Proposal “vulnerability-disclosure-compensation“ (Active)Back
| Title: | Critical vulnerabilities disclosure and independant security contribution |
| Owner: | DeltaXV |
| Monthly amount: | 200 DASH (6806 USD) |
| Completed payments: | no payments occurred yet (2 month remaining) |
| Payment start/end: | 2026-07-07 / 2026-09-04 (added on 2026-07-06) |
| Final voting deadline: | in 1 month |
| Votes: | 310 Yes / 36 No / 40 Abstain |
| Will be funded: | No. This proposal needs additional 34 Yes votes to become funded. |
|
Manually vote on this proposal (DashCore - Tools - Debugconsole): gobject vote-many 74502da7c676af03049687172b9b1ea14315ff5d1585b77ed67752776af63762 funding yes Please login or create a new DashCentral account for comfortable one button voting! | |
Proposal description
Hi everyone, I'm DeltaXV a blockchain security researcher and whitehat. You can find me on X (@deltaxv_) and Github (@DeltaXV).
During the month of June 2026, I have uncovered 3 different critical severity vulnerabilities, that would have led to major impact on the Dash network and Master nodes.
My contribution is as follows:
1. Dash core does not track the EvoNode platformNodeID in its mempool.
- Summary: This would have allowed an attacker to cause a network-wide block production halt with 2 `ProRegTx`-type transactions.
- Severity: Critical
- Recovery: Recovery would have taken +24h, the chain simply stops producing blocks and no user transactions can be included with no logs or error. Even on a restart, both poison txs are reloaded from `mempool.dat` and broadcasted to the whole network, so the halt just resumes.
- Patch: fix: don't let 2 protx with the same platform-id to be presented in mempool (Commit 78b8274)
2. Dash Core masternode remote crash via QSIGSHARESINV OOM (Out-Of-Memory)
- Summary: An attacker being an unauthenticated peer with a single crafted 3 MB message forces ~1.5 TB of memory allocation on any masternode, causing an immediate OOM kill (SIGKILL). Through this OOM issue an attacker can then do the double spend attack via a very easy 51% attack and reorgs, with carefully targeted MNs
- Severity: Critical
- Fix: fix: early bail-out for huge QSIGSHARESINV and QGETSIGSHARES (Commit 3426458)
3. Dash Core remote crash via out-of-range versionBit in MNHF transaction
- Summary: An attacker can remotely crash with a single crafted transaction with versionBit >= 29 crashes any Dash node that attempts to validate it basically the whole network would crash.
- Severity: Critical
- Note: This was also discovered upstream by the dash core team
- Fix: perf: avoid re-validation of ehf signals during block-connect (Commit 54187cd).
Currently:
All patches have been implemented in Dash core 23.1.4 couple weeks ago. Thanks to PastaPastaPasta and quantum_explorer for their assistance during the bug report submission.
Compensation and what's next?
As compensation for these vulnerabilities and security contribution for the Dash ecosystem and MNs. 200 DASH per month during 2 superblocks, which covers these critical impact security contribution and frequent security reviews with coordination with the dash core team for disclosing critical vulnerabilies. As soon this proposal passes this will allow me to be rewarded for my discoveries and commit more time into reviewing the dash core implementation.
During the month of June 2026, I have uncovered 3 different critical severity vulnerabilities, that would have led to major impact on the Dash network and Master nodes.
My contribution is as follows:
1. Dash core does not track the EvoNode platformNodeID in its mempool.
- Summary: This would have allowed an attacker to cause a network-wide block production halt with 2 `ProRegTx`-type transactions.
- Severity: Critical
- Recovery: Recovery would have taken +24h, the chain simply stops producing blocks and no user transactions can be included with no logs or error. Even on a restart, both poison txs are reloaded from `mempool.dat` and broadcasted to the whole network, so the halt just resumes.
