Refer a fren and earn rewards!

Yes, take me there!

Logo

-

Adopt The SEAL Safe Harbor Agreement

Defeated
#269 - mills ERA

Created Feb 24th, 2025

Details

avatar

Edo

Forum Link: https://forum.inverse.finance/t/adopt-the-seal-safe-harbor-agreement/534

Authors: Edo, skylock.xyz


Introduction

This proposal outlines Inverse Finance’s adoption of the SEAL (Security Alliance) Whitehat Safe Harbor Agreement (“Safe Harbor Agreement”). By adopting Safe Harbor, Inverse improves the security of its on-chain assets by allowing whitehats to intervene during active exploits to save protocol funds.

What is the Safe Harbor Agreement?

The Safe Harbor Agreement addresses a critical need in crypto: enabling whitehats to intervene during active exploits when traditional responsible disclosure procedures are not feasible.

Key aspects of the agreement include:

  • Encouraging Whitehats to Protect the Protocol: By adopting Safe Harbor, Inverse incentivizes whitehats to step in and protect the protocol during active exploits by limiting their legal exposure.
  • Intervention Only During Active Exploits: Whitehats are authorized to act only when there is an active exploit that threatens the protocol. This agreement applies only to critical situations where responsible disclosure procedures would not save funds due to the urgency of the exploit, and it is not intended for routine security testing or vulnerability reporting.
  • Mandatory Return of Rescued Funds: Under the terms of the Safe Harbor, whitehats are required to return all rescued assets to a pre-designated recovery address controlled by the protocol within 72 hours of recovery.
  • Clear Guidelines and Legal Protection: The agreement establishes strict rules for how whitehats must operate during an exploit, ensuring recovery efforts are conducted professionally and safely, and minimizing the risk of mistakes or further damage to the protocol.
  • Incentivized Rescue Efforts: To motivate whitehats to act during critical situations, the agreement offers a bounty system similar to a bug bounty. Whitehats are rewarded with a percentage of the recovered assets, up to a predefined cap, for their successful interventions.

For more information, check out the Safe Harbor Agreement here.


Rationale

The Safe Harbor Agreement empowers whitehats to act immediately during an exploit, offering a swift and structured asset recovery process. Benefits of adopting the Safe Harbor Agreement include:

  • Agile Defense Against Exploits: Whitehats are authorized to intervene as soon as an active exploit is detected, enabling them to respond faster than traditional methods. Immediate action minimizes the window for malicious actors, reduces damages, and accelerates the recovery of assets during critical moments.
  • Clarified Rescue Process: The agreement ensures that every step, from intervention to fund recovery, is predetermined and streamlined. Whitehats know exactly where to send recovered funds, preventing chaotic negotiations or rushed decisions during an exploit. This clarity ensures efficient, decisive action when it matters most.
  • Clear Financial Boundaries: The predefined bounty system, with a cap matching Inverse’s existing bug bounty, ensures that whitehats are incentivized fairly without creating conflicting priorities between exploit intervention and standard vulnerability disclosure. By setting expectations upfront, Safe Harbor eliminates post-exploit negotiations, ensuring funds are returned promptly without attempted negotiations.
  • Aligning with Industry Best Practices: By adopting the Safe Harbor Agreement, Inverse aligns itself with leading security practices across the industry, reinforcing its commitment to staying at the forefront of protocol security.

Adoption of the agreement complements audits and bug bounties by providing an additional layer of security, ensuring that the protocol is better prepared to respond to active threats.


Adoption Details

Inverse Finance will adopt the agreement with the following parameters. For a full description of these adoption details, review the Safe Harbor for Protocols document.

