# Compensating security assessment costs for Lido-on-X projects

**URL:** <https://research.lido.fi/t/compensating-security-assessment-costs-for-lido-on-x-projects/1717>\
**Category:** Proposals\
**Created:** [February 17, 2022, 9:56am UTC](https://research.lido.fi/t/compensating-security-assessment-costs-for-lido-on-x-projects/1717 "2022-02-17T09:56:44Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![vsh](https://avatars.discourse-cdn.com/v4/letter/v/b19c9b/32.png) [@vsh](https://research.lido.fi/u/vsh)\
**Post date:** [February 17, 2022, 9:56am UTC](https://research.lido.fi/t/compensating-security-assessment-costs-for-lido-on-x-projects/1717/1 "2022-02-17T09:56:44Z")

</div>

The development and acceptance process of Lido-on-X protocol (Lido on Solana, Polygon, Kusama/Polkadot) involves a pre-release security assessment. These assessments are expensive and are needed not only for the team building Lido-on-X, but for the Lido DAO as a method of acceptance test (so we could say that indeed, that version of the protocol is safe to deploy, use, promote and incentivize).

It’s never boiled down to the point of contention, but the teams are extremely cognizant of the upfront costs of assessments (before they even know if their solution will have a PMF), and are de-incentivized to go for the best quality, more expensive firms. We should not put development teams in a situation where they have a conflict of interests on getting the best security practices.

My proposal here is for Lido at large, acting through LEGO, to bear all the costs of final security assessments of the Lido-on-X protocols, limited to two assessments with reputable firms per upgrade. With LEGO council in charge of judging what is a reputable firm.

I also propose to retroactively fund the security assessments for Mixbytes(), Shard Labs, and Chorus One.

The costs of doing this are quite substantial (audits costs for a full protocol are anywhere between $30k to $200k, might be even more), but I gather them to be less than bug bounty costs, which are topped at $2M per bug currently.

---

<div class="post-metadata">

**Author:** ![uba.eth](https://avatars.discourse-cdn.com/v4/letter/u/94ad74/32.png) [@uba.eth](https://research.lido.fi/u/uba.eth)\
**Post date:** [February 17, 2022, 3:09pm UTC](https://research.lido.fi/t/compensating-security-assessment-costs-for-lido-on-x-projects/1717/2 "2022-02-17T15:09:35Z")

</div>

For decentralized finance brands and protocols, security is of utmost importance. Lido should take pre-release security assessments as seriously as they possibly can be taken to protect against possible financial black swan events and damage to its brand. If the means to be able to spend incrementally more on greater prudence and higher quality security are available, and these processes have been screened properly by contributors, they should be taken.

I am in support of this proposal.

---

<div class="post-metadata">

**Author:** ![satBalwyn](https://dub1.discourse-cdn.com/flex013/user_avatar/research.lido.fi/satbalwyn/32/1673_2.png) [@satBalwyn](https://research.lido.fi/u/satBalwyn)\
**Post date:** [February 18, 2022, 6:51am UTC](https://research.lido.fi/t/compensating-security-assessment-costs-for-lido-on-x-projects/1717/3 "2022-02-18T06:51:32Z")

</div>

I do reckon the significance of pre-release security assessment and agree with the proposal. For one Lido-on-X, the project should not be released once only and it will be released with version upgrade in multi times with bug fixing and function updating. I think for every big release, a security assessment is necessary. How will the fee be covered?

---

<div class="post-metadata">

**Author:** ![Mike\_Mixbytes](https://dub1.discourse-cdn.com/flex013/user_avatar/research.lido.fi/mike_mixbytes/32/476_2.png) [@Mike\_Mixbytes](https://research.lido.fi/u/Mike_Mixbytes)\
**Post date:** [February 18, 2022, 7:39am UTC](https://research.lido.fi/t/compensating-security-assessment-costs-for-lido-on-x-projects/1717/4 "2022-02-18T07:39:54Z")

</div>

A couple of thoughts from our side. We are a security audits provider ourselves so we speak from experience:

