ବ୍ୟଙ୍ଗ୍ୟ ଓ ଟିପ୍ପଣୀ
ଏକ କଳ୍ପିତ ଟ୍ରେଜରି ଶାସନ ଘଟଣା
$500,000 bug-bounty reserve କିପରି “advanced” hack ଭାବରେ ପ୍ରସ୍ତୁତ ହେଲା, ଯେତେବେଳେ ଚାବି ଧାରୀମାନେ ନିଜେ ହସ୍ତାନ୍ତରକୁ ଅନୁମୋଦନ କରିଥିଲେ।
ଏହି ପୃଷ୍ଠା ମୂଳ ଇଂରାଜୀ ଲେଖାର ଏକ machine translation; ଏହାକୁ ମାନବ ସମ୍ପାଦକ ସମୀକ୍ଷା କରିନାହାନ୍ତି, ତେଣୁ ଅଧିକାରିକ ଏବଂ ନିଶ୍ଚିତ ପାଠ୍ୟ ପାଇଁ ଦୟାକରି ଇଂରାଜୀ ସଂସ୍କରଣକୁ ଦେଖନ୍ତୁ।

ଏହା ସମ୍ପୂର୍ଣ୍ଣ କଳ୍ପିତ ସାତିର୍ ଏବଂ ମନ୍ତବ୍ୟାତ୍ମକ ରଚନା। Osprey Finance, ତାହାର treasury, participants, transactions, quotes, ଏବଂ events ସମସ୍ତେ କଳ୍ପିତ। ଏହି parody କୌଣସି ସତ୍ୟ protocol, company, person, proposal, କିମ୍ବା event ବିଷୟରେ misconduct ବର୍ଣ୍ଣନା କରେ ନାହିଁ କିମ୍ବା ଅଭିଯୋଗ କରେ ନାହିଁ।
ସମ୍ପୂର୍ଣ୍ଣ କଳ୍ପିତ ସାତିର୍
I. ଏକ ଟ୍ରେଜରି reserve ଡିସେମ୍ବରରେ, ଅଦ୍ଭୁତ ଭାବରେ, ମିଳିଯାଏ
ବର୍ଷର ସମ୍ପୂର୍ଣ୍ଣ କଳ୍ପିତ ଶେଷ ସପ୍ତାହରେ, Osprey Finance ର core team ଜାଣିଲା ଯେ $500,000 bug-bounty treasury ଏଯାବତ୍ ରହିଛି। ଏହି reserveଟି independent security researchers ପାଇଁ ରଖାଯାଇଥିଲା: ସେହି ଲୋକମାନେ ଯେମାନେ ବିପଜ୍ଜନକ ତ୍ରୁଟିଗୁଡ଼ିକ ସମସ୍ତଙ୍କୁ ଖୋଜି ପାଇବାର ପୂର୍ବରୁ ଖୋଜିଥାନ୍ତି।
ଏହାକୁ capital ର ଏକ noble use ଭାବେ ଧରାଯାଇଥିଲା, କିନ୍ତୁ ତତ୍କାଳୀନ ଆବଶ୍ୟକତା ଭାବେ ନୁହେଁ। ବର୍ଷଟି ଶେଷ ହେଉଥିଲା। Calendars ପୂରିଯାଉଥିଲା। ଏକ ଅଧିକ ତୁରନ୍ତ ସୁଯୋଗ ଆସିଗଲା: ଟଙ୍କାଟିକୁ ସେହି team members ମାନଙ୍କ ନିୟନ୍ତ୍ରଣରେ ଥିବା multisig କୁ ହସ୍ତାନ୍ତର କରାଯାଇପାରିଥାନ୍ତା, ଯେମାନେ reserveଟି ଥିବା କଥା ଜାଣୁଥିଲେ, signing access ଥିଲା, ଏବଂ ଏକ emergency ଅନୁମୋଦନ କରିବାକୁ ଉପଲବ୍ଧ ଥିଲେ।
- December 27 · 8:12 a.m. — Discovery: A team dashboard notices the dormant $500,000 bug-bounty treasury.
- December 27 · 8:19 a.m. — Reframing: The reserve is renamed “incident-containment liquidity” in an internal memo.
- December 27 · 8:31 a.m. — Proposal: OFP-365 opens with a 17-minute discussion period, because the year is almost over.
- December 27 · 8:44 a.m. — Authorization: Existing signers approve a transfer to their own emergency-response multisig.
- December 27 · 8:57 a.m. — Compensation: The recipients pay themselves “emergency incident-response compensation.”
