Proposal “vulnerability-disclosure-compensation“ (Active)Back

Title:[REDUCED] Critical vulnerability disclosure compensation
Owner:DeltaXV
Monthly amount: 100 DASH (5101 USD)
Completed payments: 1 totaling in 100 DASH (2 month remaining)
Payment start/end: 2026-09-05 / 2026-12-04 (added on 2026-09-04)
Votes: 526 Yes / 121 No / 24 Abstain
Will be funded: Yes
Manually vote on this proposal (DashCore - Tools - Debugconsole):
gobject vote-many 10b85795a0a484e2e5167395c2d3733de39e5d613e3b7a6e3249495027c1f95e funding yes

Please login or create a new DashCentral account for comfortable one button voting!

Proposal description

Hi Dashers, 

You might be familiar with my proposal, which didn't pass due to another PO not having enough budget left. Old proposal

I decided to reduce the amount, to leave buffer for other PO and their budget demand. And to make sure budget shortage doesn't happen from my proposal.


My Dash security contribution is as follows: 

1. I have independently reviewed the Dash core implementation for a couple weeks, as goal to find critical vulnerabilities.

2. I have found 3 critical vulnerabilities including a unique finding.

  • Dash core does not track the EvoNode platformNodeID in its mempool [UNIQUE]
  • Dash Core masternode remote crash via QSIGSHARESINV OOM (Out-Of-Memory)
  • Dash Core remote crash via out-of-range versionBit in MNHF transaction

3. My report were all valid, with a 3/3 and 100% valid ratio.

4. Privately disclosed the reports (PGP encrypted) to Pasta. And acknowledged as being valid.


For anyone willing to know more about me:

- Here's my X account.

- I found a critical vulnerability in a EVM precompile that would have exposed $1,7m in btc, usdc, etc to be stolen from a bridge.

- I recently found a critical vulnerability in Litecoin core implementation, that could have led to network-wide crash. 

- I secured a $5.5 billion TVL blockchain by ranking 1st in the Base Audit Competition.

- I found other serious vulnerabilties in many multi-billion dollar blockchains.


Compensation and what's next?

As compensation for these vulnerabilities and security contribution for the Dash ecosystem and MNs. 100 DASH per month, which covers these critical impact security contribution and more frequent security reviews with coordination with the dash core team for disclosing critical vulnerabilies. As soon this proposal passes this will allow me to be rewarded for my discoveries and commit more time into reviewing the dash implementation.

Show full description ...

Discussion: Should we fund this proposal?

Submit comment
 
4 points,25 days ago
Thank you for disclosing the vulnerabilities in Dash. We definitely do really appreciate people helping keep the Dash network secure.

I'm hesitant to pay out $16,000 (over three months) for something someone used AI to find.

Did the other blockchains compensate you for disclosing their vulnerabilities? If so, will you tell us how much they each paid you?

Suppose we fund you one month, but not the three months that you are requesting - then would you be upset and resent Dash? Does the $16,000 buy your benevolence? Are you our friend or our enemy - and does that depend on if we pay you enough money?

I'm sorry to sound combative, these are just honest questions and I haven't made up my mind yet. You have helped Dash, so sincerely thank you.
Reply
3 points,25 days ago
Hi, thank you for the feedback.

I think it would be more appropriate if we directly discuss about the disclosed vulnerability, which itself will tell much more about the impact, severity, feasability and thus the average amount.

The unique finding:

- It was a critical vulnerability in the mempool implementation.

- Essentially this bug could have allowed an attacker to cause a network-wide block production halt.

- Actual impact: no more block can produced and no transactions can be processed.

- Reachability: The attacker vector was permissionless and could have been triggered by anyone with no capital lost.

Some past bug bounties I had (due to NDA; I can't diclose the blockchain name):

- EVM blockchain - impact RPC API crash - 25k in USD - https://x.com/immunefi/status/1939608542614274090?s=20

- Another EVM blockchain - network-wide halt - 20k in USD - https://x.com/immunefi/status/2038596043697209732?s=20

- Immunefi average "Chain halt/Network not being able to confirm new transactions (total network shutdown)" vulnerability bounty is 10,000-25,000$. https://immunefi.com/bug-bounty/

> I'm hesitant to pay out $16,000 (over three months) for something someone used AI to find.

Tbh i believe that's a really bad take. AI involvement is really subjective, it's to be considered as a set of tools rather than a "infinite cheat code vulnerability generator", no it's not how it works lol. **I would also say, if AI is becoming so useful in security it's more important than ever to cybersecurity activity because exploit execution is becoming more and more openstream (i.e. coldcard, Liquid network, etc), therefore valid private vulnerability disclosure should naturally be rewarded rather than bad peoples when the report is valid ofc.**

Finally the funding amount is really decent and low-tier, I've proved above that it is appropriate amount by most of blockchain standard (as of today). **I'm a fully indepandant security contributor asking funding like any contributor or PO, to be afloat I would need to receive a bounty or it won't be sustainable to review Dash.** Dash has also a native network funding which imo is best way to reward security researchers that protect it's own network code implementation and it's TVL. I mean, if Dash DAO were to be an AGI it would 100% agree I guess.. because i've contributed to it's own security :D
Reply
2 points,24 days ago
Ok, thanks for the explanation, but still I'm wondering, would you consider partial funding of 100 Dash insufficient?
I personally think even $5,000 would be way-overpayment for this. In the real world people work full-time for months to earn $15,000.

