San Francisco, CA – [Date] – The Ethereum Foundation, in collaboration with leading security organizations Secureum, The Red Guild, and Security Alliance (SEAL), today announced the successful conclusion of its inaugural ETH Rangers Program. Launched in late 2024, the six-month initiative provided vital stipends to 17 individuals dedicated to public goods security work within the Ethereum ecosystem, yielding a diverse and impactful array of contributions aimed at enhancing the network’s overall resilience and integrity.
The program’s core objective was elegantly straightforward: to identify, fund, and recognize independent security researchers and developers with proven track records of making meaningful contributions to the collective security of Ethereum. In an increasingly complex and valuable decentralized landscape, where billions of dollars are locked in smart contracts and protocol-level vulnerabilities can have cascading effects, the need for proactive, community-driven security has become paramount. The ETH Rangers Program was designed as a direct response to this need, fostering a decentralized defense mechanism that mirrors the decentralized nature of the network itself.
The Imperative for Public Goods Security in Web3
The Ethereum ecosystem, currently boasting a market capitalization in the hundreds of billions and supporting a vast array of decentralized applications (dApps), DeFi protocols, and NFTs, represents a critical piece of global digital infrastructure. Its security is not merely a technical challenge but a public good, similar to national defense or clean air. However, unlike traditional public goods, securing a decentralized network often lacks a clear, centralized funding mechanism, leading to a "public goods dilemma" where individual actors may underinvest in security even though it benefits everyone.
This dilemma underscores the significance of initiatives like the ETH Rangers Program. The Ethereum Foundation, a non-profit organization supporting the development of Ethereum, recognized this gap and partnered with entities deeply embedded in the blockchain security community. Secureum, known for its security training and auditing expertise; The Red Guild, a collective of top-tier security researchers; and Security Alliance (SEAL), a non-profit focused on collective defense and incident response, brought invaluable domain expertise and operational capacity to the program’s design and execution. Their involvement ensured that the program would not only attract high-caliber talent but also effectively channel their efforts towards the most pressing security needs.
The program’s launch in late 2024, specifically noted in a December 2 blog post by the Ethereum Foundation, marked a pivotal moment in formalizing support for these independent "rangers." The selection process for the stipends emphasized demonstrable past contributions and a clear proposal for future work that would benefit the wider ecosystem, from identifying critical vulnerabilities to developing new security tools, educating developers, or contributing to threat intelligence and incident response protocols.
A Spectrum of Achievements: Reinforcing Ethereum’s Foundations
As the six-month program concludes, the breadth and depth of the 17 stipend recipients’ work are truly impressive. Their efforts span critical areas of blockchain security, demonstrating the multifaceted approach required to safeguard a global, permissionless network. The consolidated outcomes highlight the program’s success in cultivating a robust, decentralized security posture for Ethereum.
"The ETH Rangers Program has unequivocally proven the power of decentralized defense," stated a spokesperson from the Ethereum Foundation, reflecting on the program’s conclusion. "By empowering independent researchers and contributors, we’ve integrated new tools, critical research, and actionable intelligence into the very fabric of the Ethereum ecosystem. This model not only strengthens our collective security but also fosters innovation in the public goods space."
The work undertaken by the ETH Rangers directly addresses vulnerabilities that could lead to significant financial losses, reputational damage, or even existential threats to the network. From identifying subtle protocol-level bugs to building educational resources that prevent common smart contract errors, each contribution strengthens a link in Ethereum’s security chain.
Spotlight on Transformative Projects
Several projects stood out for their immediate impact and strategic importance:
SunSec & DeFiHackLabs: Cultivating a New Generation of Defenders
The collaboration between SunSec and the DeFiHackLabs community exemplified the program’s multiplier effect. SunSec, a prominent security researcher, leveraged the stipend to significantly expand DeFiHackLabs’ educational and tooling initiatives. Over the six-month period, DeFiHackLabs achieved an extraordinary volume of output:
- Extensive Educational Content: They published numerous comprehensive write-ups on critical vulnerabilities, dissecting real-world exploits and providing detailed post-mortems. These resources serve as invaluable learning tools for aspiring and seasoned security researchers alike.
- Interactive Workshops and Seminars: Regular workshops were conducted, covering advanced topics in smart contract security, secure coding practices, and exploit analysis. These sessions attracted hundreds of participants, significantly upskilling the community.
