Replies: 1 comment
-
Thanks to Sasha, there is bug bounty platform similar to discussed above: https://immunefi.com/ |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Insights.
Having a couple of conversations with auditors (Sigma Prime and Trail of Bits), I found that previous approach about inviting auditors was incorrect. There are several major reasons why:
Solution.
First of all, entity of auditor must be removed completely from the contract. The responsibility of publishing audit should be moved to the developers who are interested to prove the quality of the contract.
a) Developer deposits some amount of money into the project.
b) There are some rules about bounty distribution, like "confirming major issue -> send 10% of deposit to the hacker".
c) Hacker opens an issue against the latest deployed version of contract, secretly transferring the details.
d) Developer can accept the issue and it triggers transfer procedure, or reject.
e) In case of developer's rejection, hacker may open the details of the issue to ask council to be the judges of the decision.
f) Council decision will be accepted unconditionally.
To decrease council participation frequency, there should be fines introduced.
Milestones.
Beta Was this translation helpful? Give feedback.
All reactions