  1. Asset Recovery Address:
ChainAddress
Ethereum0x926df14a23be491164dcf93f4c468a50ef659d5b
OP0xa283139017a2f5BAdE8d8e25412C600055D318F8
Base0x586CF50c2874f3e3997660c0FD0996B090FB9764
Arbitrum0x23dEDab98D7828AFBD2B7Ab8C71089f2C517774a
BNB Chain0xF7Da4bC9B7A6bB3653221aE333a9d2a2C2d5BdA7
  1. Scope: The assets under scope will include all assets in scope on Inverse Finance’s immune bug bounty page as of 2025-01-29: https://immunefi.com/bug-bounty/inversefinance/scope
  2. Contact Details:
  1. Bounty Terms:
  • Bounty Percentage: 20%
  • Bounty Cap (USD): $100,000
  • Retainable: true
    1. After rescuing funds during an exploit, whitehats may deduct their bounty from the total recovered amount before transferring the remainder to the protocol’s designated asset recovery address.
  • Identity Verification: Anonymous
    1. Whitehats are allowed to remain anonymous and are not required to provide their legal name or undergo identity verification.
  • Diligence Requirements: None

Implementation Plan

  1. Register Agreement On-Chain:
  • The agreement will be registered on Ethereum in the Safe Harbor Registry at address 0x8f72fcf695523a6fc7dd97eafdd7a083c386b7b6, including all adoptionDetails. This ensures transparency and immutability.
  1. Update ToS:
  • Exhibit D: User Adoption Procedures will be added to Inverse Finance’s Terms of Services. References to Safe Harbor will also be added to Inverse Finance’s technical documentation.
  1. Communicate Adoption:
  • An official announcement will be made across all Inverse Finance’s official communication channels, explaining the adoption and its significance to the community.
  1. Future Updates to Scope:
  • New smart contracts deployed by Inverse Finance will be reviewed and added to the Safe Harbor Agreement scope via governance vote, ensuring continued protection.

Conclusion

Adopting the SEAL Whitehat Safe Harbor Agreement equips Inverse Finance with a rapid response mechanism for active exploits, enabling whitehats to step in effectively when needed most. The agreement provides clear guidelines for action, increasing the protection of user funds and demonstrating Inverse Finance's commitment to proactive security.


References


Please share your thoughts and feedback in the discussion below before the proposal moves to a formal vote.

