# \[SIP5.20\] Adopt the SEAL Whitehat Safe Harbor Agreement

**URL:** <https://forum.summer.fi/t/sip5-20-adopt-the-seal-whitehat-safe-harbor-agreement/735>\
**Category:** Summer Improvement Proposals \[SIPs\]\
**Tags:** sip5, seal-safe-harbor, security, seal\
**Created:** [February 16, 2026, 6:43pm UTC](https://forum.summer.fi/t/sip5-20-adopt-the-seal-whitehat-safe-harbor-agreement/735 "2026-02-16T18:43:47Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![jensei](https://yyz1.discourse-cdn.com/flex009/user_avatar/forum.summer.fi/jensei/32/69_2.png) [@jensei](https://forum.summer.fi/u/jensei)\
**Post date:** [February 16, 2026, 6:43pm UTC](https://forum.summer.fi/t/sip5-20-adopt-the-seal-whitehat-safe-harbor-agreement/735/1 "2026-02-16T18:43:47Z")

</div>

### 1. Overview:

This SIP proposes that the Lazy Summer DAO formally adopt the SEAL (Security Alliance) Whitehat Safe Harbor Agreement, enabling authorized whitehats to intervene during active exploits under predefined rules, incentives, and legal protections.

> _ **RFC:** [[RFC] Adopt the SEAL Whitehat Safe Harbor Agreement](https://forum.summer.fi/t/rfc-adopt-the-seal-whitehat-safe-harbor-agreement/586)_

* * *

### 2. Motivation:

Lazy Summer Protocol operates DAO-governed, risk-assessed vaults designed for simplicity and passive participation. While audits, monitoring, and risk reviews are essential preventative controls, they do not eliminate the possibility of active exploits.

During a live exploit, speed and clarity matter more than process purity.

Traditional responsible disclosure frameworks are too slow in situations where funds are actively being drained. The [SEAL Safe Harbor Agreement](https://frameworks.securityalliance.org/safe-harbor/overview) creates a pre-authorized, rule-bound framework that allows vetted whitehats to intervene immediately and recover funds without legal ambiguity.

Adopting Safe Harbor provides:

- A last-line-of-defense mechanism during active exploits.
- Clear predefined bounty expectations.
- Removal of post-exploit negotiation ambiguity.
- Alignment with industry-standard incident response practices.

* * *

### 3. Specification:

#### 3.1 Adoption of the SEAL Safe Harbor Agreement

Lazy Summer DAO will formally adopt the SEAL Whitehat Safe Harbor Agreement under the following finalized parameters.

#### Protocol Details

Protocol Name: `Lazy Summer Protocol`  
Summer Governor: `0xBE5A4DD68c3526F32B454fE28C9909cA0601e9Fa`  
Timelock Address: `0x447BF9d1485ABDc4C1778025DfdfbE8b894C3796`  
Protocol Access Manager: `0xf389BCEa078acD9516414F5dabE3dDd5f7e39694`

#### Bounty Terms

Based on [[RFC]](https://forum.summer.fi/t/rfc-adopt-the-seal-whitehat-safe-harbor-agreement/586) feedback and informal signaling:

- **Percentage:** 10% of recovered funds
- **Per-Incident Cap:** $100,000 USD
- **Aggregate Cap:** $100,000 USD
- **Retainable:** No (non-retainable; all funds must be returned first)
- **Identity Requirement:** Pseudonymous

Clarifications:

- Whitehats may intervene only during active exploits.
- All recovered funds must be returned to designated recovery addresses within 72 hours.
- Bounty is paid after verification by the protocol.
- Safe Harbor does not apply to routine bug bounty disclosures or security research.

#### Diligence Requirements

Whitehats acting under Safe Harbor must:

- Act in good faith to minimize harm.
- Only interact with contracts strictly necessary to halt or mitigate the exploit.
- Return all recovered funds within 72 hours.
- Identify themselves pseudonymously to designated security contacts for coordination.

#### Designated Security Contacts

The following contributors are nominated as Safe Harbor coordination contacts:

- LS Guardians: @jensei @blockful @Raphael_Anode @halaprix @MasterMojo @JavierD @chrisb @Sixty - via [Signal Group](https://signal.group/#CjQKIFoFcIiS83AKZWLlTRhfovPSFGGkoGpP5VLNCGWeNe4_EhDehOfY_zDHUB91ipCnX3tj)
- @BlockAnalitica (on risk coordination)
- Labs Co
- Lazy Summer Foundation

#### Chains & Asset Recovery Addresses

Recovery addresses are defined per supported chain and controlled by the DAO or Guardian structure.

