In late 2024, a significant initiative designed to bolster the security of the Ethereum ecosystem, the ETH Rangers Program, was launched by the Ethereum Foundation in collaboration with prominent security organizations: Secureum, The Red Guild, and the Security Alliance (SEAL). This program aimed to provide crucial financial support, in the form of stipends, to individuals and teams dedicated to performing essential public goods security work within Ethereum. The core objective was clear: to foster and fund independent efforts that enhance the overall resilience and security posture of the decentralized network, while simultaneously recognizing and rewarding individuals with a proven track record of impactful contributions to the broader Ethereum community.
Now, following the successful completion of its initial six-month phase, the program has unveiled the impactful outcomes achieved by its 17 stipend recipients. The diversity and depth of their contributions are remarkable, spanning critical areas such as in-depth vulnerability research, the development of vital security tooling, comprehensive educational initiatives, proactive threat intelligence gathering, and rapid incident response capabilities. These collective achievements underscore a fundamental truth: securing a decentralized network like Ethereum necessitates a decentralized defense strategy, where a broad spectrum of independent actors contribute to a robust and multi-layered security framework. The work undertaken by these ETH Rangers has directly resulted in the creation of infrastructure and knowledge that will amplify security benefits across the entire Ethereum ecosystem, from protocol-level research to global developer education.
Project Highlights: Diverse Contributions to Ecosystem Security
The ETH Rangers Program has illuminated a range of critical security advancements. Among the notable recipients, SunSec, in partnership with the DeFiHackLabs community, has delivered an exceptional volume of security education and tooling. During the stipend period, DeFiHackLabs significantly expanded its reach and impact:
- Educational Content Expansion: They developed and disseminated a substantial amount of educational material, including detailed security vulnerability write-ups and comprehensive tutorials. This content was made accessible through various platforms, including their GitHub repository and public community channels.
- Tooling Development: The team actively contributed to the development and refinement of security tools, enhancing the capabilities available to developers and researchers for identifying and mitigating potential risks.
- Community Engagement: DeFiHackLabs fostered a vibrant community environment, actively engaging with hundreds of security researchers. This engagement not only disseminated knowledge but also encouraged collaborative problem-solving and the sharing of best practices.
The sheer scale of community activation driven by DeFiHackLabs is particularly noteworthy. Their model effectively acts as a force multiplier, transforming a single stipend into widespread educational output that benefits a vast network of security researchers, thereby elevating the collective security intelligence of the ecosystem.
Another impactful initiative was the Ketman Project, spearheaded by a recipient focused on DPRK IT Worker Investigations. This project addresses a critical and persistent operational security threat facing the Ethereum ecosystem: the infiltration of North Korean (DPRK) IT workers who often pose under false identities within blockchain projects. Over the stipend period, the Ketman Project achieved significant milestones:
- Scalability and Operationalization: They successfully built and scaled the Ketman Project, transforming it from a concept into a functional operation dedicated to identifying and expelling these malicious actors.
- Threat Identification: The project meticulously identified and documented instances of DPRK IT workers attempting to gain access or already embedded within blockchain projects.
- Reporting and Mitigation: They developed robust reporting mechanisms to alert relevant parties and contribute to the proactive mitigation of these threats, thereby safeguarding project integrity and user funds.
This work directly confronts one of the most pressing operational security challenges currently confronting the Ethereum ecosystem, highlighting the proactive and investigative nature of the ETH Rangers’ efforts.
Nick Bax emerged as a multi-faceted contributor, significantly impacting the ecosystem through his involvement in Incident Response and Threat Intelligence. His contributions were primarily channeled through SEAL 911 incident response efforts, alongside dedicated work on DPRK threat mitigation and public awareness campaigns. Bax’s efforts were instrumental in bolstering the ecosystem’s ability to react to and learn from security incidents, while also contributing to the broader understanding of emerging threats.
The imperative for enhanced security education, particularly in regions historically underrepresented in the global cybersecurity landscape, was addressed by Guild Audits through their intensive smart contract security bootcamps. These programs are designed to cultivate the next generation of Ethereum security researchers. The capacity-building impact of these bootcamps is substantial, establishing a vital pipeline of skilled security professionals, particularly in areas where access to such specialized training has been limited. This initiative is crucial for diversifying the talent pool and ensuring a more globally representative approach to Ethereum’s security.
Furthermore, Palina Tolmach of Runtime Verification focused on advancing usable formal verification through the Kontrol project. Kontrol is a sophisticated formal verification tool designed for Ethereum smart contracts. Tolmach’s work aimed to enhance its accessibility and utility for a broader audience of developers and security researchers. Key improvements to Kontrol included:
- Enhanced Usability: Significant efforts were made to simplify the user interface and workflow of Kontrol, making it more intuitive for developers with varying levels of formal verification expertise.
- Expanded Verification Capabilities: The tool’s capacity to verify a wider range of smart contract properties and identify more complex vulnerabilities was demonstrably improved.
- Integration and Documentation: Efforts were made to streamline integration with existing development environments and to produce comprehensive documentation, further lowering the barrier to entry for its adoption.
All of this work is publicly available under open-source licenses on GitHub, significantly enriching the formal verification tooling landscape for all security researchers and developers working within the Ethereum ecosystem.
Addressing Systemic Vulnerabilities: DoS Research and Broader Contributions
A dedicated research team within the ETH Rangers Program focused on Ethereum Execution Client DoS Research. They developed a sophisticated testing framework to systematically evaluate the robustness of Ethereum execution clients when subjected to message-flooding denial-of-service (DoS) attacks. This critical research involved testing all five major execution clients: Geth, Besu, Erigon, Nethermind, and Reth. The team’s rigorous testing uncovered a significant number of vulnerabilities:
- Bug Discovery: A total of 14 bugs were identified across various network protocol layers of the tested execution clients.
