The Ethereum Foundation, in collaboration with leading security organizations Secureum, The Red Guild, and Security Alliance (SEAL), announced the successful conclusion of its inaugural six-month ETH Rangers Program. Launched in late 2024, this pioneering initiative was designed to provide crucial stipends to individuals dedicated to enhancing the resilience and integrity of the Ethereum ecosystem through public goods security work. The program’s wrap-up in mid-2025 marks a significant milestone, demonstrating the profound impact of a decentralized approach to network defense and the vital role of independent researchers and developers in safeguarding one of the world’s most critical blockchain infrastructures.
The ETH Rangers Program emerged from a recognition that securing a decentralized network like Ethereum demands a similarly decentralized and proactive defense strategy. With billions of dollars in value locked in smart contracts and an ever-evolving threat landscape ranging from sophisticated state-sponsored actors to opportunistic exploiters, the need for robust, community-driven security initiatives has never been more pressing. The program’s core objective was clear: to identify, fund, and empower individuals with proven track records of making meaningful contributions to security work that benefits Ethereum as a whole, rather than specific commercial entities. This included efforts spanning vulnerability research, development of essential security tooling, educational initiatives, threat intelligence gathering, and incident response. The program deliberately sought to support "unglamorous but essential" work, often overlooked by traditional funding models, yet critical for the long-term health and stability of the network.
The Genesis of a Decentralized Defense Strategy
Ethereum, as the preeminent smart contract platform, underpins a vast and complex ecosystem of decentralized applications (dApps), financial protocols (DeFi), and NFTs. The security of its core protocol and the applications built upon it is paramount. Historically, security efforts have often been reactive, responding to breaches rather than proactively fortifying the system. The Ethereum Foundation, along alongside its partners Secureum, known for its security auditing and education, The Red Guild, a collective of security researchers, and Security Alliance (SEAL), dedicated to incident response and threat intelligence, recognized the need for a sustained, independent security workforce.
The ETH Rangers Program was conceived as a mechanism to formalize and fund this distributed effort. By providing direct stipends, the program aimed to remove financial barriers for talented individuals, allowing them to dedicate their expertise to public goods security without the pressures of commercial engagements. This model underscores a foundational principle of decentralization: strength through distributed participation and collective responsibility. The launch in late 2024 positioned the program to address emerging threats and solidify security practices as the ecosystem continued its rapid expansion.
Collective Impact: A Diverse Portfolio of Security Enhancements
Over its six-month tenure, the ETH Rangers Program supported 17 stipend recipients, whose collective output has been impressively broad and impactful. The initiatives undertaken by these "Rangers" spanned the full spectrum of security work, illustrating the multi-faceted nature of protecting a complex digital infrastructure. Consolidated outcomes from their efforts include:
- Enhanced Vulnerability Research: Identifying and mitigating critical weaknesses in both core protocol components and widely used smart contracts.
- Development of Essential Security Tooling: Creating open-source tools that empower developers and auditors to build more secure applications and detect flaws more efficiently.
- Expansion of Global Security Education: Training new generations of security researchers and developers, particularly in underrepresented regions, to foster a more diverse and robust talent pool.
- Strengthened Threat Intelligence and Incident Response Frameworks: Proactively identifying emerging threats, tracking malicious actors, and improving the speed and effectiveness of responses to security incidents.
- Mitigation of Sophisticated Attack Vectors: Addressing complex and persistent threats, including state-sponsored infiltration and denial-of-service vulnerabilities.
These achievements collectively reinforce the program’s core thesis: that securing a decentralized network truly necessitates a decentralized defense. Each independent contribution acts as a node in a broader security network, multiplying effects and building robust layers of protection across the entire Ethereum ecosystem.
Project Highlights: Spotlight on Innovation and Impact
The program showcased several standout projects, each addressing critical security challenges with innovative solutions:
SunSec & DeFiHackLabs: Pioneering Security Education and Tooling
SunSec, in collaboration with the vibrant DeFiHackLabs community, made extraordinary strides in security education and tooling. Over the stipend period, DeFiHackLabs:
- Developed and released numerous open-source security tools, making advanced analysis techniques accessible to a wider audience.
- Conducted multiple intensive workshops and training sessions, educating hundreds of aspiring security researchers on advanced smart contract vulnerabilities and auditing methodologies.
- Published extensive documentation and educational materials, democratizing knowledge and fostering a culture of security awareness within the developer community.