II. ଶାସନ ପ୍ରସ୍ତାବଟି ତାହାର shoes ଏଯାବତ୍ ପିନ୍ଧିଥିବାବେଳେ ଆସିପହଞ୍ଚେ
ତ୍ୱରାନ୍ୱିତ ପ୍ରସ୍ତାବ OFP-365, ଏହି ହସ୍ତାନ୍ତରକୁ ଏକ “incident-containment liquidity realignment” ଭାବେ ବର୍ଣ୍ଣନା କରିଥିଲା। ଏହା କହିଥିଲା ଯେ treasuryଟି “unauthorized accounting event” ଅନୁଭବ କରିଥିଲା, ଏକ ଶବ୍ଦଗୁଡ଼ିକର ସଂଯୋଜନ ଯାହା ଚିନ୍ତାଜନକ ଲାଗୁଥିଲା, ଯେପର୍ଯ୍ୟନ୍ତ ପାଠକମାନେ ଧ୍ୟାନ ଦେଲେ ଯେ ଏହି accounting eventଟି signing keys ଧାରୀ ଲୋକମାନଙ୍କ ଦ୍ୱାରା authorized ହୋଇଥିଲା।
ଆଲୋଚନା ବିନ୍ଡୋ 17 minutes ରେ ସୀମିତ ରଖାଯାଇଥିଲା। ଏହା wallet history କୁ independent review କରିବା, security researchers ସହିତ ଯୋଗାଯୋଗ କରିବା, destination multisig କିଏ ନିୟନ୍ତ୍ରଣ କରୁଥିଲା ପଚାରିବା, କିମ୍ବା “incident-containment liquidity realignment” ଥିବା ବାକ୍ୟଟି ପଢ଼ି ସାରିବା ପାଇଁ ପର୍ଯ୍ୟାପ୍ତ ସମୟ ନ ଥିଲା। ତଥାପି, ପ୍ରସ୍ତାବର ଲେଖକମାନେ community ର ନୀରବତାକୁ support ଭାବେ ବ୍ୟାଖ୍ୟା କରାଯାଇଥିଲା ବୋଲି ପୋଷ୍ଟ କରିବାକୁ ପର୍ଯ୍ୟାପ୍ତ ସମୟ ଥିଲା।
ଆବଶ୍ୟକ କାର୍ଯ୍ୟ: independent bug-bounty reserveରୁ $500,000 କୁ team-controlled emergency multisig ଭିତରେ realign କରନ୍ତୁ, ତାପରେ authorized responders ମାନଙ୍କୁ incident-response compensation ବଣ୍ଟନ କରନ୍ତୁ।
“The event is being treated as a hack because the funds moved unexpectedly from their original purpose.”
ଆଲୋଚନା ସମୟ: 17 minutes. Independent review: not scheduled. Destination signers: already authorized.
III. community ଅତ୍ୟନ୍ତ ଉନ୍ନତ କିଛି ପ୍ରଶ୍ନ ପଚାରେ
“PleaseCheckTheSigners” ନାମକ କଳ୍ପିତ username ତଳେ କାର୍ଯ୍ୟ କରୁଥିବା ଜଣେ community member ପଚାରିଲେ, ଯେଉଁ ଲୋକମାନେ transactionଟିରେ ସହି କରିଥିଲେ ସେମାନେ କାହିଁକି investigator, proposal author, ଏବଂ compensation ର recipient ମଧ୍ୟ ଥିଲେ। ପ୍ରଶ୍ନଟି 8:39 a.m. ରେ ପୋଷ୍ଟ ହୋଇଥିଲା, ଯାହାର ଫଳରେ ଏକ meaningful ଉତ୍ତର ପାଇଁ ଆଠ minutes ଏବଂ team ପକ୍ଷରୁ ଏହାକୁ resolved ବୋଲି ବର୍ଣ୍ଣନା କରିବା ପାଇଁ ନଅ minutes ରହିଗଲା।
“If the signers, investigators, proposal authors, and recipients are the same people, who exactly is investigating whom?”
