Livepeer Subgraph Audit Proposal

Direct Grant Application

Livepeer Subgraph Audit Proposal

1. Applicant + Payout Details

  • Applicant: BuildersDAO
  • Main contact: James (jmulq)
  • Payment address: 0x615fd4ed2cd90b8d33d2eb2e3df663f9722246b5 on Arbitrum

2. Scope

Problem Statement

The Livepeer subgraph is core ecosystem infrastructure. It supports Explorer views, governance surfaces, delegator tooling, and tokenomics analysis across the Livepeer ecosystem.

The subgraph has not yet had a structured audit, so Livepeer lacks a current baseline for its indexing performance and subgraph size, as well as a clear picture of current technical debt, data model issues, and indexing gaps. This creates risk when adding new features, because new indexing work may build on top of unmeasured or unresolved technical debt.

The current roadmap identifies per round delegator and orchestrator stake and earnings as an important indexing gap for income, tax reporting, and time-series views. Recent subgraph issues, including an edge case that caused indexers to error and affected delegator withdrawals, also reinforce the need for a comprehensive audit. Auditing the current subgraph first will give Livepeer a clearer foundation for future remediation and feature work, including known data discrepancies, non-deterministic indexing risks, technical debt, and schema constraints.

Proposed Solution

BuildersDAO will perform a focused technical audit of the Livepeer subgraph.

The audit will review the current codebase, schema, manifest, mapping logic, protocol coverage, query suitability, testing setup, maintainability, and failure-prone indexing patterns. The final output will be a structured audit report with prioritised findings, evidence, and recommended remediation steps.

This proposal is audit-only. Remediation PRs, InfraDAO indexing benchmarks, and implementation of per round stake/earnings indexing can be funded separately after the findings are triaged.

As part of the audit, BuildersDAO will hold one 60 minute community session with relevant Livepeer maintainers, ecosystem contributors, and active subgraph users. The goal is to gather known pain points, recurring data discrepancies, unreported issues, important query paths, and context from teams that have worked around subgraph limitations. Input from this session will inform the audit focus and be reflected in the final report where relevant.

Where useful, BuildersDAO will support findings with selected evidence checks against important subgraph entities, known transactions, provided datasets, chain logs, or contract state. These checks are intended to help identify and evidence specific issues; they are not exhaustive data reconciliation or a guarantee that every historical record is correct.

In Scope

  • Comprehensive subgraph audit covering repository setup, protocol coverage, schema, manifest, mappings, query suitability, testing, indexing performance, storage, and maintainability
  • InfraDAO baseline indexing metrics for the current subgraph
  • One community input session with interested maintainers, ecosystem contributors, and active subgraph users to gather recurring pain points, known discrepancies, unreported issues, and priority query/use-case needs.
  • Review of known data accuracy concerns or discrepancies raised by ecosystem contributors, using provided examples, datasets, endpoints, transactions, or account histories where available.
  • Selected evidence checks for important entities, queries, events, or protocol flows where useful.
  • Audit report and community retro post

Out Of Scope

  • Remediation PRs
  • Full implementation of per round delegator/orchestrator stake and earnings
  • Local or CI-based full indexing benchmarks
  • Exhaustive historical reconciliation of every indexed record

Dependencies / Assumptions

  • Livepeer confirms the repository branch, deployment hash, and subgraph endpoint.
  • Livepeer maintainers provide important Explorer/product queries where available.
  • Livepeer helps identify and invite relevant contributors or users for the community input session, such as Explorer maintainers, data consumers, and contributors who have previously worked around subgraph limitations.
  • Livepeer maintainers and ecosystem contributors provide any known subgraph data discrepancies, alternative indexed datasets, relevant endpoints, or account/transaction examples that can be used as evidence during review.
  • InfraDAO is available to run indexing benchmarks in a consistent environment.
  • Livepeer maintainers will confirm whether any findings should be treated as sensitive before public GitHub issues are created.
  • This audit will identify and prioritise remediation work, but implementation is not included in this grant.