I mean, what is the large value... are you saying the network should pay you tons of money so that you will be nice and not attack Dash? is that the threat? or do you sincerely think the amount of work you did is worth $15,000?

I don't think bug-finding is a function of human labor anymore; now it's done by AI. Right? Dash doesn't offer the large bug-bounties now that we used to offer.

I'm not saying that your contribution isn't appreciated, it is. Thank you. But I just think the request for a lot of money from us seems obsolete now, I'm sorry. I personally would support giving a more reasonable compensation, now that times have changed.
Reply
2 points,24 days ago
I am funding them for one month and not the others.
Reply
2 points,24 days ago
It's supposed to be a 3 time payment bounty instead of a full one time amount. It avoid putting pressure on the budget and leaves more funding to others. Kindly read my comment above which clarifies the amount backed with data. Dash is no different of other blockchain in security (vulns and impact stays the same), in fact it is better when we explore how much activity it has than other blockchains
Reply
1 point,24 days ago
> I don't think bug-finding is a function of human labor anymore; now it's done by AI. Right? Dash doesn't offer the large bug-bounties now that we used to offer.

That is just not true in the real world your explanation and assumption doesn't hold. AI is by far better in coding/development than the average software engineer (SE), however of course we need human SE for the development pipeline. Likewise the same holds for security research, AI has improved a lot in security it doesn't mean it is reliable at 100% because by nature vulnerability research is more complex than scanning a codebase.

This month Liquid Network was hacked for 4,000 BTC, they probably had the same reasoning as you. And relied on their "AI bug-finding generetor" while it has been proven their AI that fixed bug A introduced the critical bug B, which led to hack. It's not rocket science to understand that any security contribution should be taken with highest priority.

> I mean, what is the large value... are you saying the network should pay you tons of money so that you will be nice and not attack Dash? is that the threat? or do you sincerely think the amount of work you did is worth $15,000?

**you left my comment unaddressed and took your own personal conclusion...** In my comment I have explained what are the compensation for a vulnerability of that severity and impact. Just to re-iterate, a single permissionless attacker being able to halt Dash block production and transaction processing is a critical vulnerability by any cybersecurity framework. I do have provided substantial details about the average payout for average "Chain halt/Network not being able to confirm new transactions (total network shutdown)" vulnerability on immunefi which is 10,000-25,000$. If you look on the "last 90 days" immunefi leaderboard, critical vulnerabilities are being found and rewarded on a daily basis by "human labor" while every project integrated latest AI models. Both these points disproves your reasoning that security is not worth the cost while others are compensate those who secure their projects. https://immunefi.com/leaderboard/

I sincerely believe you do not consider security with a high priority because of the AI lore and you're downplaying the contribution with no substential input besides "we could have found it!". That's confusing that such a security sensitive
Reply
1 point,24 days ago
-> proposal get's this kind of treatment while it is largely decent compared to other proposals.
Reply
2 points,24 days ago
Did you actually spend months of full-time hard work finding this vulnerability?

If not, do you think your brilliance and skill (using AI) is worthy of as much money as normal people work hard for months to earn?

$15,000 isn't something to be frivolously handed out charitably just because we are a DAO.

In the past, finding bugs required a lot of human time and effort and rare skills; now you can just prompt AI. It's still something important and valuable, yes - but the effort required has changed. Compensation should change.

Reporting a vulnerability is a helpful and appreciated service, but it should be rewarded according to the value of effort put into finding it. And in the past few months AI has really changed that.

Just because black-hats can cause major damage, doesn't mean white-hats should want overcompensation for not being criminals. Fair compensation plus a small bonus is appropriate - and genuine appreciation, of course.


Suppose someone lost his million-dollar painting, and I found it and I know it belongs to him. I would go return it to him; it's his property. Then, if it took me $20-worth of effort to go find him to return it to him, then I should request $20. That would be fair. Out of gratitude, he might offer to pay me $50, and I would be thankful. $50 would be overcompensation for the value of my actual effort: the value owed is not a percentage of the million dollars; the just compensation is for the valuation of my effort. The painting is his property, and I would be out-of-line to think I had a claim on that. My being honorable should be assumed as a given; we have property-rights, he is the owner of the painting, and stealing it would be a crime.

Of course realistically a million-dollar painting is likely to be stolen when someone finds it, but that doesn't mean we therefore have to award someone overcompensation just for simply doing what's right. Doing what's right is normal. The owner gets his property returned to him, then the owner compensates the person what it cost them to return it, and that's that. Simple justice. The person returning the painting isn't entitled to overcompensation just for not committing a crime.

$15,000 seems like way more than the economic value of the time and effort it would take someone using AI to find a vulnerability. Am I wrong? For example, if it took 4 hours of work, then I think about $400 would be more than fair. I used to work hard for $14/hour for years, real physical labor.