DAO-governed Timelock/Treasury Address:

- Ethereum: `0x447BF9d1485ABDc4C1778025DfdfbE8b894C3796`
- Optimism: `0x25B97896A1d731875B3aec785977E421029Fc90A`
- Unichain: `0x25B97896A1d731875B3aec785977E421029Fc90A`
- Sonic: `0x4c32A28AD95deaBc06bF7C83AdEbCF6fe6721ED9`
- Arbitrum: `0x447BF9d1485ABDc4C1778025DfdfbE8b894C3796`
- Base: `0x447BF9d1485ABDc4C1778025DfdfbE8b894C3796`
- HyperEVM: `0x0C939b702524fDaBa4914E905Bcb850182308141`

In case of timelock compromise, use Guardian Multisig:

- Ethereum: `0x91E4482CF58aC14d8DC25290d828b2A4D9492BA4`
- Optimism: `0x91E4482CF58aC14d8DC25290d828b2A4D9492BA4`
- Unichain: `0x91E4482CF58aC14d8DC25290d828b2A4D9492BA4`
- Sonic: `0x91E4482CF58aC14d8DC25290d828b2A4D9492BA4`
- Arbitrum: `0x91E4482CF58aC14d8DC25290d828b2A4D9492BA4`
- Base: `0x91E4482CF58aC14d8DC25290d828b2A4D9492BA4`
- HyperEVM: `0x91E4482CF58aC14d8DC25290d828b2A4D9492BA4`

Initial coverage includes:

- Ethereum: [summer-earn-protocol/packages/deployment/ignition/deployments/chain-1/deployed\_addresses.json at main · OasisDEX/summer-earn-protocol · GitHub](https://github.com/OasisDEX/summer-earn-protocol/blob/main/packages/deployment/ignition/deployments/chain-1/deployed_addresses.json)
- Optimism: [summer-earn-protocol/packages/deployment/ignition/deployments/chain-10/deployed\_addresses.json at main · OasisDEX/summer-earn-protocol · GitHub](https://github.com/OasisDEX/summer-earn-protocol/blob/main/packages/deployment/ignition/deployments/chain-10/deployed_addresses.json)
- Unichain: [summer-earn-protocol/packages/deployment/ignition/deployments/chain-130/deployed\_addresses.json at main · OasisDEX/summer-earn-protocol · GitHub](https://github.com/OasisDEX/summer-earn-protocol/blob/main/packages/deployment/ignition/deployments/chain-130/deployed_addresses.json)
- Sonic: [summer-earn-protocol/packages/deployment/ignition/deployments/chain-146/deployed\_addresses.json at main · OasisDEX/summer-earn-protocol · GitHub](https://github.com/OasisDEX/summer-earn-protocol/blob/main/packages/deployment/ignition/deployments/chain-146/deployed_addresses.json)
- Arbitrum: [summer-earn-protocol/packages/deployment/ignition/deployments/chain-42161/deployed\_addresses.json at main · OasisDEX/summer-earn-protocol · GitHub](https://github.com/OasisDEX/summer-earn-protocol/blob/main/packages/deployment/ignition/deployments/chain-42161/deployed_addresses.json)
- Base: [summer-earn-protocol/packages/deployment/ignition/deployments/chain-8453/deployed\_addresses.json at main · OasisDEX/summer-earn-protocol · GitHub](https://github.com/OasisDEX/summer-earn-protocol/blob/main/packages/deployment/ignition/deployments/chain-8453/deployed_addresses.json)
- HyperEVM: [summer-earn-protocol/packages/deployment/ignition/deployments/chain-999/deployed\_addresses.json at main · OasisDEX/summer-earn-protocol · GitHub](https://github.com/OasisDEX/summer-earn-protocol/blob/main/packages/deployment/ignition/deployments/chain-999/deployed_addresses.json)

#### Scope Definition

ChildContractScope:  
`All`

All contracts and child contracts deployed prior and after to adoption are in scope.

#### 3.2 Implementation Plan

1. **Register Agreement Onchain**  
The finalized parameters will be registered in the SEAL Safe Harbor Registry:  
`0x1eaCD100B0546E433fbf4d773109cAD482c34686`
2. **Instruct Labs Co to [Update Terms of Service & Docs](https://frameworks.securityalliance.org/safe-harbor/self-adoption-guide/#4-update-terms-of-service--docs)**  
To ensure all users are informed and legally covered.
3. **An official announcement shall be shared across all communication channels, explaining the adoption and its significance to the community.**

* * *

### 4. Risk Assessment:

Operational risk can involve miscommunication during an exploit leading to confusion.

