Back to Medium Spender
Rejected
Requested:
97.00K DOT

#67 Security Audit of trustless Ethereum 2.0 Light Client, developed as a Substrate Pallet

Proposer:
12bM...P5F4
 
in Democracy
Beneficiary:
(97.00K DOT)
7th Jul '23

t3rn has developed a trustless Ethereum 2.0 light client as a Substrate Pallet, compatible with all Dotsama Parachains, for the benefit of the Polkadot Ecosystem. t3rn’s parachain will have the Ethereum 2.0 light client pallet installed on Polkadot and will be available via an accessible API; our portal precompile interface simplifies integration with smart contracts, enhancing process automation.

The clients standard pallet interface streamlines blockchain interactions, reducing technical difficulties and boosting efficiency. Lastly, through the use of the t3rn protocol, we facilitate secure and convenient cross-chain transfers and swaps, broadening the reach of blockchain operations.

Having developed the pallet, we are seeking support in covering the auditing costs, ensuring utmost security, before pushing our product to market.

Please view the full proposal here

Show More

Proposal Failed

The approval was lesser than the threshold for this track.
Summary
Failed
2.3%Aye
AyeNay
97.7%Nay
Ayes(16)
284.63K DOT
Nays(128)
12.04M DOT
Support
120.15K DOT
Voting Details
Approval0.00%Threshold0.00%
Support0.00%Threshold0.00%
Please Log In to comment
Users are saying...
Based on all comments and replies

Overall 42 % of users are feeling optimistic. Oak Security has granted auditors access to their private repo and is awaiting confirmation of readiness for an audit. They plan to continue unit functional testing and increase test coverage while open-sourcing code documentation alongside security audits results. Additionally, they are considering ongoing monitoring of light client upgrades over time due to anticipated hard fork updates in Eth2.

Overall 57 % of users are feeling neutral. A project seeker is inquiring if their code is open source and requesting a link to share it, while another participant suggests amendments for a proposal submission, including detailed testing methods, resource allocation, experience with ETH2.0 Light Clients audits, and considering the Polkadot Assurance Legion bounty program.

AI-generated from comments

6Comments
0%
0%
100%
0%
0%
12q7...87jL
 
 
7th Jul '23

Is ze code open source? If so can share link pls

Hide replies
12bM...P5F4
 
 
7th Jul '23

@33eab44f3a7645faa6d88154c

The private repo has been made accessible to the auditors cited in the proposal and we are more than happy to have then confirm this.

However, we don't believe it makes sense to open source the project prior to auditing. Other than that, the pallet is deployed to Rococo and there are screenshots of the working code in the proposal itself.

Happy to answer any other questions you may have

dashboard profile icon
0xtaylor
 
 
11th Jul '23
(Edited)

I would be curious to see the maturity of the code to better understand if it is ready for a security audit. Does the code have the following characteristics:

  • Commented code
  • Are all TODO's/FIXME's removed
  • Is there supporting documentation
  • Are functions named coherently
  • Do you have a full test suite including fuzz tests

Also, have you considered running this through the Polkadot Assurance Legion?

Hide replies
12bM...P5F4
 
 
12th Jul '23

@0xtaylor

thanks for the heads up, happy to get connected with Polkadot Assurance Legion, you can reach me on Telegram if you would like to discuss further

The most important parts of eth2 light client are all unit tested with >80% coverage of the codebase, and the status quo as outlined in a proposal:

  • continue unit + functional testing and increase test coverage.
  • code + docs will be open sourced and published alongside with the security audits results. It's safe to assume more bugs will come out during the following QA + audit phases
dashboard profile icon
0xtaylor
 
 
13th Jul '23
12Qz...hT1m
 
 
16th Jul '23

Hi, community! We are Oak Security, one of the auditor firms mentioned in the proposal. Our public audits reports can be found here: https://github.com/oak-security/audit-reports Given some of the questions, we would like to clarify the following:

  • We have been provided with access to the source code
  • We have performed a pre-audit validation of the source code and deem it ready for audit within the timeframe provided by the team
  • We have previously worked with the team and have provided them with security advisory to ensure smooth audit preparation and full readiness in line with our guidelines
  • All findings will be made public at the end of the audit

We hope this clarifies the questions.

