“ASP will run the pilot: every funded team will receive an AI-assisted review ahead of its full audit, with lower-cost AI screening available to earlier-stage teams, and all five tools running in parallel for evaluation.”
40%· weak fit · The Venture23 Aleo team has relevant security and dev tooling expertise, but they operate in the Aleo ecosystem rather than Arbitrum, making them an adjacent but not native applicant.
Trust
100%· model self-report 85% · first seen 2026-09-09 · v6
Verified
2026-09-15 · reverted: earlier open match was a regex false positive
The Arbitrum Foundation is offering a one-year security program to fund AI-assisted screening, full audits, bug bounties, and Security Council support for teams building on Arbitrum. The program targets ecosystem teams seeking to improve smart contract security, with deliverables including vulnerability remediation and protocol-level security contributions. Applications will open by October 1st, 2026, on a rolling basis until funds are exhausted. Funding comes from the Foundation's existing balance of $1.76M USDC and 25M ARB, less predicted outstanding deployments.
Eligibility: Ecosystem teams building on Arbitrum, with preference for early-stage projects; requires at least 1 year of runway and capacity to cover part of audit cost (based on lessons learned).
Pipeline
Trust breakdown (4/4 checkable facts verified)
Signal
Weight
Result
Note
deadline
0.35
100%
source says rolling
amount
0.25
100%
figure appears in source
apply link
0.075
100%
link in source
funder
0.075
100%
named in source
source quality
0.15
60%
forum post
model confidence
0.1
85%
model self-report
corroboration
bonus
+10%
3 sources
Fit breakdown (against the ORG_* profile)
Signal
Weight
Result
Note
model fit
0.5
70%
model rated 70%
ecosystem overlap
0.25
0%
arbitrum vs aleo
category overlap
0.15
33%
security, dev_tooling, research vs zk, privacy, infra, dev_tooling, security, interoperability
# [](#p-77664-arbitrum-security-program-1)Arbitrum Security Program
## [](#p-77664-abstract-2)Abstract
The Arbitrum Foundation proposes to continue and evolve the Arbitrum Audit Program (AAP) - [launched on 1 August 2025](https://blog.arbitrum.foundation/arbitrums-10m-audit-program-is-live-apply-to-secure-your-smart-contracts/) with a one-year mandate - into a broader Arbitrum Security Program (ASP), running for a further 12 months on a rolling-application basis.
* **From “Audit” to “Security”.** AAP delivered on its original purpose - real vulnerabilities surfaced and remediated before mainnet, with a high share of net-new teams brought to Arbitrum - and demonstrated where subsidised security converts into the most ecosystem value. Building on that, the mandate broadens to four pillars covering the full security lifecycle: AI-assisted screening ahead of a full audit, the human-conducted audit itself, the Arbitrum bug bounty program, and the ArbitrumDAO Security Council.
* **No new treasury request.** ~$2M in cumulative audit commitments is expected by AAP’s close. The remaining $1.76M USDC + 25M ARB held by the Foundation becomes ASP’s operational budget, less ~$1.2M in predicted outstanding deployments.
* **Operational refinements from a year of experience.** The audit committee technical expert retainer is right-sized to $2.5k/month based on expected workload; the [DAO-approved](https://snapshot.box/#/org/arbitrum/s:arbitrumfoundation.eth/proposal/0xa8d3dbf1b6cbe81847b5165da5d194d2fc554ae223f6ccf77f53c3fdecc6987e) alignment framework is maintained as the program’s baseline; program changes adopt a lightweight optimistic approval process to reduce governance overhead; and idle funds are put to work in low-risk management strategies.
The program runs for one year (or until funds are exhausted), managed by the Arbitrum Foundation and supported by the audit committee as technical SME, with quarterly transparency reports and a final summary report to the DAO.
