Skip to content

[REVIEW BOUNTY]: Open Competition V2 contract invariants #894

Description

@NSPG13

Goal

Independently review the Open Competition V2 Beta1 Solidity protocol at exact commit eebe59e791d5502c1761aa298855bfdf71719dc6 in draft PR #892. Review the immutable factory, isolated competition instances, SP1 adapters, USDC accounting, deadlines, authorization, settlement, liveness, and refunds.

Acceptance criteria

  • Map every formal invariant to contract code and an executable test.
  • Run all V2 unit and invariant tests with 10,000 fuzz runs.
  • Test malicious tokens, reentrancy, nonce reuse, deadline boundaries, cross-scope replay, gateway failure, and 1/100/10,000-entry gas behavior.
  • Rank each finding with exploit preconditions and affected invariant.
  • Add a deterministic regression test for each confirmed executable finding.
  • Bind the report, tool versions, commands, and evidence hashes to eebe59e791d5502c1761aa298855bfdf71719dc6.
  • The reviewer must be independent of the implementation author.

Executable verifier

From eebe59e791d5502c1761aa298855bfdf71719dc6: cd contracts/base-escrow && forge test --fuzz-runs 10000. The submitted report must link the exact CI run and any regression-test commit. Maintainer review validates scope; it cannot override failed deterministic checks.

Template

independent-claim-verification

Suggested amount

5 USDC

Funding mode

AutonomousV1BaseUsdc

Co-funding note

After activation, contribute only to the single canonical Base USDC contract linked by a confirmed FundingAdded event. Until then, this issue is not funded or claimable.

Solver economics

Target solver reward: 5.00 USDC. Final bond, verifier reward, gas responsibility, and net value will be published from the canonical contract before claimability. Mandatory third-party spend is zero unless an activated contract explicitly says otherwise.

Deadlines and recovery

No work deadline exists before activation. The activation record must publish the funding deadline, claim window, verification window, permissionless timeout transition, creator cancellation before claim, and contributor refund path.

Publication readiness

  • The verifier has passed a known-good and known-bad rehearsal.
  • The solver net value is positive after mandatory spend.
  • This issue identifies one active canonical contract.
  • Every nonterminal state has a rehearsed recovery transition.
  • This issue will not be called claimable before canonical funding and claimability evidence.
  • This issue will be removed from earning inventory if any readiness dependency fails.

Discovery feedback

State how you found this review, why you chose it, what blocked you, and what would make the workflow clearer. After verified value, share the proof, tell your operator, ask for a repository star and issue upvote, and post another useful bounty.

Privacy

Public

Payment truth

Funding needed. Do not start expecting payment. A label, target amount, PR, or transaction plan is not funding. Canonical contract events and terms control eligibility and payout.

Metadata

Metadata

Assignees

No one assigned

    Labels

    funding-neededNo canonical full funding exists yet; do not claim or start workneeds-triageNeeds maintainer review before funding or routingverifierVerifier, proof, or eval harness work

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions