Home / News / Bounty - ICDevs.org Big SHA256

Austin Fatheree, February 22 2022

Big SHA256-KECCAK - #14

Current Status: Freezer

This Bounty has been put in the freezer due to completion elsewhere: https://forum.dfinity.org/t/completed-dfinity-bounty-4-keccak-256-and-sha3-motoko-library-2000-in-icp/18469/22

  • Discussion (02/22/2022)
  • Ratification
  • Open for application
  • Assigned
  • In Review
  • Closed

Forum Link - Discussion

Bounty Details

  • Bounty Amount: $4,000 USD of ICP at award date.
  • ICDevs.org Acceleration: For every ICP sent to 1a25118faf5e325df52b38ff021560e6e0232b816f6526eb575156a6cb5f1ce1, ICDevs.org will add .25 ICP to this issue and .75 ICP to fund other ICDevs.org initiatives for each 1 ICP donated
  • Project Type: Single Contributor
  • Opened: 02/20/2022
  • Time Commitment: Days
  • Project Type: Library
  • Experience Type: Intermediate - Motoko
  • Issue Type: Motoko Library


This bounty gives the opportunity to

  • learn how sha256 works
  • learn how keccak works(Ethereum Hashing)
  • learn advanced motoko parsing and type management
  • learn about cycle management and multi step processes

The goal of this bounty is to create a workflow for calculating a sha256 and keccak in motoko for very large files or data structures. SHA256 is a cryptographic hash function that outputs a value that is 256 bits long for a given data that can be verified by other processes that have access to the data. Keccak is a hash algo used in calculating hashes on the EVM.

More info about SHA256 can be found at:


More info about Keccak can be found at https://keccak.team/specifications.html

We already have a SHA256 library/crypto libraries for motoko at:

https://github.com/enzoh/motoko-sha https://github.com/aviate-labs/crypto.mo

The current library currently fails if the data passed in is too large. The canister will run out of cycles.The developer will need to create a library to support computing the hash over large data arrays. You will need to use a library like Pipelinify.mo. Using pipelinify is not required if another, better method is available. The bounty applicant may also enhance pipelinify.mo for their needs.

The library will need to provide the following functions(or equivalent with a different multi-step processing library):

sha256_bytes([Nat8]) -> Pipelinify.ProcessResponse; //sets up a sha process for a large Nat8 array
sha256_blob(Blob) -> Pipelinify.ProcessResponse; //sets up a sha process for a blob
sha256_datazone(Buffer<Buffer<Nat8>>) -> Pipelinify.ProcessResponse; //sets up a sha process for a buffer of byte buffers

sha256_process(Pipelinify.StepRequest) -> Result<ProcessResponse,ProcessError>; //executes a step

sha256_result(Pipelinify.ProcessingStatusRequest) -> [Nat8];

clear_cache(?Pipelinify.ProcessingStatusRequest) -> bool; //clean out any pipelinify cache for a status request, or the entire cache if null

keccak_bytes([Nat8]) -> Pipelinify.ProcessResponse; //sets up a sha process for a large Nat8 array
keccak_blob(Blob) -> Pipelinify.ProcessResponse; //sets up a sha process for a blob
keccak_datazone(Buffer<Buffer<Nat8>>) -> Pipelinify.ProcessResponse; //sets up a sha process for a buffer of byte buffers

keccak_process(Pipelinify.StepRequest) -> Result<ProcessResponse,ProcessError>; //executes a step

keccak_result(Pipelinify.ProcessingStatusRequest) -> [Nat8];

clear_cache(?Pipelinify.ProcessingStatusRequest) -> bool; //clean out any pipelinify cache for a status request, or the entire cache if null

The developer will need to experiment with process chunking strategies and make recommendations about how much data can be processed during one process cycle. Hopefully, we can remove this requirement once deterministic time slicing is integrated.

The final delivery should include test cases for both single step and multistep calculation.

The output of this library will be important for future bounties around calculating EVM witnesses.

The package should be deployed as a vessel package.

To apply for this bounty you should:

  • Include links to previous work writing tutorials and any other open-source contributions(ie. your github).
  • Include a brief overview of how you will complete the task. This can include things like which dependencies you will use, how you will make it self-contained, the sacrifices you would have to make to achieve that, or how you will make it simple. Anything that can convince us you are taking a thoughtful and expert approach to this design.
  • Give an estimated timeline on completing the task.
  • Post your application text to the Bounty Thread

Selection Process

The ICDevs.org developer’s advisors will propose a vote to award the bounty and the Developer Advisors will vote.

Bounty Completion

Please keep your ongoing code in a public repository(fork or branch is ok). Please provide regular (at least weekly) updates. Code commits count as updates if you link to your branch/fork from the bounty thread. We just need to be able to see that you are making progress.

The balance of the bounty will be paid out at completion.

Once you have finished, please alert the dev forum thread that you have completed work and where we can find that work. We will review and award the bounty reward if the terms have been met. If there is any coordination work(like a pull request) or additional documentation needed we will inform you of what is needed before we can award the reward.

Bounty Abandonment and Re-awarding

If you cease work on the bounty for a prolonged(at the Developer Advisory Board’s discretion) or if the quality of work degrades to the point that we think someone else should be working on the bounty we may re-award it. We will be transparent about this and try to work with you to push through and complete the project, but sometimes, it may be necessary to move on or to augment your contribution with another resource which would result in a split bounty.


The bounty was generously funded by the DFINITY Foundation. If you would like to turbocharge this bounty you can seed additional donations of ICP to 1a25118faf5e325df52b38ff021560e6e0232b816f6526eb575156a6cb5f1ce1. ICDevs will match the donation 0.25 ICP to this bounty and 0.75 ICP to other ICP Activities. All donations will be tax deductible for US Citizens and Corporations. If you send a donation and need a donation receipt, please email the hash of your donation transaction, physical address, and name to donations@icdevs.org. More information about how you can contribute can be found at our donations page.

General Bounty Process


The draft bounty is posted to the DFINITY developer’s forum for discussion


The developer advisor’s board will propose a bounty be ratified and a vote will take place to ratify the bounty. Until a bounty is ratified by the Dev it hasn’t been officially adopted. Please take this into consideration if you are considering starting early.

Open for application

Developers can submit applications to the Dev Forum post. The council will consider these as they come in and propose a vote to award the bounty to one of the applicants. If you would like to apply anonymously you can send an email to austin at icdevs dot org or sending a PM on the dev forum.


A developer is currently working on this bounty, you are free to contribute, but any splitting of the award will need to be discussed with the currently assigned developer.

In Review

The Dev Council is reviewing the submission


The award has been given and the bounty is closed.

Other ICDevs.org Bounties