- On a proposal, stage teams have no way to estimate audit costs and book slots with the auditing teams. Currently, this presents a huge blocker and a serious possible financial risk because even if you deliver on your proposed code you might not be able to book good auditors. If this risk is somewhat mitigated, Lido will attract a lot more teams to its ecosystem, especially those that are on the smaller/younger side.
- Totally agree with the point about audits being much more capital effective than bug bounty. If our clients paid $2M for every critical we find during audits, a portion of them would be bankrupt at this point for sure))

---

<div class="post-metadata">

**Author:** ![DeFiYaco](https://dub1.discourse-cdn.com/flex013/user_avatar/research.lido.fi/defiyaco/32/2084_2.png) [@DeFiYaco](https://research.lido.fi/u/DeFiYaco)\
**Post date:** [February 18, 2022, 7:52am UTC](https://research.lido.fi/t/compensating-security-assessment-costs-for-lido-on-x-projects/1717/5 "2022-02-18T07:52:37Z")

</div>

I can speak from our experience working on Lido for Polygon:  
We take security very seriously since these products are impacting users and underlying network stability and decentralisation.  
For that reason, we made a decision to do the re-audit and delay the launch for ~1 month. Audit put a significant extra cost on Lido for Polygon development.  
Also, since it delayed the launch, the time where we expect to start earning from the project was also delayed.  
That being said, Shard Labs fully supports this proposal and we think it will benefit the expansion of Lido ecosystem in the long term.

---

<div class="post-metadata">

**Author:** ![vsh](https://avatars.discourse-cdn.com/v4/letter/v/b19c9b/32.png) [@vsh](https://research.lido.fi/u/vsh)\
**Post date:** [February 18, 2022, 8:31am UTC](https://research.lido.fi/t/compensating-security-assessment-costs-for-lido-on-x-projects/1717/6 "2022-02-18T08:31:51Z")

</div>

A snapshot vote on this will start today:  
[https://snapshot.org/#/lido-snapshot.eth/proposal/0xb9e4f39f6cf7a3b375744f1cf5d6061e6db08b58334ce6f0da02f18c68e28222](https://snapshot.org/#/lido-snapshot.eth/proposal/0xb9e4f39f6cf7a3b375744f1cf5d6061e6db08b58334ce6f0da02f18c68e28222)

---

<div class="post-metadata">

**Author:** ![gmo477](https://dub1.discourse-cdn.com/flex013/user_avatar/research.lido.fi/gmo477/32/1071_2.png) [@gmo477](https://research.lido.fi/u/gmo477)\
**Post date:** [February 22, 2022, 4:07pm UTC](https://research.lido.fi/t/compensating-security-assessment-costs-for-lido-on-x-projects/1717/7 "2022-02-22T16:07:42Z")

</div>

I completely support this proposal as well based on the points outlined by the team. The only question I’d ask the team is whether the LEGO grants program budget should be expanded (which I would also strongly support). My understanding is that the established budget allocates 240K LDO per quarter across all LEGO grants ([https://lego.lido.fi/](https://lego.lido.fi/)). I don’t know what the expectations are in terms of volume of security assessments but if the entire budget is just over $400k per quarter at current price levels and these audits can reach up to $200K in cost then I’d think the team would want to create some add’l room in the budget for other LEGO grants.

---

<div class="post-metadata">

**Author:** ![vsh](https://avatars.discourse-cdn.com/v4/letter/v/b19c9b/32.png) [@vsh](https://research.lido.fi/u/vsh)\
**Post date:** [February 22, 2022, 4:51pm UTC](https://research.lido.fi/t/compensating-security-assessment-costs-for-lido-on-x-projects/1717/8 "2022-02-22T16:51:00Z")

</div>

The LEGO budget can be extended with a governance vote if needed, so if it’s dried up with security assessments and/or bug bounty payouts, we will be able to ask for a top-up.  
But it’s a good idea to pre-extended it for the next period, thanks.

