Pectra Audit Competition Launches on Cantina

3 months ago

Today, we're excited to denote the Pectra Audit Competition, kicking disconnected connected Cantina! This month-long lawsuit volition tally from February 21 to March 24, and we're excited to spot what issues the information assemblage tin find.

Why Pectra Matters

Some of the cardinal EIPs for Pectra are listed below

From EOAs to Smart Accounts (EIP-7702)

  • Enhances Externally Owned Accounts (EOAs) with astute declaration features.

Key Benefits

  • Transaction Batching: Combine aggregate operations into a azygous transaction.
  • Gas Sponsorship: Others tin wage fees for the account.
  • Alternative Authentication: Use hardware information modules oregon passkeys for authorization.
  • Spending Controls: Limit token usage/outflows for improved security.
  • Recovery Mechanisms: Safer plus extortion without changing the main account.

Safety Checks

  • Chain-Specific: Delegations valid lone connected 1 concatenation ID.
  • Nonce-Bound: Tied to the account's existent nonce, auto-invalidated erstwhile it changes.
  • Revocability: The EOA proprietor tin revoke/replace existing delegations astatine immoderate time.

Validator UX Improvements

EIP-7251

  • Raises Max Validator Balance from 32 ETH to 2048 ETH.
  • Enables automatic reward compounding and validator consolidation (merge aggregate validators with shared withdrawal credentials).

EIP-7002

  • Execution Layer Triggerable Withdrawals: Allows an Ethereum code (not conscionable the validator signing key) to trigger exits.
  • Reduces Trust successful Delegation: The relationship proprietor (human, DAO, etc.) tin unit exits without relying connected the validator.

EIP-6110

  • Speeds Up Deposit Processing: Cuts hold clip from ~9 hours to ~13 minutes.
  • Removes the pre-merge buffer for deposit processing (no longer needed post-merge).

Blob Scaling (EIP-7691)

  • Increases Ethereum's Blob Capacity by 50% (average from 3 to 6, max from 6 to 9).
  • Blobs are short-lived information for L2 proofs, reducing L1 fees by 10–100×.
  • EIP-7623 caps worst-case artifact size to negociate higher bandwidth.
  • Future scaling volition impact data sampling truthful that nodes store lone subsets of blob data.

For a much broad overview, person a look astatine the Pectra leafage connected ethereum.org.

Scope of the Audit

This contention specifically targets Pectra code. Any vulnerabilities discovered that are not circumstantial to Pectra should beryllium reported done the Ethereum Foundation Bounty Program. By keeping the absorption connected Pectra successful this competition, we anticipation to aboveground imaginable issues anterior to the mainnet hard fork.

Ethereum Protocol Attackathon Recap

The Ethereum Protocol Attackathon, which was precocious hosted connected Immunefi, has besides been concluded. In collaboration with Immunefi and the Ecosystem Funding Initiative, large ecosystem players — Bybit, Wormhole, Arbitrum Foundation, The Graph, GMX, and Base — generously donated matching funds alongside the Ethereum Foundation. This corporate effort underscored the community's dedication to gathering a much unafraid and resilient blockchain ecosystem.

Ready to Begin?

Head to Cantina's contention page to get started. For much accusation connected reporting vulnerabilities extracurricular of the competition, delight sojourn the Ethereum Foundation's Bug Bounty Program.

We look guardant to your discoveries. Good luck, and blessed auditing!

View source