💔 [Analysis] The Broken EIP Security Incentive - Dean Eigenmann

After the delayed Constantinople fork, security researcher Dean Eigenmann explains the misaligned incentives for in finding and reporting bugs. Namely, the bulk of any social and economic gain to be had from disclosing flaws is not present during early phases of development when finding and patching flaws is most opportune. Instead researchers and the wider community are incentivized to wait as long as possible to disclose when a successful launch matters more than before and considerable social attention has accrued. To fix this, Dean suggests introducing an exponential decay on the bounties offered to make early discovery and disclosure more profitable.

Let us know what you loved about the report, what may be missing, or share any other feedback by filling out this short form. All responses are subject to our Privacy Policy and Terms of Service.

Suggested Research Based on your Watchlists

Create a new watchlist