FeedProjects
Developers
Settings
🎉 A new chapter begins: Boardroom has joined Agora
Learn more
protocol logo
Explore / Projects
Olympus DAO

Proposals

Members

Information

Create Proposal

Olympus DAO

ProposalsMembersInformation
Proposal
Back to Proposals
closedEnded 4 years ago · Snapshot (Offchain)

OIP-77: New Tier for Bug Bounty & Awarding of One Retroactive Bounty

By 0x131b...cCbf80

Summary

This proposal is designed to add a third tier of bugs to the Bug Bounty program outlined in OIP-17, OIP-34, and OIP-38. This new tier will cover “bugs/exploits which could lead to an incorrect rebase amount” and will provide a flat fee reward of $33,333 per vulnerability/exploit. This OIP also will retroactively award 1 bug bounty of this size to a submission previously received through ImmuneFi which would have qualified under this tier, should it pass review by engineering.

Motivation

After we launched the bug bounty with ImmuneFi we have received a a bug which, in extreme cases, could lead to incorrect rebase amounts. This bug does not qualify under Tiers 1 or 2 of the Bug Bounty as currently specified. However, Bug Bounty Management unanimously agrees the efforts of the whitehats who brought this to our attention should be rewarded, and we should encourage people to bring forward more bugs of this nature.

Accordingly, I believe it is in Olympus’ best interest to add the additional “bug type” to the Bug Bounty program created through OIP-17, and to provide a bounty of $33,333 and a Proof of Whitehat NFT to the aforementioned whitehats should their bug submission pass review with engineering.

Proposal

Change the text of the Olympus Bug Bounty from:

Critical vulnerabilities are further subcategorized into two tiers:

Tier 1: For bugs/exploits which would lead to a loss of bond funds or a loss of user funds, a flat reward of USD 333 333 is provided.

Tier 2: For bugs/exploits which would lead to a loss of treasury funds, a flat reward of USD 3 333 333 is provided.

To

Critical vulnerabilities are further subcategorized into three tiers:

Tier 1: For bugs/exploits which would lead to a loss of bond funds or a loss of user funds, a flat reward of USD 333 333 is provided.

Tier 2: For bugs/exploits which would lead to a loss of treasury funds, a flat reward of USD 3 333 333 is provided.

Tier 3: For bugs/exploits which would lead to an incorrect rebase amount, a flat reward of USD 33 333 is provided.

Additionally this OIP authorizes the retroactive awarding of one Tier 3 Bounty and one Proof of Whitehat NFT to one whitehat team which had previously submitted a bounty which would have qualified under Tier 3 (the details of which will be disclosed once a fix is implemented), if said bug passes review with engineering which it is currently undergoing.

Polling Period

The polling process begins now and will end at 10:00 UTC on February 3rd 2022. After this, a Scattershot vote will be put up at 10:00 UTC on February 4th 2022.

Poll

For: The text of the Bug Bounty program, on the ImmuneFi website, will be changed as previously specified and one Tier 3 bounty and proof of whitehat nft will be awarded retroactively.

Against: The text of the Bug Bounty program will not be changed.

Continue Reading
Connect Wallet to Add Note
0
Votes 195
VoterCast PowerVote & Rationale
0x31C7...6F3346
9,640

Change Bug Bounty Program

0x318A...E22C67
6,701

Change Bug Bounty Program

0xa59f...925d1B
5,192

Change Bug Bounty Program

0xf5B4...d99A72
4,648

Change Bug Bounty Program

0xeAbe...DF74c6
2,546

Change Bug Bounty Program

SHOW MORE
VOTE POWER
0
Connect Wallet
Proposal Status
  • Tue February 08 2022, 11:00 amVoting Period Starts
  • Fri February 11 2022, 11:00 amEnd Voting Period
Current Results

1-Change Bug Bounty Program

52,500.025

99.96%

2-Do nothing

18.837

0.04%
DocumentationBrandingContact Us
Home
This Project is Currently Disabled

If you would like to enable it, please checkout below.

Boardroom Subscription

Sign up for an individual subscription (access all projects on the platform)

Subscribe
Enable Project

Enable the entire project for every user

Enable Project
Contact Us