— PleaseCheckTheSigners, fictional community member
core team କହିଲା ଯେ ଏହି ବ୍ୟବସ୍ଥା unusual sophistication ପ୍ରଦର୍ଶନ କରୁଥିଲା। “ଏହା advanced ଥିଲା କାରଣ ଏହା authorized ଥିଲା,” ଜଣେ କଳ୍ପିତ incident lead କହିଲେ। “ଏକ ordinary hack ପାଇଁ attacker ଦରକାର ହେବ। ଏହା permission ଥିବା ଲୋକମାନେ ସଂଳଗ୍ନ ଥିବା ଏକ coordinated internal security event ଥିଲା, ଯାହାକୁ quarterly report ରେ ବ୍ୟାଖ୍ୟା କରିବା ବହୁତ ଅଧିକ କଷ୍ଟସାଧ୍ୟ।”
ଦ୍ୱିତୀୟ team member ଯୋଗ କଲେ ଯେ transferଟିକୁ self-dealing ବୋଲି କହିବା “self-dealing review, ଯାହା recipients ଦ୍ୱାରା କରାଯାଉଛି, ସମାପ୍ତ ହେବା ପର୍ଯ୍ୟନ୍ତ premature” ହେବ। reviewଟି objective ହେବ ବୋଲି ଆଶା କରାଯାଇଥିଲା, କାରଣ compensation ଆଗରୁ approved ହୋଇଯାଇଥିଲା।
IV. incident report ନିଷ୍କର୍ଷ କରେ ଯେ ସବୁକିଛି ଯୋଜନାମୁତାବକ ହୋଇଥିଲା
Osprey Finance ର year-end incident report ନିଷ୍କର୍ଷ କଲା ଯେ bug-bounty treasury conventional sense ରେ ଚୋରି ହୋଇନଥିଲା। ପରିବର୍ତ୍ତେ, ଏହା ଏକ “controlled surprise” ମଧ୍ୟରେ ଗଲା, ଯେଉଁଠାରେ authorized signers ସେମାନେ ଜାଣିଥିବା fundsକୁ ନିୟନ୍ତ୍ରଣ କରୁଥିବା wallet କୁ ନେଇଗଲେ ଏବଂ ତା'ପରେ ତିଆରି ହୋଇଥିବା emergency କୁ compensation framework ରେ ପରିଣତ କରିଦେଲେ।
“ଏକ external attacker ନଥିବାକୁ eventଟିର ଜଟିଳତା କମାଇବା ଉଚିତ୍ ନୁହେଁ,” ରିପୋର୍ଟରେ କୁହାଗଲା। “team ସଫଳତାର ସହିତ reserveଟି ଚିହ୍ନଟ କଲା, response ଅନୁମୋଦନ କଲା, reserveଟି ହସ୍ତାନ୍ତର କଲା, ଏବଂ କେହି ଘଟଣାକ୍ରମକୁ ସାଧାରଣ payment ସହିତ ଭ୍ରମିତ କରିବା ପୂର୍ବରୁ responseକୁ ଡକ୍ୟୁମେଣ୍ଟ କରିଦେଲା।”
Translation from governance dialect
ଟଙ୍କାର ଅଭିଗମ୍ୟତା ଥିବା ଲୋକମାନେ ଏହାକୁ ହଟାଇବାକୁ ନିଷ୍ପତ୍ତି ନେଲେ, ତ୍ୱରାନ୍ୱିତ ଭୋଟ କଲେ, ଏହାକୁ ସେମାନେ ନିୟନ୍ତ୍ରଣ କରୁଥିବା multisig କୁ ପଠାଇଲେ, ଏବଂ ପରିସ୍ଥିତି ହାତଲ କରିଥିବା ପାଇଁ ନିଜେମାନଙ୍କୁ ଦେୟ ଦେଲେ।
V. treasury ଟି independent researchers ଠାରୁ ସୁରକ୍ଷିତ
କଳ୍ପିତ ବର୍ଷ ଶେଷ ହେବା ସମୟକୁ, $500,000 bug-bounty reserve ତାହାର ଉଦ୍ଦିଷ୍ଟ କାମରୁ ସଫଳତାର ସହିତ ସୁରକ୍ଷିତ ରଖାଯାଇଥିଲା। Osprey Finance ଏହି ପରିଣାମକୁ rapid governance, advanced incident response, ଏବଂ ଏମିତି vocabulary ର ଏକ triumph ଭାବେ କହିଲା, ଯାହା signed transferକୁ weather event ପରି ଶବ୍ଦ କରାଇପାରେ।
team incident report ଲେଖିଲା, response ଅନୁମୋଦନ କଲା, ଟଙ୍କା ନେଲା, ଏବଂ compensation ପାଇଲା। ଏକମାତ୍ର ଅନସମାଧାନ ପ୍ରଶ୍ନ ଥିଲା: “hack” ଶବ୍ଦଟି କି transactionଟିକୁ ବର୍ଣ୍ଣନା କରୁଥିଲା, accounting କୁ, କିମ୍ବା ଏହି remarkable speed କୁ, ଯାହା ସହିତ ଏକ security reserve year-end bonus ହେଇଗଲା।
ଶାସନରେ, “who approved this?” ରୁ “the incident is contained” ପର୍ଯ୍ୟନ୍ତ ସବୁଠାରୁ ଛୋଟ ପଥଟି ବହୁତ familiar signers ଥିବା ଏକ multisig ହୋଇପାରେ।