ecosystem-contributions icon indicating copy to clipboard operation
ecosystem-contributions copied to clipboard

Delegate Mission Request: Fraud Proof CTF Mission Request

Open opjulian opened this issue 1 year ago • 0 comments

Delegate Mission Request: Fraud Proof CTF Mission Request

Delegate Mission Request Summary: To ensure the security of fraud proofs in advance of the full launch, this mission proposes creating a public CTF / short-term bug bounty to draw focus from top security talent.

S5 Intent: Intent 1: Progress towards technical decentralization

Proposing Delegate: Gonna.eth

Proposal Tier 1: Fledgling

Baseline grant amount: 50k OP for coordination, up to 200k OP in potential rewards

Should this Foundation Mission be fulfilled by one or multiple applicants: One

Start date: ASAP

Completion date: Before OP mainnet fraud proof launch

Apply Here

Specification

How will this Delegate Mission Request help accomplish the above Intent? The most important step towards technical decentralization is getting fraud proofs live on OP Mainnet. While they are currently live on Goerli, the bug bounty is low and not drawing much attention. A ton of attention from top security researchers would help provide the security confidence needed to move towards a mainnet launch.

What is required to execute this Delegate Mission Request?

  • Analyze fraud proof systems to determine complete list of possible risks that could arise.
  • Determine payouts for each possible risk being identified.
  • Set up a fun “event” structure to make it more like a concentrated CTF than a typical bounty.
  • Market it to gain awareness and excitement in the security community.
  • Run the event.
  • Judge submissions and determine payouts.

How should the Token House measure progress towards this Mission?

  • Event coordinated with payouts and plan approved by OP security team.
  • Event runs successfully.

How should badgeholders measure impact upon completion of this Mission?

  • Did the event surface vulnerabilities that could have created problems if deployed to mainnet?
  • At the end of the event, does the OP team feel confident that fraud proofs are ready for mainnet?

opjulian avatar Feb 15 '24 20:02 opjulian