Skip to main content

PAL Community Report 2024 / H2

Date: 22.02.2025

This Community report summarizes the activity of the Polkadot Assurance Legion (PAL) during the period July-December 2024. From 2025 onward, PAL will be publishing community reports on a quarterly basis.

PAL

PAL is a community-driven initiative that aims to make Polkadot a safer and more attractive place for both builders and users by allocating funds from the Polkadot treasury (bounty #22) to advance security in Rust / Polkadot SDK.

In 2024 H2, PAL saw an enlargement in the scope of its activities. Initially, PAL was only providing funding for Rust audits of Polkadot projects (parachains and smart contracts). As a result of OpenGov Ref. #107, the mandate of PAL was extended to also include audits of common-good functionality. What comes to mind are pallets that are used by System Chains, or pallets that are of importance to multiple Polkadot projects. Funding for Solidity audits is now also available.

Beyond audits, PAL now can also provide incentives for the development of common-good tooling which benefits security in the Polkadot ecosystem. Furthermore, PAL can also provide support for other common-good security initiatives. Find out more about the various funding opportunities on PAL’s homepage.

Summary

In the period July-December 2024, PAL has provided funding for 7 parachain audits, and 1 security tool.

The conducted audits helped secure xxx lines of code (LOC) and identify a total of 26 issues, 5 of which classified as High Impact. 2 of the audits are continuous, meaning that they are carried on all the code pushed by a team during several weeks / months.

PAL also started providing funding for its first security tool - Coinfabrik Scout, a static analysis tool which enables developers to identify common vulnerabilities in their code (e.g. unsafe math). This project also includes a machine learning dataset which can be used to RAG train a model on Polkadot-SDK vulnerabilities -- scout-substrate-dataset. This dataset is also available on Hugging Face. In 2024 H2, PAL funded the successful delivery of the first 2 milestones of the project.

Spending breakdown:

WhatHow much
Audits84,262 DOT
Tooling10,695 DOT
Curator salaries17,534 DOT
Total112,491 DOT

Overview

Audits

IDAuditCo-fundedLOCCriticalHighMedLowReport
1691laos-coinfabrik-24078,434 DOT18,1900112report
2423frequency-srl-240918,000 DOT9,3790002report
2424peaq-srl-2409*18,000 DOT(continuous)TBATBATBATBAreport coming soon
2427hydration-pashov-24106,511 DOT9750135report
2661zeitgeist-oak-241014,814 DOT6,2730344report
2662astar-srl-24112,023 DOT1250000report
2838moonbeam-srlabs-2411*2,023 DOT(continuous)TBATBATBATBAreport coming soon

The reports for audits marked with * are still not available, once ready they will be included in this report.

Tooling

IDAuditPaid outCategoryGithubDocs
2460Coinfabrik Scout 50% of MS14,425 DOTStatic AnalysisGithuboffer, milestones
2700Coinfabrik Scout 50% of MS1 and MS26,270 DOTStatic AnalysisGithuboffer, milestones

Other

The PAL curators have received in total 17,534 DOT as remuneration for their work. This corresponds to $3,000 per curator per month, using the 30d EMA DOT price.