惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园 - 三生石上(FineUI控件)
Hugging Face - Blog
Hugging Face - Blog
M
MIT News - Artificial intelligence
T
Tailwind CSS Blog
Webroot Blog
Webroot Blog
S
Secure Thoughts
N
News and Events Feed by Topic
月光博客
月光博客
TaoSecurity Blog
TaoSecurity Blog
Microsoft Azure Blog
Microsoft Azure Blog
B
Blog RSS Feed
N
News | PayPal Newsroom
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
小众软件
小众软件
Recent Commits to openclaw:main
Recent Commits to openclaw:main
P
Privacy & Cybersecurity Law Blog
GbyAI
GbyAI
K
Kaspersky official blog
WordPress大学
WordPress大学
P
Proofpoint News Feed
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
博客园 - 叶小钗
W
WeLiveSecurity
Jina AI
Jina AI
The Cloudflare Blog
Project Zero
Project Zero
Simon Willison's Weblog
Simon Willison's Weblog
V
Vulnerabilities – Threatpost
L
LangChain Blog
Forbes - Security
Forbes - Security
PCI Perspectives
PCI Perspectives
Engineering at Meta
Engineering at Meta
Google DeepMind News
Google DeepMind News
Recorded Future
Recorded Future
博客园 - 【当耐特】
H
Heimdal Security Blog
A
About on SuperTechFans
Cisco Talos Blog
Cisco Talos Blog
T
Threat Research - Cisco Blogs
云风的 BLOG
云风的 BLOG
Spread Privacy
Spread Privacy
L
LINUX DO - 最新话题
L
Lohrmann on Cybersecurity
Last Week in AI
Last Week in AI
Google DeepMind News
Google DeepMind News
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
I
Intezer
Martin Fowler
Martin Fowler
S
Securelist
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint

Ethereum Foundation Blog

Checkpoint #9: Apr 2026 | Ethereum Foundation Blog How L1 and L2s can build the strongest possible Ethereum | Ethereum Foundation Blog The Promise of Ethereum: Introducing the EF Mandate | Ethereum Foundation Blog This Is Fine (Until the Grant Runs Out) | Ethereum Foundation Blog Treasury Staking Initiative | Ethereum Foundation Blog The Ethereum Foundation's Commitment to DeFi | Ethereum Foundation Blog Protocol Priorities Update for 2026 | Ethereum Foundation Blog Announcing the Platform Team at EF | Ethereum Foundation Blog Ethereum Protocol Studies 2026 | Ethereum Foundation Blog Executive Leadership Update | Ethereum Foundation Blog An update from Tomasz | Ethereum Foundation Blog Introducing the EF Academic Secretariat 2026 PhD Fellowship | Ethereum Foundation Blog Allocation Update - Q4 2025 | Ethereum Foundation Blog Checkpoint #8: Jan 2026 | Ethereum Foundation Blog Devcon 8 is coming to Mumbai, India in November 2026 | Ethereum Foundation Blog Hegota Upgrade EIP Proposal Timelines | Ethereum Foundation Blog Shipping an L1 zkEVM #2: The Security Foundations | Ethereum Foundation Blog The Future of Ethereum’s State | Ethereum Foundation Blog Devconnect Argentina Recap | Ethereum Foundation Blog Allocation Update - Q3 2025 | Ethereum Foundation Blog Making Ethereum Feel Like One Chain Again | Ethereum Foundation Blog Checkpoint #7: Nov 2025 | Ethereum Foundation Blog Fusaka Mainnet Announcement | Ethereum Foundation Blog 2 weeks to Devconnect: Everything you need to know | Ethereum Foundation Blog Unveiling ESP's New Grants Program | Ethereum Foundation Blog Fusaka Update – Transaction Gas Limit Cap arrives with EIP-7825 | Ethereum Foundation Blog Fusaka Update - Information for Blob users | Ethereum Foundation Blog Announcing the 2026 EF Internship | Ethereum Foundation Blog Supporting privacy with new funding mechanisms | Ethereum Foundation Blog The Ethereum Foundation’s Commitment to Privacy | Ethereum Foundation Blog Checkpoint #6: Oct 2025 | Ethereum Foundation Blog Privacy Cluster Leadership Announcement | Ethereum Foundation Blog Fusaka Testnet Announcement | Ethereum Foundation Blog Announcing the districts of the Ethereum World’s Fair | Ethereum Foundation Blog Fusaka $2,000,000 Audit Contest! | Ethereum Foundation Blog Holešky Testnet Shutdown Announcement | Ethereum Foundation Blog The Ecosystem Support Program's Next Chapter | Ethereum Foundation Blog Protocol Update 003 — Improve UX | Ethereum Foundation Blog Protocol Update 002 - Scale Blobs | Ethereum Foundation Blog Trillion Dollar Security - Phase 2 | Ethereum Foundation Blog Join Us: EF Protocol Reddit AMA - August 29th, 2025 | Ethereum Foundation Blog Protocol Update 001 – Scale L1 | Ethereum Foundation Blog lean Ethereum | Ethereum Foundation Blog Celebrating 10 Years of Ethereum | Ethereum Foundation Blog Checkpoint #5: July 2025 | Ethereum Foundation Blog Allocation Update - Q2 2025 | Ethereum Foundation Blog The Future of Ecosystem Development at the EF | Ethereum Foundation Blog Shipping an L1 zkEVM #1: Realtime Proving | Ethereum Foundation Blog Partial history expiry announcement | Ethereum Foundation Blog Checkpoint #4: Berlinterop | Ethereum Foundation Blog World Experience: Updates from the Next Billion Fellowship | Ethereum Foundation Blog Now accepting interns - Join the Ethereum Season of Internships | Ethereum Foundation Blog Tickets are live for the Ethereum World’s Fair! And we're launching the Supporter Program | Ethereum Foundation Blog Ethereum Foundation Treasury Policy | Ethereum Foundation Blog Checkpoint #3: June 2025 | Ethereum Foundation Blog Announcing the Devconnect ARG Scholars Program | Ethereum Foundation Blog Announcing Protocol | Ethereum Foundation Blog Nyota Interop Recap ✨ | Ethereum Foundation Blog Allocation Update - Q1 2024 | Ethereum Foundation Blog Announcing the Ethereum Protocol Fellowship Cohort 5 | Ethereum Foundation Blog Ethereum Protocol Fellowship Cohort 4 Recap | Ethereum Foundation Blog Sepolia Incident | Ethereum Foundation Blog Announcing the Devcon SEA venue! | Ethereum Foundation Blog Devconnect Scholars Program - Ethereum Stories from Istanbul and Beyond | Ethereum Foundation Blog Dencun Mainnet Announcement | Ethereum Foundation Blog ZK Grants Round | Ethereum Foundation Blog Eth2 at ETHWaterloo: Prizes for Eth2 education, tooling, and research | Ethereum Foundation Blog eth2 quick update no. 2 | Ethereum Foundation Blog Devcon4 Ticket Sales | Ethereum Foundation Blog Announcing Swarm Proof-of-Concept Release 3 | Ethereum Foundation Blog Devcon4 Announcement | Ethereum Foundation Blog Announcing May 2018 Cohort of EF Grants | Ethereum Foundation Blog Announcing World Trade Francs: The Official Ethereum Stablecoin | Ethereum Foundation Blog Announcing Beneficiaries of the Ethereum Foundation Grants | Ethereum Foundation Blog Geth 1.8 - Iceberg¹ | Ethereum Foundation Blog Farewell and Welcome | Ethereum Foundation Blog Security Alert - Solidity - Variables can be overwritten in storage | Ethereum Foundation Blog Uncle Rate and Transaction Fee Analysis | Ethereum Foundation Blog Announcement of imminent hard fork for EIP150 gas cost changes | Ethereum Foundation Blog Dev Update: Formal Methods | Ethereum Foundation Blog On Inflation, Transaction Fees and Cryptocurrency Monetary Policy | Ethereum Foundation Blog Onward from the Hard Fork | Ethereum Foundation Blog C++ DEV Update - July edition | Ethereum Foundation Blog The Devcon2 site is now live! | Ethereum Foundation Blog Security Alert - DoS Vulnerability in the Soft Fork | Ethereum Foundation Blog DAO Wars: Your voice on the soft-fork dilemma | Ethereum Foundation Blog Smart Contract Security | Ethereum Foundation Blog Security Alert – Geth suffers from a very low probable DoS attack vector - Update immediately | Ethereum Foundation Blog On Settlement Finality | Ethereum Foundation Blog Ethereum Foundation and Wanxiang Blockchain Labs announce a blockbuster event combining Devcon2 and the 2nd Global Blockchain Summit in Shanghai, September 19–24, 2016 | Ethereum Foundation Blog Ethereum Partners with R3CEV on Lizardcoin, Bringing Together the Best of Centralized Finance and Blockchain Technology | Ethereum Foundation Blog From Smart Contracts to Courts with not so Smart Judges | Ethereum Foundation Blog BTC Relay included in Ethereum Bounty Program | Ethereum Foundation Blog Ethereum DEV Update: C++ Roadmap | Ethereum Foundation Blog Cut and try: building a dream | Ethereum Foundation Blog Ambients Applied to Ethereum | Ethereum Foundation Blog Mihai’s Ethereum Project Update. The First Year. | Ethereum Foundation Blog Getting to the Frontier | Ethereum Foundation Blog The Ethereum Development Process | Ethereum Foundation Blog Gav’s Ethereum ÐΞV Update V | Ethereum Foundation Blog
Trillion Dollar Security Day at Devconnect | Ethereum Foundation Blog
2026-02-03 · via Ethereum Foundation Blog

