Comet Vulnerability Disclosure (Patched) - Bug Bounty Program Reward
This is a resubmission of proposal #202 with a lower bug bounty reward amount which I believe to be in line with the DAO’s wishes, given the closeness of reaching quorum for the previous amount.
A heartfelt thank you to she256, PGov, Wintermute, and a16z for having voted in favor of proposal #202. While the proposal did not pass, your support did not go unnoticed and will not be forgotten by myself nor the broader community.
Background
NOTE: The vulnerability has been patched and no user funds are at risk.
For the full details and context related to the vulnerability disclosure, as well as discourse between the OpenZeppelin and Compound Labs teams, and Compound community members, please see here.
On November 13th, I had disclosed a vulnerability for the Base Comet WETH market’s smart contracts which would have enabled an attacker to directly steal user funds via the withdraw and transfer methods. I was given the blessings from the OpenZeppelin and Compound Labs teams in making this proposal for the purposes of proposing a reward for my professionalism and collaboration in addressing the vulnerability.
Bug Bounty Program Reward
Leaning on the support from the OpenZeppelin and Compound Labs teams and other Compound community members (such as experienced security researcher Daniel Von Fange) for guidance and their assessment of reward fairness, I would like to make a humble ask for ~33% less than the maximum Compound Bug Bounty Program reward: $100,000 worth of COMP tokens, at $55.82 per COMP, rounded down; the COMP price was sourced from Etherscan (publicly and freely accessible) at 10:30am EST on December 9, 2023.
I am sincerely appreciative of the opportunity to have collaborated alongside the best teams and individuals in discussing and remedying this vulnerability, and look forward to continuing my contributions both as a Compound builder and vigilant community member.
Thank you very much for both your time and consideration.
| Voter | Cast Power | Vote & Rationale |
|---|---|---|
0x9AA8...62cCF1 | 256,017 | FOR |
0x8d07...e6A265 | 70,006 | FOR |
Wintermute Governance | 53,926 | FOR |
0x2B38...77bf33 | 32,509 | AGAINST |
0x3FB1...2d4C8A | 25,550 | FOR |
VOTE POWER
Proposal Status
- Mon December 11 2023, 11:55 amVoting Period Starts
- Thu December 14 2023, 06:11 amEnd Voting Period
- Thu December 14 2023, 06:12 amQueue Proposal
- Sat December 16 2023, 06:14 amExecute Proposal
Current Results
1-FOR
432,444.4
2-AGAINST
32,509.145
3-ABSTAIN
N/A Tokens
