Cosmos Hub Proposal: #954
Permissionless ICS 3rd Party Audit
Turnout:53.21%
Quorum:40.00%
Yes: 79.7%
104,574,024 ATOM
No: 2%
2,659,559 ATOM
No With Veto: 0%
42,212 ATOM
Abstain: 18.2%
23,853,120 ATOM
Voting Period
-Proposer
cosmos1mtdkdv8cf0sdyugffzf80h80fs65qw2xmm3smj
Deposit End
Submit Time
Description
Authors: Simply Staking
TL;DR - Simply Staking will commission Zellic to conduct a third-party audit of the Permissionless ICS feature. This will follow a similar format and process as our third-party audit conducted last year on Replicated Security (Prop 687) and this year on Hydro (Prop 927), and Interchain Security (ICS) using the Inactive Validator Set (Prop 943)
Background
This proposal aims to use community pool funds to commission a third-party audit for Permissionless ICS. Permissionless ICS will allow anyone to create an opt-in consumer chain, without a governance proposal. This will allow chains to launch more quickly and with less friction.
For more information, we advise you to review the CHIPs forum post.
As we saw in one of our proposals regarding an audit of key Cosmos Infrastructure (ICS) in Proposal #687, it Is always key to get a second set (or more) of auditors who had no involvement in the designing and building of the code to audit the codebase. This will allow for unbiased vulnerabilities to be disclosed (if any).
Details of Funding Request
Zellic, one of the most reputable auditors in the space, will conduct this audit. With the audit scope already known to the auditor, they (Zellic) have presented a quote and timeline for the audit. Zellic is seeking $90,000 for the audit of the Permissionless ICS codebase with an estimated 3.6 engineer-weeks over the course of a 2.4 calendar-week period by 2 Zellic security engineers.
We believe that the terms and quotes presented by Zellic are fair and ideal. It is a relatively small request for an audit of this importance.
Management
Since this is a community pool spending proposal, we want to ensure the community that the funds will arrive at the designated recipient by creating a multi-sig.
The multisig should be comprised of various reputable parties:
- Damien, Simply Staking
- Jehan, Informal, Inc
- Brian, Informal, Inc
The multi-sig address is: cosmos1eq62mta47ltpmncknzf70v3z70vn834fxxq5ra
Breakdown of Fees
We (Simply Staking) will be the main point of contact with Zellic, meaning we will handle all things related to answering their questions and queries. We will also act as the main coordinator for building and maintaining the multisig to ensure a smooth transfer of funds from the multisig address to the designated recipient (Zellic). For the work with Zellic and the multi-sig coordination, we seek a compensation fee of around 10% of the audit quote.
Funding
Zellic Quote: $90,000 + 25% price buffer to account for the volatility of the ATOM token during the voting period: $112,500
Simply Staking Fees: $9,000
- Community consensus via forum and on-chain proposals
- Sourcing vendor quotes
- Coordinating vendor payments and milestones
- Multi-sig coordination
Total ask ~ $121,500 ~ 24,850 ATOM (at $4.89 as of 27/08)
All leftover funds will be sent back to the community pool.
Governance votes
The following items summarize the voting options and what it means for this proposal:
YES - You agree that this external audit should be funded.
NO - You disagree that this external audit should be funded.
NO WITH VETO - A ‘NoWithVeto’ vote indicates a proposal either (1) is deemed to be spam, i.e., irrelevant to Cosmos Hub, (2) disproportionately infringes on minority interests, or (3) violates or encourages violation of the rules of engagement as currently set out by Cosmos Hub governance. If the number of ‘NoWithVeto’ votes is greater than a third of total votes, the proposal is rejected and the deposits are burned.
ABSTAIN - You wish to contribute to the quorum but you formally decline to vote either for or against the proposal.