The Ethereum Foundation, together with Secureum, The Red Guild, and the Security Alliance (SEAL), has published the final report for ETH Rangers, a security-focused initiative designed to fund independent researchers providing public goods for the Ethereum ecosystem. Launched in late 2024, the program aimed to strengthen Ethereum’s security posture by backing contributors working on critical but often underfunded security efforts.
Six-Month Program Delivered Measurable Results
According to the report, the project supported 17 grantees during a six-month funding period. Their work led to several notable outcomes, including the recovery or freezing of more than $5.8 million, the reporting or documentation of over 785 vulnerabilities and client bugs, the identification of approximately 100 North Korean IT workers across multiple teams, and the handling of more than 36 incident responses.
These figures highlight that ETH Rangers went beyond academic or theoretical security work. The initiative had direct operational impact across asset protection, bug discovery, client-level issue tracking, and ecosystem-wide incident response. In practical terms, it helped reinforce Ethereum’s broader security infrastructure through coordinated public-interest research.
Funding Public-Goods Security Research
The structure of ETH Rangers reflects a broader effort to support independent security researchers whose work benefits the entire ecosystem, even when it is not tied to a single commercial entity. By funding these contributors, the Ethereum Foundation and its partners sought to close a persistent gap in public-goods security work and enable sustained engagement on high-impact tasks.
The final report also points to a more systematic approach to security across Ethereum. Compared with one-off bounties or ad hoc collaborations, recurring support programs can help build a more reliable researcher network, improve vulnerability discovery, and strengthen coordination during major incidents. Based on the reported outcomes, ETH Rangers appears to have delivered meaningful value in its first run and may serve as an important model for future ecosystem security efforts.