- Open-Source Security Tools: Several open-source tools were developed and maintained, aiding in vulnerability detection, static analysis, and incident response. These tools democratize access to advanced security capabilities.
- Community Engagement: DeFiHackLabs fostered a vibrant community, providing mentorship, peer review, and collaborative research opportunities. This community activation turned one stipend into an educational output reaching hundreds of security researchers, creating a sustainable pipeline of talent.
Ketman Project: Countering State-Sponsored Threats
One recipient’s work on the Ketman Project addressed a particularly insidious and pressing operational security threat: the infiltration of blockchain projects by North Korean (DPRK) IT workers operating under false identities. This sophisticated form of cyber espionage and financial crime poses a direct risk to project integrity and user funds. Over the stipend period, the Ketman Project:
- Identified and Exposed DPRK Operatives: Through meticulous investigation and intelligence gathering, the project successfully identified multiple individuals suspected of being DPRK IT workers embedded within various blockchain ventures.
- Developed Detection Methodologies: New techniques and indicators of compromise (IoCs) were developed to detect such infiltrations, aiding projects in screening potential hires and monitoring their workforce.
- Disseminated Critical Threat Intelligence: The findings and methodologies were shared with relevant security organizations and projects, contributing to a more informed and proactive defense against state-sponsored threats.
This work directly mitigates a significant geopolitical and operational security risk to the Ethereum ecosystem, protecting projects from espionage, theft, and sanctions evasion.
Nick Bax: Rapid Response and Threat Mitigation
Nick Bax’s contributions were multifaceted, focusing on immediate incident response and proactive threat intelligence. His work primarily channeled through SEAL 911, the Security Alliance’s rapid response arm, which provides emergency assistance to projects under attack.
- Incident Response Leadership: Bax played a crucial role in coordinating responses to several high-profile security incidents, helping projects contain breaches, mitigate losses, and conduct post-mortems.
- DPRK Threat Mitigation: Building on intelligence from projects like Ketman, Bax actively contributed to efforts to identify and neutralize threats posed by DPRK operatives.
- Public Awareness Campaigns: He engaged in public education, sharing vital security best practices, emerging threat vectors, and lessons learned from incidents to raise the overall security posture of the community.
His proactive and reactive security efforts have been instrumental in safeguarding projects and educating the wider user base.
Guild Audits: Bridging the Global Security Talent Gap
Guild Audits, recognizing the global demand for skilled smart contract auditors, focused on capacity building, particularly in historically underrepresented regions.
- Intensive Security Bootcamps: They conducted rigorous smart contract security bootcamps, training the next generation of Ethereum security researchers. These bootcamps covered fundamental concepts, advanced exploit techniques, and auditing methodologies.
- Regional Focus: A significant portion of their efforts targeted communities in Africa, aiming to cultivate local talent and foster a more diverse and inclusive security landscape.
The capacity-building impact of Guild Audits is profound, creating a pipeline of skilled security researchers and fostering economic opportunity in regions that can greatly benefit from participation in the global blockchain economy.
Palina Tolmach: Enhancing Formal Verification with Kontrol
Palina Tolmach of Runtime Verification dedicated her stipend to improving Kontrol, an open-source formal verification tool designed for Ethereum smart contracts. Formal verification is a rigorous method for proving the correctness of code, critical for high-assurance systems. Her key improvements included:
- Usability Enhancements: Streamlining the user interface and improving documentation to make Kontrol more accessible to a broader range of developers and security researchers, reducing the barrier to entry for this complex but powerful technique.
- Performance Optimizations: Enhancing the tool’s efficiency and speed, allowing for faster and more comprehensive analysis of smart contracts.
- Feature Expansion: Adding new functionalities and improving existing ones to cover a wider array of contract patterns and potential vulnerabilities.
All of Tolmach’s work is open source on GitHub, significantly improving the formal verification tooling landscape for the entire security research community and making advanced security analysis more attainable.
Ethereum Execution Client DoS Research: Fortifying the Core Protocol
A dedicated research team focused on the foundational layer of Ethereum: its execution clients. They developed a sophisticated testing framework to systematically evaluate the robustness of these clients (Geth, Besu, Erigon, Nethermind, and Reth) against message-flooding denial-of-service (DoS) attacks.