- Potential Impacts: These vulnerabilities, if exploited, could lead to several adverse outcomes, including:
- Increased Resource Consumption: Attackers could potentially trigger excessive CPU or memory usage, leading to client instability or outright crashes.
- Network Instability: Exploitation could disrupt the normal functioning of network nodes, potentially leading to temporary network partitions or degraded performance.
- Denial of Service: In severe cases, attackers could achieve a complete denial of service, preventing legitimate nodes from participating in network consensus or transaction processing.
The findings from this research underscore a crucial reality: no single execution client is entirely immune to message-flooding attacks. This highlights the ongoing need for proactive development of effective countermeasures, such as adaptive rate-limiting mechanisms, to further fortify the network against such threats. The testing framework and the detailed findings have been shared directly with the Ethereum Foundation’s Protocol Security team, providing invaluable insights to inform future client security research and development efforts.
A Spectrum of Security Contributions: Other Stipend Recipients
While detailed write-ups for every recipient are not feasible within this report, the contributions of the remaining ETH Rangers span a wide array of essential security-related public goods:
- Kelsie Nabben authored a significant book, "Decentralised Digital Security Community: Inscriptions," drawing upon 2.5 years of ethnographic research into decentralized digital security communities, including firsthand engagement with SEAL. This work provides invaluable qualitative insights into the human element of cybersecurity within decentralized systems.
- The Mothra team developed Mothra, a Ghidra extension specifically designed for EVM bytecode reverse engineering. Notably, it includes support for EOF (Ethereum Object Format) decompilation, a crucial advancement for analyzing complex smart contract code. The team also published detailed technical documentation on their development process, sharing their expertise openly.
- SomaXBT produced a comprehensive four-part series on blockchain forensics and the crypto threat landscape. This series delved into critical topics such as fund tracing, attribution techniques for illicit activities, and the application of open-source intelligence (OSINT) methods in the blockchain space.
- Peter Kacherginsky launched BlockThreat, a platform dedicated to blockchain threat intelligence. BlockThreat analyzes past blockchain security incidents, dissecting their root causes and offering valuable lessons learned for the broader community.
- The Attack Vectors initiative built attackvectors.org, an open-source, continuously updated guide that details the most prevalent attack vectors in Decentralized Finance (DeFi). It also provides actionable prevention strategies for developers and users. Furthermore, this group made significant contributions to SEAL’s Wallet Security Framework and has been recognized as a SEAL Steward.
- Tim Fan developed D2PFuzz, a fuzzing framework for the DevP2P protocol. This framework incorporates differential testing across multiple execution layer clients, enabling the discovery of bugs through both single-client and cross-client analysis.
- nft_dreww has been actively contributing through the publication of security articles, hosting educational classes via Boring Security, and conducting security audits on various Ethereum public goods projects.
- Jean-Loïc Mugnier created a Web3 transaction simulation Chrome extension. This tool intercepts and simulates transactions before they are finalized by the wallet, offering users a crucial layer of pre-transaction analysis. Mugnier also conducted research into simulation spoofing techniques.
- Alexandre Melo produced a series of security workshop videos, covering a broad spectrum of advanced topics including fuzzing techniques, smart account security, AI-driven auditing, Solana security, and the intricacies of zero-knowledge proofs.
- Ho Nhut Minh enhanced CuEVM, a GPU-accelerated EVM implementation, by adding multi-GPU support. They also developed a Golang library for seamless integration with the Medusa fuzzer, benchmarking their advancements on high-performance Nvidia H100 GPUs.
- Sergio Garcia built the Tracelon Monitoring Bot, a Telegram bot designed for real-time block monitoring across Ethereum, Bitcoin, and Base. The bot provides crucial alerts for ERC20 balance changes and has continued to contribute to SEAL’s 911 incident response efforts.
Looking Ahead: Sustaining Decentralized Defense
The ETH Rangers Program was conceived with a clear vision: to empower individuals engaged in the often unglamorous, yet critically important, security work that underpins the Ethereum ecosystem. The remarkable diversity of their contributions vividly illustrates the multifaceted nature of "public goods security." This endeavor extends far beyond mere bug detection; it encompasses the development of essential tools, the dissemination of vital knowledge through education and training, the meticulous documentation of findings, the swift and effective response to security incidents, and ultimately, the continuous effort to enhance the overall resilience of the ecosystem.
By actively supporting public goods security work, the ETH Rangers Program has successfully integrated novel tools, groundbreaking research, and critical intelligence into the broader Ethereum landscape. This decentralized approach to security builds a more robust and trustworthy foundation for developers and users worldwide, fostering an environment where innovation can thrive with greater confidence.
The Ethereum Foundation expresses its profound gratitude to all 17 stipend recipients for their invaluable contributions. Special acknowledgment is due to The Red Guild for their hands-on involvement in meticulously reviewing submissions, structuring project milestones, and providing detailed, constructive feedback throughout the program’s duration. The collaborative efforts of Secureum and Security Alliance (SEAL) were also instrumental in the successful establishment and execution of this vital program. The insights and advancements generated by the ETH Rangers Program represent a significant step forward in fortifying Ethereum’s security infrastructure, setting a precedent for future initiatives aimed at cultivating a resilient and secure decentralized future.