---

<div class="post-metadata">

**Author:** ![Tayo01node](https://avatars.discourse-cdn.com/v4/letter/t/a5b964/32.png) [@Tayo01node](https://research.lido.fi/u/Tayo01node)\
**Post date:** [February 23, 2022, 9:58am UTC](https://research.lido.fi/t/compensating-security-assessment-costs-for-lido-on-x-projects/1717/9 "2022-02-23T09:58:13Z")

</div>

Yh, I think it is a good idea

---

<div class="post-metadata">

**Author:** ![wminshew](https://dub1.discourse-cdn.com/flex013/user_avatar/research.lido.fi/wminshew/32/325_2.png) [@wminshew](https://research.lido.fi/u/wminshew)\
**Post date:** [February 25, 2022, 2:12am UTC](https://research.lido.fi/t/compensating-security-assessment-costs-for-lido-on-x-projects/1717/10 "2022-02-25T02:12:34Z")

</div>

generally in favor of this but curious if the team has considered more decentralized alternatives to formal audits (e.g. pre-release community bounty bug programs or something like code4rena)?

---

<div class="post-metadata">

**Author:** ![vsh](https://avatars.discourse-cdn.com/v4/letter/v/b19c9b/32.png) [@vsh](https://research.lido.fi/u/vsh)\
**Post date:** [February 25, 2022, 6:19am UTC](https://research.lido.fi/t/compensating-security-assessment-costs-for-lido-on-x-projects/1717/11 "2022-02-25T06:19:27Z")

</div>

Bug bounties are there but they are not an alternative to audits. They fill a different role. Code4rena is something we want to try but it’s not a replacement to an audit either, it’s an additional thing (though would go to the same budget).

---

<div class="post-metadata">

**Author:** ![vsh](https://avatars.discourse-cdn.com/v4/letter/v/b19c9b/32.png) [@vsh](https://research.lido.fi/u/vsh)\
**Post date:** [February 27, 2022, 5:37pm UTC](https://research.lido.fi/t/compensating-security-assessment-costs-for-lido-on-x-projects/1717/12 "2022-02-27T17:37:57Z")

</div>

The vote passed - we can start refunding the audits on demand:  
[https://snapshot.org/#/lido-snapshot.eth/proposal/0xb9e4f39f6cf7a3b375744f1cf5d6061e6db08b58334ce6f0da02f18c68e28222](https://snapshot.org/#/lido-snapshot.eth/proposal/0xb9e4f39f6cf7a3b375744f1cf5d6061e6db08b58334ce6f0da02f18c68e28222)

---

<div class="post-metadata">

**Author:** ![DeFiYaco](https://dub1.discourse-cdn.com/flex013/user_avatar/research.lido.fi/defiyaco/32/2084_2.png) [@DeFiYaco](https://research.lido.fi/u/DeFiYaco)\
**Post date:** [February 28, 2022, 7:50pm UTC](https://research.lido.fi/t/compensating-security-assessment-costs-for-lido-on-x-projects/1717/13 "2022-02-28T19:50:17Z")

</div>

So far, Shard Labs transferred 48300 USDC to Oxorio for the auditing expenses.

Transactions:  
0x9f44bc8f24df0e4750c6cbc4706d6ad9e10cc29693892b2ea73f85a2cc84c4c0  
0x2b444b9eb017f308a7e27e50b88cda5d6a213aaa85b5fbb960fe3c554a7288ad  
0x4df087bc894a59f2ee5579f10b3e12d062b8cbfb06c6de678ba308cd65cb6548  
0x1ff3827882e3f6b1968be0c4c1286c866fb12769786e589c426a086934b6c336

Forum did not allow me to post more than 2 links so I just provided tx hashes.

There is still one pending PR to be reviewed for version 1 and the new codebase for version 2 which is currently in development. Transactions for those will be posted once they are executed.

The compensation can be issued here: 0x4290db8e966a880d7Fd734884FBa93ee671984ea

---

<div class="post-metadata">

**Author:** ![Mike\_Mixbytes](https://dub1.discourse-cdn.com/flex013/user_avatar/research.lido.fi/mike_mixbytes/32/476_2.png) [@Mike\_Mixbytes](https://research.lido.fi/u/Mike_Mixbytes)\
**Post date:** [March 25, 2022, 1:29pm UTC](https://research.lido.fi/t/compensating-security-assessment-costs-for-lido-on-x-projects/1717/14 "2022-03-25T13:29:56Z")

