lobster-dao / overview

Description-FAQ of the process
MIT License
115 stars 24 forks source link

Explicitly mentioned value add for airdroppers: second set of eyes on their smart contracts #26

Closed tartakovsky closed 2 years ago

tartakovsky commented 2 years ago

Random sketch of an idea on how to make airdropping to $LOBS more attractive for projects. Many projects would probably be glad for a second set of eyes on their smart contracts to debug them. We can assemble a list of typical vulnerabilities / mistakes and maybe check for them as part of the proposition. Also suggests a possible relationship with ImmuneFi?

Feedback so far:

Graham: With the number of good developers on the airdrop list this type of proofread or preliminary check will likely happen by default. We could somehow help that be known as a benefit though.

Eugene: yeah, that's kinda the point. It should probably be explicitly stated as a benefit if it's gonna happen anyway. Also we as a community can systematize it a bit, if there isn't yet a good resource on what vulnerabilities to check for.

Another point is that if it's explicitly stated, projects might want to come to us at earlier stage.

Amazongirl: We need to canvas the skill set of the lob community and make up a list of skills we can offer to project founders, such as product testing, fundraising, marketing, collaboration opptys (many lobs are probably project founders themselves), and so on.

scar: Ok but what makes being a lob a benefit? Code423 incentives it already. And like it was mentioned immunefi too. So what would make lobs incentivized to do it as lobs

Eugene: make the package sweeter? It's not the only thing the community might provide, but an additional part

if the only thing they want is the audit from a couple of guys working in an audit firm, or from a bunch of (unaffiliated?) bug hunters on ImmuniFi – sure, it's better to go there

scar: Perhaps we could be the light at the the tunnel. The mentions of bug finders reporting bugs and not getting rightful recognition or even ghosted

Maybe as lobs are some of the most recognized devs. We could help figure out whether that bug was exploitable or not and make sure researchers and protocols abide by the law

Eugene: as a potential benefit to ImmuneFi the community might provide a shame deterrent to those who are ghosting

scar: I get your point. But imagine the next meme coin bragging about being audited by lobs

Graham: We would want a disclaimer stating that it is in no way an endorsement or formal audit.

Gas One Cent: The reviews can expand to docs and UI/UX to allow non-tech people to participate

tartakovsky commented 2 years ago

Additional idea: Projects get access to using LobsterDAO HR for posting their vacancies if they airdrop.

Arguments: It's nice to present it as a separate point. I'm sure many projects are not exactly aware which channels are there. Hunting is a pita in the space. Having a new HR source might be very attractive.

tartakovsky commented 2 years ago

~the main proposal was rugged by ivan~

ivan: Forget auditing and code review. There are 9 fig projects on the line. I ll never associate myself w audits or security reviews while having 0 understanding of it. It’s the best way to get rekt and fucked

U can CODE by making some cool feature or product! Don’t offer it as securit service