FeedProjects
Developers
Settings
🎉 A new chapter begins: Boardroom has joined Agora
Learn more
protocol logo
Explore / Projects
Compound

Insights

Proposals

Discussions

Members

Information

Reports

Create Proposal

Compound

InsightsProposalsDiscussionsMembersInformationReports
ProposalExecutable Code
Back to Proposals
executedEnds a year ago ·  Onchain

Compound Bug Bounty Program with Immunefi

By 0x3FB1...2d4C8A

Summary

After working closely with many of Compound DAO’s delegates, Immunefi is working with PGov to bring our proposal to an onchain vote to further develop the existing bug bounty program for Compound and to host it on Immunefi’s platform. Our platform will provide access to industry-leading security researchers and will provide a greater long-term security that benefits Compound and its community.

During the development of the public proposals, we focused on providing a thorough bug bounty program while structuring the backend details such as the creation of the bounty program, deciding on the program administrators, the features of the subscription packaging, bug report reviews, and the validation and payment processes.

More details can be found in the two public proposals below:

First Proposal

Second Proposal/Update (includes scope of Compound’s bug bounty program)

Reward Structure and Fee

The bug bounty reward breakdown for the severity payout to the security researchers is as follows:

  • Critical: $50,000 - $1,000,000
  • High: $10,000 - $50,000
  • Medium: $5,000
  • Low: $1,000

This breakdown is based on our current client roster along with Compound’s position in the rankings of CMC, Coingecko, and DefiLlama. The program will be able to payout the reward in COMP. The reward suggestion above is based on the top tier DeFi lending protocol on our platform such as Sky (formerly MakerDAO), Sparks, AAVE, and Morpho.

Immunefi’s annual subscription fee is $57,500, which includes the highest tier Managed Triage Services, access to Safe Harbor, 30 KYCs for security researchers, the program design, and hosting of the program. The highest tier of Managed Triage Services was requested by the bounty program administrators as a result of the preliminary technical assessment of every report that the Immunefi team provides before it is prepared and delivered to the administrators for validity of a bug report.

Program Administrators, Bug Report Review, and Bug Fixes

All Bug Reports that pass through Immunefi will be reviewed by OpenZeppelin, Dmitry, and Arr00, with Compound Labs as secondary eyes if a conclusion cannot be reached. If necessary, the Immunefi meditation team will also be able to assist in mediating issues arising from the review of the bug report with the security researchers.

Though Immunefi considers any processes around fixing bug reports to be outside the consideration of payments, it is understood that this needs to be accounted for in a DAO environment. Specifically, fixes may take more time to be implemented, and need to be fully deployed before payouts can be made due to the need for the payment process to be more transparent with DAO processes. For example, if a payout process is initiated while a bug still has not been fixed, it may provide enough information for one or more people to find the vulnerability and exploit it. Because of this, payments to the security researcher may be delayed until a discovered bug has been appropriately addressed.

Budget:

$57,500 for ImmuneFi will be sent to: 0x7119f398b6c06095c6e8964c1f58e7c1baa79e18

$500,000 for the Bug Bounty will be sent to: 0x429D01a5ff7f7880081f858B50C26452255477f5. This multisig is controlled by the reviewers and governance working group. The remaining $500,000 budgeted will only be sent if this first half is exhausted.

Continue Reading
Connect Wallet to Add Note
0
Never Miss a ProposalSign up for Compound notifications
Cast Vote
Votes 23
VoterCast PowerVote & Rationale
0x683a...D26C02
90,065

FOR

0x66cD...B765F9
80,042

FOR

Wintermute Governance
80,003

FOR

0x3FB1...2d4C8A
80,000

FOR

FranklinDAO (Prev. Penn Blockchain)
80,000

FOR

SHOW MORE
VOTE POWER
0
Connect Wallet
Proposal Status
  • Fri October 25 2024, 05:18 pmPublished Onchain 0x3FB1...2d4C8A
  • Sun October 27 2024, 01:19 pmVoting Period Starts
  • Wed October 30 2024, 07:19 amEnd Voting Period
  • Wed October 30 2024, 07:20 amQueue Proposal
  • Fri November 01 2024, 07:22 amExecute Proposal
Current Results

1-FOR

692,217.1

99.99%

2-ABSTAIN

100

0.01%

3-AGAINST

N/A Tokens

0%
Quorum 692,317.1/400,000
DocumentationBrandingContact Us
Press space bar to start a drag. When dragging you can use the arrow keys to move the item around and escape to cancel. Some screen readers may require you to be in focus mode or to use your pass through key