In late 2024, a significant initiative aimed at bolstering the security of the Ethereum network was launched, marking a pivotal moment in the ongoing efforts to safeguard decentralized infrastructure. The Ethereum Foundation, in collaboration with key security-focused organizations Secureum, The Red Guild, and the Security Alliance (SEAL), unveiled the ETH Rangers Program. This groundbreaking initiative was designed to provide vital financial support, in the form of stipends, to independent individuals dedicated to public goods security work within the expansive Ethereum ecosystem.
The program’s objective was clear and focused: to empower and fund grassroots efforts that demonstrably enhance the resilience and security posture of Ethereum. Simultaneously, it sought to formally recognize individuals who had already established a track record of meaningful contributions to critical security work that benefits the entire Ethereum community. This dual approach recognized both the need to incentivize ongoing security endeavors and to honor those already making a tangible difference.
Now, with the conclusion of the six-month ETH Rangers Program, the tangible outcomes of the 17 stipend recipients’ diligent work are coming to light. The scope of their contributions is nothing short of impressive, spanning a wide spectrum of crucial security domains. This includes in-depth vulnerability research, the development of essential security tooling, comprehensive educational initiatives, sophisticated threat intelligence gathering, and proactive incident response mechanisms. The collective output from these dedicated individuals underscores a fundamental truth: securing a decentralized network necessitates a decentralized defense. From the foundational layers of protocol-level vulnerability research to the widespread dissemination of knowledge through global developer education, these independent researchers have forged infrastructure that promises to amplify security effects across the entirety of the Ethereum ecosystem.
Project Highlights: Illuminating Key Contributions
The ETH Rangers Program has yielded a diverse array of impactful projects, each contributing to the overall security and robustness of Ethereum. Among the most notable are:
SunSec – DeFiHackLabs: A Force Multiplier for Security Education
The collaboration between SunSec and the DeFiHackLabs community has resulted in an extraordinary volume of security education and tooling development. During the stipend period, DeFiHackLabs, under SunSec’s guidance, achieved several key milestones:
- Extensive Educational Content Creation: Over 50 detailed educational articles and tutorials were produced, covering a broad range of smart contract security topics, from foundational principles to advanced exploitation techniques.
- Development of Security Tools: Several open-source security tools and scripts were developed and released, aimed at assisting developers and auditors in identifying common vulnerabilities. These tools have been integrated into existing security workflows.
- Community Engagement and Training: The community organized and hosted multiple online workshops and live coding sessions, directly engaging with hundreds of security researchers and developers. These sessions provided practical, hands-on learning experiences.
- Vulnerability Disclosure Assistance: DeFiHackLabs provided support and guidance to community members who discovered vulnerabilities, facilitating responsible disclosure processes and ensuring that critical issues were addressed by project teams.
The sheer scale of community activation demonstrated by DeFiHackLabs is particularly noteworthy. The project operates as a potent multiplier, transforming a single stipend into a cascade of educational output that benefits a vast network of security researchers. This model effectively democratizes access to high-quality security knowledge, empowering a wider range of individuals to contribute to Ethereum’s security.
Ketman Project – DPRK IT Worker Investigations: A Critical Defense Against State-Sponsored Threats
One recipient focused their stipend on a critically important, albeit often overlooked, security threat: the infiltration of North Korean (DPRK) IT workers into blockchain projects. The Ketman Project, built and scaled with the stipend, actively works to identify and expunge these malicious actors who often operate under fake identities, posing a significant risk to the integrity and security of decentralized applications and protocols.
During the stipend period, the Ketman Project achieved the following:
- Developed Advanced Detection Methodologies: Created and refined sophisticated techniques for identifying suspicious patterns in developer activity, code contributions, and network interactions that are characteristic of DPRK operatives.
- Identified and Reported Infiltrated Workers: Successfully identified multiple instances of DPRK IT workers embedded within various blockchain projects. These findings were rigorously documented and reported to relevant project teams and security organizations, leading to the removal of compromised individuals.
- Published Threat Intelligence Reports: Released detailed reports outlining the modus operandi of DPRK IT workers, providing valuable intelligence to the broader blockchain security community. These reports include analysis of their tactics, techniques, and procedures (TTPs).
- Enhanced Due Diligence Frameworks: Contributed to the development of more robust due diligence processes for blockchain projects, helping them to better screen potential contributors and mitigate the risk of state-sponsored infiltration.
This work directly addresses one of the most pressing operational security threats facing the Ethereum ecosystem today. The persistent efforts of the Ketman Project and its allies are crucial in maintaining the trust and security of decentralized platforms against sophisticated adversaries.
Nick Bax – Incident Response and Threat Intelligence: A Multifaceted Security Sentinel
Nick Bax, a seasoned security professional, made significant contributions across multiple critical areas, primarily through his involvement with SEAL 911 incident response, DPRK threat mitigation, and public awareness campaigns. His work exemplifies the proactive and reactive measures necessary to maintain a secure blockchain environment.