- Patch: fix: don't let 2 protx with the same platform-id to be presented in mempool (Commit 78b8274)
2. Dash Core masternode remote crash via QSIGSHARESINV OOM (Out-Of-Memory)
- Summary: An attacker being an unauthenticated peer with a single crafted 3 MB message forces ~1.5 TB of memory allocation on any masternode, causing an immediate OOM kill (SIGKILL). Through this OOM issue an attacker can then do the double spend attack via a very easy 51% attack and reorgs, with carefully targeted MNs
- Severity: Critical
- Fix: fix: early bail-out for huge QSIGSHARESINV and QGETSIGSHARES (Commit 3426458)
3. Dash Core remote crash via out-of-range versionBit in MNHF transaction
- Summary: An attacker can remotely crash with a single crafted transaction with versionBit >= 29 crashes any Dash node that attempts to validate it basically the whole network would crash.
- Severity: Critical
- Note: This was also discovered upstream by the dash core team
- Fix: perf: avoid re-validation of ehf signals during block-connect (Commit 54187cd).
Currently:
All patches have been implemented in Dash core 23.1.4 couple weeks ago. Thanks to PastaPastaPasta and quantum_explorer for their assistance during the bug report submission.
Compensation and what's next?
As compensation for these vulnerabilities and security contribution for the Dash ecosystem and MNs. 200 DASH per month during 2 superblocks, which covers these critical impact security contribution and frequent security reviews with coordination with the dash core team for disclosing critical vulnerabilies. As soon this proposal passes this will allow me to be rewarded for my discoveries and commit more time into reviewing the dash core implementation.
Show full description ...
Discussion: Should we fund this proposal?
Submit comment
|
No comments so far?
Be the first to start the discussion! |
Is there a way to contact you outside of Twitter/X ?
Would you mind, setting up a temporary (throwaway) forwarding mailbox?
Up for this proposal, down for DCG.
Thanks for all the constructive feedbacks. I have seen questions being raised about the proposal amount being too "excessive". It isn't, and I can prove it.
On average and by industry standards this type of critical vulnerability is compensated for more than 10x this proposal amount. A good similar example recently this researcher disclosed a high severity vulnerability to zcash and was rewarded 75,000 USD for a p2p attack vector that would have led to targeted nodes being taken down at a network-wide scale, requiring a restart. -> https://x.com/0x15_eth/status/2060286003928052145
The vulnerability I have found is by far more severe and would instantly halt block production with no more transactions being accepted. The impact would persist even after node restart with no direct indication of the actual root cause (no errors, no logs). Which mean dash network could be down for a longer period. Which could have exposed some third party bridges to direct theft (double spend, etc) and arbitrage of the dash price post-exploit.
Rationally thinking the native dash network governance funding, can't make more sense for providing compensation for securing it's own code that is running on every single Master Node. I don't see a more obvious purposes that this ;) I've made sure to adapt the proposal to the dash governance scale to make sure it won't disturb other core and community proposals. This proposal amounts only for +2% of the total budget which directly compensate as crucial security contribution that directly relate to the dash network, MNs and other proposals :D
Thanks to everyone who is voting,
DeltaXV
"
>lysergic
1 point,21 days ago
I support this guy, he works hard, and has the results to prove it."
From the Dash growth proposal, https://www.dashcentral.org/p/dash-growth-q3-2026.
Why is lysergic being unnecessarily negative and down right dishonest towards a PO? Off the bat, completely inappropriate negativity from him towards this PO, that has fixed a critical vulnerability in our chain. But on "Dash growth" which is not even a core function of the network, lysergic is basically inviting Joel to bed? What's going on here?
You should be this way towards *every PO that is beneficial towards the network*. You shouldn't be playing favorites based on "who I like/don't like". This is a form of corruption called nepotism, defined as:
3. The favoring of relatives or **personal friends** because of their relationship rather than because of their abilities.
This PO has solved a major problem with our network. Joel has never done anything like that. But lysergic is just so happy to GIFT him 530 DASH A MONTH FOR YEARS ON END, but a PO solves a critical vulnerability in our network and he's jumping down his throat, challenging his claims and estimation of worth and basically calling the PO a liar trying to cheat the network?
Come on. This is wildly inappropriate behavior. If lysergic has the ability to "wave Joel on through", he has the ability to do that to this PO x10. But he's not. He's extremely unfriendly towards him with NO JUST CAUSE. This is a violation of the principles of the network.
