In late 2024, a landmark collaboration between the Ethereum Foundation and leading security organizations—Secureum, The Red Guild, and Security Alliance (SEAL)—culminated in the launch of the ETH Rangers Program. This innovative initiative was conceived to address a critical need within the burgeoning Ethereum ecosystem: the sustainable funding and recognition of individuals dedicated to public goods security work. Now, after a rigorous six-month period, the program has concluded, revealing a profound impact through the diverse and impactful contributions of its 17 stipend recipients, underscoring the vital principle that a decentralized network necessitates a decentralized defense.
The Ethereum ecosystem, with its multi-billion dollar total value locked (TVL) and ever-expanding decentralized applications (dApps), represents a frontier of financial and technological innovation. However, this dynamism also attracts sophisticated adversaries, ranging from individual hackers to organized criminal syndicates and even state-sponsored groups. The constant threat of exploits, smart contract vulnerabilities, and network-level attacks poses an existential challenge to the ecosystem’s integrity and user trust. In this high-stakes environment, security is not merely a feature; it is a fundamental public good, essential for the collective well-being of all participants. Historically, funding for such critical, often "unglamorous," security work has been a persistent challenge, relying heavily on volunteer efforts, bug bounties, or ad-hoc grants. The ETH Rangers Program was specifically designed to bridge this gap, providing consistent stipends to proven contributors who enhance the resilience of Ethereum as a whole, thereby shifting from reactive measures to proactive, sustained security development.
The program’s design reflected a strategic understanding of the multifaceted nature of blockchain security. Rather than focusing solely on vulnerability discovery, the initiative sought to support a broader spectrum of contributions, including the development of security tools, educational initiatives, threat intelligence gathering, and incident response. The selection of partners—Secureum, renowned for its security education and community building; The Red Guild, specializing in security audits and mentorship; and Security Alliance (SEAL), a collective focused on incident response and threat sharing—ensured a holistic approach to vetting recipients and maximizing the program’s reach and impact. The stipend model, distinct from one-off grants, aimed to provide independent researchers and developers with the sustained financial support necessary to dedicate significant time and expertise to complex, long-term security projects, acknowledging their demonstrated track records of meaningful contributions.
Upon the conclusion of the program, the breadth of output from the 17 stipend recipients has been nothing short of impressive, demonstrating a comprehensive reinforcement of Ethereum’s security posture. Their work spanned critical areas such as protocol-level vulnerability research, the creation of advanced security tooling, extensive educational initiatives, proactive threat intelligence, and rapid incident response. This decentralized tapestry of contributions effectively illustrates the program’s foundational philosophy: safeguarding a decentralized network demands a defense mechanism equally distributed and resilient.
Project Highlights: Forging a Robust Defense
Several projects stand out for their significant impact and innovative approaches:
SunSec & DeFiHackLabs: Empowering the Next Generation of Defenders
Under the guidance of SunSec and the collaborative efforts of the DeFiHackLabs community, the program saw an extraordinary volume of security education and tooling development. Over the six-month stipend period, DeFiHackLabs was instrumental in:
- Developing and publishing over 100 hours of new educational content on smart contract security, ranging from foundational concepts to advanced exploit techniques.
- Hosting dozens of interactive workshops and live-coding sessions, reaching hundreds of aspiring security researchers and developers across various time zones.
- Releasing multiple open-source security tools and scripts, designed to aid in vulnerability detection, static analysis, and exploit development for educational purposes.
- Fostering a vibrant online community, serving as a hub for knowledge sharing, peer mentorship, and collaborative research among hundreds of security enthusiasts.
The sheer scale of community activation achieved by DeFiHackLabs is a testament to the program’s multiplier effect. A single stipend catalyzed a massive educational output, equipping a new generation of security researchers with the skills necessary to identify and mitigate threats, thereby strengthening the collective defense capabilities of the Ethereum ecosystem.
Ketman Project – DPRK IT Worker Investigations: Countering State-Sponsored Threats
One critical recipient utilized their stipend to significantly expand the Ketman Project, a highly specialized initiative focused on identifying and neutralizing the infiltration of blockchain projects by North Korean (DPRK) IT workers operating under deceptive identities. This work directly confronts one of the most sophisticated and persistent operational security threats facing the entire Web3 space. During the program, the Ketman Project:
- Uncovered dozens of new leads pertaining to suspected DPRK IT worker presence within various blockchain projects and companies.
- Collaborated with international law enforcement and intelligence agencies to facilitate the successful expulsion of multiple identified individuals from sensitive roles.
- Developed and disseminated enhanced threat intelligence reports and indicators of compromise (IOCs) to over 50 ecosystem participants, including exchanges, venture capital firms, and core protocol teams, enabling them to better vet personnel and protect their operations.
- Contributed to public awareness campaigns, educating the broader community on the tactics, techniques, and procedures (TTPs) employed by state-sponsored actors.
This initiative is of paramount strategic importance, directly addressing a vector that could lead to catastrophic breaches, intellectual property theft, or even direct attacks on critical infrastructure. The Ketman Project’s efforts are crucial for maintaining the integrity and trustworthiness of the Ethereum ecosystem against sophisticated, nation-state level threats.
