# Whitelist of addresses for SAIL DAO deployments

**URL:** <https://forum.osmosis.zone/t/whitelist-of-addresses-for-sail-dao-deployments/2188>\
**Category:** SAIL\
**Tags:** passed\
**Created:** [January 12, 2024, 7:02pm UTC](https://forum.osmosis.zone/t/whitelist-of-addresses-for-sail-dao-deployments/2188 "2024-01-12T19:02:51Z")\
**Posts on this page:** 16\
**Page:** 1

<div class="post-metadata">

**Author:** ![kerber0x](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.osmosis.zone/kerber0x/32/1662_2.png) [@kerber0x](https://forum.osmosis.zone/u/kerber0x)\
**Post date:** [January 12, 2024, 7:02pm UTC](https://forum.osmosis.zone/t/whitelist-of-addresses-for-sail-dao-deployments/2188/1 "2024-01-12T19:02:51Z")

</div>

Based on passing of [prop 708: Sail DAO](https://daodao.zone/gov/osmosis/proposals/708), this proposal grants permission to the following addresses for the ability to upload CosmWasm contracts to Osmosis without seeking further governance approval for each upload.

osmo1pscy6u25wq7r8dmpepny5r0xk095xfzduvzf29epradu8dr68fvs8mv2vn : this dao is administered by members of the SAIL program, including members from White Whale, Eris Protocol, BackBone Labs and Racoon. Will be used to deploy White Whale contracts.

osmo1s7vag2t8pg40qj73lhnfg08ylvc33w0r27pyvy : this address is administered by the Racoon team. Will be used to deploy the Racoon protocol.

osmo1ezgx7dhm2zag0lplje68j47cx9e8nft44k9f07r7qp7m7uc5u8ysn482ps : this dao is administered by BackBone Labs. Will be used to deploy the BackBone Labs related contract.

---

<div class="post-metadata">

**Author:** ![LeonoorsCryptoman](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.osmosis.zone/leonoorscryptoman/32/208_2.png) [@LeonoorsCryptoman](https://forum.osmosis.zone/u/LeonoorsCryptoman)\
**Post date:** [January 15, 2024, 2:31pm UTC](https://forum.osmosis.zone/t/whitelist-of-addresses-for-sail-dao-deployments/2188/2 "2024-01-15T14:31:14Z")

</div>

Yes, following the approval of 702 & 708 this is also the best route to take to whitelist these addresses and reap the full benefits of the swap 🙂

---

<div class="post-metadata">

**Author:** ![FlyingCircus](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.osmosis.zone/flyingcircus/32/1659_2.png) [@FlyingCircus](https://forum.osmosis.zone/u/FlyingCircus)\
**Post date:** [January 17, 2024, 5:16am UTC](https://forum.osmosis.zone/t/whitelist-of-addresses-for-sail-dao-deployments/2188/3 "2024-01-17T05:16:05Z")

</div>

I think that contracts uploaded should need approval as an extra security measure. I mean we live in an age that cyber attacks flourish.  
Wouldn’t it be a good security measure to approve contracts in case of a breach?

---

<div class="post-metadata">

**Author:** ![kerber0x](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.osmosis.zone/kerber0x/32/1662_2.png) [@kerber0x](https://forum.osmosis.zone/u/kerber0x)\
**Post date:** [January 17, 2024, 1:06pm UTC](https://forum.osmosis.zone/t/whitelist-of-addresses-for-sail-dao-deployments/2188/4 "2024-01-17T13:06:38Z")

</div>

Hi @FlyingCircus , I understand your concern. White Whale contracts are open source, anyone can find and validate them [here](https://github.com/White-Whale-Defi-Platform/white-whale-core), have been audited multiple times, they are live in 8 chains and securing over $10M in TVL.

BackBone Labs contracts have also been audited as far as I know, can’t speak for Racoon protocol though.

Also, consider that whitelisting allows the teams to deploy time-sensitive patches rapidly in case of an exploit.

---

<div class="post-metadata">

**Author:** ![LeonoorsCryptoman](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.osmosis.zone/leonoorscryptoman/32/208_2.png) [@LeonoorsCryptoman](https://forum.osmosis.zone/u/LeonoorsCryptoman)\
**Post date:** [January 17, 2024, 1:37pm UTC](https://forum.osmosis.zone/t/whitelist-of-addresses-for-sail-dao-deployments/2188/5 "2024-01-17T13:37:59Z")

</div>

In addition to what @kerber0x posts; the whitelisting of addresses gives the approved teams the luxury of deploying permissionlessly, while the community still have a gatekeepers function who is allowed to have that perk.

This is the closest thing Osmosis has come to being permissionless for smartcontracts, while still preserving some level of safety in terms of not allowing everyone to upload everything.

---

<div class="post-metadata">

**Author:** ![FlyingCircus](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.osmosis.zone/flyingcircus/32/1659_2.png) [@FlyingCircus](https://forum.osmosis.zone/u/FlyingCircus)\
**Post date:** [January 17, 2024, 2:31pm UTC](https://forum.osmosis.zone/t/whitelist-of-addresses-for-sail-dao-deployments/2188/6 "2024-01-17T14:31:18Z")

</div>

Hey @kerber0x and @LeonoorsCryptoman , i get it and i am all in, I mean i did vote yes, but still trying to voice a concern that isn’t an unlikely scenario. We do have to keep in mind before allowing others free pass on contracts not especially these daos.  
The concern was never for the daos, was actually for malicious attacks on the Dao by a third party, as the daos are vetted before being allowed to do upload any contract.

