[GIP-16] Bug Bounty: 08.2022 Payout and process structuring
AI summary
This proposal seeks to approve a $150,000 payment to a whitehat hacker for discovering a critical bug in the Gearbox protocol, plus a $15,000 fee to Immunefi for facilitating the bounty. It also aims to streamline future bug bounty payouts by authorizing a financial multisig (a wallet requiring multiple signatures for transactions) to release funds. Finally, it proposes establishing a Bug Bounty Oversight Committee to manage bug reports and coordinate responses.
If passed, the whitehat hacker will receive $150,000 and Immunefi will receive $15,000 from the DAO's treasury. Future bug bounty payouts will be faster, as they won't require a full DAO vote, benefiting security researchers and the protocol's responsiveness. A new committee will be formed to oversee security, potentially improving the protocol's overall security posture.
Voting results
🐳 Whale votes
0 votes > 5% VPFull proposal
This proposal consists of three parts.
The first part authorizes a payout of an Immunefi bounty for a critical bug discovered on August 12.
Parts 2 and 3 aim to formalize and streamline the processes regarding oversight and payouts of bug bounties.
Part 1: August Bug Bounty Payout
On August 12.08.2022, all 4 Credit Managers were paused by the pause function - due to a reported bug on Immunefi. That happened quickly after developers confirmed the bug and tested the vulnerability. A week later the fix was made, tested, soft-audited & deployed. The protocol was thus unpaused. Post-mortem…