Actions

Action 1
0x8f72...b7b6
.adoptSafeHarbor(

Inverse Finance,

edo@inverse.finance,

Edo,

karm@inverse.finance,

Karm,

cryptoharry@inverse.finance,

Harry,

nour@inverse.finance,

Nour,

Treasury,INV,

0,

0x,

Treasury,

0,

0x,

Fed Frontier,

0,

0x,

DOLA,

0,

0x,

GovMills,

0,

0x,

0x941c...259D,

0,

0x,

xINV,

0,

0x,

0x1ba8...7F76,

0,

0x,

DolaPayroll,

0,

0x,

XinvManager,

0,

0x,

XinvVestorFactory,

0,

0x,

DebtRepayer,

0,

0x,

DebtConverter,

0,

0x,

DBR,

0,

0x,

FiRMSimpleEscrow,

0,

0x,

Fed FiRM,

0,

0x,

FiRM WETH Market,

0,

0x,

FiRMOracle,

0,

0x,

FiRM CRV Market,

0,

0x,

0x2F32...2125,

0,

0x,

0x0266...6462,

0,

0x,

FiRM cvxCRV Market,

0,

0x,

FiRMINVEscrow,

0,

0x,

FiRM INV Market,

0,

0x,

DbrDistributor,

0,

0x,

FiRM st-yCRV Market,

0,

0x,

0xfc63...Bd4E,

0,

0x,

FiRMBorrowController-v1.1,

0,

0x,

0xCcAB...1eBB,

0,

0x,

FiRM DAI Market,

0,

0x,

FiRM CVX Market,

0,

0x,

0xf2a2...a9C1,

0,

0x,

0x0aBb...123c,

0,

0x,

0x1dfE...D774,

0,

0x,

0x894B...7b61,

0,

0x,

FiRM wstETH Market,

0,

0x,

DbrAuction,

0,

0x,

DSA,

0,

0x,

sDOLA,

0,

0x,

0x3B3E...cA61,

0,

0x,

FiRM WBTC Market,

0,

0x,

0x857E...10a0,

0,

0x,

FiRM st-yETH Market,

0,

0x,

0xbBE5...e166,

0,

0x,

FiRM sFRAX Market,

0,

0x,

0x9078...5F48,

0,

0x,

0xfBd9...4aBd,

0,

0x,

FiRM COMP Market,

0,

0x,

0x882d...94e0,

0,

0x,

FiRM sUSDe Market,

0,

0x,

FirmALE-v2,

0,

0x,

0x6C5F...8f1F,

0,

0x,

FiRM crvUSD-DOLA Market,

0,

0x,

0xCB21...00c3,

0,

0x,

0x4eF6...0c0f,

0,

0x,

0xD785...3Ec1,

0,

0x,

0x92B5...ed4E,

0,

0x,

0xc193...9117,

0,

0x,

0x6c59...f911,

0,

0x,

0x11D3...1975,

0,

0x,

sINV-v2,

0,

0x,

0x43A7...A7bc,

0,

0x,

FiRM yv-crvUSD-DOLA Market,

0,

0x,

FiRM cbBTC Market,

0,

0x,

0x5CB5...c75D,

0,

0x,

0xAbFC...dF81,

0,

0x,

0x1979...7b81,

0,

0x,

0x5B4e...a749,

0,

0x,

0xE61D...E401,

0,

0x,

0xd356...C687,

0,

0x,

0xAb56...1701,

0,

0x,

0x5cbe...EB51,

0,

0x,

FiRM PT-sUSDe-27MAR25 Market,

0,

0x,

0xD723...8F15,

0,

0x,

0x6277...7400,

0,

0x,

0xB3C1...5058,

0,

0x,

FiRM sUSDe-DOLA Market,

0,

0x,

FiRM yv-sUSDe-DOLA Market,

0,

0x,

0x141E...78f5,

0,

0x,

0xD2F1...79D6,

0,

0x,

0xA859...2C79,

0,

0x,

0x0ABe...FC9B,

0,

0x,

FiRM sUSDS-DOLA Market,

0,

0x,

FiRM yv-sUSDS-DOLA Market,

0,

0x,

0x44e2...1df0,

0,

0x,

0xdB0A...a140,

0,

0x,

0xc182...5E6F,

0,

0x,

FiRM scrvUSD-DOLA Market,

0,

0x,

FiRM yv-scrvUSD-DOLA Market,

0,

0x,

0x09B5...986d,

0,

0x,

0xA949...0924,

0,

0x,

0xbEda...2742,

0,

0x,

0x3A2a...639f,

0,

0x,

0x3725...4564,

0,

0x,

0x86bD...fA23,

0,

0x,

FiRM scrvUSD-sDOLA Market,

0,

0x,

FiRM yv-scrvUSD-sDOLA Market,

0,

0x,

0xda50...9a04,

0,

0x,

FiRMBorrowController-v2,

0,

0x,

0x54F1...FE84,

0,

0x,

0xe082...34fc,

0,

0x,

FiRM deUSD-DOLA Market,

0,

0x,

0x2521...5CcE,

0,

0x,

0x918A...b46D,

0,

0x,

0x15f7...536b,

0,

0x,

0xF353...59f5,

0,

0x,

FiRM yv-deUSD-DOLA Market,

0,

0x,

GovernanceSender,

0,

0x,

ReceiptTokenHelper,

0,

0x,

0xf840...c1e7,

0,

0x,

1,

Treasury Working Group on Optimism,Op-GovernanceProxy,

0,

0x,

Op-sINV,

0,

0x,

10,

Treasury Working Group on ARB 2,Arb-GovernanceProxy,

0,

0x,

Arb-sINV,

0,

0x,

42161,

Treasury Working Group on Base,Base-GovernanceProxy,

0,

0x,

Base-sINV,

0,

0x,

8453,

Treasury Working Group on BSC,

,

56,

20,

100000,

true,

0,

None,

https://bafybeiakxvysdvsvupqcibkpifugzwcnllzt2udjk3l4yhcix7dqxxqyp4.ipfs.w3s.link/agreement.pdf

)

Proof of Reviews

Members allowed to make Drafts can sign the fact that they reviewed the Draft Proposal

Loading...

For Votes

0 voters

0.00 votes

Against Votes

1 voters

22.19k votes

avatar

CryptoHarry

22.19k

Subscribe to Our Newsletter

Join thousands of subscribers in receiving weekly updates about Inverse products, partnerships, and early-bird news shared only with subscribers!

Products

sDOLADOLAsINVINVFiRM

Social