The sheer scale of community activation achieved by DeFiHackLabs is remarkable. By leveraging the stipend, SunSec effectively transformed a single investment into an educational output that reached hundreds of security researchers, acting as a powerful multiplier for security expertise across the ecosystem. This initiative is vital for continually replenishing and upskilling the talent pool required to secure Ethereum’s ever-expanding landscape.
Ketman Project: Countering State-Sponsored Threats
One critical stipend recipient dedicated their efforts to building and scaling the Ketman Project, an initiative specifically focused on identifying and expelling North Korean (DPRK) IT workers who have infiltrated blockchain projects using deceptive identities. Over the six months, the Ketman Project:
- Identified several suspected DPRK-affiliated individuals operating within the blockchain space, providing actionable intelligence to affected projects and law enforcement.
- Developed sophisticated methodologies and tools for detecting and verifying the presence of these illicit actors.
- Collaborated with various security firms and government agencies to share intelligence and coordinate mitigation efforts.
This work directly confronts one of the most pressing operational security threats facing the Ethereum ecosystem today, safeguarding projects from espionage, intellectual property theft, and potential funding of illicit state activities. The proactive nature of this intelligence gathering is crucial in an environment where trust is paramount but often exploited.
Nick Bax: Enhancing Incident Response and Threat Intelligence
Nick Bax emerged as a multi-front contributor, primarily through his involvement with SEAL 911 incident response, his efforts in DPRK threat mitigation, and his commitment to public awareness. His contributions included:
- Playing a key role in numerous rapid response efforts to ongoing security incidents, helping to minimize damage and coordinate recovery.
- Actively contributing to intelligence sharing networks, providing timely updates on emerging threats and attack vectors.
- Raising public awareness about prevalent scams and sophisticated attack techniques through educational content and community engagement.
Bax’s work exemplifies the critical need for agile and informed incident response capabilities, ensuring that the ecosystem can react swiftly and effectively when security breaches occur, thereby protecting users and assets.
Guild Audits: Cultivating Global Security Talent
Guild Audits made significant contributions to capacity building by running intensive smart contract security bootcamps. These programs were instrumental in training the next generation of Ethereum security researchers, with a particular focus on expanding access in historically underrepresented regions. Their key achievements included:
- Conducting multiple comprehensive bootcamps, successfully graduating cohorts of skilled security auditors.
- Developing a standardized curriculum for smart contract security, covering fundamental concepts to advanced exploit techniques.
- Creating a pipeline for new talent to enter the Ethereum security community, fostering diversity and expanding global expertise.
The capacity-building impact of Guild Audits’ smart contract security bootcamps is substantial, creating a vital influx of skilled security researchers and helping to ensure that security expertise is not concentrated in just a few geographic areas.
Palina Tolmach: Advancing Formal Verification with Kontrol
Palina Tolmach, representing Runtime Verification, dedicated her stipend to improving Kontrol, an advanced formal verification tool designed for Ethereum smart contracts. Her work focused on making this powerful tool more accessible and user-friendly for developers and security researchers. Key Kontrol improvements delivered include:
- Enhancing the user interface and overall developer experience, reducing the barrier to entry for formal verification.
- Adding support for new Solidity features and EVM opcodes, ensuring the tool remains current with protocol developments.
- Improving performance and scalability, allowing for more efficient verification of complex smart contracts.
All of this work is open source and available at github.com/runtimeverification/kontrol, significantly improving the formal verification tooling landscape for all security researchers. Formal verification is a rigorous method for mathematically proving the correctness of code, making improvements to tools like Kontrol absolutely fundamental for preventing subtle yet critical bugs in smart contracts.
Ethereum Execution Client DoS Research: Fortifying Core Infrastructure
A dedicated research team focused on core protocol security by developing a sophisticated testing framework. This framework was designed to systematically evaluate the robustness of Ethereum execution clients against message-flooding denial-of-service (DoS) attacks. By rigorously testing all five major execution clients—Geth, Besu, Erigon, Nethermind, and Reth—they uncovered a staggering 14 bugs across different network protocol layers. These vulnerabilities, if exploited, could lead to:
- Node Disconnections: Disrupting the peer-to-peer network and isolating nodes.
- Resource Exhaustion: Overwhelming client resources, potentially leading to crashes or severe performance degradation.
- State Bloat: Forcing clients to process and store excessive amounts of data, impacting network health.
The findings underscore that no execution client is entirely immune to message-flooding attacks, emphasizing the continuous need for robust countermeasures like adaptive rate-limiting. The testing framework and its comprehensive results have been shared with the Ethereum Foundation’s Protocol Security team, directly informing future client security research and development to build a more resilient core network.