## [](#p-77664-motivation-3)Motivation
The AAP was [approved by ArbitrumDAO](https://forum.arbitrum.foundation/t/arbitrum-audit-program/28368) to remove a barrier facing early-stage teams: third-party audits are the industry norm, but their cost puts them out of reach for many young projects. The program’s full design - objectives, eligibility, application process, auditor approval, and alignment commitments including Arbitrum exclusivity - is set out in the original proposal, and its performance has been reported quarterly ([#1](https://forum.arbitrum.foundation/t/arbitrum-audit-program-transparency-report-1/30392), [#2](https://forum.arbitrum.foundation/t/arbitrum-audit-program-transparency-report-2/30597), [#3](https://forum.arbitrum.foundation/t/arbitrum-audit-program-transparency-report-3/30976)).
### [](#p-77664-results-4)Results
_(covering Q1-Q3 and preliminary Q4, prior to final report)_
367 applications were received through preliminary Q4, with application-to-decision time averaging 2-3 weeks. To date, 18 completed audits reviewed 71,366 lines of code and identified 385 vulnerabilities - 13 critical and 40 high - remediated before mainnet. The average audit cost was $50,706, approximately $15 per line of code, which sits below the industry average of $70,000 for mid-complexity DeFi audits as per market references provided by [Sherlock](https://sherlock.xyz/post/smart-contract-audit-pricing-a-market-reference-for-2026) and [Zealynx](https://www.zealynx.io/research/audit-ops/audit-pricing-2026). The total commitments are expected to reach ~$2M once in-progress and pending audits are activated.
### [](#p-77664-what-worked-5)What Worked
* **The program delivered on its original mandate.** With ~60% of funded teams net new to the ecosystem, it attracted security-first founders who might otherwise have launched elsewhere.
* **It demonstrated Arbitrum’s dedication to user security.** Funding security work upfront led to tangible critical findings, remediated before mainnet.
* **Operationally the program matured.** A growing referral channel now drives roughly half of onboarded teams, and pricing has stayed within benchmarked ranges.
### [](#p-77664-lessons-learned-6)Lessons Learned
* **Early-stage teams didn’t have enough runway to benefit from audits.** Some recipients were unable to move forward after receiving funding, in a few cases winding down within months. Future eligibility should require at least 1 year of runway and the capacity to cover part of the audit cost.
* **Value secured has concentrated in later-stage teams** that could typically fund audits themselves - a tension with the early-stage mandate, since younger projects generally need more time to grow TVL for their product.
* **Lead times are long.** Audit contract signature to mainnet launch averages ~135 days for teams not yet live.
* **Impact was real, but visibility was low.** Audit subsidies set Arbitrum apart from other ecosystems, but the program received too little visibility to capitalize on that. Going forward, funded teams will be asked to publicly acknowledge the subsidy, among other improvements to program communications.
These results and lessons, among others, shape the adjustments below.
## [](#p-77664-specifications-7)Specifications
### [](#p-77664-program-adjustments-8)Program Adjustments
#### [](#p-77664-h-1-expand-scope-with-ai-audits-9)**1\. Expand Scope with AI Audits**
AAP identified five AI security agents to be trialed under this program. ASP will run the pilot: every funded team will receive an AI-assisted review ahead of its full audit, with lower-cost AI screening available to earlier-stage teams, and all five tools running in parallel for evaluation.
#### [](#p-77664-h-2-expand-scope-with-core-protocol-security-bug-bounty-security-council-10)**2\. Expand Scope with Core Protocol Security: Bug Bounty & Security Council**
Audits are point-in-time; protecting the core protocol that every funded team builds on also requires continuous review of live code and emergency response - the program’s third and fourth pillars:
* **Bug Bounty (continuous review).** Arbitrum operates a [bug bounty](https://immunefi.com/bug-bounty/arbitrum/) covering the Arbitrum One and Arbitrum Nova smart contracts, with rewards of up to $2,000,000 for critical findings - a maximum that has never been paid out since the Foundation began running the program. Its scope remains the Arbitrum protocol codebase; ecosystem teams’ codebases are covered through the AI-screening and audit pathway above.
* **Security Council (emergency response).** The ArbitrumDAO Security Council is the DAO-elected body empowered by the Constitution to respond to security emergencies affecting the protocol in production, and has been historically funded by the AF on behalf of the DAO.
Both are included for the reason set out in the Abstract: redirecting part of the unspent allocation toward the security layers with the highest impact on the ecosystem - every team, user, and dollar of TVL on Arbitrum ultimately depends on the integrity of the core protocol they protect - with no change to the bounty’s scope and reward terms or to the Council’s compensation, election process, and constitutional mandate. Bug and bounty reporting will be provided yearly at a high level, e.g., total payout amounts.
#### [](#p-77664-h-3-maintain-alignment-framework-11)**3\. Maintain Alignment Framework**
After strict exclusivity created material friction during AAP, the requirement was revised via a [formal governance proposal](https://forum.arbitrum.foundation/t/improvements-to-the-arbitrum-audit-program/30697) into a DAO-approved, alignment-based framework, which ASP adopts as its baseline.
#### [](#p-77664-h-4-introduce-a-lightweight-governance-process-12)**4\. Introduce a Lightweight Governance Process**
Adjusting the exclusivity framework during AAP showed that putting every program change through the full governance process adds significant overhead. ASP therefore adopts the optimistic approval framework from the recent [Code of Conduct proposal](https://snapshot.box/#/org/arbitrum/s:arbitrumfoundation.eth/proposal/0xf78c223115031090b918ea09fa585d340718a426a21eb1556d81d19892e10b39): changes posted to the forum by the AF take effect after 14 days unless a combined 5% of delegated VP (measured at the time of posting) raises objections, in which case the change goes to an off-chain vote at the non-constitutional quorum. The AF is responsible for monitoring objections and tallying VP.
#### [](#p-77664-h-5-enable-idle-funds-deployment-13)**5\. Enable Idle Funds Deployment**
Lastly, with the majority of AAP funds remaining unproductive for the duration of the program, we propose that ASP deploy idle funds into low-risk management strategies.
### [](#p-77664-budget-14)Budget
AAP was funded through a 30M ARB allocation, part of which was converted to cover audit commitments and the $60k technical expert retainer; roughly $1.23M was committed by the end of Q3, expected to reach ~$2M by program close (cumulative over the program’s duration). ASP requests no new funding: it operates from the actual remaining balance already held by the Foundation - $1.76M USDC plus 25M ARB - less ~$1.2M in predicted outstanding deployments (final amount depends on total audit commitments, some of which may not materialize). This budget covers the expanded scope:
* Audit, AI screening and security subsidies for ecosystem teams.
* Arbitrum protocol bug bounties: operation of the bug bounty program, with contingent reward payouts for validated findings.
* Security Council: member compensation of $5,000 per member per month across the 12-member Council, i.e., $720,000 per year.
* Technical expert: retainer of $2,500/month (down from $5,000/month, or $60,000/year, in AAP), reflecting updated workload.
* All other costs (legal, program management, operations) remain covered by the Arbitrum Foundation.
As in AAP, funds committed towards audits will be disclosed in each quarterly transparency report, giving the DAO visibility into deployment pace against the remaining balance. Any balance unspent at term end returns to the ArbitrumDAO treasury unless the DAO approves a continuation
## [](#p-77664-timeline-15)Timeline
With AAP applications closed on 31 July 2026 and an approximate two-month wind-down underway, continuity of a live audit offering is an important matter for builders on Arbitrum. We propose the following governance timeline, subject to delegate feedback:
1. August 13th → Proposal posted in the forum (complete)
2. August 20th → Binding off-chain vote following non-constitutional quorum
3. By October 1st → Applications open for the program, with an official announcement declaring the start date and the one-year clock.