All of the sudden you become an expert in critical vulnerability, threat analysis and evaluation of the merits of bugs found. But when Joel puts up a proposal, you lose all criticality in your eye. Everything is "just so amazing, such great work!"
You are a hypocrite and a liar and you are trying to keep other POs OUT of the treasury so you and your cabal can corner the market on the DAO's funds for nefarious purposes. That is the only logical explanation for your aggressive and dishonest behavior here.
So far you haven't brought a single argument that technically disprove this critical vulnerability besides weak and bad faith lowballing, it is valid from A to Z, acknowledged by pasta and QE.
the collaterall **is never** spent, and it never leaves the attackers wallet.
- When broadcasting the ProRegTx, the collateral utxo is not a transaction input. The tx only contains a reference to CollateralOutput and txid + output index and signature ownership. The utxo doesn't move..
- Whatever happens to the attackers ProRegTx transactions, the collateral utxo was never an input to anything. Basically, I'm telling you that the attacker can spend his coins as nothing ever happend.
> Because this proposal feel more like a shakedown and that's why Pasta and QE had to chime in, because the ask is too much,
The disclosure was PGP-encrypted, privately sent to Pasta, with no upfront compensation request. Pasta and QE were personally asked to provide their input on this proposal. *Nothing was withheld*.
For compensation amount please check other comments they already have substential details.
Did you understand that?
It seems, that there are comprehension problems...
I've proved it with direct evidence from the code, that the attackers balance DOESN'T change. so it doesn't matter if it's 400 or 4000 dash he keep the whole balance.
> lysergic wrote: "requires a person to have 4000 Dash"
omg, and what prevents anyone from holding 4000 dash bro. Anyone is freely able to aqcuire and hold dash coins, what's the issue with it. That's irrelevant to the critical vulnerability in itself while **the attacker actually keeps the whole balance...**, the attack is free. The only reason for bringing this up, is just to downplay the vulnerability while it holds no technical basis to the exploitability and validity.
This proposal is here to compensate my security contribution into privately disclosing 3 critical issue including a unique finding acknowledged by pasta and QE. I honestly don't understand where this hostility comes from. I acted in good faith. This a direct net contribution provided to the dash ecosystem and community.
I explain where it comes from. These MNOs are part of a cabal of hidden MNOs that secretly coordinate their votes together. Their plan is that "only certain people are allowed to have successful proposals", that way Joel and his group can play "kingmakers" and if you don't "kiss the ring" you can't get any funding.
This allows them to control the Dash funding experience and control who gets paid, what's considered valuable and what's not, so that Dash becomes THEIR network, not the network of the MNOs and greater community. Its a cynical attack, and unfortunately your proposal is caught in the cross-fire.
They do this to EVERY growth proposal in our network.
Its a power move; if I force him to lie then I gain power over him (like exposing him later using another of his or someone else's statements), whereas by claiming "I have no evidence" he can try to TRICK me (and others) and gain power over us instead.
This kind of thinking is BATTLE THINKING. I.e. Lysergic VIEWS US ALL AS ENEMIES!
But factually there's litterally no reason to vote NO for such proposal. I've been honest through all my comments and backed all my claims with evidence including from the dash code implementation itself (source of truth). Everything is documented to Pasta and QE with their acknowledgments. So there's no point doing back and forth with peoples that doesn't want to process plaint and direct facts. hopefully the majority is not compomised and acting malicious in the network.
You're correct, there is absolutely ZERO REASON to vote no for this proposal, which makes their actions counterintuitive. Unless they are compromised.
So why do we have not one, but AT LEAST TWO MNOs deliberately voting and arguing AGAINST the best interests of the network??? That doesn't make sense. These bugs are acknowledged as critical vulnerabilities by our core team, so their discoverer should be handsomely rewarded.
That would make sense in literally _every other_ cryptocurrency community. It would be completely non-controversial. But for some reason, in Dash, we have a whole group of people who WORK TOGETHER **TO GET THE WORST OUTCOMES POSSIBLE FOR DASH**.
That means its an attack! This is not "random" behavior, but deliberate coordinated behavior designed as an ATTACK on the Dash DAO, to prevent it from being effective and voting in a way that grows the network.
These MNOs are voting against THEIR OWN BEST INTERESTS, which means they are likely being compensated elsewhere, in secret for this betrayal.
When you eliminate the impossible, whatever remains, no matter how improbable, MUST be the truth!
It looks like they're trying to subtly control the network from the shadows by colluding together in the background, and I'm making it publicly clear that that is unacceptable behavior that abrogates the social contract that Dash relies on and should be censured and banned.
Its that important.
You project your transparency onto me, because I'M THE ONE WHO READ YOU from front to back. YOU are the transparent one here. Its obvious that you are corrupt and only support Joel and a few others while attacking literally _everyone_ else. Meaning you are abusing your voting power for your own gain, which makes you ineligible to participate here.
What I would like to see: Good communication and cooperation between you and DCG, so that any loss of efficiency can be avoided.
It all boils down to, do you reduce the dash network as being a cheap and useless blockchain where network-wide halt bugs are considered as ok. Because as clarified in the above comment, the compensation amount is largely justified and has broad and direct beneficial contribution on the dash ecosystem.
So your hesitation to pay it out looks pathologically skeptical and unnecessarily critical of a PO who *has already done work for the network*. This attitude, despite clear evidence to the efficacy of the bug discovered and the value others place on finding such a bug, adds fuel to claims that a group of masternode owners are deliberately colluding in the background to cynically deny funding to viable POs that are outside a certain group of "curated and selected proposal owners".
This would likely be an attempt to create a "rubber stamp culture", where if you don't have the explicit approval and seal of this cabal, you can never get a proposal passed. This, if my allegations are correct, would be a violation of the principles of the DAO and would open said MNOs up to censure and eventually POSE banning.
That "select group of curated people" **is supposed to be we the MNOs. All of us, together, out in the open.** No "hidden group collusion" allowed. Doing so is a breach of contract for a MNO (i.e. operating in good faith - which the network is deliberately designed to incentivize, showing how insidious and unnatural this kind of arrangement would be), and grounds for dismissal from the network.
Please don't contribute to the impression that you are a member of this cabal, that I allege with evidence indeed does exist, by being pathologically skeptical and irrationally negative towards POs seeking funding for legitimate work.
Similar to you, I have many disagreements with the PO on a personal level, and that on occasion is a source of conflict, but I am not so petty or foolish to allow my personal feelings get in the way of supporting his work. He does great work, even if sometimes he is a Royal Ass ! therealDashman21, you should grow up and little, and leave the personal grudges at the door and start using your votes more effectively.
Oh, btw, you should've taken your own advice. You're "overselling it" here. If you were truly innocent of the charge, *you would've said* "I'm not part of any such cabal". You wouldn't try to speak for the whole network and definitively claim that "no such cabal exists", because how would you know? You don't know every MNO and their affiliation.
But by saying this, you let SLIP what your true motivations are. You don't want us to think that this cabal even exists, so you LIE and SPEAK FOR EVERY OTHER MNO and say "there is no cabal". Even though YOU DON'T KNOW THAT.
I've never spoken to you personally outside of this public venue, so how would you know that I'm not part of such a cabal, for example? Or MNO# 104, or 556? But yet you still speak for those MNs *definitively* as if you somehow KNOW their affiliations. Which means YOU ARE LYING HERE! That was a mistake!
In other words, your intentions are that we do not believe such a cabal exists at all, NOT proving your innocence! Its more important to you to HIDE THIS CABAL than proving your innocence of the charge is.
Which likely means that **you KNOW such a cabal DOES exist and you're part of it** and you're trying to throw the scent off of the trail by forcefully declaring "no cabal exists", instead of SPEAKING FOR YOURSELF and declaring that the charge against you is false.
You have been caught, LIAR!
Again the simple fact that you deny this is almost proof enough (you are a liar). There IS a cabal and YOU DON'T WANT US THINKING about it. It has nothing to do with "voting the way I don't like". The vote hasn't gone my way SEVERAL TIMES now over the years, and I don't complain about it. Lowering the proposal fee, funding Joel and Mark Mason, changing the block reward split, defunding Dash Nigeria, Dash Venezuela, Dash help, Dash Latam. These things happened and I still participate in good faith, UNLIKE YOU.
It has nothing to do with personal hate towards POs, stop putting words in my mouth! I already told you why I don't like Joel, because he hogged Dash boost funds to prevent smaller proposals outside the main treasury from getting funding while still receiving a 300 Dash per month stipend from the treasury himself. That's corruption!
Also, he recieves now a 530 Dash proposal a month WITHOUT REALLY DOING ANYTHING. And he's bribed you, Tantestefana and other MNOs into corruptly "supporting his efforts" while GASLIGHTING EVERYONE ELSE. You guys attacked proposals that are "outside your group" and got them defunded so that only Joel and your cabal will get paid. THAT IS CORRUPTION!!!!
The DAO is not supposed to function that way. We're only supposed to vote in the BEST INTERESTS OF THE NETWORK, not your own private, personal interests. You colluding in the background to swing votes your way with other MNOs is a BREACH OF CONTRACT!!!
Dash GROWTH DOESN'T DO ANYTHING! We don't gain anything from having them. If it were defunded tomorrow NOTHING WOULD CHANGE!! Nobody watches his shows, nobody engages with him on twitter, its just the same circle jerk over and over every month AND YOU, MR. PATHOLOGICALLY SKEPTICAL NEVER CALL THIS OUT, which is strong evidence of a cabal and you being part of it.
You NEVER HAVE A PROBLEM with the lack of engagement, lack of price movement and lack of actual growth that proposal provides. You don't have any problems with "the price tag" of 18k a month FOR NOTHING, seriously literally ANYONE ELSE could do what he does FOR FREE and it would be more worth it than what we get now.
You don't care about his lack of efficacy Because YOU and your comments are NOT SERIOUS. You don't care about the Dash DAO, you are invested in TEARING DASH DOWN by gaslighting and trickery and lying, and false pretense.
You "pretend" to care about "the ask" and "what the benefit is" but you just use this as a false shield so that you can attack POs that are outside your little group. That is not how you are supposed to behave in the DAO and it proves that you are illicitly coordinating behind the scenes with other MNOs for your OWN SELFISH PURPOSES.
You don't give ANY OTHER POs a single benefit of the doubt. This is a critical vulnerability! And you're pinching pennies, scrutinizing and looking for excuses TO NOT PAY THE MAN! Because YOU ARE CORRUPT! Your goal is to subtly remove all other participants from the treasury so that ONLY JOEL AND HIS GROUP get any funding.
You are only FAKING "disagreements" with Joel. You don't actually disagree with any of his behavior "similar to me", you LIAR. You don't care that he hogged Dashboost funds. You don't care that he spilt the discord and damaged the community with censorship, you don't care that he got rid of DASH LATAM which was our LARGEST GROWTH COMMUNITY. All of these actions are INAPPROPRIATE and grounds for censure, but YOU DON'T CARE AT ALL. In fact, you engage in these SAME ACTIONS along with him.
So YOU'RE LYING! You don't disagree with him at all except superficially (pretending to call him a "Royal Ass", again PRETENSE, FALSEHOOD!), whereas with other POs you spitefully attack them all the time, constantly insinuate false accusations against them and generally are just mean-spirited and act CONTRARY to how the DAO is supposed to function, while hiding behind "the ask is too big".
You claim I am "pettily allowing my personal feelings to get in the way". That's NONSENSE! I believe that ALL PO's should be funded so long as they are providing proof/evidence of the efficacy of their work. My position towards PO's is EXTREMELY OPEN! I have argued MORE THAN ONCE that so long as there's even just A CHANCE that a proposal succeeds at its stated goals **then we should fund it**.
So YOU ARE WRONG AND LYING/FALSELY ACCUSING ME! I am against Joel and his proposal because HE IS CORRUPT! Hogging Dashboost funds so that smaller POs can't get paid HURTS THE DASH NETWORK! If you really cared like you say you do, YOU WOULDN'T LIKE THAT EITHER!!!! Corruption MEANS THE DASH COMMUNITY DIES!!! WHY WOULD YOU BE OKAY WITH SUPPORTING CORRUPTION???
Lysergic, you should take your own advice, stop being corrupt, STOP LYING AND PROJECTING your issues onto other people, and stop supporting Joel just because you two are butt buddies in collusion with each other to exclude everyone else from getting funded.
If you support Joel YOU MUST SUPPORT every other PO that does similar work or better. This proposal is such a proposal, as were the Latam proposals that you relentlessly attacked and many other growth proposals that have popped up recently. All shut down by your DISHONEST LIES.
150k active android wallet users in Venezuela in the previous 30 days AND YOU ATTACKED THEM RELENTLESSLY, YOU ARE OBVIOUSLY LYING!!! Joel has NEVER gotten anywhere NEAR that much adoption for us, and yet you never attack him or claim "his proposal isn't worth it".
STOP BEING A LIAR AND LEARN TO VOTE IN A WAY THAT BENEFITS THE NETWORK INSTEAD OF YOUR OWN POCKET!
No one has succeeded so far.
Your attempt to rob the community's budget is of no interest!
NO!
Было время когда Эван Даффилд (Evan Duffield) официально предлагал взломать DASH за 1 000 000 долларов.
Ни кто не смог до сих пор.
Ваша попытка ограбить бюджет сообщества не интересна!
НЕТ!
More seriously, i have no idea of what you are talking. And I don't want to know it.
btw I'm logically *part of the community* acting as a security contributor and you can't do anything about it.
month during 4 months for example. So MNOs could vote yes for one month and no
for the others for example.
I would agree to spend 100 Dash for his contribution.
(Personally, I have to work six weeks to earn 100 Dash...)
This is another example of MNOs using nonsensical reasoning to justify not supporting our community. Again, I allege this is due to them belong to a "pet cabal", where only certain proposals are allowed to "sail through with no question", while every other thing good for the Dash ecosystem is scrutinized, ridiculed and gaslit to death, until the "Dash community" is only Joel and his groups.
This is part of a cynical strategy to get around the fact that Dash has an unlimited treasury basically that can afford to pay for our ecosystem participants, which other coins do not have and cannot do. This naturally means that Dash will pull ahead of other chains in adoption and growth month by month until its obvious it is the largest, best and most used cryptocurrency.
In order to prevent this outcome, MNOs are bribed, cajoled and gathered into these "groups" in order to subtly attack everything that's "not in the fold", so that Dash's ecosystem doesn't grow.
And the reason why this is a problem is because, again I allege, that these cabal members are in cahoots with our competition for their own selfish reasons.
You can see Joel give Monero clout on twitter, basically ignoring their history of aggressive abuse, and championing them as a "premium privacy solution" even though its now common knowledge that Monero's privacy doesn't work and never has. Just like pet owners do. If you get bitten by someone's pet, they'll just shrug it off and blame it on you.
Their pet can do no wrong. This is the kind of relationship that Monero, BCH, Nano and other coins hope to foster, because *they are not serious about cryptocurrencies*. They don't want to see Satoshi's dream fulfilled, they just want to "feel good, because they made the 'right' choice, hehehehe".
They want to "rub Nano's/Monero/BCH's success" in your face AT ANY COST, even if it means destroying cryptocurrency and having to pretend. This is called "Cynical suggestioning" and it is the ONLY WAY for the fiat mafia to fight against cryptocurrency.
I honestly don't know what to say about this proposal. I offered the security researcher 2000$ even though our bug bounty program is stopped, but he didn't think it was a correct amount for the severity of the issue. If it had been in the before AI times I think this would have warranted around 20k USD. But we are not in the before AI times. We are in the AI times.