Mitigation:

- Predefined recovery addresses
- Designated security contacts
- Registry-based transparency

* * *

### 5. Voting:

> If **YES:** Lazy Summer DAO formally adopts the SEAL Whitehat Safe Harbor Agreement.

> If **NO:** The DAO declines to adopt the Safe Harbor framework at this time.

* * *

Tagging all [@Recognized\_Delegates](https://forum.summer.fi/groups/recognized_delegates) for review, before it is posted for an onchain vote ~18/02/2026.

---

<div class="post-metadata">

**Author:** ![Sixty](https://yyz1.discourse-cdn.com/flex009/user_avatar/forum.summer.fi/sixty/32/115_2.png) [@Sixty](https://forum.summer.fi/u/Sixty)\
**Post date:** [February 17, 2026, 10:02am UTC](https://forum.summer.fi/t/sip5-20-adopt-the-seal-whitehat-safe-harbor-agreement/735/2 "2026-02-17T10:02:25Z")

</div>

All the parameters look good, and the recovery addresses are accurate 🤝

---

<div class="post-metadata">

**Author:** ![MasterMojo](https://yyz1.discourse-cdn.com/flex009/user_avatar/forum.summer.fi/mastermojo/32/8_2.png) [@MasterMojo](https://forum.summer.fi/u/MasterMojo)\
**Post date:** [February 19, 2026, 2:19pm UTC](https://forum.summer.fi/t/sip5-20-adopt-the-seal-whitehat-safe-harbor-agreement/735/3 "2026-02-19T14:19:37Z")

</div>

This looks good. SIP time.

---

<div class="post-metadata">

**Author:** ![dickson](https://avatars.discourse-cdn.com/v4/letter/d/57b2e6/32.png) [@dickson](https://forum.summer.fi/u/dickson)\
**Post date:** [March 13, 2026, 5:42pm UTC](https://forum.summer.fi/t/sip5-20-adopt-the-seal-whitehat-safe-harbor-agreement/735/4 "2026-03-13T17:42:50Z")

</div>

gm! The agreement details are now deployed on-chain! We added some addtional addresses, but all terms should be the same:

> **[Address: 0xc1698c5d...ca8a8638e | BaseScan](https://basescan.org/address/0xc1698c5d9d169146712b0397f9f8315ca8a8638e)**
>
> Contract: Unverified | Balance: $0 across 0 Chains | Transactions: 5 | As at Mar-13-2026 05:42:42 PM (UTC)

