Manage a bounty program for vulnerability reports
Proposal Details
Description
As the DAO owns the smart contracts and manages the development of the protocol, we are requesting to cover the rewards needed for every vulnerability found in the Decentraland bounty program. The Decentraland foundation is committed to triage, answering, and fixing every disclosure received. Every payment will be published publicly.
Voting Power
Manage a bounty program for vulnerability reports This proposal has been ENACTED by a DAO Committee Member (0xfe91c0c482e09600f2d1dbca10fd705bc6de60bc)
Manage a bounty program for vulnerability reports This proposal is now in status: PASSED. Voting Results: * Yes 100% 7,520,426 VP (87 votes) * No 0% 0 VP (0 votes)
Much needed these have been proven to work well. Thought i already voted yes and commented.
Thanks for your response, and glad to know this will be considered! I do think this is super important and needs to exist, so I wish y'all luck with the program!!
As a land owner I voted yes on this proposal because I can't think of anything more important than protecting our smart contracts. We need incentives large enough to encourage those to have found vulnerabilities within the system to report them.
Hi! Thanks for raising this point. The DAO won't be forced to pay rewards if they consider that the treasury is being compromised. It is hard to estimate how many reports are we going to have and pay but we are conscious that every development must be audited until goes to production. I think that if we start having too many valid reports per day, we will need to slow down the development and improve the quality. How we can mitigate this? well, I believe that the DAO will stop sending the funds and raise its voice to have a better development process.
Hey I am so for this program existing. I even voted yes and asked a few questions on the original poll. But before this gets passed — I would like to call attention to this being a **governance proposal** and not a grant proposal, meaning once it is approved it is binding forever, as I understand. I am curious to know the allocation of funds, and if there are caps per year? I understand and believe in the importance of these bounty programs, but what stops them from draining all the dao funds if there are multiple threats? Hopefully not, but how do we mitigate this possibly scenario? Or do you have data from previous bugs to show that this wouldn't be an issue? Sorry if I'm stuck on the wrong issue here, but would like to know how this will be handled before I vote, but thanks for all you do!
I voted YES because I believe there is nothing more important than ensuring the security and stability of our platform. By incentivizing security researchers with appropriate bounties, I believe this will both: 1) Prevent those with knowledge of exploits from taking advantage of them. 2) Encourage well qualified individuals to audit the smart contracts. Best wishes with this proposal.
8 Comments