In the end he is asking for 400 Dash. There are a lot of factors at play in order to figure out if it's worth that much. I had told the PO I would support the proposal if it was less. I told him "if it’s 100 dash I will support it. At 150 dash you will get some support, I won’t go out of my way, but I would vote for that myself." He decided to go for 200 Dash. I might still vote for it, but it really depends on what else there is to vote for in this cycle. I do want DeltaXV to be compensated for his work. I'm guessing that he spent at least a few days on this.
1. In a free market, the seller offers their services at the price that they feel its worth. The buyer either accepts this price or walks.
Seeing as how nobody else found these vulnerabilities, and how we've already accepted the fixes, and taking into account that it doesn't seem that the PO held off on submitting the bug reports until the price was agreed upon (i.e. the PO made a gesture of good faith), it is my opinion that we should accept the price that they are asking for.
2. You yourself say it would've been worth ~20k in the before times. So, taking into account that these are the "after times" and AI still didn't catch it in time, I think "roughly half" of the "before time value" + a non-AI finder's fee, is quite a fair bargain and actually a steal. A human was better than AI in the "after times", I think that warrants a considerable reward despite the fact that we're in the "after times". Wouldn't you agree?
3. I think you of all people know this well, but for those who are unaware, WE DO NOT NEED TO PINCH PENNIES. THE DASH TREASURY **RENEWS EVERY MONTH**. There is no need to worry about "how can we afford this". Most proposals are downvoted for no reason and this is used as an excuse ("We just don't have the money! Sorry! tee hee, suckers"). This is not appropriate behavior for the DAO. We have here a set of critical vulnerabilities discovered by an independent dev, we should reward them and compensate their efforts.
4. What is there that could have more importance to spend on than independent developers finding critical issues in the blockchain? I can't think of anything more important that is currently come up
5. I will remind that "“Dash Growth Q3 2026" is accepted for 530 (!!) Dash PER MONTH, and I guarantee you Joel doesn't do anything half as important as this. I even asked, "What does Joel do with the money?" in the discord and NOBODY COULD TELL ME. Nobody could answer me. So should we *really* be pinching pennies with this guy? For what? So Joel can buy another lambo or something?
6. The Dash treasury is supposed to RESPOND POSITIVELY TO FUNDING REQUESTS THAT BENEFIT THE NETWORK. Its NOT supposed to troll DAOs and POs looking for funding by "pretending like we don't have any money left". THE TREASURY RENEWS EVERY MONTH! IT IS MEANT TO BE SPENT!
To be fully clear; we knew about 2 of the 3 issues before he reported them, and they were already fixed in a non-public development branch.
"AI still didn't catch it in time"
AI found each of these issues, for us, finding these issues didn't happen with GPT 5.4, but did with 5.5. Things change as new models get released.
Unfortunately, for the purposes of determining the value of this PO's contribution, this is too little too late, imo. Its just not relevant from a management perspective.
>AI found each of these issues, for us, finding these issues didn't happen with GPT 5.4, but did with 5.5. Things change as new models get released.
See above.
I can confirm that around June 8, this researcher reached out to me on Discord and raised a vulnerability of concern. After that initial contact, we ran additional automated and AI-assisted security audits, which identified a number of issues. I asked the researcher to encrypt and send over their full report.
At approximately the same time that the researcher shared their initial report, covering what is listed here as Issue 1, one of our developers independently identified the same issue using Codex.
We confirmed Issue 1 and began additional rounds of internal investigation on June 8 and 9.
On June 11, we began preparing the v23.1.4 release.
Around June 13, the researcher shared additional reports, including Issues 2 and 3 listed here. Both of those issues had already been identified internally during the audits that started on June 8, and fixes for both were already implemented or in progress by that time.
The researcher did real work and independently identified these issues. I do want to acknowledge that. Our internal work was done privately before the release of v23.1.4 to minimize the risk of exploitation. However, after the researcher's early message that "yes the chain can be instantly halted in 2 Txs. tested locally against a local node", we had enough signal to begin the investigation that led to the fixes. With or without the later reports, the fixes delivered in v23.1.4 would have been the same.
v23.1.4 was publicly released on June 18, and early versions were deployed as early as June 14.
