In a significant stride towards bolstering the resilience and security of the decentralized web, the Ethereum Foundation, in collaboration with leading security entities Secureum, The Red Guild, and Security Alliance (SEAL), announced the successful conclusion of the inaugural ETH Rangers Program. Launched in late 2024, this six-month initiative provided crucial stipends to 17 independent individuals and teams dedicated to public goods security work within the vibrant Ethereum ecosystem. The program’s wrap-up marks a pivotal moment, showcasing a diverse array of outcomes ranging from critical vulnerability research and the development of advanced security tooling to comprehensive educational initiatives, proactive threat intelligence, and rapid incident response. These collective efforts underscore a fundamental truth in the evolving landscape of Web3: safeguarding a decentralized network necessitates a truly decentralized defense.
The Genesis of a Decentralized Defense Initiative
The Ethereum ecosystem, with its ever-growing complexity and the immense value locked within its smart contracts and protocols, has consistently faced an escalating threat landscape. Malicious actors, ranging from individual hackers to sophisticated state-sponsored groups, continually seek vulnerabilities to exploit for financial gain or strategic disruption. Recognizing that traditional, centralized security models are insufficient for a global, permissionless network, the Ethereum Foundation, alongside its partners, conceptualized the ETH Rangers Program. The initiative was born from a pressing need to foster and fund independent security researchers and developers who contribute to the common good, often in less visible but profoundly impactful ways.
Secureum, known for its rigorous security education and auditing; The Red Guild, a collective of top-tier security researchers and auditors; and Security Alliance (SEAL), a rapid-response collective addressing Web3 security incidents, brought their collective expertise and networks to the table. This collaboration ensured a holistic approach, from identifying deserving individuals with proven track records to providing mentorship and structure for their projects. The program’s core objective was clear: to channel financial support towards independent efforts that directly enhance the overall security posture of Ethereum, acknowledging that collective vigilance and innovation are the strongest bulwarks against emerging threats. By providing stipends, the program empowered these "rangers" to dedicate their expertise to critical, often unglamorous, security work that benefits every user and builder on Ethereum.
A Spectrum of Contributions: Pillars of Ecosystem Resilience
The 17 stipend recipients, carefully selected for their demonstrated commitment and impact, embarked on a wide range of projects over the six-month period. Their work collectively addressed multiple layers of the Ethereum security stack, reflecting the multifaceted nature of public goods security. From deep dives into protocol-level vulnerabilities to widespread developer education, these independent researchers and developers built foundational infrastructure and knowledge that promises to multiply security effects across the entire ecosystem. The diversity of their output serves as a testament to the program’s success in identifying and nurturing talent across various security disciplines.
Project Highlights: Innovations and Critical Safeguards
The program yielded several standout projects, each contributing significantly to different facets of Ethereum’s security. These highlights illustrate the depth and breadth of the ETH Rangers’ impact:
SunSec & DeFiHackLabs: Empowering the Next Generation of Security Researchers
SunSec, in collaboration with the DeFiHackLabs community, delivered an extraordinary volume of security education and tooling. Their efforts focused on democratizing access to high-quality security knowledge and practical skills. Over the stipend period, DeFiHackLabs was instrumental in:
- Developing advanced security tools: These tools helped researchers identify vulnerabilities more efficiently.
- Creating comprehensive educational materials: Ranging from beginner-friendly guides to advanced exploit analyses.
- Hosting workshops and mentorship programs: Training hundreds of aspiring security researchers in smart contract auditing and Web3 security best practices.
- Analyzing recent exploits: Providing detailed post-mortems to learn from past incidents.
The sheer scale of community activation achieved by DeFiHackLabs is particularly notable. By leveraging the stipend, SunSec acted as a powerful multiplier, transforming initial funding into educational output that reached and upskilled hundreds of security researchers globally. This capacity-building directly addresses the talent gap in Web3 security, fostering a more robust and knowledgeable defense community.
Ketman Project – DPRK IT Worker Investigations: Countering State-Sponsored Threats
One of the most critical and strategically important contributions came from a recipient who built and scaled the Ketman Project. This initiative focused on the highly sensitive and increasingly prevalent threat of North Korean (DPRK) state-sponsored IT workers infiltrating blockchain projects under fake identities. These actors are notorious for their involvement in sophisticated cyberattacks and financial theft, often to circumvent international sanctions. Over the stipend period, the Ketman Project achieved significant milestones:
- Developed advanced methodologies: For identifying suspicious digital footprints and behavioral patterns indicative of DPRK operatives.