Key contributions include:
- Active Incident Response: Played a pivotal role in SEAL 911’s rapid response efforts to numerous security incidents within the Ethereum ecosystem, providing critical analysis and mitigation strategies during active exploits.
- DPRK Threat Mitigation: Collaborated with the Ketman Project and other initiatives to counter the threat posed by North Korean IT workers, contributing expertise in threat analysis and counter-intelligence.
- Development of Threat Intelligence Resources: Contributed to the creation and maintenance of threat intelligence databases and frameworks, providing valuable insights into emerging attack vectors and adversary tactics.
- Public Awareness and Education: Authored articles and participated in discussions aimed at educating the broader community about prevalent security risks and best practices for protecting digital assets and decentralized applications.
Bax’s multifaceted contributions highlight the interconnectedness of incident response, threat intelligence, and proactive defense mechanisms in safeguarding the Ethereum ecosystem.
Guild Audits – Security Education in Africa and Beyond: Building Future Security Talent
Guild Audits has been instrumental in fostering security expertise through intensive smart contract security bootcamps, effectively training the next generation of Ethereum security researchers. This initiative is crucial for developing a global pipeline of skilled professionals capable of securing complex decentralized systems.
The impact of Guild Audits’ bootcamps includes:
- Comprehensive Curriculum Development: Designed and delivered rigorous training programs covering advanced smart contract auditing techniques, formal verification methods, and secure coding practices.
- Global Reach and Accessibility: Conducted bootcamps in various regions, with a particular focus on Africa, aiming to bridge the security talent gap and empower underrepresented communities with in-demand skills.
- Creation of a Skilled Talent Pool: Graduated numerous participants who have gone on to contribute to security audits, vulnerability research, and the development of secure smart contracts within the Ethereum ecosystem.
- Partnerships and Mentorship: Forged partnerships with other security organizations and provided ongoing mentorship to alumni, fostering a supportive community for continuous learning and professional development.
The capacity-building impact of Guild Audits’ smart contract security bootcamps is substantial. They are creating a vital pipeline of skilled security researchers in regions that have historically been underrepresented in the global Ethereum security community, thereby diversifying and strengthening the ecosystem’s overall security resilience.
Palina Tolmach – Kontrol: Making Formal Verification More Accessible
Palina Tolmach, working with Runtime Verification, dedicated her stipend to enhancing Kontrol, a powerful formal verification tool for Ethereum smart contracts. Her work focused on making this sophisticated tool more accessible and user-friendly for developers and security researchers, thereby lowering the barrier to entry for formal verification practices.
Key Kontrol improvements delivered include:
- Enhanced User Interface and Experience: Streamlined the user interface of Kontrol, making it more intuitive and easier for users to navigate and leverage its advanced features.
- Improved Documentation and Tutorials: Developed comprehensive documentation, including detailed guides and practical tutorials, to assist users in understanding and effectively applying Kontrol to their smart contracts.
- Integration with Development Workflows: Worked on better integration of Kontrol with common development environments and tools, allowing for seamless incorporation into existing smart contract development pipelines.
- Expanded Verification Capabilities: Introduced new verification patterns and strengthened existing ones, enabling Kontrol to analyze a wider range of smart contract logic and identify more complex potential issues.
All of this work has been made open-source and is available on GitHub, significantly improving the formal verification tooling landscape for all security researchers. This effort democratizes access to a critical security technology, empowering more developers to build more secure smart contracts from the outset.
Ethereum Execution Client DoS Research: Fortifying Network Infrastructure
A dedicated research team utilized their stipend to develop a sophisticated testing framework designed to systematically evaluate the robustness of Ethereum execution clients against message-flooding denial-of-service (DoS) attacks. This research is fundamental to understanding and mitigating vulnerabilities in the core infrastructure of the Ethereum network.
Key findings and outcomes from this research include:
- Development of a Comprehensive Testing Framework: Created an automated framework capable of simulating realistic message-flooding scenarios across various network protocol layers.
- Extensive Testing of Major Clients: Conducted rigorous testing on all five major Ethereum execution clients: Geth, Besu, Erigon, Nethermind, and Reth.
- Discovery of Critical Bugs: Identified a significant total of 14 bugs across different execution clients and network protocol layers. These vulnerabilities, if exploited, could lead to:
- Node Crashes: Causing individual nodes to become unresponsive and cease operation.
- Network Partitioning: Potentially isolating segments of the network, disrupting consensus and transaction propagation.
- Increased Resource Consumption: Leading to excessive CPU and memory usage, impacting node performance and stability.
- Demonstrated Universality of Vulnerability: The findings conclusively highlight that no single execution client is entirely immune to message-flooding attacks. This underscores the pervasive nature of such threats within decentralized networks.
