We deployed the version from the exact commit hash that was audited by Cyfrin. We’ll always stick to the best practices possible on security (in that case meaning we would only deploy and use audited code), while also being aware of the time sensitivity of the situation.
The concerns Clowes addressed will be resolved. And we’ll be deploying a new version in the next weeks. It was already checked by Cyfrin and the new version address all the points. It’s not a critical vulnerability but it’s important to be addressed.
That said, the proposal passed and executed successfully. We have the first withdrawal going from the registrar controllers directly to the endowment!!
Next steps:
- @kpk to calculate how much USDC we need to transfer in order to maintain 6 months of runway in the timelock
- Execute the transfer ASAP so we don’t risk SPP streams being canceled and Labs can withdraw their stream
- @kpk to include this routine each quarter, next run would be in the first weeks of July
Less coordination cost and capital getting yield sooner.