- Collaborated with intelligence agencies and private security firms: Sharing critical threat intelligence to track and neutralize these threats.
- Conducted in-depth investigations: Leading to the identification and expulsion of several DPRK-linked individuals from various blockchain projects.
This work directly confronts one of the most pressing operational security threats facing the Ethereum ecosystem and the broader Web3 space. By disrupting these clandestine operations, the Ketman Project significantly mitigates the risk of large-scale exploits and intellectual property theft, safeguarding the integrity and financial stability of numerous decentralized applications.
Nick Bax – Incident Response and Threat Intelligence: On the Front Lines
Nick Bax emerged as a multi-faceted contributor, primarily through his involvement in SEAL 911 incident response, DPRK threat mitigation, and crucial public awareness campaigns. His work highlights the urgent and reactive nature of security in a live network environment. Key contributions included:
- Rapid incident response: Participating in SEAL 911 operations, providing immediate analysis and coordination during active exploits and emergencies, often preventing further financial losses.
- DPRK threat intelligence sharing: Actively contributing to efforts to identify and expose North Korean illicit activities, complementing the Ketman Project’s objectives.
- Public awareness initiatives: Disseminating critical information about phishing scams, social engineering tactics, and common vulnerabilities to the broader Ethereum community, empowering users to protect themselves.
Bax’s efforts underscore the vital role of real-time threat intelligence and coordinated incident response in minimizing damage and building collective resilience against sophisticated attacks.
Guild Audits – Security Education in Africa and Beyond: Global Capacity Building
Guild Audits made a profound impact on global security capacity by running intensive smart contract security bootcamps. These programs were designed to train the next generation of Ethereum security researchers, with a particular focus on historically underrepresented regions. The curriculum covered:
- Deep dives into Solidity and EVM security: Teaching participants how to identify and mitigate common smart contract vulnerabilities.
- Practical auditing methodologies: Equipping students with hands-on experience in analyzing and securing decentralized applications.
- Mentorship and career guidance: Connecting emerging talent with established professionals in the field.
The capacity-building impact of Guild Audits’ bootcamps is immense. By creating a pipeline of skilled security researchers in regions like Africa, the program not only addresses a global talent shortage but also fosters diversity and inclusion within the Ethereum security community, strengthening its overall adaptive capabilities.
Palina Tolmach – Kontrol: Usable Formal Verification: Advancing Rigor in Code
Palina Tolmach of Runtime Verification dedicated her stipend to significantly improving Kontrol, a cutting-edge formal verification tool for Ethereum smart contracts. Formal verification uses mathematical methods to prove the correctness of software, offering the highest level of assurance against bugs in critical code. Tolmach’s work focused on making this complex tool more accessible and user-friendly for a broader audience of developers and security researchers. Key Kontrol improvements included:
- Enhanced user interface and documentation: Simplifying the process for defining properties and interpreting results.
- Improved integration with existing development workflows: Making it easier for projects to incorporate formal verification into their continuous integration/continuous deployment (CI/CD) pipelines.
- Expanded support for complex contract patterns: Allowing for more sophisticated analysis of DeFi protocols.
- Performance optimizations: Reducing the time and computational resources required for verification.
All of this work is open-source at github.com/runtimeverification/kontrol, directly enhancing the formal verification tooling landscape for all security researchers and raising the bar for smart contract security across the ecosystem.
Ethereum Execution Client DoS Research: Safeguarding Network Stability
A dedicated research team tackled a foundational aspect of network security: the robustness of Ethereum execution clients. They developed a sophisticated testing framework to systematically evaluate these critical software components (Geth, Besu, Erigon, Nethermind, and Reth) against message-flooding denial-of-service (DoS) attacks. Such attacks aim to overload clients, disrupting network operations. Their rigorous testing led to the discovery of an alarming 14 bugs across different network protocol layers. These vulnerabilities could lead to:
- Client crashes and unresponsiveness: Taking nodes offline and reducing network participation.
- Memory leaks and resource exhaustion: Degrading client performance and stability over time.
- Chain divergence or network partitioning: Potentially leading to consensus issues and disrupting the blockchain’s integrity.
The findings critically highlighted that no major execution client is completely immune to message-flooding attacks. This research underscores the urgent need for further development of effective countermeasures, such as adaptive rate-limiting mechanisms. The testing framework and detailed results have been shared directly with the Ethereum Foundation’s Protocol Security team, providing invaluable insights to inform future client security research and development.
