FeedProjects
Developers
Settings
🎉 A new chapter begins: Boardroom has joined Agora
Learn more
protocol logo
Explore / Projects
Arbitrum

Proposals

Discussions

Members

Information

Create Proposal

Arbitrum

ProposalsDiscussionsMembersInformation
Proposal
Back to Proposals
closedEnded a year ago ·  Onchain

Ethereum Protocol Attackathon Sponsorship

By 0xF92F...1E37B4

Abstract

This proposal seeks funding from the Arbitrum DAO to support an Attackathon, a large-scale security audit event hosted by the Ethereum Foundation and Immunefi. The Attackathon will focus on securing the Ethereum protocol with three key phases: education, active bug hunting, and result evaluation. The initiative aims to raise over $2 million, with $500,000 already committed by the Ethereum Foundation. This effort is crucial for ensuring Ethereum’s stability, which is vital to maintaining the reliability of projects on Arbitrum.

Motivation

As a Layer 2 on Ethereum, Arbitrum is directly dependent on the security of the Ethereum protocol. Given that Arbitrum is EVM-compatible, any vulnerabilities in Ethereum could potentially impact Arbitrum’s ecosystem. This Attackathon is particularly timely given the recent major Ethereum hard forks, which have introduced new code that requires careful auditing.

Additionally, the Attackathon will include an educational program featuring live technical walkthroughs and detailed documentation from Ethereum Foundation, client teams, Solidity developers, and Immunefi. This program will cater to security researchers at all levels, helping to build a stronger security community around both Ethereum and Arbitrum. The increased awareness and participation in Ethereum’s security will ultimately benefit Arbitrum by ensuring a more secure underlying infrastructure.

Rationale

The Attackathon aligns with Arbitrum’s mission to support a secure and scalable Ethereum ecosystem. By contributing to this initiative, Arbitrum will directly enhance Ethereum’s security, which supports the reliability of Arbitrum. Moreover, the educational component will upskill security researchers, giving them the tools to audit and secure both the Ethereum and Arbitrum ecosystems.

Additionally, Arbitrum will benefit from increased visibility as a proactive participant in Ethereum security efforts, enhancing its credibility and reputation among developers, users, and security researchers. By sponsoring the Attackathon, Arbitrum positions itself as a leader in the ecosystem, contributing to long-term sustainability and security.

Detailed Financial Justification

The goal of securing $2M in total funding aligns with other major security audits in the blockchain ecosystem. Comparable initiatives include:

  • MakerDAO contest on Sherlock: $1.35M
  • Euler contest on Cantina: $1.25M
  • Uniswap v4 contest on Cantina: $2.35M
  • Firedancer contest on Immunefi: $1M

The Attackathon funding goal reflects the importance of thoroughly securing Ethereum’s core protocol. With $500,000 already committed by the Ethereum Foundation, additional sponsorship from Arbitrum DAO will help us reach this $2M target, ensuring participation from top-tier security researchers and maximizing the event’s impact.

Outcome Metrics

By setting clear goals for participation, reports submitted, and transparency, we can effectively track the impact of the Attackathon. Key outcome metrics include:

  • Secure over 100 security researcher signups before the program’s launch.
  • Achieve participation from over 100 distinct individuals submitting reports.
  • Submit more than 150 reports by the conclusion of the Attackathon.
  • Publish an audit-style report summarizing findings for the Arbitrum and Ethereum communities.

These metrics will demonstrate the program’s effectiveness in attracting top security talent and identifying critical vulnerabilities across both ecosystems.

Community Feedback Loop

To ensure transparency and alignment with community expectations, we will provide regular updates on the Attackathon’s progress through Arbitrum forums and governance channels. These updates will include detailed reports on fund usage, security vulnerabilities identified, and overall outcomes. Community feedback will be encouraged through these platforms to maintain alignment with the community’s goals and priorities.

Breakdown of Expenditures

100% of the funds raised from Arbitrum and other sponsors will be allocated to security researcher payouts based on the severity of the bugs they find. Immunefi has waived their usual fees for this event, so all funds will be directly used for researcher rewards. If any funds remain after the Attackathon, they will be rolled over to an audit contest focused on securing the Pecta hardfork.

Estimated Timeline

  • November 20: Detailed program announcement and education kickoff
  • November 27: Attackathon hunting begins
  • January 22: Attackathon concludes and results compilation begins
  • January 23: Review period begins
  • Late March: Results announced

Overall Cost

The Arbitrum DAO is invited to sponsor the Attackathon with a $100,000 USD commitment, payable in ETH, ARB, or USDC. This sponsorship includes:

  • 1x Unique NFT with leaderboard rank
  • Leaderboard listing on the sponsor landing page
  • Mid-roll logo placement on Sponsor and Program Landing Page
  • An Arbitrum Boost (Audit Contest) on Immunefi with up to a $100K rewards pool at 100% Immunefi Discount within 180 days of the conclusion of the Ethereum program
  • 1x Dedicated Twitter post announcing sponsorship from Immunefi Twitter handle

By supporting the Attackathon, Arbitrum will leverage the event’s findings to ensure its network remains secure and robust. This initiative not only enhances security but also demonstrates Arbitrum’s commitment to the broader Ethereum ecosystem.

Multi-Sig Address for DAO Deposit

To deposit the funds, the Arbitrum DAO can use the following multi-sig address: 0x022ec7543BfB377BbEB6676E5ba5Ecf3950dA889

Continue Reading
Connect Wallet to Add Note
0
Votes 413
VoterCast PowerVote & Rationale
0x1B68...88eeaD
17.735M

AGAINST

0x11cd...3e3A8F
15.149M

AGAINST

Wintermute Governance
13.697M

AGAINST

0xAD16...0C6144
7.477M

AGAINST

0x8326...8FF3fE
1.472M

AGAINST

SHOW MORE
VOTE POWER
0
Connect Wallet
Proposal Status
  • Tue September 17 2024, 03:58 amPublished Onchain 0xF92F...1E37B4
  • Fri September 20 2024, 04:24 amVoting Period Starts
  • Fri October 04 2024, 05:54 amEnd Voting Period
  • Queue Proposal
  • Execute Proposal
Current Results

1-AGAINST

58.765M

98.3%

2-ABSTAIN

991,526.56

1.66%

3-FOR

25,789.857

0.04%
DocumentationBrandingContact Us
Home
This Project is Currently Disabled

If you would like to enable it, please checkout below.

Boardroom Subscription

Sign up for an individual subscription (access all projects on the platform)

Subscribe
Enable Project

Enable the entire project for every user

Enable Project
Contact Us