Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bug Bounty #243

Closed
avalonche opened this issue Aug 9, 2022 · 1 comment
Closed

Bug Bounty #243

avalonche opened this issue Aug 9, 2022 · 1 comment

Comments

@avalonche
Copy link
Collaborator

Bug Bounty

There is an initial audit and a possible second audit by an independent auditing team (see #224). However there should be a bug bounty program to improve and ensure the security of mev-boost and PBS. Some considerations are:

What platforms should the bug bounty be on?

Some candidates include:

How much should the bug bounty be?

  • Immunefi has bounties from a few thousand upwards to $10M
  • While mev-boost is an important piece of infrastructure, the potential impact and loss of funds is not as great and / or immediate as in some smart contracts. This should be considered in determining the bounty size
  • We can quantify validator rewards and make a reward proportional to the likelihood and impact of the issue

How should it be financed?

  • It seems reasonable that flashbots will bootstrap the initial bug bounty
  • What amount of funding would be needed initially and reserved?
  • However, it would be ideal and encouraged that participants in the space (node operators, builders, searchers, EF, etc.) contribute to the security budget and potentially support research, client teams and decentralization efforts to improve the ecosystem by contributing to something like gitcoin grants
@come-maiz
Copy link
Contributor

Two alternatives brought by Ethereum Foundation security are:

We should register in disclose.io, anyway.
Joining the ethereum foundation sounds amazing. This makes sense if the scope is the entire proposer/builder separation design and prototypes. However, it's not very clear if this makes sense to the ethereum foundation, and it's not clear how we participate here. Like, how do collect Flashbot's funds and the funds from other interested organizations.

@jtraglia jtraglia closed this as completed Nov 4, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants