[RFC] Recompensation Plan for SSIP and SSRP LPs

Recompensation Plan for SSIP and SSRP LPs

Scope: To propose a recompensation plan to restore all pre-security incident LP positions.

Summary: In response to the security incident on November 14th concerning the UNO Risk investment dApp, we propose a reestablishment of the pre-event status of all LP positions. This restoration will maintain balanced token economics via a time-bound burn event.

What Happened?

Uno Re’s SSIP and SSRP capacity pools were exploited on 14th November; the malicious actor altered the claimsAssessor role to an attacker-controlled EOA, which was consequently used to call the policyClaim function on the vaults to drain them.

Consequently, a total of 32.4M $UNO, 127.9K $USDC, 59.3K $USDT, and 18.4 $ETH were misplaced.

Since the security incident, our focus and urgency have been placed on continuously tracing the misappropriated funds, reaching out to the CEXs, wallet providers, and Mixers involved in the laundering of these funds to freeze the exploiter accounts.

For a more detailed look into the (ongoing) effort, please refer to this constantly updated tweet thread and our Post-Mortem report.

The Administration of the proposed restoration:

The three standout options for the restoration of these positions can be:

  1. Via Airdrop of UNO, USDC, USDT, ETH tokens on both ETH and BSC networks directly for all users 1:1 for the complete exploited amount
  2. Via restoration of positions in the re-deployed v2 contracts (read more about the changes here) along with pending rewards accumulated on their positions from the time of the exploits till the date of redeployment.
  3. Via a Claim dashboard Merkle for claiming $UNO tokens directly - Unclaimed Tokens get migrated to Option 2 automatically

This proposal leaves room for the rest of the UNO DAO members to suggest other possible means of administration for up to 1 week. Please note all current pending rewards on non-harvested positions will also be returned 1:1 on all the above options.

Compensation Plan for SSIP and SSRP stakers [Option 2]:

We proposed to allocate a portion of the current protocol treasury - of USD value of 230k - to acquire 155k USDT, 32.3k USDC, and 18.4 ETH, which will then be further used to create respective SSIP positions on both ETH and BSC sides and distribute the SSIP LP tokens 1:1 with their previous holdings. These funds will then be used to restore capacity and the LP positions of every staker as they stood pre-event.

The 32.4M token holdings for SSIP and SSRP $UNO capacity vault holders will be distributed as SSIP and SSRP LP tokens, respectively, 1:1 with their previous holdings per the exploit block timestamp. This will be compensated from the currently unreleased tokenomics tranches. The 32.4M UNO tokens will be taken from our current total max releasable supply as per tokenomics, which is around 207M as per tokenomics schedule.

It will be split as shown below:

  1. 16M UNO tokens from the team supply tranche
  2. 8M UNO tokens from the Reinsurance cell / Liquidity tranche
  3. 6.77M Tokens from Acquisitions tranche
  4. 1.63M Tokens from Treasury tranche

It is worth noting that the Reinsurance Cell / Liquidity tranche was designed into $UNO Tokenomics to act as the final backstop for any black swan events (such as this one). For the utilizations from Acquisitions and Treasury tranches, if the majority of DAO members wish to utilize the same from other tokenomics tranches, then kindly raise the same in discourse.

Still - in accordance with our practice of being conservative and overly cautious with regards to tokenomics - to bring parity back to our low emission and maintain a deflationary token model, we additionally propose to burn 64.8M $UNO (twice the exploited amount in UNO, to account for damage caused) from the total supply, from all tranches. The proposed token utilization from various tokenomics tranches is as follows:

  1. Team - 4.8M UNO tokens
  2. Community Incentive & Rewards - 6.8M UNO tokens
  3. Advisory, Legal & PR - 4.08M UNO tokens
  4. Operational Expenses - 6.4M tokens
  5. Marketing Expenses - 11.2M tokens
  6. Acquisitions - 1.63M tokens
  7. Reinsurance Cell / Liquidity - 26.53M tokens
  8. Treasury - 3.36M tokens.

As such, our updated Total supply will become ~320M tokens.

The Logistics of the proposed restoration:

If this proposal passes, the following actions will be executed:

  1. A total of 64.8M $UNO tokens will be burnt within 48 hours of proposal passage
  2. The development of patched v2 contracts will be initiated and will be sent out for audit - the timeline for this is expected to be around 3-4 weeks, however please note that this is an educated estimate.
  3. At this point, the new deployment and restoration of all SSIP and SSRP positions will take place; the protocol will resume normal operations, and each user will be able to freely withdraw / keep participating in the protocol as they see fit.
  4. The UNO Guardian is multisig members and will be elected.

Recompensation Positions Snapshot

If you’ve been affected by the security incident, please check the below sheet; locate your address and check if the numbers are valid and correct (especially if you managed to withdraw something).

ssrp-ssip-holders

(If you had previously submitted a request via our discord tickets, your positions will be considered on a case-by-case basis for transactions done post exploit block number. This will be added to a separate data sheet.)

For the Active Insurance Policy Holders:

For current insurance policyholders who have active policies with us, kindly verify your policies in the spreadsheet attached; if you find your wallet below, please create a ticket on our discord server, and we will either pause for 4-6 weeks (to account for v2 redeployment) or else arrange an alternate coverage policy for you with one of our partners.

ssrp-ssip-holders and active policies.

What Happens if We Recover the Funds?

A portion of the recovered funds will be used to replenish the treasury assets, and a significant majority of the recovered funds (after accounting for the success fee for our contracted recovery experts) will be allocated towards a pool that will be used to buyback and burn $UNO tokens from the CS. This plan will also be put to vote via a partial DAO process; veUNO holders will be responsible for deciding whether to use these funds as such or propose their ideas for the same (f.e.incentivisation of vault liquidity, etc.).

Please note that this proposal is just in the RFC stage; after incorporating feedback and suggestions from the community, the finalised proposal will be put up for voting in 1 week.

8 Likes

Amazing work by the Team, Solid statement :1st_place_medal::gem::closed_lock_with_key:

2 Likes

Great to see the plans. I would be ok with option 2, where we basically continue where we left off. If you airdrop directly into people’s wallets, as in option 1, that can cause some to decide not to continue to stake anymore, which is not ideal perhaps. It would be very good, and bullish for the project overall, if you can state on socials at some point, that all accounts have been reset to where we were before.

2 Likes

Thanks for the great proposal, another testament of the quality and professionalism of this project team.

My preference would be the dashboard-with-default-option, assuming this allows us to specify a target wallet address- because this gives us some flexibility in reorganizing our tokens. This also has some interesting implications because you decouple past history from the new wallet and it will be a fresh airdrop, after a hack.

3 Likes

Fantastic work on the proposal team. Option 2 looks the most sensible and from feedback, it seems like community are happy with it. I got my veUNO ready to vote, I’m sure the community wouldn’t mind if voting starts earlier! Possibly tomorrow if the team is ready :heart:

3 Likes

I personally would also vote for option 2 given it would be the best compensation plan there could be. Of course it may not satisfy every single person, it is the best solution for the entire community. Nothing is perfect. So let’s put it to vote.

1 Like

One more thing I want to mention guys. I already mentioned this in a ticket on Discord but was told to also mention it here. My wallet that I used for staking was compromised (a drainer contract, silly me, lesson learnt etc.), but the recompensation plans are probably all going to be using the wallet that was active at the time UnoRe had it’s security issue. So my question and/or suggestion was to, in some cases, have a more personal approach and see if I (and it can happen to anyone) could get my recompensation in a new wallet. My plan would be to restake the USDC amount I used in the past again, but of course using this new wallet. Any UNO rewards that have accumulated in the meantime should then be sent to my new wallet. Let me know if this is a possibility. The alternative is that I keep my old, and compromised, wallet and hope nothing bad will happen (yes, I’m moving all my holdings out of that wallet to a new one). Thanks, and good luck with voting, and implementing your plans!

We can try to do this, Please tag me on discord.

We might need you to prove ownership of the old wallet, proof it was hacked/police reports about the incident.

1 Like

The proposal has passed as per our snapshot vote Snapshot dated Nov 30, 2023, 7:47 PM.

As per the same, we have initiated the development of the v2 contract updates and completed the token burn event to negate the inflation from the additional tokens being induced into the market for the recommendation plan. The details regarding the full 64.8M token burn event have been documented below:

Account Burn Amount From wallet 1 Amount Txn From wallet 2 Amount Txn
1. Team - 4.8M UNO tokens 4,800,000.00 0xa5d9F1959cCffA786E75e2CcEc106c70e227ADd4 4,800,000 https://etherscan.io/tx/0x3d6fa1e507553f8b19f0de6de130f84b50eae0fa913de5abc99a64d49466ea00 na na na
2. Community Incentive & Rewards - 6.8M UNO tokens 6,800,000.00 0xdC49af0eFA174B79B90080B072dCeCe09A106f39 310,000 https://etherscan.io/tx/0xe4355c6f65e233b2510cd70bab2a3333fc18e885dee3a248167a4667c3143359 0x4d2161f63A228422f8A0c7A1406eb9BE3fa33f50 6,490,000 https://etherscan.io/tx/0x904a563fdbc552e354f8d26e7bf0380ad457ca47f030feb97db087b0c7d48c3d
3. Advisory, Legal & PR - 4.08M UNO tokens 4,080,000.00 0x97dfa7013B3f58100798cc08BD3962b3Ac928Fd8 3,525,000 https://etherscan.io/tx/0x639acb8c6a6f2774bc64cd0cb9b516b323bd5ab63c2c87a920c6d190fdda63d4 0x461860C873Ce73D2828E0b004758608223d2A6BB 555,000 https://etherscan.io/tx/0x8247b23bf3683f7ddbce7c560853f416d2bae8e19782aaa0a686c19f73b82370
4. Operational Expenses - 11.2M tokens 11,200,000.00 0x0f46A1CC4881F4AA3fA5587091bfbB42a546b59c 6,550,000 https://etherscan.io/tx/0x2ea3c4ebd2da84e76b086f65835198dede9c8e5f895080cc673993c43d402ff1 0xfa3780a2423E91aF32c16f7Fc56691D5E49Fa6FC 4,650,000 https://etherscan.io/tx/0x508d482be597fdbf22f02c7d2a17fbd11d3cfffc6d18d97b5a8e6c9141b54c35
5. Marketing Expenses - 6.4M tokens 6,400,000.00 0xcfAe960A8bCB970d6eFA7e1327A39E56577dAd39 6,400,000 https://etherscan.io/tx/0x63286bd54c3c338f2bca9301ae7ba9b5806641c2cd7db87b631174a788342040 na na na
6. Acquisitions - 1.63M tokens 1,630,000.00 0xe93D2BDa90374E27375dc088ee20AED7EEAaB863 1,630,000 https://etherscan.io/tx/0x617e8a8f85b8da8c9f2b5c72643d79bfcce88794b70b4578cfdfdd57a713733c na na na
7. Reinsurance Cell / Liquidity - 26.53M tokens 26,530,000.00 0x2c73868440EAd93574270688eCD1DBa7e1B222b5 26,530,000 https://etherscan.io/tx/0x12588ea9c9867757cd5c4c975758320ce1109f76e26a2d3a5b6f0fc644b37ebb na na na
8. Treasury - 3.36M tokens. 3,360,000.00 0xA7f8B0DA0073ff91a30B6682aBB13416aAD7d30c 3,300,000 https://etherscan.io/tx/0x2f61f965f80c11961249f621ed81571c19344b07c69a44773836a048be4b7a41 0x7f4C824dF0767a5e4eb420Ef816F45F8324E2024 60,000 https://etherscan.io/tx/0x1e1b6329e33c43784651953b6843f658cea27874f6fea51a1fd89562e05608ce

Additional Comments:

  1. Comments / Feedback from the community has been severely inadequate during this proposal discourse. Olympus Council members have not shown any significant contributions to the DAO in the last couple of months and their lack of involvement in such a critical proposal only undermines our community strength. Anyways our Governance activity did hit a new ATH if you counting votes, but this is not productive DAO governance FYI. To progress fruitfully as a DAO towards a fully decentralized Insurance and Reinsurance provider we need to do better.
  2. There were some miscalculations in the amount of token to be burned from Operational Expenses and Marketing Expenses tranches in the original proposal - the fixed calculation amounts were applied in the corresponding tokenomics wallets during the actual burn event and have been recorded correctly above.
2 Likes