---

<div class="post-metadata">

**Author:** ![LeonoorsCryptoman](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.osmosis.zone/leonoorscryptoman/32/208_2.png) [@LeonoorsCryptoman](https://forum.osmosis.zone/u/LeonoorsCryptoman)\
**Post date:** [January 17, 2024, 6:50pm UTC](https://forum.osmosis.zone/t/whitelist-of-addresses-for-sail-dao-deployments/2188/7 "2024-01-17T18:50:29Z")

</div>

You mean more the risk where a malicious actor gets control of the DAO / multi-sig / address which is whitelisted?

---

<div class="post-metadata">

**Author:** ![FlyingCircus](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.osmosis.zone/flyingcircus/32/1659_2.png) [@FlyingCircus](https://forum.osmosis.zone/u/FlyingCircus)\
**Post date:** [January 17, 2024, 8:02pm UTC](https://forum.osmosis.zone/t/whitelist-of-addresses-for-sail-dao-deployments/2188/8 "2024-01-17T20:02:47Z")

</div>

Exactly my good man, not easy at all but not impossible either.

---

<div class="post-metadata">

**Author:** ![kerber0x](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.osmosis.zone/kerber0x/32/1662_2.png) [@kerber0x](https://forum.osmosis.zone/u/kerber0x)\
**Post date:** [January 18, 2024, 10:29am UTC](https://forum.osmosis.zone/t/whitelist-of-addresses-for-sail-dao-deployments/2188/9 "2024-01-18T10:29:19Z")

</div>

Hence the multisigs. It’s harder for a malicious actor to get access to multiple keys than a single one.

---

<div class="post-metadata">

**Author:** ![FlyingCircus](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.osmosis.zone/flyingcircus/32/1659_2.png) [@FlyingCircus](https://forum.osmosis.zone/u/FlyingCircus)\
**Post date:** [January 18, 2024, 2:06pm UTC](https://forum.osmosis.zone/t/whitelist-of-addresses-for-sail-dao-deployments/2188/10 "2024-01-18T14:06:27Z")

</div>

That is quite true, not unheard of though, thus my question in the theoretical scenario that it happens.

---

<div class="post-metadata">

**Author:** ![wendelmelo](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.osmosis.zone/wendelmelo/32/1711_2.png) [@wendelmelo](https://forum.osmosis.zone/u/wendelmelo)\
**Post date:** [January 18, 2024, 3:12pm UTC](https://forum.osmosis.zone/t/whitelist-of-addresses-for-sail-dao-deployments/2188/11 "2024-01-18T15:12:10Z")

</div>

Olá caros amigos, proposta válida. Com grande escalabilidade. Votei sim!

---

<div class="post-metadata">

**Author:** ![Wassie](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.osmosis.zone/wassie/32/994_2.png) [@Wassie](https://forum.osmosis.zone/u/Wassie)\
**Post date:** [January 18, 2024, 5:34pm UTC](https://forum.osmosis.zone/t/whitelist-of-addresses-for-sail-dao-deployments/2188/12 "2024-01-18T17:34:44Z")

</div>

We voted yes, but do we really need that many addresses to deploy?

---

<div class="post-metadata">

**Author:** ![LeonoorsCryptoman](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.osmosis.zone/leonoorscryptoman/32/208_2.png) [@LeonoorsCryptoman](https://forum.osmosis.zone/u/LeonoorsCryptoman)\
**Post date:** [January 18, 2024, 7:26pm UTC](https://forum.osmosis.zone/t/whitelist-of-addresses-for-sail-dao-deployments/2188/13 "2024-01-18T19:26:38Z")

</div>

I am a bit wondering how big the chance is… because that is quite important to take into account as well.

---

<div class="post-metadata">

**Author:** ![FlyingCircus](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.osmosis.zone/flyingcircus/32/1659_2.png) [@FlyingCircus](https://forum.osmosis.zone/u/FlyingCircus)\
**Post date:** [January 18, 2024, 7:47pm UTC](https://forum.osmosis.zone/t/whitelist-of-addresses-for-sail-dao-deployments/2188/14 "2024-01-18T19:47:06Z")

</div>

The chances aren’t that big for something like this to happen IF people are careful. But i really needed to address the matter to make everyone think.  
As i said above it’s not likely but it isn’t unheard of. Multi sig wallets help with security as more than one people need to sign but still coordinated attacks may occur so people do need to keep on their toes. Especially if one’s wallet is whitelisted and can upload anything.

---

<div class="post-metadata">

**Author:** ![JohnnyWyles](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.osmosis.zone/johnnywyles/32/3114_2.png) [@JohnnyWyles](https://forum.osmosis.zone/u/JohnnyWyles)\
**Post date:** [January 19, 2024, 10:22am UTC](https://forum.osmosis.zone/t/whitelist-of-addresses-for-sail-dao-deployments/2188/15 "2024-01-19T10:22:42Z")

</div>

1 address per team,  
If you mean the action proposal data, every team with access currently needs to be resubmitted along with the additions.

---

<div class="post-metadata">

**Author:** ![kerber0x](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.osmosis.zone/kerber0x/32/1662_2.png) [@kerber0x](https://forum.osmosis.zone/u/kerber0x)\
**Post date:** [January 19, 2024, 1:19pm UTC](https://forum.osmosis.zone/t/whitelist-of-addresses-for-sail-dao-deployments/2188/16 "2024-01-19T13:19:27Z")

</div>

The SAIL prop entails bringing multiple projects on board. One address is for White Whale, the one for BackBone Labs and the third for Racoon. Check it out [Sail With the Whale V2: SAIL DAO (Updated)](https://forum.osmosis.zone/t/sail-with-the-whale-v2-sail-dao-updated/1041)