During Devconnect Buenos Aires, the Ethereum Foundation and Secureum TrustX brought together Ethereum security practitioners for Trillion Dollar Security Day, a focused event exploring what it would take to securely support a trillion-dollar Ethereum economy.

The event brought together around eighty participants from across the Ethereum Security Ecosystem—spanning Infrastructure, Interoperability, Layer 1 & 2, Onchain, Offchain, Privacy, and Wallets—to assess the current security landscape, surface shared challenges, and identify concrete next steps across the stack.

The discussions and outputs from this event contribute to the Ethereum Foundation’s ongoing One Trillion Dollar Security (1TS) initiative.

Why a Trillion Dollar Security Day?

The Trillion Dollar Security day was designed to create focused, in-person discussions within individual layers, bringing together practitioners who work on similar parts of the stack to assess current security posture, share operational realities, and identify near-term priorities. The outcomes of these sessions were then synthesized to highlight patterns and dependencies across the broader ecosystem.

The goals of the Trillion Dollar Security gathering were to:

  • Evaluate Ethereum’s security posture across the full stack, identifying gaps, challenges, and emerging risks
  • Enable short-term execution by aligning ecosystem actors around actionable priorities
  • Strengthen long-term security through coordination, shared standards, and ecosystem empowerment

Participants split into breakout sessions by layer, discussing what is working today, what is not, and where effort is most urgently needed.

Snapshot: Cross-Layer Observations

Across the seven layers, participants surfaced several recurring themes:

  • Security is often treated as a milestone rather than a continuous process
  • Trust assumptions are insufficiently communicated to users
  • Critical security tooling and public goods lack sustainable funding
  • Coordination and incentives—not cryptography—remain dominant risk factors

The table below captures a condensed view of key issues and immediate next steps identified during the sessions.

LayerKey IssuesIdentified Immediate Next Steps
Layer 1 & 2Quantum risk, weak L1/L2 coordination, cloud dependence, compressed testingExpand EPF onboarding, create L2 liaisons, improve EIP versioning & ownership
WalletsBlind signing, paywalled security, low coordinationForm an Open Signing Alliance, neutral/on-chain EIP-7730 registry, wallet dashboards
Onchain“Audited ≠ secure”, weak IR, OpSec failuresFund OSS security tooling, create DeFi security visibility, promote SEAL
InteropUnsafe trust assumptions, UX favors speed over safetyInterop trust ratings, clearer disclosures, improve canonical bridge UX
InfrastructureFrontend hacks, RPC centralization, DNS SPOFsVerifiable frontends, infra transparency dashboards, light-client wallets
OffchainMisaligned incentives, Web2 attack-surface blind spotsSecurity frameworks, certifications, public-goods staffing models

Key Themes by Layer

Full presentations for each layer can be found here.

Layer 1 & 2: Coordination Remains a Bottleneck

Ethereum’s multiclient architecture, specification-driven development, and conservative Layer 1 change process continue to provide strong security foundations. However, participants highlighted risks stemming from limited coordination between L1 and L2s, compressed testing timelines, over-reliance on cloud infrastructure, and concerns around supply-chain attacks.

Key challenges include limited community and L2 participation in All Core Devs calls, constrained client team capacity to review evolving EIPs early, and ongoing L1–L2 bridging and RPC resilience concerns.

Proposed next steps focus on expanding the Ethereum Protocol Fellowship (EPF), creating clearer L2 liaison roles, improving EIP versioning and ownership expectations, and strengthening moderation and accessibility in coordination forums.

Wallets: User Security Remains Too Opaque

Progress on signing standards such as EIP-7730 and improvements to wallet discoverability were noted as positives. At the same time, most hardware wallets still rely on blind signing, and wallet participation in shared security discussions remains limited.