Broader Contributions: Other Vital Initiatives
Beyond these highlighted projects, other stipend recipients contributed across a wide array of security-related public goods, further demonstrating the diverse needs of the ecosystem:
- Kelsie Nabben: Authored a comprehensive book based on 2.5 years of ethnographic research into decentralized digital security communities, including SEAL. Her work provides invaluable insights into the human and organizational aspects of blockchain security.
- Mothra Team: Developed Mothra, a Ghidra extension for EVM bytecode reverse engineering, complete with support for EOF (EVM Object Format) decompilation. They also published detailed technical write-ups on the development process, advancing critical analysis tools for auditors.
- SomaXBT: Published a four-part series on blockchain forensics and the crypto threat landscape. This series delved into fund tracing, attribution techniques, and Open-Source Intelligence (OSINT) methods, providing essential knowledge for investigating illicit activities.
- Peter Kacherginsky: Launched BlockThreat, a platform dedicated to blockchain threat intelligence. BlockThreat analyzes past security incidents and their root causes, serving as a critical resource for learning from historical exploits and preventing future ones.
- Attack Vectors: Built attackvectors.org, an open-source, continuously updated guide detailing top attack vectors in DeFi and corresponding prevention strategies. They also contributed to SEAL’s Wallet Security Framework and became a SEAL Steward, deepening their commitment to ecosystem safety.
- Tim Fan: Developed D2PFuzz, a DevP2P protocol fuzzing framework that employs differential testing across multiple execution layer clients. His research successfully identified bugs through both single-client and cross-client testing, improving core network protocol robustness.
- nft_dreww: Contributed significantly through publishing security articles, hosting educational classes via Boring Security, and conducting audits on Ethereum public goods projects, bridging the gap between advanced research and practical application.
- Jean-Loïc Mugnier: Created a Web3 transaction simulation Chrome extension that intercepts and simulates transactions before they reach the wallet. This vital tool, coupled with his simulation spoofing research, significantly enhances user security against malicious transactions.
- Alexandre Melo: Produced a series of insightful security workshop videos covering advanced topics such as fuzzing, smart accounts, AI-driven auditing, Solana security, and zero-knowledge proofs, making complex subjects more accessible to the community.
- Ho Nhut Minh: Enhanced CuEVM, a GPU-accelerated EVM implementation, by adding multi-GPU support and a Golang library for seamless integration with the Medusa fuzzer. His benchmarking on Nvidia H100 GPUs pushes the boundaries of efficient security testing.
- Sergio Garcia: Developed the Tracelon Monitoring Bot, a Telegram bot offering real-time block monitoring across Ethereum, Bitcoin, and Base, including ERC20 balance change alerts. He also continued his crucial contributions to SEAL 911 incident response, providing immediate support during security incidents.
Looking Ahead: The Future of Decentralized Security
The ETH Rangers Program set out to support individuals engaged in the often-overlooked yet utterly essential security work for Ethereum, and its conclusion unequivocally demonstrates the success of this model. The sheer variety and depth of contributions reflect the true breadth of what "public goods security" entails. It extends far beyond merely discovering bugs; it encompasses the proactive development of tools, the rigorous training of new talent, the meticulous documentation of knowledge, the swift response to incidents, and the continuous enhancement of the ecosystem’s overall resilience.
By fostering and funding these diverse public goods security initiatives, the program has seamlessly integrated new tools, cutting-edge research, and critical intelligence directly into the broader Ethereum ecosystem. This decentralized approach to defense not only fortifies the network against current threats but also establishes a more robust and adaptable foundation for developers, users, and innovators worldwide. The success of the ETH Rangers Program serves as a compelling blueprint for future funding models, proving that direct support for independent security researchers is an invaluable investment in the long-term viability and security of decentralized technologies.
The Ethereum Foundation, Secureum, The Red Guild, and Security Alliance extend their profound gratitude to all 17 stipend recipients for their tireless efforts and invaluable contributions. Special appreciation is also given to The Red Guild for their hands-on involvement in meticulously reviewing submissions, structuring project milestones, and providing detailed, constructive feedback throughout the program. This collaborative spirit, spanning funding bodies, security experts, and independent researchers, is the very essence of a strong, decentralized defense. As Ethereum continues to evolve, programs like ETH Rangers will remain critical pillars in its ongoing commitment to security and integrity.