1EHR...L2c8
 
 
28th Jul '23
(Edited)

If the assurance legion bounty doesn't take care of you (it may be outside their scope), we'll vote aye on a repost. But please also resolve/handle some/all of the issues mentioned by Taylor. Thanks

Hide replies
12bM...P5F4
 
 
29th Jul '23

@5CHzH9A3gYs7DJdgVRHG7gKgzqpb1yTV8E2CtV3NT7R59Ya7

I will certainly provide you with updates on the ongoing discussions with PAL.

Considering the significance and past achievements of the Eth2-Polkadot bridging solutions, it would be beneficial to include at least two experienced auditors to review the combination of Substrate, Eth2, and Solidity. There are several hard fork updates anticipated for Eth2. As such, it would be ideal if we could arrange for ongoing monitoring of the light client upgrades over an extended period.

Issues previously raised by Taylor have been addressed and resolved before launching this referendum.

The functional version of the light client for Sepolia (an Eth2 testnet) is accepting the latest headers on t0rn's testnet parachain on Rococo(-> ethereumBridge pallet on PolkadotJS explorer) and available to test it for any event or transaction inclusion validation by using the most recent data from Sepolia available at Sepolia Etherscan.

Thank you for reaching out and happy to provide more context where needed

15aS...xNK3
 
 
30th Jul '23
(Edited)

If this doesn't pass, I would encourage you to resubmit this proposal with some amendments:

  • Submit a smaller proposal that only covers the first audit and fund a portion such as 5-10% yourself towards the audit. This way you also have some skin in the game.
  • Work with Oak to Include the statement of work and test plan for the audit as currently scoped. Your current proposal does not go into much detail about what will be tested and how. i.e. - static analysis, manual review, fuzzing, formal verification? How many resources are you provided and what is the length of the engagement? Does Oak Security have experience auditing other ETH2.0 Light Clients?

I think with those changes and adding further information. you'll be in a much better position to get this passed.

Cheers,

-0xTaylor

Hide replies
12bM...P5F4
 
 
2nd Aug '23

@0xTaylor__ Both OAK and Halborn employ the mentioned techniques - static analysis, manual review, fuzzing, and formal verification. That being said, it's a fair point that we could have provided a more detailed breakdown of the auditing processes.

Anyways, thanks @0xTaylor for advise + feedback here. 3 more days here until we know the results, we will evaluate and decide our next steps from there 🤞

15uQ...hq6w
 
 
13th Aug '23

Hello,

We are in the process of validating a true need for a service to assist teams with crafting and completing successful treasury proposals, so they can focus on building. We would love to hear about your experience with this proposal. If you are willing to take a few minutes, please fill out this form about your experience with the OpenGov treasury proposal process: https://forms.gle/MwDij4adXEQd7Um79

Feel free to leave out any details that your team is not comfortable with sharing, but the more info you can provide, the better we will be able to assess the potential need for our services.

For more info, follow us on Twitter/X: https://twitter.com/OpenGovAssist


Discover similar proposals


#1526
13bf...tdoE
Deciding

SQD (fka Subsquid) - Public Data Indexing Infrastructure for Polkadot and Kusama ...

Summary

See More

16th Apr '25
69%

Medium Spender

Medium Spender

#1526 SQD (fka Subsquid) - Public Data Indexing Infrastructure for Polkadot and Kusama ...
13bf...tdoE
16th Apr '25
69%

Summary

Proponent: Subsquid Lab Official - 13bfKSQXoBn3AMLtZaW6BKv797fqZzsD3PYF6xpJDir3tdoE Beneficiary: Subsquid Lab Official - 13bfKSQXoBn3AMLtZaW6BKv797fqZzsD3PYF6xpJDir3tdoE

Contact Details: Subsquid Labs GmbH 6300 Zug, Switzerland mf@subsquid.io

Short description: Ongoing development and maintenance costs for public SQD Archives