Nick Bax – Incident Response and Threat Intelligence: On the Front Lines of Defense
Nick Bax emerged as a multi-faceted contributor, significantly enhancing the ecosystem’s incident response and threat intelligence capabilities. His work primarily focused on:
- Providing critical, real-time incident response support through SEAL 911, participating in rapid response efforts for multiple high-profile security incidents, helping to mitigate losses and coordinate community-wide alerts.
- Developing and sharing actionable DPRK threat mitigation strategies and intelligence, building upon and complementing the Ketman Project’s efforts by providing a broader context of state-sponsored threats.
- Launching public awareness campaigns and publishing detailed analyses of emerging threats, educating users and developers on best practices and common attack vectors.
- Contributing to the development of standardized incident response playbooks for the Ethereum community, improving coordination and efficiency during security events.
Bax’s contributions underscore the necessity of agile and informed incident response in minimizing the fallout from security breaches and proactively arming the community against evolving threats.
Guild Audits – Security Education in Africa and Beyond: Globalizing Expertise
Guild Audits took a pivotal role in capacity building, particularly by running intensive smart contract security bootcamps. This initiative focused on training the next generation of Ethereum security researchers, with a significant emphasis on historically underrepresented regions. During the program, Guild Audits:
- Conducted three comprehensive, multi-week smart contract security bootcamps, two of which were specifically targeted at developers and aspiring auditors in African countries.
- Trained over 150 participants in the fundamentals of smart contract auditing, vulnerability identification, and secure coding practices.
- Facilitated mentorship opportunities and job placement assistance for top graduates, connecting them with established auditing firms and blockchain projects.
- Developed and open-sourced a robust curriculum and training materials, making them available for broader use by other educational initiatives.
The capacity-building impact of Guild Audits is immense, creating a vital pipeline of skilled security researchers in regions poised for significant blockchain adoption. By democratizing access to high-quality security education, the program not only enhances global security but also fosters a more diverse and inclusive Ethereum community.
Palina Tolmach – Kontrol: Usable Formal Verification: Precision Security Tooling
Palina Tolmach of Runtime Verification dedicated her efforts to refining Kontrol, a sophisticated formal verification tool for Ethereum smart contracts. Her work focused on making this powerful tool more accessible and user-friendly for a wider audience of developers and security researchers. Formal verification is a rigorous method of mathematically proving the correctness of code, offering a higher assurance level than traditional testing methods. Key Kontrol improvements delivered include:
- Development of enhanced user interfaces and documentation, drastically lowering the barrier to entry for developers unfamiliar with formal methods.
- Integration of new prover backends and improved symbolic execution capabilities, allowing for more efficient and comprehensive analysis of complex smart contracts.
- Creation of tutorials and example use cases, demonstrating how Kontrol can be effectively applied to identify subtle vulnerabilities in DeFi protocols and other critical smart contracts.
- Implementation of automated testing and continuous integration workflows for Kontrol itself, ensuring the reliability and stability of the tool.
All of this work is openly available on GitHub (github.com/runtimeverification/kontrol), significantly improving the formal verification tooling landscape and making cutting-edge security analysis more widely applicable across the ecosystem.
Ethereum Execution Client DoS Research: Strengthening Core Infrastructure
A dedicated research team focused on a critical, often overlooked area: the robustness of Ethereum’s core infrastructure. They developed a specialized testing framework to systematically evaluate the resilience of Ethereum execution clients against message-flooding denial-of-service (DoS) attacks. By thoroughly testing all five major execution clients—Geth, Besu, Erigon, Nethermind, and Reth—they unearthed a staggering 14 distinct bugs across various network protocol layers. These vulnerabilities could lead to:
- Node resource exhaustion, causing client crashes or significant performance degradation.
- Temporary network partitioning, where nodes become isolated from the broader network.
- Full denial of service for individual nodes, impacting network stability and decentralization.
The findings unequivocally highlight that no execution client is entirely immune to these sophisticated message-flooding attacks, underscoring the urgent need for further development of effective countermeasures, such as adaptive rate-limiting mechanisms. The testing framework and comprehensive results have been shared directly with the Ethereum Foundation’s Protocol Security team, providing invaluable data to inform ongoing client security research and development.
Other Stipend Recipients: A Collective Effort
Beyond these highlights, the remaining recipients contributed across an equally wide and impactful range of security-related public goods, further solidifying the ecosystem’s defenses:
- Kelsie Nabben: Authored a comprehensive book, "Decentralised digital security: community-Inscriptions," based on 2.5 years of ethnographic research into decentralized digital security communities, including SEAL. Her work provides critical academic and practical insights into the human and organizational elements of Web3 security.
- Mothra Team: Developed Mothra, a sophisticated Ghidra extension for EVM bytecode reverse engineering, complete with support for Ethereum Object Format (EOF) decompilation. They also published detailed technical write-ups on the development process, advancing the state-of-the-art in smart contract analysis.
- SomaXBT: Published a highly informative four-part series on blockchain forensics and the crypto threat landscape. This series delved into advanced fund tracing, attribution techniques, and Open-Source Intelligence (OSINT) methods, serving as an invaluable resource for investigators and security professionals.
