FeedProjects
Developers
Settings
🎉 A new chapter begins: Boardroom has joined Agora
Learn more
protocol logo
Explore / Projects
Aave

Insights

Proposals

Discussions

Members

Information

Reports

Create Proposal

Aave

InsightsProposalsDiscussionsMembersInformationReports
Proposal
Back to Proposals
closedEnded 2 years ago · Snapshot (Offchain)

[ARFC]. BGD. Aave v3.1 Cantina competition

By 0xf71f...c61E02

 

Simple summary

Proposal for the Aave DAO to have a Cantina security competition for the upcoming Aave v3.1 upgrade, to complement the other security procedures already completed. The budget will be a total of $195’000, with $150’000 prize pool and the rest ($45’000) allocated to platform and judging fees.

 

Motivation

With the Aave v3.1 upgrade well received by the community, and now entering into its final stages of pre-activation governance procedures, from the BGD side we have been thinking on how to add even more security assurances, in addition to what was already done and described HERE.

Open security competitions/contests are getting important adoption as a good pre-production mechanism: a scope is defined for some public code, and any security researcher can look into it for a limited period of time, in order to the prizes from a common prize pool. The more bugs found (and more unique, amongst other characteristics of the finding), the better the rewards.

We think that a competition can have extra security value for the improvements included into Aave v3.1, and after evaluating different solutions in the market, we have decided that doing an open Cantina competition fits into our requirements.

 

Specification

After discussions with their team regarding options, we propose to create a Cantina competition with the following characteristics:

  • $150’000 total prize pot, with the following limitations:

    • If there is any High (highest grade) finding, the whole $150’000 prize pot will be distributed.
    • If there is only Medium or lower grade findings, $50’000 prize pot will be distributed.
    • If there is only Lower/Informational, $20’000 prize pot will be distributed.

    The total of funds will be transferred initially to Cantina, and if applicable reimburse afterwards to the Aave DAO contracts.

  • 20% fees over the total prize pot, amounting $30’000. Additional $15’000 for Cantina judging.

  • The competition will last for 10 calendar days.

  • Start of the competition will depend on governance procedures timing, but if all are approved, the target will be beginning of the week of May 6th.

  • Before the start, BGD Labs will collaborate with Cantina to have the best possible setup for researchers to tackle the competition, including but not limited to all required extra documentation. During the competition, we will also give all necessary support.

  • The execution of the on-chain AIP proposal will act as a binding agreement between the Aave DAO and Cantina.

  • Only current or previous team members of BGD Labs and Certora, MixBytes (auditors of v3.1) during the last 6 months are non-eligible for any prizes in the competition, given the conflict of interest. Any other entity or individual is allowed to participate.

 

Next steps

  • In parallel to this Snapshot, we will start preparations for a positive outcome, including the AIP that will mark the final approval, releasing the funds.
Continue Reading
Connect Wallet to Add Note
0
Votes 544
VoterCast PowerVote & Rationale
0x57ab...112922
138,267

For

0xaFDA...353a6E
80,000

For

StableLab
40,054

For

EzR3aL
35,925

For

Wintermute Governance
24,243

For

SHOW MORE
VOTE POWER
0
Connect Wallet
Proposal Status
  • Mon April 29 2024, 08:34 amVoting Period Starts
  • Thu May 02 2024, 08:34 amEnd Voting Period
Current Results

1-For

375,446.639

2-Against

2.272

0%

3-Abstain

0.273

0%
DocumentationBrandingContact Us