FeedProjects
Developers
Settings
๐ŸŽ‰ A new chapter begins: Boardroom has joined Agora
Learn more
protocol logo
Explore / Projects
Gearbox DAO

Proposals

Members

Information

Create Proposal

Gearbox DAO

ProposalsMembersInformation
Proposal
Back to Proposals
closedEnded a year ago ยท Snapshot (Offchain)

[GIP-169]: Additional integration audits

By 0xb9b7...6CceeA

Summary

This proposal aims to request funds from the DAO in the size of 15000 USDC, in order to pay for an audit of new integrations. The audit will be conducted by Decurity and Watchpug over the span of 1 week. Gearbox has always placed security front and center. Smart contract auditing is critical to ensuring the safety of user funds and it is also critical to building trust with users, so allocating a budget for auditing new integrations and updates seems reasonable.

Audit scope

This is a limited-scope audit that reviews integrations as discussed between Gearbox contributors and Decurity / Watchpug.

The following adapter / price feed contracts are reviewed by Decurity:

  • https://github.com/Gearbox-protocol/integrations-v3/blob/sky-adapters-3_0/contracts/adapters/sky/DaiUsdsAdapter.sol
  • https://github.com/Gearbox-protocol/integrations-v3/blob/sky-adapters-3_0/contracts/adapters/sky/StakingRewardsAdapter.sol
  • https://github.com/Gearbox-protocol/integrations-v3/blob/sky-adapters-3_0/contracts/helpers/sky/StakingRewardsPhantomToken.sol
  • https://github.com/Gearbox-protocol/integrations-v3/blob/sky-adapters/contracts/adapters/sky/DaiUsdsAdapter.sol
  • https://github.com/Gearbox-protocol/integrations-v3/blob/sky-adapters/contracts/adapters/sky/StakingRewardsAdapter.sol
  • https://github.com/Gearbox-protocol/integrations-v3/blob/sky-adapters/contracts/helpers/sky/StakingRewardsPhantomToken.sol
  • https://github.com/Gearbox-protocol/oracles-v3/blob/next/contracts/oracles/updatable/PythPriceFeed.sol

The following price feed contracts are reviewed by Watchpug:

  • https://github.com/Gearbox-protocol/oracles-v3/blob/pendle-pt-pf-3_1/contracts/oracles/pendle/PendleTWAPPTPriceFeed.sol
  • https://github.com/Gearbox-protocol/oracles-v3/blob/pendle-pt-price-feed/contracts/oracles/pendle/PendleTWAPPTPriceFeed.sol

Budget Breakdown

The total budget for final review includes 15000 USDC payment (10 000 USDC for Decurity audit and 3000 USDC for Watchpug audit, and 2000 USDC is proposed to be reserved as an extra if required). Post-audit, the community can expect a detailed audit report, highlighting any vulnerabilities found and their severity. Like it was always done before (https://docs.gearbox.finance/risk-and-security/audits-bug-bounty).

About Decurity

Decurity is a team of veteran hackers who dived into the blockchain and smart contract security in the early days. Top-2 in @Paradigm and @OpenZeppelin CTF, previously audited Gearbox, 1inch, yearn, compound and other protocols (check here for details).

About Watchpug

Watchpug is a security team that collaborates with protocol developers, offering practical security knowledge and in-depth auditing for Solidity smart contracts. Previously did several audits of Pendle (check here and here).

Continue Reading
Connect Wallet to Add Note
0
Votes 15
VoterCast PowerVote & Rationale
0xC4CA...43153B
71.795M

Accept

0xb9b7...6CceeA
46.838M

Accept

0xf3D4...49d89E
34.691M

Accept

0xdAb4...40a38D
29.219M

Accept

0x81E8...Fd2c08
27.949M

Accept

SHOW MORE
VOTE POWER
0
Connect Wallet
Proposal Status
  • Wed October 16 2024, 07:26 amVoting Period Starts
  • Sat October 19 2024, 07:26 amEnd Voting Period
Current Results

1-Accept

211.937M

Quorum 211.937M/200M
DocumentationBrandingContact Us
Home
This Project is Currently Disabled

If you would like to enable it, please checkout below.

Boardroom Subscription

Sign up for an individual subscription (access all projects on the platform)

Subscribe
Enable Project

Enable the entire project for every user

Enable Project
Contact Us