3. Deliverables + Acceptance Criteria

Deliverable 1: Final Audit Report + Baseline Metrics

Acceptance criteria:

  • Current Livepeer subgraph is reviewed across schema, manifest, mappings, protocol coverage, query suitability, performance risks, and testing/CI.
  • Recent and known incident contexts are reviewed where relevant to identify related classes of risk, including:
    • The recent unhandled null / indexer error incident that affected delegator withdrawals.
    • Prior reports of non-deterministic indexing behaviour where context is available.
    • Known data discrepancies or accuracy concerns raised by Livepeer maintainers or ecosystem contributors.
  • InfraDAO baseline metrics are collected for the current subgraph.
  • Findings are documented with severity, evidence, and recommendations.
  • Findings are classified as:
    • Critical production / indexing risk
    • Non-breaking remediation
    • Breaking/schema-impacting
    • Future feature work
    • Larger redesign
  • Final audit report includes:
    • Audited commit and scope
    • Methodology
    • Prioritised findings table
    • Detailed findings with evidence and recommendations
    • Protocol coverage notes or matrix where useful
    • Selected evidence check notes where useful
    • Query suitability notes
    • Incident-related risk notes where applicable
    • Remaining risks and future work
  • Public GitHub issues or milestone items are created for non-sensitive findings where useful. Findings considered sensitive by Livepeer maintainers will remain in the report or be shared through the appropriate private channel.
  • Final forum update/retro is published documenting the audit output and recommended next steps.

4. Milestones + Payment Tranches

Total grant request: $6,500 USD-equivalent in LPT

This includes the required 10% allocation for reporting, retroactive post, and community engagement.

Milestone What Will Be Delivered Verification Method Target Date Payout Amount
1 Final subgraph audit report, baseline metrics, forum retro post Final report delivered, findings documented with severity/evidence/recommendations, issues or milestone items linked where useful, forum update published End of Week 2 $6,500

5. Update Cadence

  • Cadence: Lightweight updates as needed during the 2-week audit.
  • Working channel: Private Discord coordination with Livepeer maintainers.
  • Community input: One 60-minute input session during the audit window, open to relevant maintainers, ecosystem contributors, and active users suggested by Livepeer.
  • Public update: Final forum update/retro published on completion.

Updates may include:

  • Open questions
  • Blockers
  • Urgent findings
  • Scope risks
  • Expected completion timing

Given the short audit timeline, ongoing public progress updates are not expected unless the audit is delayed or a material issue is found.

6. Budget + Use Of Funds

Category Amount Notes
Audit and technical review $5,700 Protocol coverage, schema, manifest, mappings, query suitability, testing/CI, indexing resilience, recent incident review, selected evidence checks, and maintainability review
Coordination and reporting $800 Maintainer coordination, final audit report, and forum update/retro
Total $6,500 Paid in LPT using the Direct Grant conversion process

7. Impact

Expected Impact

If successful, this grant will give Livepeer a clear, prioritised view of the current subgraph’s correctness risks, technical debt, indexing gaps, production failure risks, and future remediation priorities.

Expected outcomes:

  • Current indexing gaps, technical debt, and data-model risks are identified and prioritised.
  • The recent class of null-handling/indexing-failure issue is reviewed for related risks.
  • Livepeer has baseline indexing metrics from a consistent InfraDAO environment.
  • Livepeer has a remediation backlog that can be used to fund or assign follow-on fixes.

How Impact Will Be Evidenced

Impact will be evidenced by:

  • Final audit report
  • Prioritised findings table
  • Detailed findings with evidence and recommendations
  • InfraDAO baseline
  • GitHub issues or milestone items where useful
  • Final forum update/retro

Risks + Mitigations

  • Risk: Some data correctness concerns require broader historical reconciliation to prove fully.

    Mitigation: The audit will use selected evidence checks where useful, but exhaustive reconciliation is out of scope and will be documented separately if needed.