Participants pointed to the competitive wallet landscape as a structural barrier to collaboration, alongside an over-reliance on the Ethereum Foundation to drive coordination.

A key proposal was the creation of an Open Signing Alliance, anchored in Ethereum’s values of openness, neutrality, and the walkaway test. Additional priorities include hosting the EIP-7730 registry in a neutral—or on-chain—context and funding wallet-focused security dashboards to improve transparency and legitimacy.

Onchain Security: Tooling and Visibility Lag Behind Risk

Onchain security continues to benefit from a growing pool of experienced security researchers, improved tooling (e.g. Foundry), and increased awareness of incident response through efforts such as SEAL911. However, security is still often treated as a checkbox, and “audited” is frequently conflated with “secure.”

Participants emphasized that most recent losses stem from operational security failures, not novel smart-contract exploits. Other challenges include increasing protocol complexity, limited invariant monitoring, and a lack of economic audits.

Immediate next steps include sustained funding for open-source security tooling (fuzzers, static and dynamic analyzers), improved visibility into DeFi security posture (a “L2BEAT-like” approach), and broader adoption of SEAL frameworks and checklists for different contract classes.

Interoperability: Trust Assumptions Must Be Explicit

Ethereum users benefit from a wide range of interoperability options and increasingly fast, low-cost UX. At the same time, participants highlighted that many interop protocols rely on poorly communicated trust assumptions, leading users to mistake “fast and cheap” for safe.

Many non-canonical bridges fail the walkaway test, and risk often persists after bridging due to wrapped assets and downstream dependencies.

Proposed actions include developing interop trust ratings that clearly specify assumptions and verification models, setting strong expectations for explicit trust disclosures by cross-chain aggregators, and improving the speed and cost of canonical bridges to reduce reliance on unsafe alternatives. A follow-up interoperability workshop was also proposed.

Privacy: UX and Infrastructure Are the Primary Constraints

There was broad agreement that privacy is increasingly seen as a normal and necessary part of Ethereum’s future, with encouraging progress in zero-knowledge research and institutional adoption. However, user experience, cost, and infrastructure limitations remain major blockers.

Key challenges include RPC-based tracking, difficulties around private data storage and recovery, a lack of builders focused on private wallet UX, and the absence of hardware support for privacy-preserving keys.

Suggested next steps include greater use of light-client data over P2P RPC, investment in private wallet UX, research into ZK-capable hardware signers, and engagement with regulators to seek clearer guidance for permissionless privacy technologies.

Infrastructure & Offchain Security: The Invisible Attack Surface

Frontend compromises, DNS hijacks, RPC centralization, and software supply-chain attacks were repeatedly cited as underappreciated risks. Participants also noted a lack of sustainable economic alignment for non-profits providing critical security public goods.

Key challenges include the false separation between “Web2” and “Web3” security, limited accountability for off-chain failures, and the tendency to trade security for speed or convenience. The inability to easily run nodes over Tor was also highlighted.

Proposed next steps include building verifiable frontend prototypes, increasing transparency around RPC and infrastructure health, advancing security frameworks and certifications, and creating structured collaboration models where private companies contribute dedicated time and resources to security public goods.

Event Reflections

Participants rated the quality of discussion and relevance of topics as excellent, highlighting the value of in-person, cross-layer exchange. The primary areas for improvement were logistical, including group size and opportunities for structured networking.

There was strong demand for future work focused on applied security standards, shared tooling, and practical “how-to” guidance for implementation.

What Comes Next

The Trillion Dollar Security gathering highlighted the value of bringing security practitioners together in person to build shared understanding and momentum. Focused, face-to-face discussions helped accelerate alignment on standards, tooling, and practical solutions in ways that are difficult to achieve through asynchronous coordination alone.

The discussions also underscored the importance of maintaining a continuously updated, shared view of Ethereum’s security posture. As the ecosystem evolves, staying ahead of emerging risks requires regularly reassessing what is working, where assumptions no longer hold, and which areas need renewed attention to support a trillion-dollar economy.

The insights from Buenos Aires will continue to inform the Ethereum Foundation’s One Trillion Dollar Security efforts, alongside ongoing work across the ecosystem. Near-term focus remains on supporting execution, enabling adoption of open and neutral security standards, and strengthening the foundations needed to keep Ethereum secure at scale.

With thanks to the security layer champions @vdWijden, @barnabas, @zachobront, @ethzed, @mattaereal, @ncsgy and @ThewizardofPOS. And @0xRajeev and @fredrik0x for hosting.