# Round Two Starts Today: ETHSecurity Initiatives

*Onchain security is everyone's problem and nobody's “job”. The ETHSecurity Initiatives Round is our attempt to change that.*

By [TheDAO Security Fund](https://paragraph.com/@thedao.fund) · 2026-09-15

---

What is one thing that would make Ethereum meaningfully safer?  
  
The ETHSecurity Initiatives Round aims to answer that question and fund the best answers. The round is live starting today at [initiatives.thedao.fund](http://initiatives.thedao.fund), with several initiatives on it already and room for a hundred more. 

In our first funding round, more than 20 ecosystem funders and 3,934 donors joined us, and together we put over $1.6M into diverse Ethereum security projects. To date, we've coordinated the funding of over 1,000 ETH to 135 security projects in total. Every payment is on our transparency page, and more than 100 of those teams have already posted about the impact they have had thanks to these donations: [https://thedao.fund/transparency](https://thedao.fund/transparency)

The first round spread funds widely; this round will instead go deep. We will source important security initiatives, post them publicly, and coordinate the funding & execution of the best of them. Think of it as Ethereum's security to-do list, and anyone can add initiatives to the list!

**Today:** Proposing and Fundraising for Ethereum security initiatives is live!  
**Mid-November:** ETHSecurity Badge holders allocate our funds (details coming soon™).  
**End of January:** Round 2 ends and the initiatives left unfunded close with it.

![](https://storage.googleapis.com/papyrus_images/7fd6f17760bfea77509e01801f8fce9cf6f32965b0347074f6d7117570bcb9d8.jpg)

h/t to Owocki for meme inspiration

  
**On The Board Today**  

----------------------------

Ethereum’s to-do list is already filling in with two kinds of initiatives: (1) RFPs (Request for Proposals), which outline a budget and draft milestones, but have no team chosen yet. (2) Grants, which name the team up front, because that team already has a head start on the work. Here’s what’s live today:

*   **End-to-End Formally Verified Vyper Compiler** ($600,000, Grant: Vyper Foundation). Vyper secures billions in Curve, Yearn and Lido. An audit means a lot more when the compiler itself is proven safe. [](https://initiatives.thedao.fund/initiative/end-to-end-formally-verified-vyper-compiler)[https://initiatives.thedao.fund/initiative/vyper-verified-compilation-and-secure-language-upgrades](https://initiatives.thedao.fund/initiative/vyper-verified-compilation-and-secure-language-upgrades)
    
*   **Decentralized, Privacy-Preserving EDR** ($300,000, Grant: Auditware). Endpoint detection (think CrowdStrike) is one of the strongest tools in the OpSec toolbox, but almost no one in crypto runs it, because there isn't an EDR that lives up to our values… yet. [https://initiatives.thedao.fund/initiative/privacy-preserving-edr](https://initiatives.thedao.fund/initiative/privacy-preserving-edr)
    
*   **Provider-Independent, Client-Verified ENS Resolution** ($150,000, RFP: team wanted). Today your wallet resolves an ENS name by trusting one RPC provider's answer. This library checks two and verifies against the chain. [https://initiatives.thedao.fund/initiative/provider-independent-client-verified-ens-resolution](https://initiatives.thedao.fund/initiative/provider-independent-client-verified-ens-resolution)
    
*   **Production-Ready Local-First Safe UI** ($120,000, RFP: team wanted). A Safe multisig UI you can run with nothing but an RPC endpoint and a wallet, so there's no hosted frontend to trust. [https://initiatives.thedao.fund/initiative/production-ready-local-first-safe-ui](https://initiatives.thedao.fund/initiative/production-ready-local-first-safe-ui)
    
*   **Directory of Value** ($185,000, RFP: team wanted). A permissionless registry of the contracts that hold large amounts of value, so researchers and white hats know where to look. [https://initiatives.thedao.fund/initiative/directory-of-value](https://initiatives.thedao.fund/initiative/directory-of-value)
    
*   **OPSEC Ratings Coalition** ($150,000, RFP: team wanted). At least six OpSec auditing firms agreeing on one public rating standard: an L2BEAT for OPSEC. [https://initiatives.thedao.fund/initiative/opsec-ratings-coalition-to-build-maintain-an-l2beat-for-opse](https://initiatives.thedao.fund/initiative/opsec-ratings-coalition-to-build-maintain-an-l2beat-for-opse)
    
*   **Community Fuzzing Tooling for Ethereum Ecosystem Projects** ($150,000, RFP: team wanted). Continuous, compute-heavy fuzzing as a shared service instead of every project paying for its own. [https://initiatives.thedao.fund/initiative/community-fuzzing-tooling-for-ethereum-ecosystem-projects](https://initiatives.thedao.fund/initiative/community-fuzzing-tooling-for-ethereum-ecosystem-projects)
    
