Bounty to Hacxyk for fallback oracle misconfiguration
Simple Summary
This proposal releases the 50โ000 USDC pre-approved by the Aave community on forum and Snapshot to the Hacxyc team, for their finding concerning a misconfiguration on Aave v3 fallback oracle.
Abstract
During the past month of April, the security firm Hacxyk disclosed to the Aave community a misconfiguration on the fallback oracle used for Aave v3 pools across markets. This disclosure was analysed from a technical perspective and a bounty proposed to the Aave community to approve HERE. After having support in both forum and Snapshot, this on-chain proposal will release the pre-approved 50โ000 USDC to Hacxyk.
Relevant links
-
Governance discussion: https://governance.aave.com/t/bgd-proposal-for-bounty-fallback-oracle-misconfiguration/8421
-
Snapshot vote: https://snapshot.org/#/aave.eth/proposal/0xb4886ff25f454773a779be3627863181ec7dbe1fb6b6e631678610dbe3f03a88
Implementation
This proposal exclusively releases 50โ000 USDC from the Aave V2 Ethereum collector, to the Ethereum account provided by the Hacxyk team.
The implementation can be found on https://github.com/bgd-labs/aip-hacxyk-bug-bounty/blob/main/src/contracts/PayloadBountyHacxykFallbackOracle.sol
Simple tests can be found on https://github.com/bgd-labs/aip-hacxyk-bug-bounty/blob/main/test/PayloadBountyHacxykFallbackOracle.t.sol
Target Contracts
PayloadBountyHacxykFallbackOracle = https://etherscan.io/address/0xF4294973B7E6F6C411dD8A388592E7c7D32F2486#code
Copyright
Copyright and related rights waived via CC0.
| Voter | Cast Power | Vote & Rationale |
|---|---|---|
0xaFDA...353a6E | 93,460 | YAE |
0xdd45...B74Cc5 | 65,498 | YAE |
0x683a...D26C02 | 62,743 | YAE |
0xFe23...9bE636 | 48,741 | YAE |
0x36C4...bE2A8A | 41,364 | YAE |
VOTE POWER
Proposal Status
- Published Onchain
0xf71f...c61E02
- Thu July 07 2022, 02:26 pmVoting Period Starts
- Sun July 10 2022, 01:34 pmEnd Voting Period
- Sun July 10 2022, 04:13 pmQueue Proposal
- Wed July 13 2022, 03:03 pmExecute Proposal
Current Results
1-YAE
362,190.8
2-NAY
N/A Tokens