</div>

MixBytes transferred 12,000 USDT to Dedaub as an advance for the auditing services.  
**[Ethereum Transaction Hash (Txhash) Details | Etherscan](https://etherscan.io/tx/0x1d82ed613797d7b0c4525cac55ff493d2f3f3d67e74b0ca2b23dacd54c6f73f4)**  
The compensation for MixBytes can be issued here: 0x193128E013bB56d150555833Dc2a669d07D11842  
52,500 USDT is still outstanding and needs to be paid to this address: 0xF5Da01d6aFfEf5af0E326bff01b6A1c2bd93c046

---

<div class="post-metadata">

**Author:** ![kadmil](https://dub1.discourse-cdn.com/flex013/user_avatar/research.lido.fi/kadmil/32/1958_2.png) [@kadmil](https://research.lido.fi/u/kadmil)\
**Post date:** [April 7, 2022, 7:11pm UTC](https://research.lido.fi/t/compensating-security-assessment-costs-for-lido-on-x-projects/1717/15 "2022-04-07T19:11:25Z")

</div>

> [@Mike\_Mixbytes](#):
>
> 0x193128E013bB56d150555833Dc2a669d07D11842

First batch sent: [Ethereum Transaction Hash (Txhash) Details | Etherscan](https://etherscan.io/tx/0x3f66179cfac881f18a843ea4d27dbefcf807c87ddeaa7d08ce4cf18fdfd8e2f9)

---

<div class="post-metadata">

**Author:** ![FelixLts](https://dub1.discourse-cdn.com/flex013/user_avatar/research.lido.fi/felixlts/32/379_2.png) [@FelixLts](https://research.lido.fi/u/FelixLts)\
**Post date:** [April 20, 2022, 11:06am UTC](https://research.lido.fi/t/compensating-security-assessment-costs-for-lido-on-x-projects/1717/16 "2022-04-20T11:06:45Z")

</div>

Hi all,

Chorus One commissioned and paid for two audits for the initial Lido on Solana program in Q2/3 2021:

- $15,000 for an initial Brahma Systems audit
- $90,000 for a thorough Neodyme audit of the initial Lido on Solana (Solido) program and all related components

In addition, the about to be released bSOL / Terra Anchor integration was audited by Neodyme again in Q1/2 2022:

- $90,000 for Neodyme audit of Anker; the stSOL → bSOL Solana/Wormhole/Terra interaction and integration into Anchor

All audit reports can be found [here](https://docs.solana.lido.fi/security).

| Vendor | Amount USD | Date of pmt | Pmt method |
| --- | --- | --- | --- |
| Bramah Systems | 8,750.00 | 7-Jun-2021 | [c1-audit-pmt-proof.pdf - Google Drive](https://drive.google.com/file/d/1aMtfH8nykRurWrUs6XDuO0k98Kre5PvF/view?usp=sharing) |
| Bramah Systems | 8,750.00 | 9-Aug-2021 | |
| Neodyme | 90,000.00 | 28-Dec-2021 | |
| Neodyme | 90,000.00 | 29-Mar-2022 | [Solscan](https://solscan.io/tx/stTnQmCMs7GetdyGNuUeZDaFVkfU1LWFfLVmFNfxfZr7CmhEUT7Krk9ygeEFwCBJpgjrum3Q81PLRnb5angub2G) |
| TOTAL | 197,500.00 | | |

We would like to ask for the reimbursement to this Ethereum address:

0x3983083d7fa05f66b175f282ffd83e0d861c777a

We sent transactions to and from this address from our Lido operator address to confirm that it’s ours:

> **[Ethereum Transaction Hash (Txhash) Details | Etherscan](https://etherscan.io/tx/0x9b2d3cbbf4474b58b6208257c903aacd6864fe26618e297edefad7792ee42a00)**
>
> Ethereum (ETH) detailed transaction info for txhash 0x9b2d3cbbf4474b58b6208257c903aacd6864fe26618e297edefad7792ee42a00. The transaction status, block confirmation, gas fee, Ether (ETH), and token transfer are shown.