*   **thatsRekt: EVM Exploit Alerts for the Public Good** ($45,000, Grant: thatsRekt). Scans the trusted security accounts on X for live exploits and turns them into onchain alerts anyone can read. [https://initiatives.thedao.fund/initiative/thatsrekt-evm-exploit-alerts-for-the-public-good](https://initiatives.thedao.fund/initiative/thatsrekt-evm-exploit-alerts-for-the-public-good)
    
*   **Automated EIP Compliance Checks for Ethereum Clients** ($20,000, Grant: PRSpec). Client teams implement EIPs by reading spec text; this checks the code against the spec so divergences get caught. [https://initiatives.thedao.fund/initiative/automated-eip-compliance-checks-for-ethereum-clients](https://initiatives.thedao.fund/initiative/automated-eip-compliance-checks-for-ethereum-clients)
    
*   **Fund Echidna Development Through 2027** ($48,000, Grant: Echidna). One of the premier open-source smart contract fuzzers, a standard tool in serious audits, funded to keep shipping. [https://initiatives.thedao.fund/initiative/fund-echidna-development-through-2027-2](https://initiatives.thedao.fund/initiative/fund-echidna-development-through-2027-2)
    

Browse the full board, or add to it, at [](https://initiatives.thedao.fund)[initiatives.thedao.fund](http://initiatives.thedao.fund).

**What We’re Doing Differently**
--------------------------------

I (Griff Green) have watched grants programs in crypto fail in countless ways for a decade. We built the ETHSecurity Initiatives Round to avoid the pitfalls.

The big one is that we all too often focus too much on building and not enough on usage and adoption. In this round, **every initiative must put at least a third of its budget behind an adoption milestone**: Named users, real integrations, TVL protected, production use in critical infrastructure. It doesn’t matter if you build something amazing if no one uses it.  
  
The second is that funding tends to be top-down. Someone with authority has an idea, a committee decides it gets funded, and then everyone waits to see how it goes. **Our initiatives are crowdsourced, and the round uses market feedback from the community to decide what gets funded.** Co-funding is the filter. If the teams that would benefit from a piece of security work won't chip in for it, then either it's the wrong solution or they don't think it's urgent or maybe they are asking for too much money, and that's all valuable information. TheDAO Security Fund will only complete initiatives the ecosystem has already signaled support for.  
  
The third is that money often goes out with no strings attached, and everyone hopes it makes an impact. In this round, **funding goes out after milestones are completed, and whether a milestone passes is decided by an independent technical reviewer with no ties to the team**, named in the grant agreement before work begins. Giveth manages the milestone payouts and double-checks the reviewer's work.  
  
We're also applying an important lesson that Round One taught us: There was real demand from big players to fund shared security, but we only had a three-week round and didn't reach out to many of them until it began. Getting large organizations to back something is not as simple as just sending ETH. Round One ended before many of them could coordinate their support. In fact, to finalize the deal with our largest, most generous sponsor, [Wintermute, for $200,000](https://x.com/Giveth/status/2059759742570942649), we had to delay announcing the final results a few days. **The ETHSecurity Initiatives round will run for over four months, until the end of January, and the fundraising conversations start now.**  
  
[The Ethereum Foundation's Trillion Dollar Security](https://blog.ethereum.org/2025/05/14/trillion-dollar-security) initiative has already mapped Ethereum's weakest points and pulled in serious people to fix them, samczsun, Mehdi Zerouali and Zach Obront among them. But the ecosystem has ideas too, and the security of Ethereum shouldn't rely on the Foundation alone; we're here to help fund and coordinate reinforcements.  
  
We have 69,000 ETH staked, earning ~5 ETH a day to support Ethereum security. We hope **ETHSecurity Initiatives becomes a Schelling point for discovering and co-funding the security holes most of us don't even know we have.**

![](https://storage.googleapis.com/papyrus_images/60244964f16aa907630d32754d0e55dd75cf98904a86558cf6b0dc9504bee6f2.png)

**Three Ways To Participate**
-----------------------------

Ready to get involved? Whether you have an idea that would make Ethereum safer, an org that would benefit from security work getting done, or a team that could deliver it, there's a way in:

**Propose.** If you already have a good idea for an initiative that would make Ethereum safer, it should take less than half an hour to propose it, and a few days for our team to approve it. Go to [https://initiatives.thedao.fund/submit](https://initiatives.thedao.fund/submit), copy the AI guide, talk it through with whichever LLM you use, and paste the result into the form. 

