Hey there ![]()
Sidestream Protocol R&D SPE here, below is our sixth monthly update.
Protocol R&D SPE - Sidestream - Update #6
- Status: On track
- Summary: July was our highest-volume month for vulnerability response so far, with a high number of incoming Immunefi reports processed through initial assessment and one report taken into in-depth analysis. In parallel, we kept the monthly release cadence and shipped the reward call delegation feature (see LIP-118) in a protocol update executed on 2026-07-30. We also invested in reducing the noise on the bug bounty side by bringing known issue identification into the existing triage process, and prepared the testnet proposal for publication.
- Key achievements
- Protocol update: We deployed a new
BondingManagerimplementation contract that adds optional reward call delegation, as specified in LIP-118. Orchestrators can now set a dedicated reward caller address that is allowed to trigger the reward call on their behalf. The change is additive and opt-in: Orchestrators that don’t use the feature are unaffected, and even an orchestrator with a reward caller configured can still call reward itself. The update ran through our full release process together with the Livepeer Security Committee. You can check the execution of this update via this transaction. - Immunefi response: Maintained continuous team-on-duty coverage, including a defined weekend duty plan, to ensure timely reaction to incoming vulnerability reports. We processed the highest number of reports so far within a month end-to-end, including significant weekend and out-of-office-hours work. The high volume is also the reason why we shifted priority and didn’t focus on further internal security reviews.
- Immunefi program scope improvement: Building on the first known issues, we took ownership of specifying known issues going forward. Each known issue documented up front might reduce the number of duplicative reports that need to be processed. We extended our triage pipeline so that every incoming report is checked for a potential new known issue, and defined a common structure for how known issues are written up. The first known issue identified through this process was specified and is currently under review.
- Testnet creation: Completed the task breakdown for the testnet implementation and finalised version of the testnet proposal, incorporating review feedback from different stakeholders. The proposal was shared publicly on the forum here.
- Backlog orchestration: Kept extending and prioritising the backlog of protocol update candidates.
- Protocol update: We deployed a new
- Planned by Next Update:
- Deployment: Select and prepare the next protocol update candidate from the structured backlog and execute the August update in case there is a suitable candidate.
- Immunefi response: Process all Immunefi submissions in time, based on their severity. Additionally, work on minimising the overhead to process each report.
- Immunefi scope improvement: Identify further known issues and extend the Immunefi scope accordingly.
- ETA for Next Update: End of August 2026
Be aware: Due to the sensitive nature of our work, it is not possible to share links to many of the concrete artifacts we created (e.g., the processed vulnerability reports and their results) as these can only be shared with the Security Committee.