[reWARDS] April '23 Budget

A significant update regarding April’s rewards:

TLDR:

  • Rewards distributed for KyberSwap Elastic pools that had not yet been distributed to LPs have been clawed back and returned to the respective Lido reWARDs multisigs.
  • This was done as a preventative measure once Kyber contributors informed the reWARDs committee about a vulnerability that had been found on the protocol.

Longer context, quoted directly from Kyber’s contributors team:

  • "On April 17th, the KyberSwap team identified a vulnerability in KyberSwap Elastic DEX, where in specific circumstances (details withheld to prevent exploitation by opportunistic blackhats), LP funds could potentially be at risk. No funds were lost.

  • The KyberSwap team took immediate action to fix the issue and disabled additional deposits. They also conducted a comprehensive review to identify any other potential related issues stemming from the discovery, but no further vulnerabilities were found.

  • However, as a precautionary measure, the team recommended that all KyberSwap Elastic LPs withdraw their funds; and quickly notified Lido DAO contributors due to the existence of significant wstETH, stMATIC and LDO liquidity. Within a couple days, most LPs were withdrawn and KyberSwap Elastic TVL dropped from ~$105m to ~$3m.

  • Kyber set a deadline to stop all farm incentive distributions on April 18th at 4pm UTC. Kyber, alongside Lido DAO’s reWARDs program had also been in the middle of incentivizing the following pools with LDO and KNC via yield farms. All remaining incentives from previous phases and from the current phases at the time of the vulnerability discovery were returned to Lido DAO’s reWARDs operational multisigs on April 26th.

  • The KyberSwap team has fixed the vulnerability issue and will redeploy KyberSwap Elastic with a target redeployment date of May 25th, after completing some audits."

Return transactions, for transparency:

Notes:

  • Many thanks to Kyber’s contributor team for identifying this, reaching out and acting fast to successfully prevent any loss of funds. cc: @Sasha_Mai

  • These retrievals have been factored in on May’s reWARDs budget, under funds left by EOM on each multisig.

  • Due to this situation and respective timelines, no rewards allocations were budgeted in the May’23 budget linked above. Once a resolution is achieved and the new KyberElastic is redeployed, it will be again considered for the allocations (June and onwards).