  • Risk: Missing context from maintainers or downstream consumers limits parts of the protocol coverage or query suitability review.

    Mitigation: BuildersDAO will request key queries, known discrepancies, incident context, and relevant examples at kickoff. If some context is unavailable, assumptions and limitations will be documented in the report.

  • Risk: The audit identifies urgent production issues before the final report is complete.

    Mitigation: Critical findings will be surfaced to Livepeer maintainers as soon as they are identified rather than waiting for the final report.

8. Prior Work + Relevant Context

BuildersDAO has experience building, auditing, and improving subgraphs with a focus on schema design, mapping correctness, protocol coverage, performance, maintainability, and The Graph best practices.

BuildersDAO is well suited to this work because:

  • BuildersDAO has previously contributed review work around the Livepeer subgraph through PR#168 and PR#175.
  • The team has domain experience with subgraph auditing
  • InfraDAO can provide practical indexer-side benchmark data
  • The output directly supports future Livepeer subgraph work, including per round stake and earnings indexing.

Team

BuildersDAO is the applicant and accountable delivery entity. The named contributors below are included for transparency and community review.

  • James M — Project Lead / Audit Reviewer

    James will coordinate the grant, manage Livepeer communication, maintain the GitHub milestone, review audit findings and support technical delivery where needed, and own the final report and retro post.

    Relevant background: James has 9 years of software development experience, including several years working in web3 infrastructure and The Graph ecosystem. He has led and contributed to subgraph audits, ground-up subgraph builds, optimisation work applying The Graph best practices, bespoke Substreams data pipelines, and Rust/Elixir-based data systems. He is especially focused on making indexed data accurate, efficient to serve, easy to maintain, and practical for real product use cases.

  • Shashwat D — Auditor & Engineer

    Shashwat will contribute to auditing the Livepeer subgraph schema, manifest, mapping logic, and protocol coverage.

    Relevant background: Shashwat has 6 years of software development experience, specializing in data indexing infrastructure, multi-chain data extraction, and standardised protocol tracking within The Graph ecosystem. As an open-source contributor to Messari, he designed and implemented production subgraphs for high-volume DeFi and streaming protocols—including Livepeer, GMX, and Ribbon—authoring custom AssemblyScript mappings and an open-source SDK to normalise heterogeneous smart contract events into unified schemas for institutional analytics. His infrastructure work extends to Graph BuildersDAO, where he engineered high-performance data pipelines utilising both Subgraphs and Rust-based Substreams to process millions of on-chain events daily.

  • Ciaran L — Auditor & Engineer

    Ciaran will contribute to auditing the Livepeer subgraph schema, manifest, mapping logic, and protocol coverage.

    Relevant background: Ciaran has 6 years of software development and data engineering experience. Formerly working in biotech, he has recently moved into the web3 space, where he has contributed to Operations, Business Development and subgraph auditing efforts at BuildersDAO.

  • InfraDAO — Indexing Benchmark Partner

    InfraDAO will run baseline indexing benchmarks in a consistent environment and provide sync, entity count, and subgraph size metrics.

    Relevant background: InfraDAO operates indexing infrastructure and can provide indexer-side measurements that are more representative than local-only benchmarking.

9. Network Engineering SPE Rubric Fit

Primary Eligibility Area

  • Tooling & Infrastructure

This grant fits Tooling & Infrastructure because the Livepeer subgraph is shared ecosystem data infrastructure used by Explorer, governance, delegator tooling, and analytics surfaces.

Design Principles Check

  • Community-originated

    Comes from a Livepeer roadmap item (Subgraph Audit & Stake/Earnings Indexing) identifying the need for subgraph audit, benchmarking, and stake/earnings readiness.

  • Pre-agreed pricing

    Total grant request is capped at $6,500

  • Impact-linked payment

    Payments are tied to a final audit report and retro post.

