FeedProjects
Developers
Settings
🎉 A new chapter begins: Boardroom has joined Agora
Learn more
protocol logo
Explore / Projects
Compound

Insights

Proposals

Discussions

Members

Information

Reports

Create Proposal

Compound

InsightsProposalsDiscussionsMembersInformationReports
ProposalExecutable Code
Back to Proposals
closedEnded 2 years ago ·  Onchain

Comet Vulnerability Disclosure (Patched) - Bug Bounty Program Reward

By 0x9c9d...79B429

Background

NOTE: The vulnerability has been patched and no user funds are at risk.

For the full details and context related to the vulnerability disclosure, as well as discourse between the OpenZeppelin and Compound Labs teams, and Compound community members, please see here.

On November 13th, I had disclosed a vulnerability for the Base Comet WETH market’s smart contracts which would have enabled an attacker to directly steal user funds via the withdraw and transfer methods. I was given the blessings from the OpenZeppelin and Compound Labs teams in making this proposal for the purposes of proposing a reward for my professionalism and collaboration in addressing the vulnerability (in line with the Compound Bug Bounty Program payout range).

Bug Bounty Program Reward

Leaning on the support from the OpenZeppelin and Compound Labs teams and other Compound community members (such as experienced security researcher Daniel Von Fange) for guidance and their assessment of reward fairness, I would like to make a humble ask for ~20% less than the maximum Compound Bug Bounty Program reward: $125,000 (denominated in various assets from the Compound Timelock, using Etherscan as a publicly-accessible pricing source for non-stable assets, as of 7:30pm EST, Monday, December 4, 2023). All stable assets prices are fixed at $1.00.

|Asset | Units | Unit Price ($) | Value ($)|

|— | — | — | —|

|REPv2 | 515.49 | $0.703079 | $362.430194|

|USDT | 500 | $1.00 | $500.00|

|DAI | 740.40 | $1.00 | $740.40|

|BAT | 3,505.14 | $0.245071 | $859.008165|

|FEI | 6,324.34 | $1.00 | $6,324.34|

|UNI | 2,245.19 | $6.13 | $13,763.01|

|USDC | 50,000.00 | $1.00 | $50,000.00|

|ETH | 23.50 | $2,238.74 | $52,610.39|

| |  | Total | $125,159.58|

The table above has been verified to be formatted correctly on comp.xyz. If it is not displaying it correctly, please reference the following Google Docs spreadsheet (identical data).

I am sincerely appreciative of the opportunity to have collaborated alongside the best teams and individuals in discussing and remedying this vulnerability, and look forward to continuing my contributions both as a Compound builder and vigilant community member. Thank you very much for both your time and consideration.

Continue Reading
Connect Wallet to Add Note
0
Votes 10
VoterCast PowerVote & Rationale
0x9AA8...62cCF1
256,017

FOR

Wintermute Governance
53,926

FOR

0xB49f...EC7948
50,004

ABSTAIN

0xed11...a5bb04
50,003

FOR

0x13BD...138548
50,000

ABSTAIN

SHOW MORE
VOTE POWER
0
Connect Wallet
Proposal Status
  • Tue December 05 2023, 12:50 amPublished Onchain 0x9c9d...79B429
  • Wed December 06 2023, 09:03 pmVoting Period Starts
  • Sat December 09 2023, 03:22 pmEnd Voting Period
  • Queue Proposal
  • Execute Proposal
Current Results

1-FOR

385,494.94

71.48%

2-ABSTAIN

100,004.03

18.54%

3-AGAINST

53,794.55

9.98%
Quorum 539,293.52/400,000
DocumentationBrandingContact Us