Hey there ![]()
Sidestream Protocol R&D SPE here - below is our third monthly update.
Protocol R&D SPE - Sidestream - Update #3
-
Status: On track
-
Summary: April was heavily focused on vulnerability response work across several reports, processing them through the full pipeline from initial assessment to in-depth analysis, including mitigation proposals. In one case, immediate action needed to be taken, which led to pausing the L1Migrator contract. Non-security scope advanced more slowly, due to vulnerability response, which is core to the SPE’s mandate, and took priority.
-
Key achievements
-
Immunefi response: Maintained continuous team-on-duty coverage to ensure timely reaction to incoming vulnerability reports. Processed several vulnerability reports end-to-end, including significant weekend and out-of-office hour action.
-
Emergency response: Coordinated and prepared the pausing of the L1Migrator contract with the Livepeer Security Committee in response to a vulnerability report.
-
Testnet proposal: Iterated with the Livepeer Security Committee on the scope of the proposal, we are nearing a point where it can be shared publicly.
-
Backlog orchestration: Extended the backlog with further update candidates, collected input from external stakeholders where needed to advance candidates, and kept prioritising the various candidates. One candidate has been chosen for the next feature protocol update.
-
-
Planned by Next Update:
-
Deployment: Prepare the next protocol update from the structured backlog.
-
Immunefi Response: Process all Immunefi submissions in time, based on their severity, and finish currently still in-progress report assessments.
-
Testnet proposal: Collect feedback from the community and push implementation work forward.
-
Feature Advancement: Advance the chosen feature towards its release.
-
-
ETA for Next Update: End of May 2026
Be aware: Due to the sensitive nature of our work, it is not possible to share links to many of the concrete artifacts we created (e.g., the processed vulnerability reports and their results) as these can only be shared with the Security Committee.
You can check implicit artifacts via the transaction and the Discord announcement.