As many people who have been around for a while know, some of my earliest compensation from Dash was related to bug bounties. I think bug bounties can be valuable tools for encouraging and rewarding serious work put into finding vulnerabilities.
That said, I think the value in this specific case is hard to assess. In the age of AI-assisted auditing, identifying vulnerabilities can sometimes require substantially less human effort than it historically did, and it is not really possible for us to independently measure how much human effort went into this particular work.
While the researcher did independently identify Issues 2 and 3, I do not think those reports provided much additional value to the project, since both issues were already known to us and actively being fixed at the time. I do believe the initial message regarding Issue 1 was valuable, because it helped direct us toward an issue that we confirmed and fixed.
In total, the researcher is asking for approximately 14k USD / 400 Dash. Annualized, that would be roughly equivalent to an 85k USD full-time salary. I do not think paying this amount is strictly necessary, but I also would not say it would be a complete waste. There is real value in encouraging responsible vulnerability disclosure.
Since v23.1.4, we have also shipped v23.1.7, which fixed a number of high and critical severity issues. Most of those were found by core developers, and at least one was found by a different external security researcher.
Overall, I do believe some compensation for responsibly disclosed vulnerabilities is valuable. However, for the past few months, DCG had inactivated its bug bounty program due to the volume of improper or low-quality submissions. As a result, submitting a proposal is currently the only practical option available to people who believe they have earned compensation for vulnerability research.
I have reviewed the code without having previous knownledge about the private fixes or any internal review. As an external researcher/individual this matters. Issue 1 was I believe directly prompted by an engineer through the 2 tx stage attack provided in the discord chat allowing codex to follow the trail, which I think is too short to be considered as being independantly found. The other bugs might have been found ealier, but I can't assume such thing and I had to privately disclose them anyway as being unique bugs without prior knowledge.
To address the AI side. As of now, there's no single AI model that can guarentee a bug free codebase, it is an impossibility in fact. AI is becoming drastically efficient as "a tool", like you've clarified. Nonetheless some vulnerabilities will simply persist despite the amount of token that can be burnt. In fact the framing of "let's just trust AI" in this industry is very dangerous and could backfire. Unfortunately, there are many malicious threat actors some are state sponsored (Lazarus, etc) that have virtually unlimited ressources and incentive to spend time and money to achieve their end goal. Protocol like Thorchain are such example of dishonest and hostile team towards security researchers and bug bounty hunters - https://x.com/QED_Audit/status/2061635604840849728?s=20 which led to multiple exploits recently against their blockchain and native DEX - https://blog.thorchain.org/thorchain-exploit-report-1 .
However in the case of dash, I would understand the reasons behind the "bug bounty program" termination. AI slop has became a pain in the ass for honest protocols and security researchers. But ultimately, if the goal is to attract honest actors some sort of incentive has to remain to make sure the code is being reviewed by whitehats. There are some great talents out there that if incentivized would make sure to catch whatever is left. Ultimately the goal is improve the process and mitigate this AI slop spammers trend with automated tools. These critical security contribution, are crucial for this ecosystem (network, users, MN, etc) legit security researcher deserves to be compensented according to their contribution.
Personally, I have directlty reported 3 critical and 1 low severity vulnerability all ended up being valid which demonstrates a 4/4 valid ratio and 100% accuracy, regardless of what could have been found internally these issues were live during years and exploitable on mainnet.
Regarding the proposal, I'm requesting a simple compensation for the security contribution. And in fact, the reason I have requested a 2 times budget was to allocate more time reviewing dash core implementation and directly privately disclose the finding with no "bug bounty request". Having proved my valid ratio, I believe it's a win win proposal for the whole network.
I don't think this is particularly relevant or helpful. Sam is already on record as stating this work would be roughly worth 20k in his assessment. Unless you disagree with him, that means that this is basically a steal. These vulnerabilities are (were) long-lived, which means you had your chance to catch them and failed. Proper compensation is therefore indicated, and its a seller's market in this case.
I believe this proposal is worth it and will be voting yes.
Everyone is going to have their own conscience to follow :)
He was nice to deal / work with during all conversations, and I for sure appreciate his work and efforts!