FeedProjects
Developers
Settings
๐ŸŽ‰ A new chapter begins: Boardroom has joined Agora
Learn more
protocol logo
Explore / Projects
BeethovenX

Proposals

Members

Information

Create Proposal

BeethovenX

ProposalsMembersInformation
Proposal
Back to Proposals
closedEnded 2 years ago ยท Snapshot (Offchain)

BIP-60: Bug Bounty For Compromised Discord Link

By 0xa182...B13a1E

Introduction and Motivation

On January 5, 2024, going to the beets.fi website will provide a user with a warning if they are invested in a pool with a known vulnerability. The message reads: โ€œYou are invested in a pool with a known vulnerability. Please remove liquidity from the affected pool(s) immediately. Read moreโ€

โ€œRead moreโ€ links to the official Beethoven X Twitter which gives a message to check the Discord for a list of affected LPs.

The tweet displayed an outdated Discord link which in the meantime has been compromised.

Background

0xc74โ€ฆed2 discovered the compromised link when trying to view the the affected pools on the Beethoven discord. The server asked for verification but was really a transaction to transfer FTM as well as other tokens. Due to a sense of urgency to remove liquidity and the belief that the links were to and from a valid server, 0xc74โ€ฆed2 completed what was thought to be a verification signature.

TX: https://ftmscan.com/tx/0x37a2055311ba66bf53764e8c29b4a8f9eaf8564d2a0d0cc7bd2c87701f8fecc9

0xc74โ€ฆed2 found the official Discord server and reported the compromised link to franzns.

Tweets containing the outdated link have been removed as a precaution.

Proposal

This proposal, if adopted, will award 0xc74โ€ฆed2 a bug bounty for discovering and reporting the compromised link thereby preventing additional losses from future victims.

Bounty rationale Wide impact potential on users Prominent display on highly trafficked homepage Urgent message increases time pressure for users to act quickly to prevent loss of funds Vanity link from official Twitter account appears authoritative 0xc74โ€ฆed2 later helped identify other channels with the compromised link aiding in swift corrective action

Execution Plan

If approved, the Treasury will send the approved amount to an address of the bug reporter.

Continue Reading
Connect Wallet to Add Note
0
Votes 54
VoterCast PowerVote & Rationale
0x43C4...69a89d
2.815M

(1st) $1500, (2nd) $3000, (3rd) $5000, (4th) Vote against

0xBC85...67D384
731,989

(1st) $1500, (2nd) Vote against, (3rd) $3000, (4th) $5000

0xf903...6CfC83
682,424

(1st) $1500, (2nd) Vote against, (3rd) $3000, (4th) $5000

0xC6Eb...5b647E
355,323

(1st) Vote against, (2nd) $1500, (3rd) $3000, (4th) $5000

0x9abF...5fF983
302,916

(1st) $1500, (2nd) $3000, (3rd) $5000, (4th) Vote against

SHOW MORE
VOTE POWER
0
Connect Wallet
Proposal Status
  • Sun January 28 2024, 01:00 pmVoting Period Starts
  • Wed January 31 2024, 01:00 pmEnd Voting Period
Current Results

1-$1500

5.906M

90.1%

2-Vote against

384,442.706

5.87%

3-$5000

181,470.539

2.77%
DocumentationBrandingContact Us
Home
This Project is Currently Disabled

If you would like to enable it, please checkout below.

Boardroom Subscription

Sign up for an individual subscription (access all projects on the platform)

Subscribe
Enable Project

Enable the entire project for every user

Enable Project
Contact Us