**Fund.** Pledge as a company to fund a specific initiative, and your logo goes on its initiative or anyone can simply donate directly to the initiative’s multisig. If you or your organization would benefit from a piece of work, put in 15% and help us raise the rest. It's a lot cheaper than paying for the whole thing yourself!

**Build.** Follow the RFPs you could deliver. When one is fully funded, a 30-day proposal window opens, and any qualified team can bid.

**The Details**
---------------

You can skip this section unless you want to get into the nitty-gritty details.

![](https://storage.googleapis.com/papyrus_images/86594c6e423dd0d9e597fda9cd15140d48cb5ffa2344aebf2569403849a032ca.png)

### **Ideation: proposing the right solutions**

Our goal is to create an open market of ideas for improving Ethereum security.

After an initiative is proposed, it needs to be approved. TheDAO Security Fund, through Giveth, reviews every submission and helps shape it into a clear initiative with a defined scope, budget, and draft milestones.

For RFPs, we're actively discussing problems and potential solutions with large ecosystem players who see opportunities to improve security for themselves and the wider ecosystem but can't take the work on themselves. RFPs are the initiatives you can put on someone else's to-do list. Every RFP comes with an example solution, so the budget, the adoption milestones, and a clear picture of what a solution could look like are outlined from day one.

Grants are for teams that are extremely well positioned to make Ethereum safer with a solution they've already been working on. A Grant proposal includes definitive milestones and a thorough justification of why this team is the one to deliver. Grants already in progress that need further funding to finish are invited too.   

### **Co-funding: market signal**

Co-funding is how we test for real need: If the potential beneficiaries of a piece of security work are willing to overcome the natural free-rider tendency and fund it, that's a strong signal. For projects with security needs, it’s also the chance to share the cost with the other teams that benefit, and with TheDAO Security Fund itself. Work that was too big for any single player to fund can get supported by those who benefit from it.

Funding comes in three ways:

*   Anyone can donate directly to each initiative's multisig. 
    
*   Companies sign pledges to sponsor specific initiatives. Pledged money is only collected once the initiative is fully funded, and the backer's logo is proudly promoted alongside the initiative.
    
*   Initiatives that aren't fully funded before mid-november will be ranked by the 200 ETHSecurity Badge holders, and the top initiatives get completed from TheDAO Security Fund's treasury. Details on how voting will work are coming soon™.
    

If an initiative doesn't get enough funding and doesn't make the badge holders' final cut by the end of January, its pledges are never collected.

  

### **Proposal submission: team selection and milestone finalization**

Once an RFP is fully funded, a 30-day proposal window opens, and teams submit proposals on the platform. The milestones in the RFP are only an illustrative draft of a potential solution, and improving them, or even throwing them out to propose a different solution is encouraged, especially given the speed of development we're seeing now in the age of AI.

When proposing the final milestones, at least a third of the budget still must be reserved for adoption, and for RFPs, the strength of those adoption milestones is an important part of how competing proposals are judged. Giveth, with the help of a team of technical experts, selects the team within 7 days of the window closing.

For a fully funded Grant there is a 15-day window in which the named team files its formal plan with the timeline and final milestones set.

  

### **Execution: turning milestones into impact**

Once a team is selected, an agreement is signed and work can start.

*   The first milestone can be paid up to 50% in advance so the team has funding to start. If more funds are needed at any point to complete the work, the team is expected to reach out to the ecosystem for a stop-gap loan.
    
*   Each milestone is judged pass or fail by an independent technical reviewer named in the agreement, and paid within 14 days of acceptance. Giveth manages the payouts and double-checks the reviewer.
    

If a milestone stalls past its agreed delivery date, the team gets a 21-day deadline to complete it. If they miss it, TheDAO Security Fund can reclaim the unspent funds and put them toward other Ethereum security initiatives.

**Reach out to us!**
--------------------

If you have an idea and want help shaping it into an initiative;

If you want to know which initiatives your organization should be backing;

If you want to help raise funds for initiatives;

Or if you just want to compare notes on what Ethereum needs next;

TALK TO US!

We are going to be at ETHSpain, ETHTokyo, Token2049, and Devcon but you can find us terminally online by DMing [@griffgreen](https://t.me/griffgreen), [@Snakeagram](https://t.me/snakeagram), or [@Cotabe](https://t.me/Cotabe) on Telegram, or emailing [info@thedao.fund](mailto:info@thedao.fund).  
  
And let's get to work securing Ethereum!

---

*Originally published on [TheDAO Security Fund](https://paragraph.com/@thedao.fund/round-two-starts-today-ethsecurity-initiatives)*
