OpenZeppelin has secured Compound since December 2021, establishing a proven track record of comprehensive protocol protection. In our current annual term (July 2024-June 2025), we’ve completed 40+ security audits, reviewed 180+ governance proposals, and identified 6 critical vulnerabilities while maintaining zero protocol losses due to security exploits.
Throughout this partnership, we’ve maintained Compound’s ecosystem security while flexibly responding to incidents and adapting to the DAO’s evolving development needs. Our collaborative approach with key contributors has optimized processes and enabled early risk mitigation across protocol operations.
This renewal continues our comprehensive security services with more detailed specifications of the coverage we’ve been providing to Compound, making our commitments more explicit.
Previously OpenZeppelin used the Vendor Payment Aera Vault adopted in Proposal 249. With the deprecation of the Vendor Payment Aera Vault, Woof! Software proposed a USDC-price-adjusted COMP streaming mechanism. This approach provides several benefits:
OpenZeppelin will continue its annual renewal model for our Security Partnership adopting the same streaming approach. Our governance proposal will initiate a deposit of 110% of the 4M USDC equivalent in COMP, approximately 100,000 COMP at time of proposal, to be streamed over the course of a year starting at the beginning of Q3 2025.
The 10% buffer is designed to accommodate potential price fluctuations while balancing capital efficiency. OpenZeppelin will only receive the prorated portion of the $4M annual value based on actual service duration.
Governance may initiate early termination through a subsequent on-chain governance proposal with at least 60 days advance notice. Unvested funds can be transferred to the DAO by anyone 10 days or more after the term ends or after the notice period expires.
This proposal grants COMP from the Comptroller to the payment streamer contract, created by the Streamer Factory (Audit Report), and initializes the stream.
More detail in this forum post.
By approving this proposal, you agree that any services provided by OpenZeppelin shall be governed by the Terms of Service that were updated as of Sep 19th, 2023.
https://tally.xyz/gov/compound/proposal/451