Archive raw data: Archive Infrastructure Metrics - July, August, September

Requested: $310,592.98

Previous proposals: https://polkadot.polkassembly.io/referenda/1447

Motivation

A) Archives

Archives are an important piece of Polkadot and Kusama data infrastructure provided by SQD (formerly Subsquid). They provide access to on-chain data for public chains in the Polkadot ecosystem. They are being used as a data source for Squids and for efficient data exploration and ad-hoc queries. The Archives, as performant data sources of historical on-chain data, are critical to the operation of backend APIs run by major projects in the Polkadot ecosystem.

Popular Polkadot dApps and projects that depend on SQD include the following:

  • Tanssi Network
  • Talisman Wallet
  • Polimec
  • Polkassembly
  • Apillon
  • Hydration
  • Giant Squid API (maintained by LimeChain)
  • SubWallet
  • FiDi
  • KodaDot
  • RMRK
  • ChainSafe (in particular the Multix multi-sig, as well as other projects)
  • Phala Network
  • Stellaswap
  • Polkascan

Since the beginning of 2024, SQD has transitioned to a paid model for supporting parachains. However, public chains continue to be available for free use. Throughout the Q3 of 2024, we provided a free public data indexing service for Substrate blockchains, allowing interested parties to access indexed data on Substrate Events, Extrinsics, Storage Items, and EVM logs. Below is a list of the public chains we currently support at no cost:

  • polkadot
  • kusama
  • asset-hub-kusama
  • asset-hub-polkadot
  • bridge-hub-polkadot
  • collectives-polkadot
  • rococo
  • westend

B) Contribution

During Q3 2024, we addressed real-world use cases that were highly requested by the community:

  • Supported Substrate extrinsic v5, enhancing compatibility for newer Substrate-based chains.
  • Updated squid templates to the new data decoder interface.

Achievements

Increase in Archival Data Demand and Infrastructure Scaling

During Q3’24, archival data demand increased approximately 3.6 times, from 3,265 GiB in Q2 to 11,713 GiB in Q3. We addressed the increasing demand for archival data by enhancing our infrastructure's throughput and redundancy through deploying archives to OVHCloud in addition to GCE, while also empowering our maintenance and engineering teams to support the expanded infrastructure effectively.

Decentralization of the SQD Network Enhancing the Polkadot Ecosystem:

In Q3’24, we continued to empower the SQD Network, driving forward our mission to strengthen the Polkadot ecosystem’s decentralization and resilience. By the end of the quarter, the SQD network had grown to include 1139 active Worker Nodes, securely storing 574TB of data and serving approximately 11TB of data per day. This expanding decentralized infrastructure enhances data processing and storage capabilities, delivering increased security, fault tolerance, and scalability for the Polkadot network.

Statistics and data

 

Over the course of Q3 2024:

  • Served a total of 12,576,410,498,732 (~11.44 TiB) of data from the substrate based archives.
  • Served 979,736 archive requests from substrate based archives.
  • The highest daily total data transfer recorded for Substrate was 375.57 GiB within a single 24-hour period (2024-09-19).

Costing

This proposal encompasses the combined costs for running Archives for Polkadot, Kusama, and other public chains, along with the development contributions, amounting to a total of $310,592.98.

Raw data for Archives can be seen here.

The proposal is submitted towards the Polkadot treasury. Here is a summary of the running costs for Archives, in a tabular format:

Contribution costs:

See More

Deciding
#1531
149F...eQ7F
Deciding

The operating cost for the research organization Polkadot Ecology Research ...

Hello everyone in the Polkadot community! We are the Polkadot Ecology Research Institute, the largest research institute in Asia focusing on the Polkadot ecosystem, and also a research organization with significant global influence within the Polkadot ecosystem. We have successfully completed all plans for the last treasury application, so we are applying here for our annual operational expenses from April 2025 to March 2026.