Diverse Contributions from Other Stipend Recipients
While the above projects represent significant breakthroughs, the remaining 11 stipend recipients also contributed across a wide range of security-related public goods, demonstrating the multifaceted nature of securing a decentralized network:
- Kelsie Nabben authored a comprehensive book based on 2.5 years of ethnographic research into decentralized digital security communities, including SEAL. This work provides invaluable academic and practical insights into the social and organizational dynamics of Web3 security.
- The Mothra team developed Mothra, a Ghidra extension for EVM bytecode reverse engineering, including crucial support for Ethereum Object Format (EOF) decompilation. Ghidra is a powerful open-source reverse engineering tool, and Mothra significantly enhances its utility for analyzing Ethereum smart contracts and identifying low-level vulnerabilities. They also published detailed technical write-ups on their development process, sharing knowledge with the wider community.
- SomaXBT published a four-part series on blockchain forensics and the crypto threat landscape. This educational resource covered essential topics like fund tracing, attribution techniques for malicious actors, and Open-Source Intelligence (OSINT) methods, equipping investigators and users with critical skills to track illicit activities.
- Peter Kacherginsky launched BlockThreat, a vital platform for blockchain threat intelligence. BlockThreat analyzes past security incidents, dissecting their root causes to provide actionable insights and preventive strategies for the ecosystem. This proactive approach helps projects avoid repeating historical mistakes.
- Attack Vectors built attackvectors.org, an open-source, continuously updated guide detailing the top attack vectors in DeFi and offering practical prevention strategies. This community resource empowers developers and users to build and interact with DeFi more securely. They also contributed significantly to SEAL’s Wallet Security Framework and became a SEAL Steward, deepening their commitment to ecosystem security.
- Tim Fan developed D2PFuzz, a DevP2P protocol fuzzing framework. This advanced tool uses differential testing across multiple Ethereum execution layer clients to uncover subtle bugs and inconsistencies in the underlying peer-to-peer communication protocols, finding vulnerabilities through both single-client and cross-client testing.
- nft_dreww contributed through publishing insightful security articles, hosting educational classes via Boring Security, and conducting audits on various Ethereum public goods projects, blending education with practical application.
- Jean-Loïc Mugnier developed a Web3 transaction simulation Chrome extension. This innovative tool intercepts and simulates transactions before they reach the user’s wallet, providing a critical layer of protection against malicious dApps or phishing attempts. His research also explored simulation spoofing, enhancing the tool’s robustness.
- Alexandre Melo produced a series of valuable security workshop videos. These covered a broad spectrum of topics, including fuzzing techniques, smart accounts, AI-driven auditing, Solana security, and zero-knowledge proofs, reaching a wide audience of developers and researchers.
- Ho Nhut Minh significantly enhanced CuEVM, a GPU-accelerated EVM implementation, by adding multi-GPU support and a Golang library for seamless integration with the Medusa fuzzer. This work drastically improves the speed and efficiency of EVM fuzzing, benchmarking impressively on high-performance Nvidia H100 GPUs.
- Sergio Garcia built the Tracelon Monitoring Bot, a Telegram bot providing real-time block monitoring for Ethereum, Bitcoin, and Base, complete with ERC20 balance change alerts. This tool offers invaluable real-time threat detection capabilities and bolsters incident response, further complemented by his continued contributions to SEAL 911.
Looking Ahead: The Enduring Impact of Decentralized Defense
The ETH Rangers Program successfully supported individuals engaged in the often "unglamorous but essential" security work that forms the bedrock of Ethereum’s integrity. The diverse range of their contributions unequivocally demonstrates that "public goods security" encompasses far more than mere bug finding. It involves the continuous development of robust tools, the systematic training of new talent, the meticulous documentation of knowledge, agile incident response, and proactive threat intelligence.
By integrating new tools, pioneering research, and actionable intelligence directly into the broader Ethereum ecosystem, the program has undeniably strengthened its foundations. This decentralized approach to defense is not merely a theoretical concept but a proven methodology for building a more secure and resilient network for builders and users worldwide. The success of this inaugural program also sets a powerful precedent for future funding models in the Web3 space, demonstrating the immense value of supporting independent contributors who work for the collective good.
The Ethereum Foundation, Secureum, The Red Guild, and Security Alliance express profound gratitude to all 17 stipend recipients for their tireless dedication and impactful contributions. Special acknowledgment is extended to The Red Guild for their hands-on involvement in reviewing submissions, structuring milestones, and providing detailed feedback throughout the program, which was instrumental to its success. As the Ethereum ecosystem continues to grow and evolve, initiatives like the ETH Rangers Program will remain crucial in fostering a proactive, adaptable, and globally distributed security posture capable of meeting the challenges of tomorrow.








