Should GnosisDAO establish bug bounty coverage for client code?
Should GnosisDAO establish bug bounty coverage for client code? by mishaderidder.eth13093 🥝 • 9mo • 0 views • 0 clicks | |
AI summary of the linked articleA proposal asks whether GnosisDAO should extend bug bounty coverage to Gnosis Chain execution client code and pay $100,000 for a disclosed EIP-7702 censorship bypass. The bypass was disclosed privately to the Gnosis Chain security team on November 5, 2025, during the Balancer exploit, and a second soft fork addressing it was deployed on November 7. The proposal states that $5,308,954.42 was recovered when the hard fork executed on December 22, 2025, and that the $100,000 request is about 2% of that amount. It also notes that the current Immunefi bounty covers only the AMB and Omnibridge contracts. | |
Curating this bc there's lots of background reading on the Balancer incident and how Gnosis chose to intervene. My commentary to the whole Gnosis fork thing: https://etherscan.io/tx/0x6893d246fc4bee564ed9c109607930f9055cd66cdece55b96d4871a6f353f254 (divested 1.8K worth of GNO last week) I still haven’t figured out why would they sacrifice neutrality? I mean 5 million dollars is quite a lot of money, but is it enough to sacrifice the neutrality of your blockchain? On the other hand it is also setting a new paradigm, what I guess they call accountability - they want to provide safe self custody banking and now there’s a safety net maybe? But well of course bottom line is who decides what transactions need to be censored? Of course there is decentralized governance in place, validators decide in the end if there’s going to be a hard fork. But it’s all very slippery indeed. Haha I’m still on the fence. For now critically watching and waiting to see where it goes. But I understand you’re selling your tokens. | |
Characters remaining: 10,000 comment guidelines | |