See More

18th Apr '25
63%

Medium Spender

Medium Spender

#1531 The operating cost for the research organization Polkadot Ecology Research ...
149F...eQ7F
18th Apr '25
63%

Hello everyone in the Polkadot community! We are the Polkadot Ecology Research Institute, the largest research institute in Asia focusing on the Polkadot ecosystem, and also a research organization with significant global influence within the Polkadot ecosystem. We have successfully completed all plans for the last treasury application, so we are applying here for our annual operational expenses from April 2025 to March 2026.  

Our team at the Polkadot Ecology Research Institute are all from the earliest builders of the Chinese Polkadot community. We have been contributing to the Polkadot ecosystem since 2019, making it more than 6 years of dedicated effort. Due to our contributions and high-quality research content, we have received support from the Polkadot Treasury for 8 consecutive times.  

  • In the past few years, we have written nearly 300 original pieces of content/in-depth reports on Polkadot and the development of its ecosystem, achieving more than 63 million views. The total word count has exceeded 1.8 million words. We are also the only institution in the Chinese market that publishes research content on the official Medium of Polkadot.
  • As of now, we have supported more than 90 Polkadot-related events in total. In 2022 and 2023, for two consecutive years, we participated as guests in the global sharing activities of the Polkadot Decoded Community Conference. The cumulative number of people reaching Polkadot from all activities has exceeded 50,000.
  • In addition, we are actively empowering the development of the Polkadot ecosystem. We have provided content/activity/community support for more than 130 projects within the ecosystem. We have provided investment and financing consultation and connection services for some projects to help investment institutions better understand them. Although we are based in the Chinese market, we have also provided assistance and support to many Polkadot ecosystem projects in other regions around the world, and most of it is provided unpaid and voluntary.
  • In the past year, we have also increased our overseas operation efforts to serve the global Polkadot market, especially in terms of Twitter operation. We currently have more than 4,700 followers, which is six times the number of followers we had during the same period last year. We have published more than 6,000 tweets in total. Our founder, Zou Yang, has also been actively creating content through his Twitter in the past year. His Twitter account has successfully been selected as one of the top 100 KOLs in the Polkadot Mindshare ranking on KAITO.

As a major institution focusing on the research of the Polkadot ecosystem in the Asia market and even globally, we have continuously contributed to the development of Polkadot over the past 6 years. Whether in a bull or bear market, our research content has been read and adopted by many institutions, and it has also become one of the important channels for ordinary users to understand the development of Polkadot. In the future, we will continue to support the development of Polkadot and its ecosystem!  

We have recently released a strategic development report on Polkadot with a word count of more than 12,000 words. This report is a comprehensive report on the current situation, challenges, competitive strategies, and various solutions of Polkadot that we have provided after conducting detailed community research (including developers) and collecting materials, taking nearly one month. It has sparked extensive discussions within the Polkadot community, been reposted and read by many institutions, and has been recognized by the Web3 Foundation. If you are interested, you can refer to this in-depth report.  

This is our work feedback report for the past year. You can check the detailed information here:

The development report of Polkadot Ecology Research Institute for 2024/4 - 2024/9

The development report of Polkadot Ecology Research Institute for 2024/10 - 2025/3

In this proposal, we are applying for 12 months of operating funds, mainly for personnel expenses. This is also our 9th application to the Polkadot Treasury. You can check out our detailed proposal and find more information about us here, as well as comments from Polkadot builders on our work.

The amount of our application is not particularly large because it is mainly for the personnel expenses of the daily operation of the research institute. The business costs and travel expenses for our participation in various Polkadot activities have always been paid by ourselves. This has been the case in the past few years, and it will still be the case for this application.  

Please consider casting your valuable vote in our favor, and feel free to leave any questions or feedback in the proposal. We will be sure to respond promptly.

P.S. The reason we're applying for treasury funding instead of going through Market Bounty is primarily due to processing timelines. From our understanding, some teams have waited several months without receiving feedback through the Market Bounty channel. Since we're currently using our own payroll funds to support the team, we require a more expedited funding process to ensure timely salary payments and team continuity. Therefore, applying directly to the treasury represents our most viable option at this time.

See More

Deciding