockchain-anchored system.

There are three roles:

🎓 Issuers (Universities / Institutions)

  • Connect their MetaMask wallet (registered by the VeraCred admin)
  • Fill in student details, credential type, and field of study
  • The credential document is uploaded to IPFS; only the SHA-256 hash + CID are anchored on-chain
  • Cost: ~.001 per credential on Polygon

👤 Students (Holders)

  • Connect their wallet to view their personal credential wallet
  • See all credentials issued to their address
  • Generate a QR code or shareable link to send to employers
  • Own their credentials permanently — even if their university closes

🏢 Employers / Verifiers (Anyone)

  • Paste a credential ID or scan a QR code
  • VeraCred queries the Polygon smart contract and compares the cryptographic hash
  • Result in under 3 seconds: ✅ VALID, ❌ REVOKED, ⚠️ EXPIRED, or 🚫 TAMPERED
  • No account needed. No fees. Fully permissionless.

How We Built It

Smart Contract Layer — Solidity on Polygon

The core of VeraCred is the VeraCred.sol smart contract, built with:

  • Solidity 0.8.24 + OpenZeppelin (Ownable, Pausable, ReentrancyGuard)
  • An Issuer Registry: only VeraCred-admin-approved institutions can issue credentials
  • A Credential Store: each credential is keyed by a unique ytes32 ID derived from keccak256(issuer + holder + hash + timestamp + nonce)
  • Hash verification: the contract stores a SHA-256 hash of the credential document; verification compares the presented document's hash against the on-chain record — any tampering produces a mismatch
  • Revocation: only the original issuing institution can revoke their own credentials
  • Full event emission for all state changes (CredentialIssued, CredentialVerified, CredentialRevoked)

Contract Infrastructure

  • Hardhat for local development, testing, and deployment
  • Polygon Amoy Testnet for staging deployments

- Auto-generates deployment.json with the contract address for the frontend on every deploy

Challenges We Ran Into

  1. Hash consistency across environments — Computing the SHA-256 hash of a credential document consistently on both the frontend (Web Crypto API) and in Solidity required careful byte encoding. We had to ensure the same encoding was used when issuing and when verifying, or the hash would never match.

  2. Wagmi v3 breaking changes — Wagmi v3 introduced significant API changes from v2. Several hooks we initially used were deprecated. Migrating our contract read/write hooks and correctly handling useAccount, useReadContract, and useWriteContract took considerable debugging time.

  3. MetaMask + Hardhat local network — Getting MetaMask to consistently connect to the local Hardhat node (chain ID 31337) required resetting the account nonce frequently during development, which slowed early iteration.

  4. IPFS in a hackathon timeframe — A true IPFS integration with Pinata requires API keys and async pinning. We built a mock IPFS service that simulates CID generation deterministically so the full flow works end-to-end without external dependencies during judging.

  5. Designing for three distinct user roles in one app — Keeping the UX clean for issuers, holders, and verifiers — each with very different mental models — without making the interface feel cluttered was a real design challenge.


Accomplishments That We're Proud Of

  • ✅ A fully working end-to-end flow — Issue → Hold → Share → Verify — all on-chain, all in the browser
  • ✅ A production-quality smart contract with 7 comprehensive test cases covering issuance, tamper detection, revocation, expiry, and access control — all passing
  • ✅ Sub-3-second verification with full cryptographic proof, no centralized server involved
  • ✅ QR code sharing — a student can generate a scannable link that takes any employer directly to the verification result
  • ✅ Deployed and live on Vercel + Polygon Amoy Testnet
  • ✅ A design system built from scratch in Vanilla CSS — responsive, dark-mode-ready, and polished enough to present to a real institution

What We Learned

  • Blockchain state is permanent — designing around immutability forces you to think more carefully about data modelling. We learned to separate "what goes on-chain" (hashes, addresses, timestamps) from "what goes off-chain" (the actual documents on IPFS).
  • W3C Verifiable Credentials are a powerful standard that the industry is converging on. Aligning VeraCred with the DID + VC model early made the architecture much cleaner.
  • UX in Web3 is still hard. Wallet connection, network switching, and transaction confirmations are friction points that mainstream users aren't used to. We tried to abstract as much of this away as possible.
  • Polygon is genuinely cheap. At ~.001 per credential issuance, a university could issue 10,000 credentials for . That changes the economics of the entire problem.
  • Hackathon scoping is everything. We initially planned Soulbound Tokens (SBTs), Web3Auth social login, and a Pinata integration. We shipped the mock IPFS and kept the core flow solid instead — the right call.

What's Next for VeraCred

Milestone Description
🔗 Soulbound Tokens (SBTs) Issue credentials as non-transferable ERC-5114 tokens for added permanence
📦 Pinata IPFS integration Replace mock IPFS with real Pinata pinning for production document storage
🔑 Web3Auth social login Allow students to log in with Google/email without needing a crypto wallet
🌍 Multi-chain support Expand to Ethereum mainnet, Base, and other L2s
🏛 Institution onboarding portal A self-service portal for universities to apply for issuer status
📱 Mobile wallet app React Native app so students can carry credentials on their phone
🤝 Employer API REST API so companies can integrate VeraCred verification into their ATS/HR systems
🇳🇬 Africa-first partnerships Pilot with Nigerian and Kenyan universities facing the most acute fraud problems

Built With

  • code
  • for
  • framework
  • generation
  • in
  • integration
  • no
  • pinata
  • qr
Share this project:

Updates

Submission history