  • Transparent by default

    Work will be coordinated with maintainers during the audit and documented publicly through the final forum update/retro.

  • Speed

    Proposed timeline is 2 weeks.

Impact Evidence Plan

  • Named adopters who will use it:

    Livepeer subgraph maintainers, Explorer maintainers, governance/data consumers, delegator tooling maintainers, and future subgraph remediation implementers.

  • Downstream dependency:

    Explorer views, governance surfaces, delegator tooling, tokenomics analysis, and future per round stake/earnings indexing depend on the subgraph.

  • Capability confirmed in the wild:

    The final output will include a published audit report, prioritised findings table, evidence-backed recommendations, and a remediation backlog that can be used to fund or assign follow-on fixes.

3 Likes

While I don’t have any feedback on any particulars of the proposal, I do support it, having worked on downstream dependencies like the Explorer. Especially given the recent incident, which importantly affected delegator withdrawals, this kind of audit should rebuild delegator trust, and prevent similar events from occurring in the future. Furthermore, deliverables like “future feature work” and “larger redesign” will be insightful after talking with various stakeholders during the community session, especially given the proposed plans for Livepeer 2.0.

1 Like

Hey @jmulq, thanks for submitting this Direct Grant application. I’m happy to publicly support it.

The Livepeer subgraph is critical ecosystem infrastructure, and its accuracy and reliability have become increasingly important as technical debt and edge cases have accumulated. The recent indexing incident involving our subgraph further highlights the importance of this work.

Funding lane: Direct Grant

Category: Tooling & Infrastructure (shared ecosystem data infrastructure)

Amount: $6,500 USD-equivalent in LPT ($5,700 audit and technical review, $800 coordination and reporting)

Decision

The Review Team approved this Direct Grant for BuildersDAO (@jmulq) to audit the Livepeer subgraph, delivered as a single milestone: a prioritized final audit report.

Rationale

Assessed against the Network Engineering SPE rubric.

  • Process compliance & scope fit. The SPE commissioned this audit after the Explorer subgraph incident and asked BuildersDAO for an audit-only proposal. That is what landed: diagnosis and reporting only, with remediation, the per-round stake/earnings feature, historical reconciliation, and full benchmarking out of scope. The subgraph feeds Explorer, governance, delegator tooling, and analytics, so it sits squarely in Tooling & Infrastructure.
  • Delivery confidence. The team ships without a long ramp: James M (9 yrs, The Graph ecosystem), Shashwat D (6 yrs indexing, prior Livepeer subgraph work via Messari), Ciaran L (6 yrs), plus InfraDAO for indexer-side baselines. Their familiarity with this subgraph is why they can read the root cause of the incident quickly (an unhandled null to field from Tenderize contract-to-contract calls, latent since ~2021).
  • Clarity & structure. One milestone with a clear definition of done: findings tiered from critical production risk down to larger redesign, each with evidence and a recommendation, non-sensitive items filed as public GitHub issues, and a closing forum retrospective. Targeted for end of Week 2 with one 60-minute community input session.
  • Quality bar & impact. The outage blocked delegator withdrawals and forced a multi-day resync over an edge case an audit should have caught. As the Technical Director put it, the subgraph breaking cost far more than an audit that could’ve prevent this, and it is the delegator who pays when this layer fails. The audit surfaces the remaining edge cases before the next incident, rebuilds delegator trust, sets InfraDAO baselines, and yields a ranked backlog for staged remediation.

Conditions & Alignment

  • Anchor to the real failure. Incident GitHub issues shared with BuildersDAO so the audit is grounded in the actual root cause.
  • Findings public by default. Non-sensitive findings filed as public GitHub issues; live production-risk items disclosed privately first, then published once safe.
  • Remediation stays separate. This grant covers audit and reporting only; remediation is scoped and priced as staged follow-up once findings are ranked.
  • Closeout. Final forum retrospective on completion, per the Monthly Reports guide, in this thread.

Mehrdad, on behalf of Network Engineering SPE