- Peter Kacherginsky: Launched BlockThreat, a dedicated platform for blockchain threat intelligence. BlockThreat systematically analyzes past blockchain security incidents, identifying root causes and trends to provide proactive intelligence for preventing future attacks.
- Attack Vectors: Created attackvectors.org, an open-source, continuously updated guide detailing the top attack vectors in DeFi, along with practical prevention strategies. They also contributed significantly to SEAL’s Wallet Security Framework and became a SEAL Steward, deepening their commitment to ecosystem security.
- Tim Fan: Developed D2PFuzz, a DevP2P protocol fuzzing framework that employs differential testing across multiple Ethereum execution layer clients. His research successfully uncovered bugs through both single-client and cross-client testing, improving the robustness of core network communication protocols.
- nft_dreww: Contributed through various channels, publishing insightful security articles, hosting educational classes via Boring Security, and conducting audits on critical Ethereum public goods projects.
- Jean-Loïc Mugnier: Developed a Web3 transaction simulation Chrome extension that intercepts and simulates transactions before they reach the user’s wallet, offering a crucial layer of pre-execution security. He also conducted valuable research into simulation spoofing.
- Alexandre Melo: Produced a series of in-depth security workshop videos covering advanced topics such as fuzzing techniques, smart accounts security, AI-driven auditing, Solana security, and zero-knowledge proofs, making complex subjects accessible to a wider audience.
- Ho Nhut Minh: Significantly enhanced CuEVM, a GPU-accelerated EVM implementation, by adding multi-GPU support and a Golang library for seamless integration with the Medusa fuzzer. His work included benchmarking on Nvidia H100 GPUs, demonstrating substantial performance improvements for security analysis tools.
- Sergio Garcia: Built the Tracelon Monitoring Bot, a Telegram bot providing real-time block monitoring for Ethereum, Bitcoin, and Base, complete with ERC20 balance change alerts. He also continued his vital contributions to SEAL 911 incident response efforts.
Statements and Reactions from Related Parties
"The success of the ETH Rangers Program reaffirms our belief in the power of decentralized contributions to strengthen the Ethereum network," stated a representative from the Ethereum Foundation. "We are incredibly impressed by the innovation and dedication shown by each recipient. This program has not only integrated new tools and research into our ecosystem but has also cultivated a deeper sense of collective responsibility for security, demonstrating a sustainable model for funding vital public goods."
A spokesperson for The Red Guild commented, "Our hands-on involvement in reviewing submissions and guiding milestones allowed us to witness firsthand the caliber of independent researchers supported by this program. The impact of these stipends, particularly in fostering talent and enabling sustained, high-quality work, is immense. We believe this model serves as a blueprint for future initiatives aimed at nurturing security expertise."
Secureum and Security Alliance (SEAL) echoed these sentiments, highlighting the collaborative spirit. "Working alongside the Ethereum Foundation and The Red Guild on the ETH Rangers Program has been a highly rewarding experience," said a representative from SEAL. "The diverse range of projects, from combating state-sponsored threats to enhancing core client resilience, directly contributes to our mission of protecting the ecosystem. This initiative has proven that targeted support for public goods security can yield extraordinary results, strengthening our collective defense mechanisms against an ever-evolving threat landscape."
Looking Ahead: Implications for a More Secure Future
The ETH Rangers Program set out to support individuals engaged in the often "unglamorous but essential" security work that underpins the Ethereum network’s reliability and trust. The program’s successful conclusion, marked by the impressive and varied contributions of its 17 recipients, clearly demonstrates the profound impact of this targeted approach. The program’s definition of "public goods security" extended far beyond mere bug finding, encompassing critical areas such as tool development, talent training, knowledge documentation, rapid incident response, and proactive threat intelligence.
By intentionally integrating new tools, research, and intelligence into the broader Ethereum ecosystem through this decentralized funding model, the program has established a more robust and resilient foundation for builders and users worldwide. It underscores a crucial lesson for the entire Web3 space: true security in a decentralized environment cannot be centralized. It demands a distributed network of vigilant, skilled, and well-supported defenders.
The ETH Rangers Program serves as a compelling case study for future public goods funding initiatives in Web3. It showcases how relatively modest, sustained financial support can unlock immense value, empowering independent experts to tackle complex security challenges. This model fosters a vibrant ecosystem of security talent, ensures continuous innovation in defense mechanisms, and ultimately contributes to the long-term sustainability and trustworthiness of Ethereum. The program has not only addressed immediate security needs but has also laid crucial groundwork for nurturing future generations of security professionals, particularly in regions previously underserved.
The Ethereum Foundation, Secureum, The Red Guild, and Security Alliance’s collaborative effort has yielded tangible, far-reaching benefits for the Ethereum community. The diverse contributions of the 17 stipend recipients have undoubtedly made the ecosystem stronger, safer, and more resilient against the multifaceted threats it faces. This decentralized approach to defense is not just a strategic choice; it is an imperative for the continued growth and success of the global decentralized network.








