Hey there,
Sidestream Protocol R&D SPE here; below is our eighth monthly update.
Protocol R&D SPE - Sidestream - Update #8
- Status: On track
- Summary: In September, we saw a reduction in incoming vulnerability reports compared to the previous two months. All incoming reports were still processed within their severity-based response times, but the lower volume gave us room to revisit investigations into previous reports that had to be deprioritized during periods of higher load. We also published two more known issues published in the Immunefi scope to reduce duplicate reports. In parallel, we prepared the next release candidate for the October window and started exploring AI-based protocol scanning as an additional proactive security layer.
- Key achievements
- Immunefi response: Maintained continuous team-on-duty coverage to ensure timely reaction to incoming vulnerability reports. Processed several vulnerability reports end-to-end, including weekend and out-of-office-hours work.
- Immunefi program scope improvement: Ensured that two new known issues (Winning tickets can settle for less than their face value; MixinReserve.claimableReserve() mid-round accounting mismatch when transcoder pool size and current-round active set diverge) were published and documented in the Immunefi program’s scope to reduce influx of additional reports on these matters.
- Testnet creation: We continued the implementation work derived from the testnet proposal and conducted a first set of internal reviews on the previously opened implementation PRs. Answered community feedback on the published testnet proposal.
- Backlog orchestration: We kept extending and prioritizing the backlog of protocol update candidates and re-evaluated the candidate list for a September release. Towards the end of the month, we picked a suitable candidate, re-initiated the discussion with the Livepeer Security Committee, and started the release preparation process. Given the overall timeline, we decided not to squeeze in the release in September but to target the October release window to ensure proper due diligence enforced by the update checklist.
- Continuous Monitoring: Despite not being a core responsibility of ours, we fulfilled a request from the Security Committee to set up temporary monitoring for 2 different protocol actions.
- AI-based protocol scanning: Researched common local harness setups for automated bug hunting and started testing different harness and model combinations against the protocol. Triaged all findings from these scans.
- Planned by Next Update:
- Deployment: Advance the October release candidate and coordinate the update.
- Testnet creation: Advance testnet implementation in case there is time left from processing incoming reports.
- Immunefi response: Process all Immunefi submissions in time, based on their severity. Additionally, work on minimizing the overhead to process each report.
- Immunefi scope improvement: Identify further known issues and extend the Immunefi scope accordingly.
- AI-based protocol scanning: Keep testing harness and model combinations, document the results.
- ETA for Next Update: End of October 2026
Be aware: Due to the sensitive nature of our work, it is not possible to share links to many of the concrete artifacts we created (e.g., the processed vulnerability reports and their results), as these can only be shared with the Security Committee.