Fortune | FORTUNE 2024年11月26日
Uniswap offers biggest ever ‘bug bounty’, promises up to $15.5 million to those who spot code vulnerabilities
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

Uniswap宣布为其最新版本Uniswap v4推出1550万美元的漏洞赏金计划,这是迄今为止规模最大的漏洞赏金。此举旨在确保v4协议的安全性,因为该协议每天处理数十亿美元的交易量。Uniswap v4在v3的基础上进行了改进,旨在降低交易成本并提供更多自定义选项。在经过多次安全检查后,Uniswap希望通过此次漏洞赏金计划进一步提升安全性,防止潜在的盗窃行为。该计划仅涵盖Uniswap v4核心合约的漏洞,并设置了不同级别的奖励,最高可达1550万美元,以鼓励白帽黑客发现并报告漏洞。

🤔 **推出1550万美元漏洞赏金:**Uniswap为其最新协议Uniswap v4推出史无前例的1550万美元漏洞赏金计划,旨在确保协议的安全性,防止潜在的盗窃行为,因为该协议每天处理数十亿美元的交易量。

🚀 **Uniswap v4的改进:**Uniswap v4基于v3版本构建,旨在降低交易成本并提供更多自定义选项,为用户和开发者带来更便捷的体验。

🛡️ **多轮安全检查:**Uniswap v4已通过了九次独立的安全审计和一次235万美元的安全竞赛,参与者达500人,但未发现严重漏洞。此次漏洞赏金计划是进一步确保协议安全性的额外措施。

💰 **分级奖励机制:**漏洞赏金计划根据漏洞的风险等级设置不同的奖励,发现“严重”漏洞可获得1550万美元, “高”风险漏洞可获得100万美元,“中”风险漏洞可获得10万美元。

⏰ **报告时限与保密性:**发现漏洞后需在24小时内报告,并在问题解决前保持保密,以确保安全性和有效性。

Uniswap, one of the largest decentralized exchanges, says it will award $15.5 million to anyone who can find vulnerabilities in the latest version of its namesake protocol. The size of the reward—which the company says is the largest ever so-called “bug bounty”—is intended to ensure the latest evolution of the protocol, known as Uniswap v4, is as secure as possible.The idea behind bug bounty programs, which are widely used in the tech sector, is to incentivize non-malicious hackers—known as “white hats”—to discover vulnerabilities in computer code before bad guys do.Uniswap v4 builds off of v3, which launched in 2021, and seeks to make transactions cheaper and more customizable. Uniswap is unrolling the bug bounty as the development phase comes to an end, and chose to make the award $15.5 million in order to beat out LayerZero, a cross-chain messaging protocol, which offered a $15 million bug bounty in 2023. The newest version of the protocol has already gone through multiple security checks, including nine independent audits and a $2.35 million security competition in which 500 researchers participated and no severe vulnerabilities were found, the company said in a statement.While v4’s security has been repeatedly evaluated, Uniswap is taking this extra step to ensure their protocol is theft-proof because it handles billions of dollars worth of volume everyday and once it is deployed it cannot be changed. “The Uniswap protocol serves as critical infrastructure for DeFi, and has secured over $2.5 trillion in trading volume, and v4 introduces limitless customization,” said Hayden Adams, CEO of Uniswap Labs. “This $15.5m bug bounty is the largest in history, reflecting our commitment to building secure smart contracts for all the users and developers building on top.”The program only covers bugs found in the Uniswap v4 core contracts and does not include, “third party contracts that were not deployed by Uniswap Labs, issues already listed in the audits for the contracts in the v4 repository, bugs in third party contracts or applications that use contracts deployed by Uniswap Labs, or issues already known internally,” according to the statement.Not all successful hackers will get $15.5 million. The payouts are based on a tiered approach that categorizes each bug using a risk score. The reward for discovering a “critical” bug is $15.5 million, while a “high” risk bug gets $1 million and a “medium” risk bug gets $100,000. To be eligible for the reward, bugs must be reported within 24 hours of discovery and kept confidential until the issue is resolved. These types of programs have been around since the 1980s when a software company called Hunter and Ready first offered a Volkswagen Beetle, or “bug,” to anyone who could find a vulnerability in their operating system. Since then, big bounties have become increasingly popular in the tech industry and are sometimes used by the U.S. government.Learn more about all things crypto with short, easy-to-read lesson cards. Click here for Fortune's Crypto Crash Course.

Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

Uniswap 漏洞赏金 DeFi 安全 v4
相关文章