Crypto projects should reduce the risk of catastrophic bugs as much as they can as the stakes are extremely high. Some tips for this include
- Facilitate responsible disclosure
- Have a clearly documented procedure for responsible disclosure, including an email address for reporting potential issues
- Provide encryption keys for well-known developers and committing them to the code repository as well as public key servers
- Quickly respond to reports, even from anonymous sources
- Award bug bounties worth a multiple of the black-market value of the exploits
- Consider faithful validation in the incentive model
- Ensure that potential attackers are incentivized to responsibly disclose vulnerabilities rather than weaponize them
- Make sure that disclosure is the most lucrative of all options
- Chain-split policies and proactive monitoring
- Take appropriate action within an hour and ideally less in the event of an accidental chain-split
- The actions taken should follow each partyโs pre-set and publicly available chain-split policy, leaving little room for surprises
- In order to be proactive against bugs in software upgrades, large stakeholders should run old and new versions simultaneously to ensure that they agree
- Defensive coding and review
- Perform stringent code reviews
- Be wary of projects that accept changes, especially to consensus code, without adequate expert review