- Discovery of Critical Bugs: The team uncovered 14 distinct bugs across different network protocol layers within all five major execution clients. These vulnerabilities could lead to severe consequences, including:
- Node Disconnections: Compromising the ability of nodes to maintain connection to the network.
- Resource Exhaustion: Overwhelming client resources (CPU, memory), leading to degraded performance or crashes.
- Temporary Chain Stalls: Potentially causing temporary disruptions in block processing and finalization.
The findings underscore that no execution client is entirely immune to such attacks and emphasize the ongoing need for robust countermeasures like adaptive rate-limiting. The testing framework and results have been shared with the Ethereum Foundation’s Protocol Security team, directly informing future client security research and development.
A Broad Canvas of Contributions
Beyond these highlighted projects, other ETH Rangers contributed across a wide range of essential security-related public goods:
- Kelsie Nabben authored a book based on 2.5 years of ethnographic research into decentralized digital security communities, including SEAL, providing invaluable insights into the human element of blockchain security.
- The Mothra team built Mothra, a Ghidra extension for EVM bytecode reverse engineering with EOF decompilation support, enhancing tools for deep code analysis.
- SomaXBT published a four-part series on blockchain forensics, covering fund tracing, attribution, and OSINT methods, vital for investigating and understanding illicit activities.
- Peter Kacherginsky launched BlockThreat, a platform for blockchain threat intelligence that analyzes past security incidents and their root causes, creating a historical knowledge base for future prevention.
- Attack Vectors developed attackvectors.org, an open-source, continuously updated guide to top DeFi attack vectors and prevention strategies, and contributed to SEAL’s Wallet Security Framework.
- Tim Fan created D2PFuzz, a DevP2P protocol fuzzing framework that performed differential testing across execution layer clients, discovering bugs through both single-client and cross-client analysis.
- nft_dreww published security articles, hosted educational classes through Boring Security, and conducted audits on Ethereum public goods projects, contributing to both knowledge dissemination and direct security enhancement.
- Jean-Loïc Mugnier developed a Web3 transaction simulation Chrome extension, enhancing user security by allowing interception and simulation of transactions before they reach the wallet.
- Alexandre Melo produced security workshop videos covering a range of advanced topics, from fuzzing and smart accounts to AI-driven auditing and zero-knowledge proofs, expanding educational resources.
- Ho Nhut Minh enhanced CuEVM, a GPU-accelerated EVM implementation, with multi-GPU support and a Golang library for integration with the Medusa fuzzer, improving performance for security analysis.
- Sergio Garcia built the Tracelon Monitoring Bot, a Telegram bot for real-time block monitoring across Ethereum, Bitcoin, and Base, offering crucial alerts for ERC20 balance changes, and continued his contributions to SEAL 911 incident response.
Looking Ahead: Sustaining Decentralized Defense
The ETH Rangers Program set out to support the often "unglamorous but essential" security work that forms the bedrock of a robust decentralized network. The sheer variety and depth of contributions from the 17 stipend recipients underscore the program’s success in achieving this goal. It demonstrates that public goods security extends far beyond mere bug finding; it encompasses building foundational tools, nurturing talent through education, documenting critical knowledge, responding swiftly to incidents, and constantly refining threat intelligence.
This decentralized approach to defense is not just a theoretical ideal; it is a practical necessity for Ethereum’s continued growth and stability. By integrating new tools, research, and intelligence from independent experts globally, the program has provided a stronger, more resilient foundation for builders and users worldwide. The model of providing direct stipends for public goods work has proven highly effective in channeling resources to where they are most needed, empowering individuals to make significant impacts without the bureaucratic overhead often associated with larger grants.
The success of this pilot program also sets a precedent for future initiatives, highlighting the value of fostering independent research and collaboration. The Ethereum Foundation, Secureum, The Red Guild, and Security Alliance have collectively demonstrated a commitment to nurturing the ecosystem’s security, acknowledging that the network’s strength ultimately derives from the collective vigilance and dedication of its community. The gratitude extended to all 17 stipend recipients, and especially to The Red Guild for their hands-on involvement in review, milestone structuring, and feedback, reflects the deeply collaborative spirit that is essential for securing the decentralized future. As the Ethereum ecosystem continues to evolve, programs like ETH Rangers will remain crucial in maintaining its security, integrity, and trustworthiness for billions of users globally.