How much time and effort did it actually take to find the Dash vulnerability? That's what I would need to know to decide fair compensation. If indeed it was months of hard work, I would like to know that.

But I'm just one individual here, and I'm not technical. The DAO can ultimately decide how much compensation is fair. :)
Reply
3 points,24 days ago
I welcome your respectful critisim. But again, that's just your personal opinion and subjective interpretation of what security research and bug bounty compensation.

I appreciate the fact you acknowledge the contribution. But you're clearly engaging in bad faith, that's the first time in my whole career i've been asked on my hours of work when I've brought critical vulnerabilities on the table. It doesn't work this way, generally a vulnerability is rewarded with an impact framework, in that case do you consider a critical vulnerability that takes down Dash for hours to be a worthless contribution? in the blockchain industry there is a specific well defined reward standard.

> $15,000 seems like way more than the economic value of the time and effort it would take someone using AI to find a vulnerability. Am I wrong? For example, if it took 4 hours of work, then I think about $400 would be more than fair. I used to work hard for $14/hour for years, real physical labor.

Bruh that's a bad example. If you were to put this on the `security.md` 95% of security researchers would skip your codebase due to the disrespect. If I remember Coldcard rewarded researcher with a "mug and some t-shirt" they had AI tools, they ended up having coldwallets being drained. $400 is according to you "more than fair" reward for a critical vulnerability, while that's would completely expose Dash to lack of review signal.

> Just because black-hats can cause major damage, doesn't mean white-hats should want overcompensation for not being criminals. Fair compensation plus a small bonus is appropriate - and genuine appreciation, of course.

I genuinely think you're tripping lol. I've have provided you across two comments so far real-time security industry data (with all of it; as of now, AI era, 2026, etc) on what consist a compensation for a "Chain halt/Network not being able to confirm new transactions (total network shutdown)" finding. Maybe more precise and real examples will help understanding:

- Sei Network - chain halt - $25,000 - https://immunefi.com/bug-bounty/sei/information/#top
- Optimism - Network not being able to confirm any new transactions, including deposits (Total network shutdown) - $50,000 - https://immunefi.com/bug-bounty/optimism/scope/#top
- Polygon - Network not being able to confirm new transactions (total network shutdown) - $10,000 - https://immunefi.com/bug-bounty/polygon/scope/#top
- Cosmos - Chain halt / liveness failure - $12,500 - https://immunefi.com/bug-bounty/cosmos/information/#top
- Hedera - Network not being able to confirm new transactions (total network shutdown) - $10,000 - https://immunefi.com/bug-bounty/hedera/information/#top
- Babylon chain - Chain halt - $15,000 - https://immunefi.com/bug-bounty/babylon-labs/information/#top

Why do you somehow expect Dash to be cheap on security instead of treating it as a core crucial part of Dash network and DAO operation when it comes responsible vulnerability disclosure. When every major blockchain offers decent rewards for this exact same bug minimum $10,000 per vulnerability that leads to chain halt.

> $15,000 seems like way more than the economic value of the time and effort it would take someone using AI to find a vulnerability. Am I wrong? For example, if it took 4 hours of work, then I think about $400 would be more than fair. I used to work hard for $14/hour for years, real physical labor.

There's no such thing as a "hourly rate" in vulnerability research most of the time everyone finds nothing eventually you can find a vulnerability, it's either a valid or invalid report. I can review a codebase for weeks/months and never find something that's part of the game, and that's the reason hours does matter only to povit to another project.

By above examples I'm far from asking "overcompensation" in this proposal, the amount is really low and appropriate for my critical findings *across multiple periods*. *With current Dash rate*, the funding request is well within industry standard. My question would how can devalue a security contribution in the case of Dash while clearly other project/blockchain value responsible disclosure of critical vulnerability that leads to a chain halt, it systematically stays above $10,000, and I never saw some hourly rate thing, because this doesn't exist in cybersecurity only if you're hired for audits etc.

I'm not willing to disturb other proposals and network budget this is the reason i've divided the amount across 3 months. I really hope that it is understood that security is important generally not only about this proposal in particular. But also for future researchers who secure dash with valid reports.
Reply
3 points,24 days ago
Okay, well I appreciate your contribution and honest involvement here, and I hope you do receive some compensation. I'm not engaging in bad-faith, just being cautious with how we allocate our scarce treasury money. You currently have a lot more yes-votes than no-votes, so clearly other masternode-owners do see the value. :)

I think bug-finding is a job that AI has already mostly taken-over, so I don't expect it to be so lucrative for highly-skilled humans in the future, but I guess we'll see.
Reply
-3 points,22 days ago
You are engaging in bad faith, stop lying. How do I know you're lying? Because you and lysergic would NEVER make these kinds of criticisms or "observations" on any of Joel's proposals. Which means you're biased towards Joel even though he doesn't do anything, and against POs like this, despite them literally securing our chain. You abuse your position and your nodes should be removed from the network.
Reply
3 points,1 month ago
Voting YES
Reply