Hey there ![]()
Sidestream Protocol R&D SPE here, below is our seventh monthly update.
Protocol R&D SPE - Sidestream - Update #7
- Status: On track
- Summary: August brought another sharp increase in Immunefi report volume, well over double what we received in July, which itself had been our highest-volume month up to that point. Handling this influx via proper triaging and initial assessments left us with little capacity for the other workstreams. We therefore focused on two things in parallel: processing the reports within their severity-based response times, and structurally reducing the overhead each individual report costs us. On the deployment side, we reviewed the backlog for an August candidate and found none that was mature and valuable enough to justify shifting focus to a release, so we deliberately skipped the August update rather than shipping for the sake of the cadence.
- Key achievements
- Immunefi response: Maintained continuous team-on-duty coverage through the highest-volume month so far: incoming reports more than doubled
compared to July, which had already been a record month. All reports were processed through initial assessment, and several were taken into report analysis end-to-end. Additionally supported with evaluation of onchain effects from the reports directed at the client. - Immunefi program scope improvement: Specified two further known issues which are currently under review by the Security Committee and a third one close to being shared. In addition, we shared a dedicated set of measures against the increased report volume with the Security Committee that are currently being enacted.
- Testnet creation: We continued the implementation work derived from the published testnet proposal. An internal PR that sets up a foundry-based repository for protocol updates with commands to spin up private and public testnets was opened and is currently under review.
- Backlog orchestration: We kept extending and prioritizing the backlog of protocol update candidates and re-evaluated the candidate list for the August release. As no candidate was ready, the update was consciously deferred instead of executed, with new candidate selection for September as the next step.
- Immunefi response: Maintained continuous team-on-duty coverage through the highest-volume month so far: incoming reports more than doubled
- Planned by Next Update:
- Deployment: Select and prepare the next protocol update candidate from the structured backlog and execute the September update in case there is a suitable candidate.
- Testnet creation: Advance testnet implementation in case there is time left from processing incoming reports.
- Immunefi response: Process all Immunefi submissions in time, based on their severity. Additionally, work on minimizing the overhead to process each report.
- Immunefi scope improvement: Identify further known issues and extend the Immunefi scope accordingly.
- ETA for Next Update: End of September 2026
Be aware: Due to the sensitive nature of our work, it is not possible to share links to many of the concrete artifacts we created (e.g., the processed vulnerability reports and their results), as these can only be shared with the Security Committee.