I voted against this pre-proposal for the following reasons:
- This is my main reason: louis88 publicly posted that there is an active vulnerability in a well-known Hive Platform before it was patched! This alone presents a major issue as it pretty much paints a target on the whole Hive ecosystem. He also dropped enough clues to encourage everyone to use AI to attack Splinterlands before the vulnerability is patched.
- I believe the bounty is excessive and sets prescedent for a $5,000 payment for every security bug in Splinterlands. Penetration tests usually start at $1,000 to $2,000, so at $5,000 there is a potential profit in hiring a pen test firm to find a bunch of vulnerabilities in Splinterlands then submit one after another for multiple payments of $5,000...
Here is the screenshot from his post that gives away some clues and has been up for a month now:
RE: SPS Governance Proposal - Pay Bug Bounty to louis88