Summary
This proposal, created on behalf of @infosec_us_team, requests 8,000,000 ACA from the Acala Treasury as a bug bounty payment and Immunefi platform fee related to a critical vulnerability affecting LDOT. The requested funds will be used for payment to infosec_us_team and the Immunefi platform fee. The issue has already been patched in Acala in the last runtime upgrade (2320).
Background
A critical security vulnerability was identified that could, under specific conditions, allow arbitrary minting of a small amount of LDOT. With enough repeats, it would be possible to drain liquidity from any LDOT DEX pairs. And if without further governance actions, unstake and withdraw all staked DOT by Homa protocol.
Key points
- The root cause lies in the polkadot-sdk, not in Acala-specific logic.
- The vulnerability has been communicated to Parity under a coordinated disclosure process.
- Acala has released runtime 2320, which includes a patch that mitigates this vulnerability on Acala and Karura.
- Parity will share more technical details publicly once:
- The underlying root cause is fully fixed in polkadot-sdk, and
- It is verified that no live chain remains impacted.