Polkassembly Logo

Create Pencil IconCreate
OpenGov

Notice: Polkadot has migrated to AssetHub. Balances, data, referenda, and other on-chain activity has moved to AssetHub.Learn more

View All Discussion

Polkadot Kusama Bridges Security Bug Bounty

userVinceCorsica_KSM
2 years ago

Proponent: 14Pn8sUxdEMgFRDgZ5J2VfcUVMLaMQhst9XuvCj9

Date: 26.01.2024

Requested DOT: $250,000 (39,100 DOT - rate 1 DOT=$6.39)

Short description:

Bridges enable transferring data, assets, and more between multiple chains. Due to their pivotal role and high transaction volumes, they have simultaneously become a hotspot for malicious activities. When exploited, these breaches can lead to significant impact including financial losses.

This proposal aims to ensure the utmost security of the bridges and promote community involvement by implementing a Security Bug Bounty Program. While all developers involved work hard to ensure the software and protocols built are bug-free, secure by design, and third-party code audits have been already performed, it is recognised security best practices to complement this. That’s why Polkadot and Kusama need community and bug bounty hunters to help to identify security vulnerabilities that could cause impact from all the severity levels before it is widely used and adopted.

To support this, the Bug Bounty participants are provided with many context details in the full proposal attached, including a threat model of the scope.

As a security vulnerability in the bridge can impact both the source and destination blockchains, a mirror bounty is raised on Kusama and Polkadot

Thanks for your time and support to make Polkadot more secure !

Comments (1)

2 years ago

To provide more details about the question raised on Polkadot direction

Element channel in relation to the amount of bounty reward being potentially low versus TVL of Polkadot and Kusama

In fact amount of bounty depends multiple drivers:

  • TVL
  • Marketing attraction
  • Type of people whitehat targeted
  • Number of times the bounty will be delivered
  • Funds available for the bounty

The proposal here try to balance these drivers by factoring the following:

  • Polkadot is not DEFI (Example Ethereum TVL is 20x Polkadot and bounty for a critical is $250K https://ethereum.org/en/bug-bounty)
  • prizes are not only funds but other type of rewards like Polkadot Blockchain Academy preferred access to attract people interested by Polkadot ecosystem
  • to pay bounty when deserved to reporters and not to “debate” to downgrade criticality and as a consequence pay out
  • to not ask too big treasury amount (here $500K) for a specific bounty program, and based of effectiveness of the bounty to adapt and ask if required more funds.
PleaseLogin to comment

Help Center

Report an Issue
Feedback
Terms and Conditions
Github

Our Services

Docs
Terms of Website
Privacy Policy

A House of Commons Initiative.

Polka Labs Private Limited 2026

All rights reserved.

Terms and ConditionsTerms of Website
Privacy Policy