| == Logs == |
| --- |
| |
| =================================================================== |
| SAFE HARBOR AGREEMENT DETAILS |
| =================================================================== |
| |
| PROTOCOL INFORMATION |
| ----------------------------------------------------------------- |
| Protocol Name: Lazy Summer Protocol |
| Agreement URI: [https://bafkreiernns2f4nv2uzvwtzjc2jboyivsu2mixz33y3xo7cvtllsuao6jy.ipfs.w3s.link/](https://bafkreiernns2f4nv2uzvwtzjc2jboyivsu2mixz33y3xo7cvtllsuao6jy.ipfs.w3s.link/) |
| |
| CONTACT DETAILS |
| ----------------------------------------------------------------- |
| Total Contacts: 3 |
| [0] |
| Name: LS Guardians |
| Contact: Signal: [Signal Group](https://signal.group/#CjQKIFoFcIiS83AKZWLlTRhfovPSFGGkoGpP5VLNCGWeNe4_EhDehOfY_zDHUB91ipCnX3tj) |
| [1] |
| Name: BlockAnalitica |
| Contact: Forum: [https://forum.summer.fi/chat/c/blockanalitica/31](https://forum.summer.fi/chat/c/blockanalitica/31) |
| [2] |
| Name: Labs Co |
| Contact: Email: [support@summer.fi](mailto:support@summer.fi) |
| |
| CHAIN SCOPE |
| ----------------------------------------------------------------- |
| Total Chains: 7 |
| [0] eip155:1 |
| Asset Recovery Address: 0x447BF9d1485ABDc4C1778025DfdfbE8b894C3796 |
| Accounts in Scope: 5 |
| [0] 0xb0f758323D3798a6A567C1601d84f30d1BCAAA0b (All) |
| [1] 0x0f0fA89471259433b6955827226f19999D93c568 (All) |
| [2] 0x9999Cb59242e8cE485F52eBF82654F3664D63E4f (All) |
| [3] 0x8888013451507E8DD7996509735E15F591886CD2 (All) |
| [4] 0xD03bD9Ef8c72Aee3DBb5b8DF83c479D847622Dba (All) |
| [1] eip155:10 |
| Asset Recovery Address: 0x25B97896A1d731875B3aec785977E421029Fc90A |
| Accounts in Scope: 4 |
| [0] 0xb0f758323D3798a6A567C1601d84f30d1BCAAA0b (All) |
| [1] 0x0f0fA89471259433b6955827226f19999D93c568 (All) |
| [2] 0x9999Cb59242e8cE485F52eBF82654F3664D63E4f (All) |
| [3] 0x8888013451507E8DD7996509735E15F591886CD2 (All) |
| [2] eip155:130 |
| Asset Recovery Address: 0x25B97896A1d731875B3aec785977E421029Fc90A |
| Accounts in Scope: 4 |
| [0] 0xb0f758323D3798a6A567C1601d84f30d1BCAAA0b (All) |
| [1] 0x0f0fA89471259433b6955827226f19999D93c568 (All) |
| [2] 0x9999Cb59242e8cE485F52eBF82654F3664D63E4f (All) |
| [3] 0x8888013451507E8DD7996509735E15F591886CD2 (All) |
| [3] eip155:146 |
| Asset Recovery Address: 0x4c32A28AD95deaBc06bF7C83AdEbCF6fe6721ED9 |
| Accounts in Scope: 7 |
| [0] 0xb0f758323D3798a6A567C1601d84f30d1BCAAA0b (All) |
| [1] 0x0f0fA89471259433b6955827226f19999D93c568 (All) |
| [2] 0x9999Cb59242e8cE485F52eBF82654F3664D63E4f (All) |
| [3] 0x8888013451507E8DD7996509735E15F591886CD2 (All) |
| [4] 0x5c841955d7EE3E2F7a077Aa0aCa3A7d724b15Da2 (All) |
| [5] 0x42AAdE02448FdAf56Bbb153B2984E3d53DC531c1 (All) |
| [6] 0xa514a99b3584D152b2BE9cBe3e7B34Ad40954410 (All) |
| [4] eip155:42161 |
| Asset Recovery Address: 0x447BF9d1485ABDc4C1778025DfdfbE8b894C3796 |
| Accounts in Scope: 5 |
| [0] 0xb0f758323D3798a6A567C1601d84f30d1BCAAA0b (All) |
| [1] 0x0f0fA89471259433b6955827226f19999D93c568 (All) |
| [2] 0x9999Cb59242e8cE485F52eBF82654F3664D63E4f (All) |
| [3] 0x8888013451507E8DD7996509735E15F591886CD2 (All) |
| [4] 0x1db04f01386c6BE2d22b7947236d8ACc05901219 (All) |
| [5] eip155:8453 |
| Asset Recovery Address: 0x447BF9d1485ABDc4C1778025DfdfbE8b894C3796 |
| Accounts in Scope: 8 |
| [0] 0xb0f758323D3798a6A567C1601d84f30d1BCAAA0b (All) |
| [1] 0x0f0fA89471259433b6955827226f19999D93c568 (All) |
| [2] 0x9999Cb59242e8cE485F52eBF82654F3664D63E4f (All) |
| [3] 0x8888013451507E8DD7996509735E15F591886CD2 (All) |
| [4] 0x4e92071F9BC94011419Dc03fEaCA32D11241313a (All) |
| [5] 0x903fB67e7c50A26F34c43efB86b49Bed5e14e7D5 (All) |
| [6] 0xaCB489beD8c98831D6b1d7A63ED46CdCf06C524D (All) |
| [7] 0x7332FeC21f1179aeA6d4Df34206aFA3B9074987c (All) |
| [6] eip155:999 |
| Asset Recovery Address: 0x0C939b702524fDaBa4914E905Bcb850182308141 |
| Accounts in Scope: 4 |
| [0] 0xb0f758323D3798a6A567C1601d84f30d1BCAAA0b (All) |
| [1] 0x0f0fA89471259433b6955827226f19999D93c568 (All) |
| [2] 0x9999Cb59242e8cE485F52eBF82654F3664D63E4f (All) |
| [3] 0x8888013451507E8DD7996509735E15F591886CD2 (All) |
| |
| BOUNTY TERMS |
| ----------------------------------------------------------------- |
| Bounty Percentage: 10 % |
| Bounty Cap (USD): $ 100000 |
| Aggregate Bounty Cap: $ 100000 |
| Retainable: No |
| Identity Requirements: Pseudonymous |
| Diligence Requirements: N/A |
| |
| =================================================================== |
