Taylor Hornby - Bonus Grant for Orchard Counterfeiting Vulnerability Bug Bounty

I’ve submitted a bonus grant nomination for Taylor Hornby. It was inspired by Zooko’s post suggesting we should be able to nominate people for retroactive grants instead of waiting for them to apply, and that Taylor should receive more. @frankbraun also reached out to me separately to advocate for a bonus grant for Taylor, having come to the same conclusion on his own. I agree.

Taylor’s requested bounty for disclosing the Orchard vulnerability works out to 0.033% of the funds at risk, a fraction of the lowest ratio among the industry precedents in his own application. I’m recommending coinholders approve an additional $750,000, doubling his request to a total of $1,500,000, which is still well under those rates.

I’m submitting this in my personal capacity, Taylor had no role in it, and none of the funds go to me or Shielded Labs.

13 Likes

Taylor’s discovery and responsible disclosure of this bug almost certainly saved Zcash. I am in complete support.

We were days or possibly even hours away from a malicious actor finding and exploiting this fatal bug in the codebase, without detection, through the use of rapidly strengthening AI tools. Taylor was in the best position here, thanks to Shielded Labs for funding and supporting his security work in advance, but also because he is a good and moral human being. I know Taylor; when I found out he discovered it, I was immediately relieved because he’s one of the good guys that I trusted would never harm Zcash.

Imagine how valuable these actions will be to the ZEC holders of the future?

15 Likes

Invaluable - we absolutely should be rewarding responsible disclosure of existential vulnerabilities. Full support.