> **[Ethereum Transaction Hash (Txhash) Details | Etherscan](https://etherscan.io/tx/0x75b465442c5becf1c72b05fa4fd90897906a1fd4b9f77485a68fe3a4100b22b9)**
>
> Ethereum (ETH) detailed transaction info for txhash 0x75b465442c5becf1c72b05fa4fd90897906a1fd4b9f77485a68fe3a4100b22b9. The transaction status, block confirmation, gas fee, Ether (ETH), and token transfer are shown.

Best,  
Felix

---

<div class="post-metadata">

**Author:** ![vsh](https://avatars.discourse-cdn.com/v4/letter/v/b19c9b/32.png) [@vsh](https://research.lido.fi/u/vsh)\
**Post date:** [April 20, 2022, 11:38am UTC](https://research.lido.fi/t/compensating-security-assessment-costs-for-lido-on-x-projects/1717/17 "2022-04-20T11:38:34Z")

</div>

Is this not included in [Lido on Solana - Proposed Transition from Chorus One to P2P](https://research.lido.fi/t/lido-on-solana-proposed-transition-from-chorus-one-to-p2p/1887) 650k LDO payment for development effort?

---

<div class="post-metadata">

**Author:** ![FelixLts](https://dub1.discourse-cdn.com/flex013/user_avatar/research.lido.fi/felixlts/32/379_2.png) [@FelixLts](https://research.lido.fi/u/FelixLts)\
**Post date:** [April 27, 2022, 11:44am UTC](https://research.lido.fi/t/compensating-security-assessment-costs-for-lido-on-x-projects/1717/18 "2022-04-27T11:44:59Z")

</div>

It is true that this audit compensation proposal came up in parallel to our other proposal. I’m honestly not sure how this should be factored in.

---

<div class="post-metadata">

**Author:** ![DeFiYaco](https://dub1.discourse-cdn.com/flex013/user_avatar/research.lido.fi/defiyaco/32/2084_2.png) [@DeFiYaco](https://research.lido.fi/u/DeFiYaco)\
**Post date:** [May 6, 2022, 3:55pm UTC](https://research.lido.fi/t/compensating-security-assessment-costs-for-lido-on-x-projects/1717/19 "2022-05-06T15:55:48Z")

</div>

Shard Labs paid an additional amount to Oxorio for auditing PR ([Fix/audit 67 by idirall22 · Pull Request #69 · Shard-Labs/PoLido · GitHub](https://github.com/Shard-Labs/PoLido/pull/69)) like it was mentioned in the original post ([Compensating security assessment costs for Lido-on-X projects - #13 by ShardYaco](https://research.lido.fi/t/compensating-security-assessment-costs-for-lido-on-x-projects/1717/13))

The payout was done in two batches of 13750 USDC:  
[Ethereum Transaction Hash (Txhash) Details | Etherscan](https://etherscan.io/tx/0xb3f7bdbbf770a56a0ec5713b5652a41c5da3b7d0545ac295b95557983678904f)  
[Ethereum Transaction Hash (Txhash) Details | Etherscan](https://etherscan.io/tx/0x21f77cf8891a682e3bd9d55a5c487cb42f4e9dcb1fa5b01580fc8b41cd92e253)

The compensation can be issued to the same address we used for the first part: 0x4290db8e966a880d7Fd734884FBa93ee671984ea

---

<div class="post-metadata">

**Author:** ![kadmil](https://dub1.discourse-cdn.com/flex013/user_avatar/research.lido.fi/kadmil/32/1958_2.png) [@kadmil](https://research.lido.fi/u/kadmil)\
**Post date:** [June 1, 2022, 1:19pm UTC](https://research.lido.fi/t/compensating-security-assessment-costs-for-lido-on-x-projects/1717/20 "2022-06-01T13:19:35Z")

</div>

Last batch of ShardLabs audit comp is sent: [Ethereum Transaction Hash (Txhash) Details | Etherscan](https://etherscan.io/tx/0xb3b1589abe803e3c090177a35d6d84ef762b2bbda392907cab8fe2511247aac9), all the audits for Lido on Polygon are compensated

[Next page](https://research.lido.fi/t/compensating-security-assessment-costs-for-lido-on-x-projects/1717.md?page=2)
