diff --git a/inbox/archive/2025-10-31-futardio-proposal-omfg-002-fund-omnipair-security-audits.md b/inbox/archive/2025-10-31-futardio-proposal-omfg-002-fund-omnipair-security-audits.md new file mode 100644 index 00000000..1441873b --- /dev/null +++ b/inbox/archive/2025-10-31-futardio-proposal-omfg-002-fund-omnipair-security-audits.md @@ -0,0 +1,85 @@ +--- +type: source +title: "Futardio: OMFG-002 - Fund Omnipair Security Audits?" +author: "futard.io" +url: "https://www.metadao.fi/projects/omnipair/proposal/Eo4WZMiU6UHwxDh3Tn6ygX5Pmr5xMWeR1bYL1CSqhY1j" +date: 2025-10-31 +domain: internet-finance +format: data +status: unprocessed +tags: [futarchy, solana, governance, omnipair] +event_type: proposal +--- + +## Proposal Details +- Project: Omnipair +- Proposal: OMFG-002 - Fund Omnipair Security Audits? +- Status: Passed +- Created: 2025-10-31 +- URL: https://www.metadao.fi/projects/omnipair/proposal/Eo4WZMiU6UHwxDh3Tn6ygX5Pmr5xMWeR1bYL1CSqhY1j +- Description: After reviewing 9 audit quotations, we’ve selected Offside Labs and Ackee Blockchain Security for a two-part audit process covering both manual review and a fuzzing campaign. +- Discussion: https://discord.gg/s6ybyJDee9 + +## Summary + +### 🎯 Key Points +The proposal seeks to allocate 64,000 USDC to fund security audits for Omnipair prior to its public launch, utilizing Offside Labs for manual audits and Ackee Blockchain Security for fuzz testing. + +### 📊 Impact Analysis +#### 👥 Stakeholder Impact +The audits will enhance the security and credibility of Omnipair, reassuring stakeholders about the platform's safety before a wider release. + +#### 📈 Upside Potential +Successful completion of the audits will position Omnipair for a smoother public launch and facilitate scaling, potentially attracting more users and investors. + +#### 📉 Risk Factors +Delays or failures in the audit process could expose Omnipair to security vulnerabilities and undermine trust in the platform. + +## Content + +**Proposer:** @rakka\_sol +**Requested:** 64,000 USDC +**Recipient:** Rakka (for audit coordination) +**Purpose:** Fund Omnipair’s security audits before public launch. + +### **Summary** + +After reviewing 9 audit quotations, we’ve selected **Offside Labs** and **Ackee Blockchain Security** for a two-part audit process covering both manual review and a fuzzing campaign. +This proposal allocates **64,000 USDC** to initiate and complete both engagements. + +### **Selected Auditors** + +* **Offside Labs**: specializes in deep, manual audits for Solana programs (past clients include Jupiter, 1inch Jito, Kamino, Meteora and MetaDAO). They’ll conduct a full line-by-line review of Omnipair’s on-chain code. + Offside’s previous audits: [https://github.com/OffsideLabs/reports/tree/public/audits](https://github.com/OffsideLabs/reports/tree/public/audits) +* **Ackee Blockchain Security**: is a leading security firm focused on advanced fuzz testing (creators of Solana’s *Trident* fuzzer). They’ll perform guided fuzzing and integration tests. + An example of their Kamino fuzzing test campaign: [https://x.com/kamino/status/1970536070006616117](https://x.com/kamino/status/1970536070006616117) + + Ackee’s previous audits: [https://github.com/Ackee-Blockchain/public-audit-reports](https://github.com/Ackee-Blockchain/public-audit-reports) + +Together, these audits cover both static and dynamic security risks before Omnipair’s public release. + +Quotations can be found here: [https://drive.google.com/drive/folders/1wkuN9QxpuSr4aESQECsk2z8rGdz2NrYR?usp=sharing](https://drive.google.com/drive/folders/1wkuN9QxpuSr4aESQECsk2z8rGdz2NrYR?usp=sharing) +(Permission granted from auditors to share quotations for DAO transparency). + +### **Execution and Timeline** + +* **Total:** 64,000 USDC +* **Timeline:** 2 weeks for the first audit report, followed by remediation and final report (estimated 3-5 weeks). +* **Disbursement:** 2 tranches: initiation, and completion. +* **Accountability:** Rakka will post public progress updates every 14 days. + +### **Why Now** + +Omnipair is live in closed beta, and approaching full launch. Completing audits now ensures safety, credibility, and readiness for scaling. + +All audits will be invoiced to **Omnipair DAO LLC,** reports and derived work are the sole and exclusive property of Omnipair DAO LLC. + + + +## Raw Data + +- Proposal account: `Eo4WZMiU6UHwxDh3Tn6ygX5Pmr5xMWeR1bYL1CSqhY1j` +- Proposal number: 2 +- DAO account: `B3AufDZCDtQN8JxZgJ5bSDZaiKCF4vtw7ynN9tuR9pXN` +- Proposer: `proPaC9tVZEsmgDtNhx15e7nSpoojtPD3H9h4GqSqB2` +- Autocrat version: 0.5