The research team has shared their comprehensive testing framework and detailed findings with the Ethereum Foundation’s Protocol Security team. This collaboration is crucial for informing further client security research and guiding the development of effective countermeasures, such as adaptive rate-limiting mechanisms, to enhance the resilience of Ethereum’s execution layer.
Other Stipend Recipients: A Diverse Spectrum of Security Contributions
While detailed write-ups were not feasible for every recipient due to space constraints, the remaining stipend recipients have made equally valuable contributions across a broad spectrum of security-related public goods. Their work collectively reinforces the decentralized nature of Ethereum’s security efforts:
- Kelsie Nabben: Authored a seminal book, "Decentralised Digital Security Communities," drawing on 2.5 years of ethnographic research into decentralized digital security communities, including SEAL. This work provides invaluable sociological and anthropological insights into the human element of blockchain security.
- Mothra Team: Developed Mothra, an advanced Ghidra extension specifically designed for EVM bytecode reverse engineering. This tool includes crucial support for EOF (Ethereum Object Format) decompilation, significantly enhancing the capabilities of security researchers analyzing smart contracts. Detailed technical write-ups on the development process have also been published.
- SomaXBT: Published an insightful four-part series on blockchain forensics and the crypto threat landscape. This series delved into fund tracing methodologies, attribution techniques for malicious actors, and open-source intelligence (OSINT) methods, providing practical guidance for investigators.
- Peter Kacherginsky: Launched BlockThreat, a comprehensive platform dedicated to blockchain threat intelligence. BlockThreat meticulously analyzes past blockchain security incidents, dissecting their root causes and providing actionable insights for preventing future occurrences.
- Attack Vectors: Created attackvectors.org, an open-source, continuously updated resource that details the most prevalent attack vectors in Decentralized Finance (DeFi). The website offers practical prevention strategies and has also contributed significantly to SEAL’s Wallet Security Framework, with the contributor becoming a SEAL Steward.
- Tim Fan: Developed D2PFuzz, a novel fuzzing framework for the DevP2P protocol. This framework employs differential testing across multiple execution layer clients, successfully identifying bugs through both single-client and cross-client testing scenarios.
- nft_dreww: Contributed actively through publishing security articles, hosting educational classes via Boring Security, and conducting vital audits on Ethereum public goods projects, demonstrating a commitment to both knowledge dissemination and direct security enhancement.
- Jean-Loïc Mugnier: Developed a Web3 transaction simulation Chrome extension designed to intercept and simulate transactions before they are finalized by the wallet. This tool, coupled with research into simulation spoofing, offers an additional layer of defense for users.
- Alexandre Melo: Produced a series of valuable security workshop videos covering a wide array of topics, including fuzzing, smart accounts, AI-driven auditing, Solana security, and zero-knowledge proofs, making advanced security concepts more accessible.
- Ho Nhut Minh: Significantly enhanced CuEVM, a GPU-accelerated EVM implementation. The improvements include robust multi-GPU support and a Golang library for seamless integration with the Medusa fuzzer, with performance benchmarks conducted on high-performance Nvidia H100 GPUs.
- Sergio Garcia: Built the Tracelon Monitoring Bot, a Telegram bot that provides real-time block monitoring across Ethereum, Bitcoin, and Base. The bot offers crucial ERC20 balance change alerts and continues to contribute to SEAL 911 incident response efforts.
Looking Ahead: The Enduring Impact of Decentralized Defense
The ETH Rangers Program was conceived with a clear purpose: to champion individuals engaged in the often unglamorous yet absolutely essential security work that underpins the Ethereum network. The remarkable diversity of their contributions serves as a powerful testament to the multifaceted nature of "public goods security" in practice. This initiative demonstrates that security extends far beyond merely identifying vulnerabilities; it encompasses the crucial tasks of developing innovative tools, cultivating expertise through training, meticulously documenting knowledge, efficiently responding to incidents, and ultimately, building a more resilient ecosystem for all.
By strategically supporting public goods security work, the ETH Rangers Program has successfully integrated a wealth of new tools, critical research, and vital intelligence into the broader Ethereum ecosystem. This decentralized approach to defense creates a more robust and secure foundation, benefiting builders and users alike, not just within Ethereum but across the global decentralized landscape.
The Ethereum Foundation expresses profound gratitude to all 17 stipend recipients for their invaluable contributions. Special thanks are extended to The Red Guild for their hands-on involvement in meticulously reviewing submissions, structuring project milestones, and providing detailed, constructive feedback throughout the program’s duration. Furthermore, the Foundation acknowledges and appreciates the collaborative efforts of Secureum and Security Alliance (SEAL) in establishing and supporting this vital initiative. The success of the ETH Rangers Program sets a precedent for future endeavors aimed at strengthening the decentralized security infrastructure upon which the future of the internet is being built.















