Proposal - Protocol R&D Special Purpose Entity

Hey there :waving_hand:

Sidestream Protocol R&D SPE here, glad to continue our work under the renewed Protocol R&D SPE - below is our fifth monthly update.

Protocol R&D SPE - Sidestream - Update #5

  • Status: On track
  • Summary: June was yet another month with a strong focus on vulnerability response work across several reports. As usual, we’ve processed them end-to-end. Based on the established monthly release cycle, we facilitated another protocol update in collaboration with the Security Committee, executed on 2026-06-25.
  • Key achievements
    • Protocol update: We updated the TicketBroker implementation contract to prevent a potential low-severity griefing attack scenario. The attacker could’ve manipulated the supply and reserve levels to only partially pay the valid ticket value, while the ticket would be permanently redeemed. The updated contract prevents partial payouts as the smallest possible measure against such an attack. The update was prepared in collaboration with the Security Committee.
    • Immunefi response: Maintained continuous team-on-duty coverage to ensure timely reaction to incoming vulnerability reports. Processed several vulnerability reports end-to-end, including significant weekend and out-of-office-hours work.
    • Immunefi program scope improvement: Suggested extending the program’s scope with guidance on known issues to reduce the number of duplicative incoming reports and supported the creation of the first known issue.
    • Backlog orchestration: Extended the backlog with further protocol update candidates, collected input from external stakeholders where needed, and kept prioritising the various candidates.
  • Planned by Next Update:
    • Deployment: Prepare and execute the next protocol update from the structured backlog.
    • Immunefi response: Process all Immunefi submissions in time, based on their severity, and finish the report assessments still in progress.
    • Proactive security work: Complete internal security review of further protocol contracts. These internal reviews serve as a proactive defense layer before vulnerabilities get reported via public bug bounty programs.
  • ETA for Next Update: End of July 2026

Be aware: Due to the sensitive nature of our work, it is not possible to share links to many of the concrete artifacts we created (e.g., the processed vulnerability reports and their results) as these can only be shared with the Security Committee.

You can check the implicit artifact of the latest protocol update via this transaction.

5 Likes